Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.842exploits catalogados
37.493CVEs com exploração pública
24.695testados em laboratório
24.482 exploits
Exploit-DBVexDay Proof
Kolibri HTTP Server 2.0 - HEAD Buffer Overflow (Metasploit)
CVE-2002-2268remotewindows03 ago 2011
Buffer overflow in Webster HTTP Server allows remote attackers to execute arbitrary code via a long URL.
50RISCO
abrir
Exploit-DBVexDay Proof
Zinf Audio Player 2.2.1 - '.pls' Local Buffer Overflow (DEP Bypass)
CVE-2004-0964localwindows03 ago 2011
Buffer overflow in Zinf 2.2.1 on Windows, and other older versions for Linux, allows remote attackers or local users to
50RISCO
abrir
Exploit-DBVexDay Proof
WordPress Plugin TimThumb 1.32 - Remote Code Execution
CVE-2011-4106webappsphp03 ago 2011
TimThumb (timthumb.php) before 2.0 does not validate the entire source with the domain white list, which allows remote a
28RISCO
abrir
Exploit-DBVexDay Proof
Open Handset Alliance Android 2.3.4/3.1 - Browser Sandbox Security Bypass
CVE-2011-2357remotemultiple02 ago 2011
Cross-application scripting vulnerability in the Browser URL loading functionality in Android 2.3.4 and 3.1 allows local
23RISCO
abrir
Exploit-DB
ZoneMinder 1.24.3 - Remote File Inclusion
CVE-2013-0332webappsphp01 ago 2011
Multiple directory traversal vulnerabilities in ZoneMinder 1.24.x before 1.24.4 allow remote attackers to read arbitrary
28RISCO
abrir
Exploit-DBVexDay Proof
Chyrp 2.x - 'action' Traversal Local File Inclusion
CVE-2011-2744webappsphp29 jul 2011
Directory traversal vulnerability in Chyrp 2.1 and earlier allows remote attackers to include and execute arbitrary loca
38RISCO
abrir
Exploit-DBVexDay Proof
Chyrp 2.x - '/includes/lib/gz.php?File' Traversal Arbitrary File Access
CVE-2011-2780webappsphp29 jul 2011
Directory traversal vulnerability in includes/lib/gz.php in Chyrp 2.0 and earlier allows remote attackers to read arbitr
43RISCO
abrir
Exploit-DBVexDay Proof
Chyrp 2.x swfupload Extension - 'upload_handler.php' Arbitrary File Upload / Arbitrary PHP Code Execution
CVE-2011-2745webappsphp29 jul 2011
upload_handler.php in the swfupload extension in Chyrp 2.0 and earlier relies on client-side JavaScript code to restrict
23RISCO
abrir
Exploit-DBVexDay Proof
HP Network Automation 9.10 - SQL Injection
CVE-2011-2403webappsphp28 jul 2011
SQL injection vulnerability in HP Network Automation 7.2x, 7.5x, 7.6x, 9.0, and 9.10 allows remote authenticated users t
23RISCO
abrir
Exploit-DBVexDay Proof
SWAT Samba Web Administration Tool - Cross-Site Request Forgery
CVE-2011-2522webappscgi27 jul 2011
Multiple cross-site request forgery (CSRF) vulnerabilities in the Samba Web Administration Tool (SWAT) in Samba 3.x befo
28RISCO
abrir
Exploit-DB
Apple Safari 5.0.5 - SVG Remote Code Execution (DEP Bypass)
CVE-2011-0222remotewindows26 jul 2011
WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of ser
28RISCO
abrir
Exploit-DBVexDay Proof
Support Incident Tracker (SiT!) 3.63 p1 - 'report_marketing.php?exc[]' SQL Injection
CVE-2011-5071webappsphp26 jul 2011
Multiple SQL injection vulnerabilities in Support Incident Tracker (aka SiT!) before 3.64 allow remote attackers to exec
23RISCO
abrir
Exploit-DBVexDay Proof
Support Incident Tracker (SiT!) 3.63 p1 - 'search.php?search_string' SQL Injection
CVE-2011-5071webappsphp26 jul 2011
Multiple SQL injection vulnerabilities in Support Incident Tracker (aka SiT!) before 3.64 allow remote attackers to exec
23RISCO
abrir
Exploit-DBVexDay Proof
Support Incident Tracker (SiT!) 3.63 p1 - 'billable_incidents.php?sites[]' SQL Injection
CVE-2011-5071webappsphp26 jul 2011
Multiple SQL injection vulnerabilities in Support Incident Tracker (aka SiT!) before 3.64 allow remote attackers to exec
23RISCO
abrir
Exploit-DBVexDay Proof
Support Incident Tracker (SiT!) 3.63 p1 - 'tasks.php?selected[]' SQL Injection
CVE-2011-5071webappsphp26 jul 2011
Multiple SQL injection vulnerabilities in Support Incident Tracker (aka SiT!) before 3.64 allow remote attackers to exec
23RISCO
abrir
Exploit-DBVexDay Proof
CA Arcserve D2D - GWT RPC Credential Information Disclosure (Metasploit)
CVE-2011-3011localwindows25 jul 2011
BaseServiceImpl.class in CA ARCserve D2D r15 does not properly handle sessions, which allows remote attackers to obtain
60RISCO
abrir
Exploit-DB
Apple Safari 5.0.6/5.1 - SVG DOM Processing (PoC)
CVE-2011-0222dososx25 jul 2011
WebKit, as used in Apple Safari before 5.0.6, allows remote attackers to execute arbitrary code or cause a denial of ser
28RISCO
abrir
Exploit-DBVexDay Proof
Tiki Wiki CMS Groupware 7.2 - 'snarf_ajax.php' Cross-Site Scripting
CVE-2011-4336webappsphp20 jul 2011
Tiki Wiki CMS Groupware 7.0 has XSS via the GET "ajax" parameter to snarf_ajax.php.
38RISCO
abrir
Exploit-DB
Oracle Sun GlassFish Enterprise Server - Persistent Cross-Site Scripting
CVE-2011-2260webappsjsp20 jul 2011
Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Sun Products Suite 2.1.1 allows remote atta
23RISCO
abrir
Exploit-DBVexDay Proof
GDI+ - 'gdiplus.dll' CreateDashedPath Integer Overflow
CVE-2011-0041doswindows18 jul 2011
Integer overflow in gdiplus.dll in GDI+ in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1
28RISCO
abrir
Exploit-DBVexDay Proof
HP OpenView Network Node Manager (OV NNM) - 'Toolbar.exe' CGI Cookie Handling Buffer Overflow (Metasploit)
CVE-2009-0920remotewindows16 jul 2011
Stack-based buffer overflow in OvCgi/Toolbar.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allow
60RISCO
abrir
Exploit-DBVexDay Proof
Java RMI - Server Insecure Default Configuration Java Code Execution (Metasploit)
CVE-2011-3556remotemultiple15 jul 2011
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and ear
60RISCO
abrir
Exploit-DBVexDay Proof
Chyrp 2.x - '/admin/help.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2011-2743webappsphp13 jul 2011
Multiple cross-site scripting (XSS) vulnerabilities in Chyrp 2.1 and earlier allow remote attackers to inject arbitrary
23RISCO
abrir
Exploit-DBVexDay Proof
Chyrp 2.x - '/includes/JavaScript.php?action' Cross-Site Scripting
CVE-2011-2743webappsphp13 jul 2011
Multiple cross-site scripting (XSS) vulnerabilities in Chyrp 2.1 and earlier allow remote attackers to inject arbitrary
23RISCO
abrir
Exploit-DBVexDay Proof
Flowplayer 3.2.7 - 'linkUrl' Cross-Site Scripting
CVE-2011-3642webappsmultiple12 jul 2011
Cross-site scripting (XSS) vulnerability in Flowplayer Flash 3.2.7 through 3.2.16, as used in the News system (news) ext
23RISCO
abrir
Exploit-DBVexDay Proof
Mozilla Firefox - 'nsTreeRange' Dangling Pointer (Metasploit) (1)
CVE-2011-0073remotewindows10 jul 2011
Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, does not properly use nsTreeRange da
60RISCO
abrir
Exploit-DBVexDay Proof
phpMyAdmin 3.x - Swekey Remote Code Injection
CVE-2011-2506webappsphp09 jul 2011
setup/lib/ConfigGenerator.class.php in phpMyAdmin 3.x before 3.3.10.2 and 3.4.x before 3.4.3.1 does not properly restric
23RISCO
abrir
Exploit-DBVexDay Proof
Blue Coat Authentication and Authorization Agent (BCAAA) 5 - Remote Buffer Overflow (Metasploit)
CVE-2011-5124remotewindows09 jul 2011
Stack-based buffer overflow in the BCAAA component before build 60258, as used by Blue Coat ProxySG 4.2.3 through 6.1 an
50RISCO
abrir
Exploit-DBVexDay Proof
phpMyAdmin 3.x - Swekey Remote Code Injection
CVE-2011-2505webappsphp09 jul 2011
libraries/auth/swekey/swekey.auth.lib.php in the Swekey authentication feature in phpMyAdmin 3.x before 3.3.10.2 and 3.4
28RISCO
abrir
Exploit-DBVexDay Proof
Symantec Backup Exec 12.5 - Man In The Middle
CVE-2011-0546remotewindows09 jul 2011
Symantec Backup Exec 11.0, 12.0, 12.5, 13.0, and 13.0 R2 does not validate identity information sent between the media s
23RISCO
abrir
anteriorpágina 321 / 817próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.