Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.496exploits catalogados
34.964CVEs com exploração pública
24.695testados em laboratório
24.443 exploits
Exploit-DB
Adobe Dreamweaver CS4 - 'ibfs32.dll' DLL Hijacking
CVE-2010-3132localwindows24 ago 2010
Untrusted search path vulnerability in Adobe Dreamweaver CS5 11.0 build 4916, build 4909, and probably other versions, a
28RISCO
abrir
Exploit-DB
Microsoft Windows Movie Maker 2.6.4038.0 - 'hhctrl.ocx' DLL Hijacking
CVE-2010-3967localwindows24 ago 2010
Untrusted search path vulnerability in Microsoft Windows Movie Maker (WMM) 2.6 allows local users to gain privileges via
28RISCO
abrir
Exploit-DBVexDay Proof
Wireshark 1.2.10 - 'airpcap.dll' DLL Hijacking
CVE-2010-3133localwindows24 ago 2010
Untrusted search path vulnerability in Wireshark 0.8.4 through 1.0.15 and 1.2.0 through 1.2.10 allows local users, and p
23RISCO
abrir
Exploit-DB
Microsoft Windows 7 - 'wab32res.dll wab.exe' DLL Hijacking
CVE-2010-3143localwindows24 ago 2010
Untrusted search path vulnerability in Microsoft Windows Contacts allows local users, and possibly remote attackers, to
28RISCO
abrir
Exploit-DBVexDay Proof
Opera 10.61 - 'dwmapi.dll' DLL Hijacking
CVE-2010-5227localwindows24 ago 2010
Untrusted search path vulnerability in Opera before 10.62 allows local users to gain privileges via a Trojan horse dwmap
23RISCO
abrir
Exploit-DBVexDay Proof
Auto CMS 1.6 - 'autocms.php' Cross-Site Scripting
CVE-2010-4882webappsphp23 ago 2010
Cross-site scripting (XSS) vulnerability in autocms.php in Auto CMS 1.6 allows remote attackers to inject arbitrary web
23RISCO
abrir
Exploit-DBVexDay Proof
MicroP 0.1.1.1600 - 'mppl' Local Buffer Overflow
CVE-2010-5299localwindows23 ago 2010
Stack-based buffer overflow in MicroP 0.1.1.1600 allows remote attackers to execute arbitrary code via a crafted .mppl f
50RISCO
abrir
Exploit-DB
Microsoft Excel - FEATHEADER Record (MS09-067)
CVE-2009-3129HIGHsob ataquelocalwindows21 ago 2010
Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Conv
100RISCO
abrir
Exploit-DBVexDay Proof
MySQL 5.1.48 - 'EXPLAIN' Denial of Service
CVE-2010-3682doslinux20 ago 2010
Oracle MySQL 5.1 before 5.1.49 and 5.0 before 5.0.92 allows remote authenticated users to cause a denial of service (mys
28RISCO
abrir
Exploit-DBVexDay Proof
Oracle MySQL < 5.1.49 - Malformed 'BINLOG' Arguments Denial of Service
CVE-2010-3679doslinux20 ago 2010
Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (mysqld daemon crash) via
28RISCO
abrir
Exploit-DBVexDay Proof
Oracle MySQL 5.1.48 - 'HANDLER' Interface Denial of Service
CVE-2010-3681doslinux20 ago 2010
Oracle MySQL 5.1 before 5.1.49 and 5.5 before 5.5.5 allows remote authenticated users to cause a denial of service (mysq
28RISCO
abrir
Exploit-DBVexDay Proof
OraclMySQL 5.1.48 - 'LOAD DATA INFILE' Denial of Service
CVE-2010-3683doslinux20 ago 2010
Oracle MySQL 5.1 before 5.1.49 and 5.5 before 5.5.5 sends an OK packet when a LOAD DATA INFILE request generates SQL err
28RISCO
abrir
Exploit-DB
Microsoft Word - Record Parsing Buffer Overflow (MS09-027)
CVE-2009-0565localwindows20 ago 2010
Buffer overflow in Microsoft Office Word 2000 SP3, 2002 SP3, and 2007 SP1 and SP2; Microsoft Office for Mac 2004 and 200
35RISCO
abrir
Exploit-DBVexDay Proof
Cacti 0.8.7 (RedHat High Performance Computing [HPC]) - 'utilities.php?Filter' Cross-Site Scripting
CVE-2010-2544webappsphp19 ago 2010
Cross-site scripting (XSS) vulnerability in utilities.php in Cacti before 0.8.7g, as used in Red Hat High Performance Co
23RISCO
abrir
Exploit-DBVexDay Proof
MySQL 5.1.48 - 'Temporary InnoDB' Tables Denial of Service
CVE-2010-3680dosphp19 ago 2010
Oracle MySQL 5.1 before 5.1.49 allows remote authenticated users to cause a denial of service (mysqld daemon crash) by c
28RISCO
abrir
Exploit-DBVexDay Proof
FreeBSD - 'mbufs()' sendfile Cache Poisoning Privilege Escalation
CVE-2010-2693localfreebsd19 ago 2010
FreeBSD 7.1 through 8.1-PRERELEASE does not copy the read-only flag when creating a duplicate mbuf buffer reference, whi
23RISCO
abrir
Exploit-DBVexDay Proof
Flock Browser 3.0.0 - Malformed Bookmark HTML Injection
CVE-2010-3202remotemultiple19 ago 2010
Cross-site scripting (XSS) vulnerability in Flock Browser 3.0.0.3989 allows remote attackers to inject arbitrary web scr
23RISCO
abrir
Exploit-DBVexDay Proof
Samba 3.0.20 < 3.0.25rc3 - 'Username' map script' Command Execution (Metasploit)
CVE-2007-2447remoteunix18 ago 2010
The MS-RPC functionality in smbd in Samba 3.0.0 through 3.0.25rc3 allows remote attackers to execute arbitrary commands
50RISCO
abrir
Exploit-DBVexDay Proof
Free Simple Software 1.0 - Remote File Inclusion
CVE-2010-3307webappsphp17 ago 2010
Multiple PHP remote file inclusion vulnerabilities in themes/default/index.php in Free Simple CMS 1.0 and earlier allow
23RISCO
abrir
Exploit-DBVexDay Proof
Free Simple Software 1.0 - Remote File Inclusion
CVE-2010-4298webappsphp17 ago 2010
SQL injection vulnerability in the download module in Free Simple Software 1.0 allows remote attackers to execute arbitr
23RISCO
abrir
Exploit-DB
Microsoft Windows - 'srv2.sys' SMB Negotiate ProcessID Function Table Dereference (MS09-050)
CVE-2009-3103remotewindows17 ago 2010
Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Window
60RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - nt!SeObjectCreateSaclAccessBits() Missed ACE Bounds Checks (MS10-047)
CVE-2010-1890doswindows17 ago 2010
The kernel in Microsoft Windows Vista SP1 and SP2, Windows Server 2008 Gold, SP2, and R2, and Windows 7 does not properl
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - KTM Invalid Free with Reused Transaction GUID (MS10-047)
CVE-2010-1889HIGHdoswindows17 ago 2010
Double free vulnerability in the kernel in Microsoft Windows Vista SP1 and SP2, and Windows Server 2008 Gold and SP2, al
41RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Win32k!GreStretchBltInternal() Does Not Handle src == dest
CVE-2010-1887doswindows17 ago 2010
The Windows kernel-mode drivers in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vist
23RISCO
abrir
Exploit-DB
Microsoft Windows - 'srv2.sys' SMB Negotiate ProcessID Function Table Dereference (MS09-050)
CVE-2009-2526remotewindows17 ago 2010
Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 do not properly validate fields in SMBv2 packets
45RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - nt!NtCreateThread Race Condition with Invalid Code Segment (MS10-047)
CVE-2010-1888doswindows17 ago 2010
Race condition in the kernel in Microsoft Windows XP SP3 allows local users to gain privileges via vectors involving thr
23RISCO
abrir
Exploit-DBVexDay Proof
Free Simple Software 1.0 - Remote File Inclusion
CVE-2010-3742webappsphp17 ago 2010
Multiple PHP remote file inclusion vulnerabilities in themes/default/index.php in Free Simple CMS 1.0 allow remote attac
23RISCO
abrir
Exploit-DB
Microsoft Windows - 'srv2.sys' SMB Negotiate ProcessID Function Table Dereference (MS09-050)
CVE-2009-2532remotewindows17 ago 2010
Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC do not properly process t
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 8 - 'toStaticHTML()' HTML Sanitization Bypass
CVE-2010-3324remotewindows16 ago 2010
The toStaticHTML function in Microsoft Internet Explorer 8, and the SafeHTML function in Microsoft Windows SharePoint Se
28RISCO
abrir
Exploit-DB
PHP-Fusion - Local File Inclusion
CVE-2010-4931webappsphp15 ago 2010
Directory traversal vulnerability in maincore.php in PHP-Fusion allows remote attackers to include and execute arbitrary
28RISCO
abrir
anteriorpágina 357 / 815próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.