Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.496exploits catalogados
34.964CVEs com exploração pública
24.695testados em laboratório
24.443 exploits
Exploit-DBVexDay Proof
Microsoft Movie Maker - Remote Code Execution (MS10-016)
CVE-2010-0265remotewindows04 set 2010
Buffer overflow in Microsoft Windows Movie Maker 2.1, 2.6, and 6.0, and Microsoft Producer 2003, allows remote attackers
28RISCO
abrir
Exploit-DBVexDay Proof
NuSOAP 0.9.5 - 'nusoap.php' Cross-Site Scripting
CVE-2010-3070webappsphp03 set 2010
Cross-site scripting (XSS) vulnerability in NuSOAP 0.9.5, as used in MantisBT and other products, allows remote attacker
23RISCO
abrir
Exploit-DBVexDay Proof
CMS WebManager-Pro - 'c.php' SQL Injection
CVE-2010-4899webappsphp02 set 2010
SQL injection vulnerability in c.php in CMS WebManager-Pro before 8.1 allows remote attackers to execute arbitrary SQL c
23RISCO
abrir
Exploit-DBVexDay Proof
OneCMS 2.6.1 - 'index.php' Cross-Site Scripting
CVE-2010-4877webappsphp02 set 2010
Cross-site scripting (XSS) vulnerability in index.php in OneCMS 2.6.1 allows remote attackers to inject arbitrary web sc
23RISCO
abrir
Exploit-DBVexDay Proof
Apple QuickTime FlashPix NumberOfTiles - Remote Code Execution
CVE-2010-0519doswindows02 set 2010
Integer overflow in QuickTime in Apple Mac OS X before 10.6.3 allows remote attackers to execute arbitrary code or cause
23RISCO
abrir
Exploit-DB
dompdf 0.6.0 beta1 - Remote File Inclusion
CVE-2010-4879webappsphp01 set 2010
PHP remote file inclusion vulnerability in dompdf.php in dompdf 0.6.0 beta1 allows remote attackers to execute arbitrary
23RISCO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat Reader and Flash Player - 'newclass' Invalid Pointer
CVE-2010-1297HIGHsob ataqueremotewindows01 set 2010
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrob
100RISCO
abrir
Exploit-DBVexDay Proof
mBlogger 1.0.04 - 'viewpost.php' SQL Injection
CVE-2010-4876webappsphp31 ago 2010
SQL injection vulnerability in viewpost.php in mBlogger 1.0.04 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
Exploit-DBVexDay Proof
HP Insight Diagnostics Online Edition 8.4 - 'globals.php?tabpage' Cross-Site Scripting
CVE-2010-3003webappsphp31 ago 2010
Cross-site scripting (XSS) vulnerability in HP Insight Diagnostics Online Edition before 8.5.0-11 on Linux allows remote
23RISCO
abrir
Exploit-DBVexDay Proof
HP Insight Diagnostics Online Edition 8.4 - 'survey.php?category' Cross-Site Scripting
CVE-2010-3003webappsphp31 ago 2010
Cross-site scripting (XSS) vulnerability in HP Insight Diagnostics Online Edition before 8.5.0-11 on Linux allows remote
23RISCO
abrir
Exploit-DBVexDay Proof
HP Insight Diagnostics Online Edition 8.4 - 'custom.php?testmode' Cross-Site Scripting
CVE-2010-3003webappsphp31 ago 2010
Cross-site scripting (XSS) vulnerability in HP Insight Diagnostics Online Edition before 8.5.0-11 on Linux allows remote
23RISCO
abrir
Exploit-DBVexDay Proof
Joomla! Component JE FAQ Pro 1.5.0 - Multiple Blind SQL Injections
CVE-2010-3211webappsphp31 ago 2010
Multiple SQL injection vulnerabilities in the JE FAQ Pro (com_jefaqpro) component 1.5.0 for Joomla! allow remote attacke
23RISCO
abrir
Exploit-DBVexDay Proof
HP Insight Diagnostics Online Edition 8.4 - 'idstatusframe.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2010-3003webappsphp31 ago 2010
Cross-site scripting (XSS) vulnerability in HP Insight Diagnostics Online Edition before 8.5.0-11 on Linux allows remote
23RISCO
abrir
Exploit-DBVexDay Proof
HP Insight Diagnostics Online Edition 8.4 - 'parameters.php?device' Cross-Site Scripting
CVE-2010-3003webappsphp31 ago 2010
Cross-site scripting (XSS) vulnerability in HP Insight Diagnostics Online Edition before 8.5.0-11 on Linux allows remote
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Plug and Play Service - Overflow (MS05-039) (Metasploit)
CVE-2005-1983doswindows30 ago 2010
Stack-based buffer overflow in the Plug and Play (PnP) service for Microsoft Windows 2000 and Windows XP Service Pack 1
60RISCO
abrir
Exploit-DB
seagull 0.6.7 - Remote File Inclusion
CVE-2010-3209webappsphp30 ago 2010
Multiple PHP remote file inclusion vulnerabilities in Seagull 0.6.7 allow remote attackers to execute arbitrary PHP code
23RISCO
abrir
Exploit-DBVexDay Proof
Apple QuickTime - '_Marshaled_pUnk' Backdoor Client-Side Arbitrary Code Execution
CVE-2010-1818doswindows30 ago 2010
The IPersistPropertyBag2::Read function in QTPlugin.ocx in Apple QuickTime 6.x, 7.x before 7.6.8, and other versions all
50RISCO
abrir
Exploit-DBVexDay Proof
Joomla! Component PicSell 1.0 - Local File Disclosure
CVE-2010-3203webappsphp30 ago 2010
Directory traversal vulnerability in the PicSell (com_picsell) component 1.0 for Joomla! allows remote attackers to read
38RISCO
abrir
Exploit-DBVexDay Proof
Nginx 0.6.38 - Heap Corruption
CVE-2009-2629locallinux29 ago 2010
Buffer underflow in src/http/ngx_http_parse.c in nginx 0.1.0 through 0.5.37, 0.6.x before 0.6.39, 0.7.x before 0.7.62, a
45RISCO
abrir
Exploit-DBVexDay Proof
Seagull 0.6.7 - SQL Injection
CVE-2010-3212webappsphp29 ago 2010
SQL injection vulnerability in index.php in Seagull 0.6.7 and earlier allows remote attackers to execute arbitrary SQL c
23RISCO
abrir
Exploit-DB
Multi-lingual E-Commerce System 0.2 - Multiple Remote File Inclusions
CVE-2010-3210webappsphp29 ago 2010
Multiple PHP remote file inclusion vulnerabilities in Multi-lingual E-Commerce System 0.2 allow remote attackers to exec
23RISCO
abrir
Exploit-DB
textpattern CMS 4.2.0 - Remote File Inclusion
CVE-2010-3205webappsphp28 ago 2010
PHP remote file inclusion vulnerability in index.php in Textpattern CMS 4.2.0 allows remote attackers to execute arbitra
23RISCO
abrir
Exploit-DB
DIY-CMS 1.0 - Multiple Remote File Inclusions
CVE-2010-3206webappsphp28 ago 2010
Multiple PHP remote file inclusion vulnerabilities in DiY-CMS 1.0 allow remote attackers to execute arbitrary PHP code v
23RISCO
abrir
Exploit-DBVexDay Proof
XOOPS 2.0.14 - 'article.php' SQL Injection
CVE-2008-2094webappsphp28 ago 2010
SQL injection vulnerability in article.php in the Article module for XOOPS allows remote attackers to execute arbitrary
23RISCO
abrir
Exploit-DBVexDay Proof
GaleriaSHQIP 1.0 - SQL Injection
CVE-2010-3207webappsphp28 ago 2010
SQL injection vulnerability in index.php in GaleriaSHQIP 1.0, when magic_quotes_gpc is disabled, allows remote attackers
23RISCO
abrir
Exploit-DBVexDay Proof
Linux Kernel < 2.6.36-rc1 (Ubuntu 10.04 / 2.6.32) - 'CAN BCM' Local Privilege Escalation
CVE-2010-2959locallinux27 ago 2010
Integer overflow in net/can/bcm.c in the Controller Area Network (CAN) implementation in the Linux kernel before 2.6.27.
23RISCO
abrir
Exploit-DBVexDay Proof
iGaming CMS - Multiple SQL Injections
CVE-2008-5841webappsphp27 ago 2010
Multiple SQL injection vulnerabilities in iGaming 1.5 and earlier allow remote attackers to execute arbitrary SQL comman
23RISCO
abrir
Exploit-DB
pecio CMS 2.0.5 - Multiple Remote File Inclusions
CVE-2010-3204webappsphp27 ago 2010
Multiple PHP remote file inclusion vulnerabilities in Pecio CMS 2.0.5 allow remote attackers to execute arbitrary PHP co
23RISCO
abrir
Exploit-DBVexDay Proof
kontakt formular 1.1 - Remote File Inclusion
CVE-2010-4878webappsphp26 ago 2010
PHP remote file inclusion vulnerability in formmailer.php in Kontakt Formular 1.1 allows remote attackers to execute arb
23RISCO
abrir
Exploit-DBVexDay Proof
EncFS 1.6.0 - Flawed CBC/CFB Cryptography Implementation
CVE-2010-3073locallinux26 ago 2010
SSL_Cipher.cpp in EncFS before 1.7.0 does not properly handle integer data sizes when constructing headers intended for
23RISCO
abrir
anteriorpágina 354 / 815próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.