Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.107exploits catalogados
34.679CVEs com exploração pública
24.695testados em laboratório
24.443 exploits
Exploit-DB
WikiWig 5.01 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2011-5267webappsphp16 mar 2011
Multiple cross-site scripting (XSS) vulnerabilities in spell-check-savedicts.php in the SpellChecker module in Xinha, as
23RISCO
abrir
Exploit-DBVexDay Proof
Sun Java Applet2ClassLoader - Remote Code Execution (Metasploit)
CVE-2010-4452remotemultiple16 mar 2011
Unspecified vulnerability in the Deployment component in Java Runtime Environment (JRE) in Oracle Java SE and Java for B
60RISCO
abrir
Exploit-DBVexDay Proof
SugarCRM 6.1.1 - Information Disclosure
CVE-2011-0745webappsphp15 mar 2011
SugarCRM before 6.1.3 does not properly handle reloads and direct requests for a warning page produced by a certain dupl
23RISCO
abrir
Exploit-DBVexDay Proof
HP OpenView Performance Insight Server - Backdoor Account Code Execution (Metasploit)
CVE-2011-0276remotewindows15 mar 2011
HP OpenView Performance Insight Server 5.2, 5.3, 5.31, 5.4, and 5.41 contains a "hidden account" in the com.trinagy.secu
60RISCO
abrir
Exploit-DBVexDay Proof
Google Android 2.0/2.1/2.1.1 - WebKit Use-After-Free
CVE-2010-1119remoteandroid14 mar 2011
Use-after-free vulnerability in WebKit in Apple Safari before 5.0 on Mac OS X 10.5 through 10.6 and Windows, Safari befo
28RISCO
abrir
Exploit-DB
Linux Kenel 2.6.37-rc1 - serial_core TIOCGICOUNT Leak
CVE-2010-4077doslinux14 mar 2011
The ntty_ioctl_tiocgicount function in drivers/char/nozomi.c in the Linux kernel 2.6.36.1 and earlier does not properly
23RISCO
abrir
Exploit-DBVexDay Proof
PHP 5.3.6 - 'shmop_read()' Integer Overflow Denial of Service
CVE-2011-1092doslinux12 mar 2011
Integer overflow in ext/shmop/shmop.c in PHP before 5.3.6 allows context-dependent attackers to cause a denial of servic
28RISCO
abrir
Exploit-DB
Oracle WebLogic - POST Session Fixation
CVE-2010-4437webappsmultiple11 mar 2011
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 9.0, 9.1, 9.2.4, 10.0.2, 1
23RISCO
abrir
Exploit-DB
FreeBSD 6.4 - Netgraph Privilege Escalation
CVE-2008-5736localbsd10 mar 2011
Multiple unspecified vulnerabilities in FreeBSD 6 before 6.4-STABLE, 6.3 before 6.3-RELEASE-p7, 6.4 before 6.4-RELEASE-p
23RISCO
abrir
Exploit-DBVexDay Proof
SmarterMail 7.3/7.4 - Multiple Vulnerabilities
CVE-2010-3486webappsasp10 mar 2011
Directory traversal vulnerability in FileStorageUpload.ashx in SmarterMail 7.1.3876 allows remote attackers to read arbi
23RISCO
abrir
Exploit-DBVexDay Proof
Xinha 0.96 - 'spell-check-savedicts.php' Multiple HTML Injection Vulnerabilities
CVE-2011-5267webappsphp10 mar 2011
Multiple cross-site scripting (XSS) vulnerabilities in spell-check-savedicts.php in the SpellChecker module in Xinha, as
23RISCO
abrir
Exploit-DBVexDay Proof
PHP 5.3.x 'Zip' Extension - 'stream_get_contents()' Denial of Service
CVE-2011-1470dosphp10 mar 2011
The Zip extension in PHP before 5.3.6 allows context-dependent attackers to cause a denial of service (application crash
23RISCO
abrir
Exploit-DBVexDay Proof
PHP < 5.3.6 'Zip' Extension - 'zip_fread()' Denial of Service
CVE-2011-1471dosphp10 mar 2011
Integer signedness error in zip_stream.c in the Zip extension in PHP before 5.3.6 allows context-dependent attackers to
28RISCO
abrir
Exploit-DB
Linux Kernel < 2.6.37-rc2 - 'TCP_MAXSEG' Kernel Panic (Denial of Service) (2)
CVE-2010-4165doslinux10 mar 2011
The do_tcp_setsockopt function in net/ipv4/tcp.c in the Linux kernel before 2.6.37-rc2 does not properly restrict TCP_MA
23RISCO
abrir
Exploit-DBVexDay Proof
PHP 5.3.x 'Intl' Extension - 'NumberFormatter::setSymbol()' Denial of Service
CVE-2011-1467dosphp10 mar 2011
Unspecified vulnerability in the NumberFormatter::setSymbol (aka numfmt_set_symbol) function in the Intl extension in PH
28RISCO
abrir
Exploit-DBVexDay Proof
CA BrightStor ARCserve for Laptops & Desktops LGServer - 'rxsSetDataGrowthScheduleAndFilter' Remote Buffer Overflow (Metasploit)
CVE-2007-3216remotewindows10 mar 2011
Multiple buffer overflows in the LGServer component of CA (Computer Associates) BrightStor ARCserve Backup for Laptops a
50RISCO
abrir
Exploit-DBVexDay Proof
WebKit 1.2.x - Local Webpage Cross Domain Information Disclosure
CVE-2011-0167remotewindows09 mar 2011
The windows functionality in WebKit in Apple Safari before 5.0.4 allows remote attackers to bypass the Same Origin Polic
23RISCO
abrir
Exploit-DBVexDay Proof
PHP < 5.3.6 'OpenSSL' Extension - 'openssl_decrypt' Ciphertext Data Memory Leak Denial of Service
CVE-2011-1468dosphp08 mar 2011
Multiple memory leaks in the OpenSSL extension in PHP before 5.3.6 might allow remote attackers to cause a denial of ser
28RISCO
abrir
Exploit-DBVexDay Proof
PHP < 5.3.6 'OpenSSL' Extension - 'openssl_encrypt' Plaintext Data Memory Leak Denial of Service
CVE-2011-1468dosphp08 mar 2011
Multiple memory leaks in the OpenSSL extension in PHP before 5.3.6 might allow remote attackers to cause a denial of ser
28RISCO
abrir
Exploit-DBVexDay Proof
Novell iPrint Client 5.52 - ActiveX Control Buffer Overflow (Metasploit)
CVE-2010-4321remotewindows07 mar 2011
Stack-based buffer overflow in an ActiveX control in ienipp.ocx in Novell iPrint Client 5.52 allows remote attackers to
50RISCO
abrir
Exploit-DBVexDay Proof
KingView 6.5.3 SCADA - ActiveX
CVE-2011-3142remotewindows07 mar 2011
Stack-based buffer overflow in an ActiveX control in KVWebSvr.dll in WellinTech KingView 6.52 and 6.53 allows remote att
35RISCO
abrir
Exploit-DBVexDay Proof
Kodak InSite 5.5.2 - '/Troubleshooting/DiagnosticReport.asp?HeaderWarning' Cross-Site Scripting
CVE-2011-1427webappsasp07 mar 2011
Multiple cross-site scripting (XSS) vulnerabilities in Kodak InSite 5.5.2 allow remote attackers to inject arbitrary web
23RISCO
abrir
Exploit-DBVexDay Proof
Kodak InSite 5.5.2 - '/Pages/login.aspx?Language' Cross-Site Scripting
CVE-2011-1427webappsasp07 mar 2011
Multiple cross-site scripting (XSS) vulnerabilities in Kodak InSite 5.5.2 allow remote attackers to inject arbitrary web
23RISCO
abrir
Exploit-DB
Quick Polls - Local File Inclusion / Deletion
CVE-2011-1099webappsphp06 mar 2011
Multiple directory traversal vulnerabilities in FocalMedia.Net Quick Polls before 1.0.2 allow remote attackers to (1) re
23RISCO
abrir
Exploit-DBVexDay Proof
vTiger CRM 5.0.4 - Local File Inclusion
CVE-2009-3249webappsphp05 mar 2011
Multiple directory traversal vulnerabilities in vtiger CRM 5.0.4 allow remote attackers to include and execute arbitrary
23RISCO
abrir
Exploit-DBVexDay Proof
Apple Mail.app - Image Attachment Command Execution (Metasploit)
CVE-2007-6165remotemultiple05 mar 2011
Mail in Apple Mac OS X Leopard (10.5.1) allows user-assisted remote attackers to execute arbitrary code via an AppleDoub
50RISCO
abrir
Exploit-DBVexDay Proof
Allied Telesyn TFTP (AT-TFTP) Server/Daemon 1.9 - Long Filename Overflow (Metasploit)
CVE-2006-6184remotewindows05 mar 2011
Multiple stack-based buffer overflows in Allied Telesyn TFTP Server (AT-TFTP) 1.9, and possibly earlier, allow remote at
50RISCO
abrir
Exploit-DBVexDay Proof
Apple Mail.app - Image Attachment Command Execution (Metasploit)
CVE-2006-0395remotemultiple05 mar 2011
The Download Validation in Mail in Mac OS X 10.4 does not properly recognize attachment file types to warn a user of an
50RISCO
abrir
Exploit-DBVexDay Proof
nostromo nhttpd 1.9.3 - Directory Traversal Remote Command Execution
CVE-2011-0751remotelinux05 mar 2011
Directory traversal vulnerability in nhttpd (aka Nostromo webserver) before 1.9.4 allows remote attackers to execute arb
23RISCO
abrir
Exploit-DBVexDay Proof
JBoss Application Server 4.2 < 4.2.0.CP09 / 4.3 < 4.3.0.CP08 - Remote Command Execution
CVE-2010-0738MEDIUMsob ataqueransomwarewebappsjsp04 mar 2011
The JMX-Console web application in JBossAs in Red Hat JBoss Enterprise Application Platform (aka JBoss EAP or JBEAP) 4.2
100RISCO
abrir
anteriorpágina 326 / 815próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.