Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.985exploits catalogados
37.617CVEs com exploração pública
24.695testados em laboratório
24.482 exploits
Exploit-DB
Joomla! Component Elite Experts - SQL Injection
CVE-2010-4944webappswindows_x8624 set 2010
SQL injection vulnerability in the Elite Experts (com_elite_experts) component for Mambo and Joomla! allows remote attac
23RISCO
abrir
Exploit-DBVexDay Proof
FreePBX 2.8.0 - Recordings Interface Allows Remote Code Execution
CVE-2010-3490webappsphp24 set 2010
Directory traversal vulnerability in page.recordings.php in the System Recordings component in the configuration interfa
23RISCO
abrir
Exploit-DBVexDay Proof
Linksys WRT54 Access Point - 'apply.cgi' Remote Buffer Overflow (Metasploit)
CVE-2005-2799remotehardware24 set 2010
Buffer overflow in apply.cgi in Linksys WRT54G 3.01.03, 3.03.6, and possibly other versions before 4.20.7, allows remote
60RISCO
abrir
Exploit-DBVexDay Proof
Microsoft MPEG Layer-3 Audio Decoder - Division By Zero
CVE-2010-0480doswindows24 set 2010
Multiple stack-based buffer overflows in the MPEG Layer-3 audio codecs in Microsoft Windows 2000 SP4, XP SP2 and SP3, Se
50RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Excel - OBJ Record Stack Overflow
CVE-2010-0822localwindows24 set 2010
Stack-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML F
60RISCO
abrir
Exploit-DB
GeekLog 1.3.8 (filemgmt) - SQL Injection
CVE-2010-4933webappsphp23 set 2010
SQL injection vulnerability in filemgmt/singlefile.php in Geeklog 1.3.8 allows remote attackers to execute arbitrary SQL
23RISCO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat Reader and Flash - 'newfunction' Remote Code Execution
CVE-2010-2168dosmultiple23 set 2010
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbi
28RISCO
abrir
Exploit-DBVexDay Proof
WAnewsletter 2.1.2 - SQL Injection
CVE-2010-4940webappsphp23 set 2010
SQL injection vulnerability in index.php in WAnewsletter 2.1.2 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
Exploit-DBVexDay Proof
Joomla! Component TimeTrack 1.2.4 - Multiple SQL Injections
CVE-2010-4926webappsphp22 set 2010
SQL injection vulnerability in the TimeTrack (com_timetrack) component 1.2.4 for Joomla! allows remote attackers to exec
23RISCO
abrir
Exploit-DBVexDay Proof
Joomla! Component Joostina - SQL Injection
CVE-2010-4929webappsphp22 set 2010
SQL injection vulnerability in the Joostina (com_ezautos) component for Joomla! allows remote attackers to execute arbit
23RISCO
abrir
Exploit-DBVexDay Proof
Adobe Shockwave Director tSAC - Chunk Memory Corruption
CVE-2010-2866doswindows22 set 2010
Integer signedness error in the DIRAPI module in Adobe Shockwave Player before 11.5.8.612 allows remote attackers to cau
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Excel - WOPT Record Parsing Heap Memory Corruption
CVE-2010-0824doswindows21 set 2010
Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute
28RISCO
abrir
Exploit-DBVexDay Proof
Novell iPrint Client - ActiveX Control 'debug' Remote Buffer Overflow (Metasploit)
CVE-2010-3106remotewindows21 set 2010
The ienipp.ocx ActiveX control in the browser plugin in Novell iPrint Client before 5.42 does not properly validate the
50RISCO
abrir
Exploit-DBVexDay Proof
@Mail 6.1.9 - 'MailType' Cross-Site Scripting
CVE-2010-4930webappsphp21 set 2010
Cross-site scripting (XSS) vulnerability in index.php in @mail Webmail before 6.2.0 allows remote attackers to inject ar
23RISCO
abrir
Exploit-DBVexDay Proof
Novell iPrint Client - ActiveX Control call-back-url Buffer Overflow (Metasploit)
CVE-2010-1527remotewindows21 set 2010
Stack-based buffer overflow in Novell iPrint Client before 5.44 allows remote attackers to execute arbitrary code via a
50RISCO
abrir
Exploit-DBVexDay Proof
Novell iPrint Client - ActiveX Control ExecuteRequest debug Buffer Overflow (Metasploit)
CVE-2010-3106remotewindows21 set 2010
The ienipp.ocx ActiveX control in the browser plugin in Novell iPrint Client before 5.42 does not properly validate the
50RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Shell LNK Code Execution (MS10-046) (Metasploit)
CVE-2010-2568HIGHsob ataqueremotewindows21 set 2010
Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 all
100RISCO
abrir
Exploit-DBVexDay Proof
Sun Java - Web Start Plugin Command Line Argument Injection (Metasploit)
CVE-2010-0886remotewindows21 set 2010
Unspecified vulnerability in the Java Deployment Toolkit component in Oracle Java SE and Java for Business JDK and JRE 6
50RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Excel - WOPT Record Parsing Heap Memory Corruption
CVE-2010-1248doswindows21 set 2010
Buffer overflow in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary
28RISCO
abrir
Exploit-DBVexDay Proof
wpQuiz 2.7 - Authentication Bypass
CVE-2010-3608webappsphp21 set 2010
Multiple SQL injection vulnerabilities in wpQuiz 2.7 allow remote attackers to execute arbitrary SQL commands via the (1
23RISCO
abrir
Exploit-DBVexDay Proof
mountall 2.15.2 (Ubuntu 10.04/10.10) - Local Privilege Escalation
CVE-2010-2961locallinux21 set 2010
mountall.c in mountall before 2.15.2 uses 0666 permissions for the root.rules file, which allows local users to gain pri
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - SMB Relay Code Execution (MS08-068) (Metasploit)
CVE-2008-4037remotewindows21 set 2010
Microsoft Windows 2000 Gold through SP4, XP Gold through SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 20
50RISCO
abrir
Exploit-DBVexDay Proof
Novell iPrint Client - ActiveX Control ExecuteRequest Buffer Overflow (Metasploit)
CVE-2008-0935remotewindows21 set 2010
Stack-based buffer overflow in the Novell iPrint Control ActiveX control in ienipp.ocx in Novell iPrint Client before 4.
50RISCO
abrir
Exploit-DBVexDay Proof
ibPhotohost 1.1.2 - SQL Injection
CVE-2010-3601webappsphp21 set 2010
SQL injection vulnerability in index.php in ibPhotohost 1.1.2 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
Exploit-DBVexDay Proof
CA CAM (Windows x86) - 'log_security()' Remote Stack Buffer Overflow (Metasploit)
CVE-2005-2668remotewindows_x8620 set 2010
Multiple buffer overflows in Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1
60RISCO
abrir
Exploit-DBVexDay Proof
IBM TPM for OS Deployment 5.1.0.x - 'rembo.exe' Remote Buffer Overflow (Metasploit)
CVE-2007-1868remotewindows20 set 2010
The management service in IBM Tivoli Provisioning Manager for OS Deployment before 5.1 Fix Pack 2 does not properly hand
50RISCO
abrir
Exploit-DBVexDay Proof
Macrovision Installshield Update Service - ActiveX Unsafe Method (Metasploit)
CVE-2007-5660remotewindows20 set 2010
Unspecified vulnerability in the Update Service ActiveX control in isusweb.dll before 6.0.100.65101 in MacroVision FLEXn
50RISCO
abrir
Exploit-DBVexDay Proof
Lyris ListManager - MSDE Weak sa Password (Metasploit)
CVE-2005-4145remotewindows20 set 2010
The MSDE version of Lyris ListManager 5.0 through 8.9b configures the sa account in the database to use a password with
50RISCO
abrir
Exploit-DBVexDay Proof
Madwifi - SIOCGIWSCAN Buffer Overflow (Metasploit)
CVE-2006-6332remotelinux20 set 2010
Stack-based buffer overflow in net80211/ieee80211_wireless.c in MadWifi before 0.9.2.1 allows remote attackers to execut
28RISCO
abrir
Exploit-DBVexDay Proof
PHP 4 - Unserialize() ZVAL Reference Counter Overflow (Cookie) (Metasploit)
CVE-2007-1286remotemultiple20 set 2010
Integer overflow in PHP 4.4.4 and earlier allows remote context-dependent attackers to execute arbitrary code via a long
50RISCO
abrir
anteriorpágina 349 / 817próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.