Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.646exploits catalogados
37.382CVEs com exploração pública
24.695testados em laboratório
24.482 exploits
Exploit-DBVexDay Proof
phlyLabs phlyMail Lite 4.03.04 - 'go' Open Redirect
CVE-2013-4266webappsphp13 jan 2013
20RISCO
abrir
Exploit-DBVexDay Proof
Java Applet JMX - Remote Code Execution (Metasploit) (1)
CVE-2013-0422CRITICALsob ataqueransomwareremotejava11 jan 2013
Multiple vulnerabilities in Oracle Java 7 before Update 11 allow remote attackers to execute arbitrary code by (1) using
100RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - Option Element Use-After-Free (MS11-081) (Metasploit)
CVE-2011-1996remotewindows10 jan 2013
Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to exe
50RISCO
abrir
Exploit-DBVexDay Proof
Ruby on Rails - XML Processor YAML Deserialization Code Execution (Metasploit)
CVE-2013-0156remotemultiple10 jan 2013
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, an
60RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 8 - Fixed Col Span ID (Full ASLR + DEP Bypass) (MS12-037)
CVE-2012-1876remotewindows10 jan 2013
Microsoft Internet Explorer 6 through 9, and 10 Consumer Preview, does not properly handle objects in memory, which allo
50RISCO
abrir
Exploit-DB
Nero MediaHome 4.5.8.0 - Denial of Service
CVE-2012-5877doswindows10 jan 2013
Nero MediaHome 4.5.8.0 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and cr
23RISCO
abrir
Exploit-DB
Nero MediaHome 4.5.8.0 - Denial of Service
CVE-2012-5876doswindows10 jan 2013
Multiple off-by-one errors in NMMediaServerService.dll in Nero MediaHome 4.5.8.0 and earlier allow remote attackers to c
23RISCO
abrir
Exploit-DBVexDay Proof
Quick.CMS / Quick.Cart - Cross-Site Scripting
CVE-2012-6430webappsphp09 jan 2013
Cross-site scripting (XSS) vulnerability in Open Solution Quick.Cms 5.0 and Quick.Cart 6.0, possibly as downloaded befor
23RISCO
abrir
Exploit-DBVexDay Proof
Dell OpenManage Server Administrator - Cross-Site Scripting
CVE-2012-6272remotemultiple09 jan 2013
Multiple cross-site scripting (XSS) vulnerabilities in Dell OpenManage Server Administrator 6.5.0.1, 7.0.0.1, and 7.1.0.
23RISCO
abrir
Exploit-DBVexDay Proof
Samsung Kies - Remote Buffer Overflow
CVE-2012-6429remotewindows09 jan 2013
Buffer overflow in the PrepareSync method in the SyncService.dll ActiveX control in Samsung Kies before 2.5.1.12123_2_7
28RISCO
abrir
Exploit-DBVexDay Proof
Prizm Content Connect - Arbitrary File Upload
CVE-2012-5190webappsphp09 jan 2013
Prizm Content Connect 5.1 has an Arbitrary File Upload Vulnerability
23RISCO
abrir
Exploit-DBVexDay Proof
Mozilla Firefox < 17.0.1 - Flash Privileged Code Injection (Metasploit)
CVE-2013-0757localmultiple08 jan 2013
The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbi
50RISCO
abrir
Exploit-DB
Advantech Webaccess HMI/SCADA Software - Persistence Cross-Site Scripting
CVE-2013-2299webappsasp08 jan 2013
Cross-site scripting (XSS) vulnerability in Advantech WebAccess (formerly BroadWin WebAccess) before 7.1 2013.05.30 allo
23RISCO
abrir
Exploit-DBVexDay Proof
Mozilla Firefox < 17.0.1 - Flash Privileged Code Injection (Metasploit)
CVE-2013-0758localmultiple08 jan 2013
Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderb
60RISCO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Google Document Embedder - Arbitrary File Disclosure (Metasploit)
CVE-2012-4915webappsphp08 jan 2013
Directory traversal vulnerability in the Google Doc Embedder plugin before 2.5.4 for WordPress allows remote attackers t
50RISCO
abrir
Exploit-DBVexDay Proof
IBM Cognos - 'tm1admsd.exe' Remote Overflow (Metasploit)
CVE-2012-0202remotewindows08 jan 2013
Multiple stack-based buffer overflows in tm1admsd.exe in the Admin Server in IBM Cognos TM1 9.4.x and 9.5.x before 9.5.2
50RISCO
abrir
Exploit-DB
Ettercap 0.7.5.1 - Stack Overflow
CVE-2012-0722dosunix07 jan 2013
20RISCO
abrir
Exploit-DBVexDay Proof
Movable Type 4.2x/4.3x - Web Upgrade Remote Code Execution (Metasploit)
CVE-2012-6315remotemultiple07 jan 2013
35RISCO
abrir
Exploit-DB
Ettercap 0.7.5.1 - Stack Overflow
CVE-2013-0722dosunix07 jan 2013
Stack-based buffer overflow in the scan_load_hosts function in ec_scan.c in Ettercap 0.7.5.1 and earlier might allow loc
23RISCO
abrir
Exploit-DBVexDay Proof
Movable Type 4.2x/4.3x - Web Upgrade Remote Code Execution (Metasploit)
CVE-2013-0209remotemultiple07 jan 2013
lib/MT/Upgrade.pm in mt-upgrade.cgi in Movable Type 4.2x and 4.3x through 4.38 does not require authentication for reque
50RISCO
abrir
Exploit-DBVexDay Proof
Havalite CMS - 'comment' HTML Injection
CVE-2013-0161webappsphp06 jan 2013
Havalite CMS 1.1.7 has a stored XSS vulnerability
23RISCO
abrir
Exploit-DBVexDay Proof
Nexpose Security Console - Cross-Site Request Forgery
CVE-2012-6493webappsmultiple06 jan 2013
Cross-site request forgery (CSRF) vulnerability in Rapid7 Nexpose Security Console before 5.5.4 allows remote attackers
23RISCO
abrir
Exploit-DBVexDay Proof
Enterasys NetSight - 'nssyslogd.exe' Remote Buffer Overflow (Metasploit)
CVE-2011-5227remotewindows04 jan 2013
Stack-based buffer overflow in the Syslog service (nssyslogd.exe) in Enterasys Network Management Suite (NMS) before 4.1
60RISCO
abrir
Exploit-DBVexDay Proof
Belkin Wireless Router - Default WPS PIN Security
CVE-2012-4366remotehardware03 jan 2013
Belkin wireless routers Surf N150 Model F7D1301v1, N900 Model F9K1104v1, N450 Model F9K1105V2, and N300 Model F7D2301v1
23RISCO
abrir
Exploit-DBVexDay Proof
e107 1.0.1 - Arbitrary JavaScript Execution (via Cross-Site Request Forgery)
CVE-2012-6433webappsphp02 jan 2013
Cross-site request forgery (CSRF) vulnerability in e107_admin/newspost.php in e107 1.0.1 allows remote attackers to hija
23RISCO
abrir
Exploit-DBVexDay Proof
e107 1.0.2 - SQL Injection (via Cross-Site Request Forgery)
CVE-2012-6434webappsphp02 jan 2013
Multiple cross-site request forgery (CSRF) vulnerabilities in e107_admin/download.php in e107 1.0.2 allow remote attacke
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - CButton Object Use-After-Free (Metasploit)
CVE-2012-4792HIGHsob ataqueremotewindows02 jan 2013
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary cod
100RISCO
abrir
Exploit-DBVexDay Proof
BlazeDVD 6.1 - '.PLF' File (ASLR + DEP Bypass) (Metasploit)
CVE-2006-6199localwindows31 dez 2012
Stack-based buffer overflow in BlazeVideo BlazeDVD Standard and Professional 5.0, and possibly earlier, allows remote at
50RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - CDwnBindInfo Object Use-After-Free (Metasploit)
CVE-2012-4792HIGHsob ataqueremotewindows31 dez 2012
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary cod
100RISCO
abrir
Exploit-DBVexDay Proof
IBM Lotus QuickR qp2 - ActiveX Buffer Overflow (Metasploit)
CVE-2012-2176remotewindows31 dez 2012
Multiple stack-based buffer overflows in a certain ActiveX control in qp2.cab in IBM Lotus Quickr 8.2 before 8.2.0.27-00
50RISCO
abrir
anteriorpágina 268 / 817próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.