Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.842exploits catalogados
37.493CVEs com exploração pública
24.695testados em laboratório
24.482 exploits
Exploit-DB
progea movicon / powerhmi 11.2.1085 - Multiple Vulnerabilities
CVE-2011-3499doswindows14 set 2011
Progea Movicon / PowerHMI 11.2.1085 and earlier allows remote attackers to cause a denial of service (memory corruption
28RISCO
abrir
Exploit-DB
Cogent DataHub 7.1.1.63 - Integer Overflow
CVE-2011-3501doswindows14 set 2011
Integer overflow in Cogent DataHub 7.1.1.63 and earlier allows remote attackers to cause a denial of service (crash) via
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft WINS - ECommEndDlg Input Validation Error (MS11-035/MS11-070)
CVE-2011-1984doswindows13 set 2011
WINS in Microsoft Windows Server 2003 SP2 and Server 2008 SP2, R2, and R2 SP1 allows local users to gain privileges by s
23RISCO
abrir
Exploit-DB
Carel PlantVisor 2.4.4 - Directory Traversal
CVE-2011-3487webappswindows13 set 2011
Directory traversal vulnerability in CarelDataServer.exe in Carel PlantVisor 2.4.4 and earlier allows remote attackers t
23RISCO
abrir
Exploit-DB
Microsoft WINS Service 5.2.3790.4520 - Memory Corruption (MS11-035)
CVE-2011-1248doswindows13 set 2011
WINS in Microsoft Windows Server 2003 SP2 and Server 2008 Gold, SP2, R2, and R2 SP1 does not properly handle socket send
35RISCO
abrir
Exploit-DBVexDay Proof
ScadaTEC ScadaPhone 5.3.11.1230 - Local Stack Buffer Overflow (Metasploit)
CVE-2011-4535localwindows13 set 2011
Buffer overflow in TurboPower Abbrevia before 4.0, as used in ScadaTEC ScadaPhone 5.3.11.1230 and earlier, ScadaTEC Modb
43RISCO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Forum Server 1.7 - SQL Injection
CVE-2012-6625webappsphp13 set 2011
SQL injection vulnerability in fs-admin/fs-admin.php in the ForumPress WP Forum Server plugin before 1.7.4 for WordPress
23RISCO
abrir
Exploit-DBVexDay Proof
KnFTP Server - Remote Buffer Overflow
CVE-2011-5166remotewindows12 set 2011
Multiple stack-based buffer overflows in KnFTP 1.0.0 allow remote attackers to execute arbitrary code via a long string
23RISCO
abrir
Exploit-DBVexDay Proof
ScadaTEC ModbusTagServer & ScadaPhone - '.zip' Local Buffer Overflow
CVE-2011-4535localwindows12 set 2011
Buffer overflow in TurboPower Abbrevia before 4.0, as used in ScadaTEC ScadaPhone 5.3.11.1230 and earlier, ScadaTEC Modb
43RISCO
abrir
Exploit-DBVexDay Proof
Procyon Core Server HMI 1.13 - 'Coreservice.exe' Remote Stack Buffer Overflow (Metasploit)
CVE-2011-3322remotewindows12 set 2011
Core Server HMI Service (Coreservice.exe) in Scadatec Limited Procyon SCADA 1.06, and other versions before 1.14, allows
50RISCO
abrir
Exploit-DB
WordPress Plugin Event Registration 5.44 - SQL Injection
CVE-2010-4839webappsphp09 set 2011
SQL injection vulnerability in the Event Registration plugin 5.32 and earlier for WordPress allows remote attackers to e
23RISCO
abrir
Exploit-DBVexDay Proof
MYRE Real Estate Software - Multiple Vulnerabilities
CVE-2011-3393webappsphp09 set 2011
Multiple cross-site scripting (XSS) vulnerabilities in findagent.php in MYRE Real Estate Software allow remote attackers
23RISCO
abrir
Exploit-DBVexDay Proof
MYRE Real Estate Software - Multiple Vulnerabilities
CVE-2011-3394webappsphp09 set 2011
SQL injection vulnerability in findagent.php in MYRE Real Estate Software allows remote attackers to execute arbitrary S
23RISCO
abrir
Exploit-DBVexDay Proof
Spring Security - HTTP Header Injection
CVE-2011-2732remotemultiple09 set 2011
CRLF injection vulnerability in the logout functionality in VMware SpringSource Spring Security before 2.0.7 and 3.0.x b
23RISCO
abrir
Exploit-DBVexDay Proof
BisonWare BisonFTP Server 3.5 - Remote Buffer Overflow (Metasploit)
CVE-1999-1510remotewindows09 set 2011
Buffer overflows in Bisonware FTP server prior to 4.1 allow remote attackers to cause a denial of service, and possibly
50RISCO
abrir
Exploit-DB
DVD X Player 5.5 Pro - Local Overflow (SEH + ASLR + DEP Bypass)
CVE-2007-3068localwindows08 set 2011
Stack-based buffer overflow in DVD X Player 4.1 Professional allows remote attackers to execute arbitrary code via a PLF
50RISCO
abrir
Exploit-DBVexDay Proof
Wireshark 1.6.1 - Malformed Packet Trace File Remote Denial of Service
CVE-2011-3483doswindows08 set 2011
Wireshark 1.6.x before 1.6.2 allows remote attackers to cause a denial of service (application crash) via a malformed ca
23RISCO
abrir
Exploit-DBVexDay Proof
DVD X Player 5.5 Pro - Overwrite (SEH)
CVE-2007-3068localwindows06 set 2011
Stack-based buffer overflow in DVD X Player 4.1 Professional allows remote attackers to execute arbitrary code via a PLF
50RISCO
abrir
Exploit-DBVexDay Proof
Linux Kernel < 2.6.36.2 (Ubuntu 10.04) - 'Half-Nelson.c' Econet Privilege Escalation
CVE-2010-4073locallinux05 set 2011
The ipc subsystem in the Linux kernel before 2.6.37-rc1 does not initialize certain structures, which allows local users
23RISCO
abrir
Exploit-DBVexDay Proof
Zikula Application Framework 1.2.7/1.3 - 'themename' Cross-Site Scripting
CVE-2011-3979webappsphp05 set 2011
Cross-site scripting (XSS) vulnerability in ztemp/view_compiled/Theme/theme_admin_setasdefault.php in the theme module i
23RISCO
abrir
Exploit-DBVexDay Proof
Linux Kernel < 2.6.36.2 (Ubuntu 10.04) - 'Half-Nelson.c' Econet Privilege Escalation
CVE-2010-3850locallinux05 set 2011
The ec_dev_ioctl function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2 does not require the CAP_NET_ADM
23RISCO
abrir
Exploit-DBVexDay Proof
Linux Kernel < 2.6.36.2 (Ubuntu 10.04) - 'Half-Nelson.c' Econet Privilege Escalation
CVE-2010-3848locallinux05 set 2011
Stack-based buffer overflow in the econet_sendmsg function in net/econet/af_econet.c in the Linux kernel before 2.6.36.2
23RISCO
abrir
Exploit-DBVexDay Proof
Apple QuickTime - PICT PnSize Buffer Overflow (Metasploit)
CVE-2011-0257localwindows03 set 2011
Integer signedness error in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a deni
50RISCO
abrir
Exploit-DB
BroadWin Webaccess Client - Multiple Vulnerabilities
CVE-2012-0241doswindows02 set 2011
Advantech/BroadWin WebAccess before 7.0 allows remote attackers to cause a denial of service (memory corruption) via a m
23RISCO
abrir
Exploit-DB
BroadWin Webaccess Client - Multiple Vulnerabilities
CVE-2012-0242doswindows02 set 2011
Format string vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code
23RISCO
abrir
Exploit-DBVexDay Proof
DVD X Player 5.5 - '.plf' Playlist Buffer Overflow (Metasploit)
CVE-2007-3068localwindows01 set 2011
Stack-based buffer overflow in DVD X Player 4.1 Professional allows remote attackers to execute arbitrary code via a PLF
50RISCO
abrir
Exploit-DB
Linux Kernel 3.0.0 - 'perf_count_sw_cpu_clock' event Denial of Service
CVE-2011-2918doslinux01 set 2011
The Performance Events subsystem in the Linux kernel before 3.1 does not properly handle event overflows associated with
23RISCO
abrir
Exploit-DBVexDay Proof
Citrix Gateway - ActiveX Control Stack Buffer Overflow (Metasploit)
CVE-2011-2882remotewindows31 ago 2011
Stack-based buffer overflow in the NSEPA.NsepaCtrl.1 ActiveX control in nsepa.ocx in Citrix Access Gateway Enterprise Ed
50RISCO
abrir
Exploit-DBVexDay Proof
IBM Open Admin Tool 2.71 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2011-3390webappsphp30 ago 2011
Multiple cross-site scripting (XSS) vulnerabilities in index.php in IBM OpenAdmin Tool (OAT) before 2.72 for Informix al
23RISCO
abrir
Exploit-DBVexDay Proof
MapServer 6.0 - '.Map' File Double-Free Remote Denial of Service
CVE-2011-2975doswindows30 ago 2011
Double free vulnerability in the msAddImageSymbol function in mapsymbol.c in MapServer before 6.0.1 might allow remote a
23RISCO
abrir
anteriorpágina 319 / 817próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.