Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.842exploits catalogados
37.493CVEs com exploração pública
24.695testados em laboratório
24.482 exploits
Exploit-DB
QQPLAYER Player 3.2 - PICT PnSize Buffer Overflow Windows (ASLR + DEP Bypass) (Metasploit)
CVE-2011-5006localwindows_x8621 nov 2011
Stack-based buffer overflow in QQPlayer 3.2.845 allows remote attackers to execute arbitrary code via a crafted PnSize v
23RISCO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Adminimize 1.7.21 - 'page' Cross-Site Scripting
CVE-2011-4926webappsphp21 nov 2011
Cross-site scripting (XSS) vulnerability in adminimize/adminimize_page.php in the Adminimize plugin before 1.7.22 for Wo
43RISCO
abrir
Exploit-DB
VMware - Update Manager Directory Traversal
CVE-2009-1523remotewindows21 nov 2011
Directory traversal vulnerability in the HTTP server in Mort Bay Jetty 5.1.14, 6.x before 6.1.17, and 7.x through 7.0.0.
28RISCO
abrir
Exploit-DB
VMware - Update Manager Directory Traversal
CVE-2011-4404remotewindows21 nov 2011
The default configuration of the HTTP server in Jetty in vSphere Update Manager in VMware vCenter Update Manager 4.0 bef
50RISCO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Alert Before Your Post - 'name' Cross-Site Scripting
CVE-2011-5107webappsphp21 nov 2011
Cross-site scripting (XSS) vulnerability in post_alert.php in Alert Before Your Post plugin, possibly 0.1.1 and earlier,
38RISCO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Lanoba Social 1.0 - 'action' Cross-Site Scripting
CVE-2011-5182webappsphp21 nov 2011
Cross-site scripting (XSS) vulnerability in lanoba-social-plugin/index.php in the Lanoba Social plugin 1.0 for WordPress
23RISCO
abrir
Exploit-DBVexDay Proof
Viscom Software Movie Player Pro SDK ActiveX 6.8 - Stack Buffer Overflow (Metasploit)
CVE-2010-0356remotewindows20 nov 2011
Stack-based buffer overflow in the MOVIEPLAYER.MoviePlayerCtrl.1 ActiveX control in MoviePlayer.ocx 6.8.0.0 in Viscom So
50RISCO
abrir
Exploit-DB
Blogs manager 1.101 - SQL Injection
CVE-2011-5110webappsphp19 nov 2011
Multiple SQL injection vulnerabilities in Blogs Manager 1.101 and earlier allow remote attackers to execute arbitrary SQ
23RISCO
abrir
Exploit-DB
Support Incident Tracker 3.65 - 'translate.php' Remote Code Execution
CVE-2011-4337webappsphp19 nov 2011
Static code injection vulnerability in translate.php in Support Incident Tracker (aka SiT!) 3.45 through 3.65 allows rem
23RISCO
abrir
Exploit-DBVexDay Proof
Wireshark - console.lua pre-loading (Metasploit)
CVE-2011-3360remotewindows19 nov 2011
Untrusted search path vulnerability in Wireshark 1.4.x before 1.4.9 and 1.6.x before 1.6.2 allows local users to gain pr
50RISCO
abrir
Exploit-DB
Valid tiny-erp 1.6 - SQL Injection
CVE-2011-4672webappsphp19 nov 2011
Multiple SQL injection vulnerabilities in Valid tiny-erp 1.6 and earlier allow remote attackers to execute arbitrary SQL
23RISCO
abrir
Exploit-DB
Support Incident Tracker 3.65 - 'translate.php' Remote Code Execution
CVE-2011-5075webappsphp19 nov 2011
translate.php in Support Incident Tracker (aka SiT!) 3.45 through 3.65 allows remote attackers to obtain sensitive infor
23RISCO
abrir
Exploit-DB
WordPress Plugin jetpack - 'sharedaddy.php' ID SQL Injection
CVE-2011-4673webappsphp19 nov 2011
SQL injection vulnerability in modules/sharedaddy.php in the Jetpack plugin for WordPress allows remote attackers to exe
23RISCO
abrir
Exploit-DB
Freelancer Calendar 1.01 - SQL Injection
CVE-2011-5109webappsphp19 nov 2011
Multiple SQL injection vulnerabilities in Freelancer calendar 1.01 and earlier allow remote attackers to inject arbitrar
23RISCO
abrir
Exploit-DBVexDay Proof
Jetty Web Server - Directory Traversal
CVE-2009-1523remotewindows18 nov 2011
Directory traversal vulnerability in the HTTP server in Mort Bay Jetty 5.1.14, 6.x before 6.1.17, and 7.x through 7.0.0.
28RISCO
abrir
Exploit-DBVexDay Proof
Viscom Image Viewer CP Pro 8.0/Gold 6.0 - ActiveX Control (Metasploit)
CVE-2010-5193remotewindows17 nov 2011
Stack-based buffer overflow in the TIFMergeMultiFiles function in the SCRIBBLE.ScribbleCtrl.1 ActiveX control (ImageView
50RISCO
abrir
Exploit-DBVexDay Proof
Viscom Image Viewer CP Pro 8.0/Gold 6.0 - ActiveX Control (Metasploit)
CVE-2010-5194remotewindows17 nov 2011
Stack-based buffer overflow in the Image2PDF function in the SCRIBBLE.ScribbleCtrl.1 ActiveX control (ImageViewer2.ocx)
23RISCO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Flexible Custom Post Type - 'id' Cross-Site Scripting
CVE-2011-5106webappsphp17 nov 2011
Cross-site scripting (XSS) vulnerability in edit-post.php in the Flexible Custom Post Type plugin before 0.1.7 for WordP
43RISCO
abrir
Exploit-DBVexDay Proof
ZOHO ManageEngine ADSelfService Plus 4.5 Build 4521 - Cross-Site Scripting
CVE-2011-5105webappsphp17 nov 2011
Multiple cross-site scripting (XSS) vulnerabilities in EmployeeSearch.cc in ZOHO ManageEngine ADSelfService Plus 4.5 Bui
23RISCO
abrir
Exploit-DB
SonicWALL Aventail SSL-VPN - SQL Injection
CVE-2011-5262webappshardware16 nov 2011
SQL injection vulnerability in prodpage.cfm in SonicWALL Aventail allows remote attackers to execute arbitrary SQL comma
23RISCO
abrir
Exploit-DBVexDay Proof
FreeWebShop 2.2.9 R2 - 'ajax_save_name.php' Remote Code Execution
CVE-2011-5147webappsphp16 nov 2011
Static code injection vulnerability in ajax_save_name.php in the Ajax File Manager module in the tinymce plugin in FreeW
23RISCO
abrir
Exploit-DB
Attachmate Reflection FTP Client - Heap Overflow
CVE-2011-5012doswindows16 nov 2011
Heap-based buffer overflow in the Reflection FTP Client (rftpcom.dll 7.2.0.106 and possibly other versions), as used in
23RISCO
abrir
Exploit-DB
Authenex A-Key/ASAS Web Management Control 3.1.0.2 - Blind SQL Injection
CVE-2011-4801webappsmultiple15 nov 2011
SQL injection vulnerability in akeyActivationLogin.do in Authenex Web Management Control in Authenex Strong Authenticati
23RISCO
abrir
Exploit-DBVexDay Proof
QuiXplorer 2.3 - Bugtraq Arbitrary File Upload
CVE-2011-5005webappsphp15 nov 2011
Unrestricted file upload vulnerability in QuiXplorer 2.3 and earlier allows remote attackers to execute arbitrary code b
23RISCO
abrir
Exploit-DBVexDay Proof
Mini-stream RM-MP3 Converter 3.1.2.1 - '.pls' Local Stack Buffer Overflow (Metasploit)
CVE-2010-5081localwindows14 nov 2011
Stack-based buffer overflow in Mini-Stream RM-MP3 Converter 3.1.2.1 allows remote attackers to execute arbitrary code vi
50RISCO
abrir
Exploit-DBVexDay Proof
optima apiftp server 1.5.2.13 - Multiple Vulnerabilities
CVE-2012-5049doswindows14 nov 2011
APIFTP Server in Optimalog Optima PLC 1.5.2 and earlier allows remote attackers to cause a denial of service (infinite l
23RISCO
abrir
Exploit-DBVexDay Proof
optima apiftp server 1.5.2.13 - Multiple Vulnerabilities
CVE-2012-5048doswindows14 nov 2011
APIFTP Server in Optimalog Optima PLC 1.5.2 and earlier allows remote attackers to cause a denial of service (NULL point
23RISCO
abrir
Exploit-DBVexDay Proof
WordPress Plugin AdRotate 3.6.6 - SQL Injection
CVE-2011-4671webappsphp14 nov 2011
SQL injection vulnerability in adrotate/adrotate-out.php in the AdRotate plugin 3.6.6, and other versions before 3.6.8,
23RISCO
abrir
Exploit-DB
Pixie CMS 1.01 < 1.04 - Blind SQL Injections
CVE-2011-4710webappsphp14 nov 2011
Multiple SQL injection vulnerabilities in Pixie CMS 1.01 through 1.04 allow remote attackers to execute arbitrary SQL co
23RISCO
abrir
Exploit-DB
Mambo 4.x - 'Zorder' SQL Injection
CVE-2011-2917webappsphp13 nov 2011
SQL injection vulnerability in administrator/index2.php in Mambo CMS 4.6.5 and earlier allows remote attackers to execut
23RISCO
abrir
anteriorpágina 312 / 817próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.