Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.753exploits catalogados
37.445CVEs com exploração pública
24.695testados em laboratório
24.482 exploits
Exploit-DB
RazorCMS 1.2.1 Stable - Cross-Site Request Forgery (Delete Web Pages)
CVE-2012-1900webappsphp08 mar 2012
Cross-site request forgery (CSRF) vulnerability in admin/index.php in RazorCMS 1.2.1 and earlier allows remote attackers
23RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player - '.mp4 cprt' Remote Overflow (Metasploit)
CVE-2012-0754HIGHsob ataqueremotewindows08 mar 2012
Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.
100RISCO
abrir
Exploit-DB
promise webpam 2.2.0.13 - Multiple Vulnerabilities
CVE-2005-3747webappsphp07 mar 2012
Unspecified vulnerability in Jetty before 5.1.6 allows remote attackers to obtain source code of JSP pages, possibly inv
23RISCO
abrir
Exploit-DBVexDay Proof
HomeSeer HS2 and HomeSeer PRO - Multiple Vulnerabilities
CVE-2011-4835webappswindows07 mar 2012
Directory traversal vulnerability in the web interface in HomeSeer HS2 2.5.0.20 allows remote attackers to access arbitr
23RISCO
abrir
Exploit-DBVexDay Proof
OSClass 2.3.x - Directory Traversal / Arbitrary File Upload
CVE-2012-1617webappsphp07 mar 2012
Directory traversal vulnerability in combine.php in OSClass before 2.3.6 allows remote attackers to read and write arbit
23RISCO
abrir
Exploit-DBVexDay Proof
HomeSeer HS2 and HomeSeer PRO - Multiple Vulnerabilities
CVE-2011-4837webappswindows07 mar 2012
Cross-site request forgery (CSRF) vulnerability in /ctrl in the web interface in HomeSeer HS2 2.5.0.20 allows remote att
23RISCO
abrir
Exploit-DB
promise webpam 2.2.0.13 - Multiple Vulnerabilities
CVE-2006-2758webappsphp07 mar 2012
Directory traversal vulnerability in jetty 6.0.x (jetty6) beta16 allows remote attackers to read arbitrary files via a %
23RISCO
abrir
Exploit-DBVexDay Proof
Etano 1.20/1.22 - 'photo_search.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2012-1110webappsphp05 mar 2012
Multiple cross-site scripting (XSS) vulnerabilities in Etano 1.22 and earlier allow remote attackers to inject arbitrary
23RISCO
abrir
Exploit-DBVexDay Proof
Etano 1.20/1.22 - 'photo_view.php?return' Cross-Site Scripting
CVE-2012-1110webappsphp05 mar 2012
Multiple cross-site scripting (XSS) vulnerabilities in Etano 1.22 and earlier allow remote attackers to inject arbitrary
23RISCO
abrir
Exploit-DBVexDay Proof
Open Realty 2.5.x - 'select_users_template' Local File Inclusion
CVE-2012-1112webappsphp05 mar 2012
Directory traversal vulnerability in Open-Realty CMS 2.5.8 and earlier allows remote attackers to include and execute ar
23RISCO
abrir
Exploit-DBVexDay Proof
Etano 1.20/1.22 - 'search.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2012-1110webappsphp05 mar 2012
Multiple cross-site scripting (XSS) vulnerabilities in Etano 1.22 and earlier allow remote attackers to inject arbitrary
23RISCO
abrir
Exploit-DBVexDay Proof
Joomla! 2.5.1 - 'redirect.php' Blind SQL Injection
CVE-2012-1116webappsphp05 mar 2012
SQL injection vulnerability in Joomla! 1.7.x and 2.5.x before 2.5.2 allows remote attackers to execute arbitrary SQL com
23RISCO
abrir
Exploit-DB
DZCP (deV!L_z Clanportal) Witze Addon 0.9 - SQL Injection
CVE-2012-5000webappsphp04 mar 2012
SQL injection vulnerability in jokes/index.php in the Witze addon 0.9 for deV!L'z Clanportal allows remote attackers to
23RISCO
abrir
Exploit-DB
AneCMS 2e2c583 - Local File Inclusion
CVE-2012-4997webappsphp04 mar 2012
Directory traversal vulnerability in acp/index.php in AneCMS allows remote attackers to include and execute arbitrary lo
23RISCO
abrir
Exploit-DB
Rivettracker 1.03 - Multiple SQL Injections
CVE-2012-4993webappsmultiple03 mar 2012
torrent_functions.php in RivetTracker 1.03 and earlier does not properly restrict access, which allows remote attackers
23RISCO
abrir
Exploit-DB
Timesheet Next Gen 1.5.2 - Multiple SQL Injections
CVE-2012-2105webappsphp03 mar 2012
Multiple SQL injection vulnerabilities in login.php in Timesheet Next Gen 1.5.2 allow remote attackers to execute arbitr
23RISCO
abrir
Exploit-DB
FlashFXP 4.1.8.1701 - Remote Buffer Overflow
CVE-2012-4992remotewindows03 mar 2012
Multiple buffer overflows in FlashFXP.exe in FlashFXP 4.2 allow remote authenticated users to execute arbitrary code via
28RISCO
abrir
Exploit-DB
Rivettracker 1.03 - Multiple SQL Injections
CVE-2012-4996webappsmultiple03 mar 2012
Multiple SQL injection vulnerabilities in RivetTracker 1.03 and earlier allow remote attackers to execute arbitrary SQL
23RISCO
abrir
Exploit-DB
phxEventManager 2.0 Beta 5 - 'search.php' search_terms SQL Injection
CVE-2012-1124webappsphp02 mar 2012
SQL injection vulnerability in search.php in phxEventManager 2.0 beta 5 allows remote attackers to execute arbitrary SQL
23RISCO
abrir
Exploit-DBVexDay Proof
starCMS - 'q' URI Cross-Site Scripting
CVE-2012-4998webappsphp02 mar 2012
Cross-site scripting (XSS) vulnerability in index.php in starCMS allows remote attackers to inject arbitrary web script
23RISCO
abrir
Exploit-DBVexDay Proof
DJ Studio Pro 5.1 - '.pls' Local Stack Buffer Overflow (Metasploit)
CVE-2009-4656localwindows02 mar 2012
Stack-based buffer overflow in E-Soft DJ Studio Pro 4.2 including 4.2.2.7.5, and 5.x including 5.1.4.3.1, allows user-as
50RISCO
abrir
Exploit-DB
Drupal 7.12 - Multiple Vulnerabilities
CVE-2007-6752webappsphp02 mar 2012
Cross-site request forgery (CSRF) vulnerability in Drupal 7.12 and earlier allows remote attackers to hijack the authent
23RISCO
abrir
Exploit-DBVexDay Proof
VideoLAN VLC Media Player 0.9.5 - RealText Subtitle Overflow (Metasploit)
CVE-2008-5036localwindows02 mar 2012
Stack-based buffer overflow in VideoLAN VLC media player 0.9.x before 0.9.6 might allow user-assisted attackers to execu
50RISCO
abrir
Exploit-DB
Novell Groupwise - Address Book Remote Code Execution
CVE-2011-4189doswindows01 mar 2012
The client in Novell GroupWise 8.0x through 8.02HP3 allows remote attackers to execute arbitrary code or cause a denial
28RISCO
abrir
Exploit-DB
ImgPals Photo Host 1.0 - Admin Account Disactivation
CVE-2012-4926webappsphp29 fev 2012
approve.php in Img Pals Photo Host 1.0 does not authenticate requests, which allows remote attackers to change the activ
23RISCO
abrir
Exploit-DB
ImgPals Photo Host 1.0 - Admin Account Disactivation
CVE-2012-4925webappsphp29 fev 2012
Multiple SQL injection vulnerabilities in approve.php in Img Pals Photo Host 1.0 allow remote attackers to execute arbit
23RISCO
abrir
Exploit-DB
Yealink VOIP Phone - Persistent Cross-Site Scripting
CVE-2012-1417webappshardware29 fev 2012
Multiple cross-site scripting (XSS) vulnerabilities in Local Phone book and Blacklist form in Yealink VOIP Phones allow
23RISCO
abrir
Exploit-DBVexDay Proof
Netmechanica NetDecision HTTP Server - Denial of Service
CVE-2012-1465doswindows29 fev 2012
Stack-based buffer overflow in the HTTP Server in NetMechanica NetDecision before 4.6.1 allows remote attackers to cause
43RISCO
abrir
Exploit-DBVexDay Proof
ASUS Net4Switch - 'ipswcom.dll' ActiveX Stack Buffer Overflow (Metasploit)
CVE-2012-4924remotewindows29 fev 2012
Buffer overflow in the CxDbgPrint function in the ipswcom.dll ActiveX component 1.0.0.1 for ASUS Net4Switch 1.0.0020 all
50RISCO
abrir
Exploit-DBVexDay Proof
Netmechanica NetDecision Dashboard Server - Information Disclosure
CVE-2012-1464remotewindows29 fev 2012
Dashboard Server for NetMechanica NetDecision before 4.6.1 allows remote attackers to obtain the installation path via a
23RISCO
abrir
anteriorpágina 295 / 817próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.