Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.313exploits catalogados
34.834CVEs com exploração pública
24.695testados em laboratório
24.443 exploits
Exploit-DBVexDay Proof
Joomla! Component JS Calendar 1.5.1 - Multiple Vulnerabilities
CVE-2010-4794webappsphp09 out 2010
Multiple cross-site scripting (XSS) vulnerabilities in the JoomlaSeller JS Calendar (com_jscalendar) component 1.5.1 and
23RISCO
abrir
Exploit-DBVexDay Proof
hplip - 'hpssd.py' From Address Arbitrary Command Execution (Metasploit)
CVE-2007-5208remotelinux09 out 2010
hpssd in Hewlett-Packard Linux Imaging and Printing Project (hplip) 1.x and 2.x before 2.7.10 allows context-dependent a
50RISCO
abrir
Exploit-DBVexDay Proof
Joomla! Component Community Builder Enhanced (CBE) 1.4.8/1.4.9/1.4.10 - Local File Inclusion / Remote Code Execution
CVE-2010-5280webappsphp09 out 2010
Directory traversal vulnerability in the Community Builder Enhanced (CBE) (com_cbe) component 1.4.8, 1.4.9, and 1.4.10 f
23RISCO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX EvoCam Web Server - GET Buffer Overflow (Metasploit)
CVE-2010-2309remoteosx09 out 2010
Buffer overflow in the web server for EvoLogical EvoCam 3.6.6 and 3.6.7 allows remote attackers to execute arbitrary cod
50RISCO
abrir
Exploit-DBVexDay Proof
UFO: Alien Invasion IRC Client (OSX) - Remote Buffer Overflow (Metasploit)
CVE-2010-2309remoteosx09 out 2010
Buffer overflow in the web server for EvoLogical EvoCam 3.6.6 and 3.6.7 allows remote attackers to execute arbitrary cod
50RISCO
abrir
Exploit-DBVexDay Proof
xWeblog 2.2 - 'arsiv.asp?tarih' SQL Injection
CVE-2010-4856webappsasp08 out 2010
SQL injection vulnerability in arsiv.asp in xWeblog 2.2 allows remote attackers to execute arbitrary SQL commands via th
23RISCO
abrir
Exploit-DBVexDay Proof
Flex Timesheet - Authentication Bypass
CVE-2010-4797webappsphp08 out 2010
Multiple SQL injection vulnerabilities in the log-in form in Truworth Flex Timesheet allow remote attackers to execute a
23RISCO
abrir
Exploit-DBVexDay Proof
OPEN IT OverLook 5 - 'title.php' Cross-Site Scripting
CVE-2010-4792webappsphp08 out 2010
Cross-site scripting (XSS) vulnerability in title.php in OPEN IT OverLook 5.0 allows remote attackers to inject arbitrar
23RISCO
abrir
Exploit-DBVexDay Proof
xWeblog 2.2 - 'oku.asp?makale_id' SQL Injection
CVE-2010-4855webappsasp07 out 2010
SQL injection vulnerability in oku.asp in xWeblog 2.2 allows remote attackers to execute arbitrary SQL commands via the
23RISCO
abrir
Exploit-DB
libc/glob(3) - Resource Exhaustion / Remote ftpd-anonymous (Denial of Service)
CVE-2010-2632dosmultiple07 out 2010
Unspecified vulnerability in the FTP Server in Oracle Solaris 8, 9, 10, and 11 Express allows remote attackers to affect
35RISCO
abrir
Exploit-DBVexDay Proof
Joomla! Component Club Manager - 'cm_id' SQL Injection
CVE-2010-4864webappsphp06 out 2010
SQL injection vulnerability in the Club Manager (com_clubmanager) component for Joomla! allows remote attackers to execu
23RISCO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat and Reader - Array Indexing Remote Code Execution
CVE-2010-3631dososx06 out 2010
Array index error in Adobe Reader and Acrobat 8.x before 8.2.5 and 9.x before 9.4 on Mac OS X allows attackers to execut
28RISCO
abrir
Exploit-DBVexDay Proof
HP-UX LPD - Command Execution (Metasploit)
CVE-2002-1473remotehp-ux06 out 2010
Multiple buffer overflows in lp subsystem for HP-UX 10.20 through 11.11 (11i) allow local users to cause a denial of ser
38RISCO
abrir
Exploit-DBVexDay Proof
Microsoft ASP.NET - Padding Oracle (MS10-070)
CVE-2010-3332remoteasp06 out 2010
Microsoft .NET Framework 1.1 SP1, 2.0 SP1 and SP2, 3.5, 3.5 SP1, 3.5.1, and 4.0, as used for ASP.NET in Microsoft Intern
35RISCO
abrir
Exploit-DBVexDay Proof
NetTerm NetFTPD - 'USER' Remote Buffer Overflow (Metasploit)
CVE-2005-1323remotewindows05 out 2010
Buffer overflow in NetFtpd for NetTerm 5.1.1 and earlier allows remote attackers to execute arbitrary code via a long US
50RISCO
abrir
Exploit-DB
Cag CMS 0.2 - Cross-Site Scripting / Blind SQL Injection
CVE-2010-4857webappsphp05 out 2010
SQL injection vulnerability in click.php in CAG CMS 0.2 Beta allows remote attackers to execute arbitrary SQL commands v
23RISCO
abrir
Exploit-DBVexDay Proof
SlimFTPd - 'LIST' Concatenation Overflow (Metasploit)
CVE-2005-2373remotewindows05 out 2010
Buffer overflow in SlimFTPd 3.15 and 3.16 allows remote authenticated users to execute arbitrary code via a long directo
50RISCO
abrir
Exploit-DBVexDay Proof
Ipswitch WS_FTP Server 5.03 - MKD Overflow (Metasploit)
CVE-2004-1135remotewindows05 out 2010
Multiple buffer overflows in WS_FTP Server 5.03 2004.10.14 allow remote attackers to cause a denial of service (service
50RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Workstation Service - NetpManageIPCConnect Overflow (MS06-070) (Metasploit)
CVE-2006-4691remotewindows05 out 2010
Stack-based buffer overflow in the NetpManageIPCConnect function in the Workstation service (wkssvc.dll) in Microsoft Wi
60RISCO
abrir
Exploit-DBVexDay Proof
Oracle 9i XDB (Windows x86) - FTP UNLOCK Overflow (Metasploit)
CVE-2003-0727remotewindows_x8605 out 2010
Multiple buffer overflows in the XML Database (XDB) functionality for Oracle 9i Database Release 2 allow local users to
50RISCO
abrir
Exploit-DBVexDay Proof
Alcatel-Lucent OmniPCX Enterprise - masterCGI Arbitrary Command Execution (Metasploit)
CVE-2007-3010CRITICALsob ataquewebappscgi05 out 2010
masterCGI in the Unified Maintenance Tool in Alcatel OmniPCX Enterprise Communication Server R7.1 and earlier allows rem
100RISCO
abrir
Exploit-DBVexDay Proof
Microsoft DirectX DirectShow - SAMI Buffer Overflow (MS07-064) (Metasploit)
CVE-2007-3901remotewindows05 out 2010
Stack-based buffer overflow in the DirectShow Synchronized Accessible Media Interchange (SAMI) parser in quartz.dll for
50RISCO
abrir
Exploit-DBVexDay Proof
GlobalScape Secure FTP Server - Input Overflow (Metasploit)
CVE-2005-1415remotewindows05 out 2010
Buffer overflow in GlobalSCAPE Secure FTP Server 3.0.2 allows remote authenticated users to execute arbitrary code via a
50RISCO
abrir
Exploit-DBVexDay Proof
DNET Live-Stats 0.8 - Local File Inclusion
CVE-2010-4858webappsphp04 out 2010
Directory traversal vulnerability in team.rc5-72.php in DNET Live-Stats 0.8 allows remote attackers to read arbitrary fi
23RISCO
abrir
Exploit-DBVexDay Proof
FreeBSD - 'pseudofs' Null Pointer Dereference Privilege Escalation
CVE-2010-4210localbsd04 out 2010
The pfs_getextattr function in FreeBSD 7.x before 7.3-RELEASE and 8.x before 8.0-RC1 unlocks a mutex that was not previo
23RISCO
abrir
Exploit-DBVexDay Proof
Savant Web Server 3.1 - Remote Overflow (Metasploit)
CVE-2002-1120remotewindows04 out 2010
Buffer overflow in Savant Web Server 3.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP G
50RISCO
abrir
Exploit-DBVexDay Proof
Surgemail SurgeWeb 4.3e - Cross-Site Scripting
CVE-2010-3201webappsphp04 out 2010
Cross-site scripting (XSS) vulnerability in NetWin Surgemail before 4.3g allows remote attackers to inject arbitrary web
23RISCO
abrir
Exploit-DBVexDay Proof
SmarterMail < 7.2.3925 - Persistent Cross-Site Scripting
CVE-2010-3425webappsasp02 out 2010
Cross-site scripting (XSS) vulnerability in UserControls/Popups/frmHelp.aspx in SmarterStats 5.3, 5.3.3819, and possibly
23RISCO
abrir
Exploit-DBVexDay Proof
SmarterMail < 7.2.3925 - LDAP Injection
CVE-2010-3486webappsasp02 out 2010
Directory traversal vulnerability in FileStorageUpload.ashx in SmarterMail 7.1.3876 allows remote attackers to read arbi
23RISCO
abrir
Exploit-DBVexDay Proof
Chipmunk Board 1.3 - 'index.php?forumID' SQL Injection
CVE-2010-4866webappsphp01 out 2010
SQL injection vulnerability in index.php in Chipmunk Board 1.3 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
anteriorpágina 345 / 815próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.