Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.496exploits catalogados
34.964CVEs com exploração pública
24.695testados em laboratório
24.443 exploits
Exploit-DBVexDay Proof
Cornerstone CMS - SQL Injection
CVE-2010-5287webappsphp22 jun 2010
SQL injection vulnerability in default.php in Cornerstone Technologies webConductor allows remote attackers to execute a
23RISCO
abrir
Exploit-DBVexDay Proof
Novell Groupwise Messenger Client - Remote Buffer Overflow (Metasploit)
CVE-2008-2703remotewindows22 jun 2010
Multiple stack-based buffer overflows in Novell GroupWise Messenger (GWIM) Client before 2.0.3 HP1 for Windows allow rem
50RISCO
abrir
Exploit-DBVexDay Proof
Job Search Engine Script - SQL Injection
CVE-2010-2609webappsphp22 jun 2010
SQL injection vulnerability in show_search_result.php in 2daybiz Job Search Engine Script allows remote attackers to exe
23RISCO
abrir
Exploit-DBVexDay Proof
Video Community portal - SQL Injection / Cross-Site Scripting
CVE-2010-2459webappsphp22 jun 2010
SQL injection vulnerability in video.php in 2daybiz Video Community Portal Script 1.0 allows remote attackers to execute
23RISCO
abrir
Exploit-DBVexDay Proof
Mercury/32 Mail SMTPD - AUTH CRAM-MD5 Buffer Overflow (Metasploit)
CVE-2007-4440remotewindows22 jun 2010
Stack-based buffer overflow in the MercuryS SMTP server in Mercury Mail Transport System, possibly 4.51 and earlier, all
50RISCO
abrir
Exploit-DBVexDay Proof
Netcat 1.10 - NT Stack Buffer Overflow (Metasploit)
CVE-2004-1317remotewindows22 jun 2010
Stack-based buffer overflow in doexec.c in Netcat for Windows 1.1, when running with the -e option, allows remote attack
50RISCO
abrir
Exploit-DBVexDay Proof
BolinTech DreamFTP Server 1.02 - Format String (Metasploit)
CVE-2004-2074remotewindows22 jun 2010
Format string vulnerability in Dream FTP 1.02 allows local users to cause a denial of service (crash) via format string
50RISCO
abrir
Exploit-DBVexDay Proof
GAMSoft TelSrv 1.5 - 'Username' Remote Buffer Overflow (Metasploit)
CVE-2000-0665remotewindows22 jun 2010
GAMSoft TelSrv telnet server 1.5 and earlier allows remote attackers to cause a denial of service via a long username.
50RISCO
abrir
Exploit-DBVexDay Proof
CA BrightStor ArcServe - Media Service Stack Buffer Overflow (Metasploit)
CVE-2007-2139remotewindows22 jun 2010
Multiple stack-based buffer overflows in the SUN RPC service in CA (formerly Computer Associates) BrightStor ARCserve Me
60RISCO
abrir
Exploit-DBVexDay Proof
Veritas Backup Exec Name Service - Remote Overflow (Metasploit)
CVE-2004-1172remotewindows22 jun 2010
Stack-based buffer overflow in the Agent Browser in Veritas Backup Exec 8.x before 8.60.3878 Hotfix 68, and 9.x before 9
60RISCO
abrir
Exploit-DBVexDay Proof
WinComLPD 3.0.2 - Remote Buffer Overflow (Metasploit)
CVE-2008-5159remotewindows22 jun 2010
Integer overflow in the remote administration protocol processing in Client Software WinCom LPD Total 3.0.2.623 and earl
50RISCO
abrir
Exploit-DBVexDay Proof
Boat Classifieds - SQL Injection
CVE-2010-2687webappsasp22 jun 2010
SQL injection vulnerability in printdetail.asp in Site2Nite Boat Classifieds allows remote attackers to execute arbitrar
23RISCO
abrir
Exploit-DBVexDay Proof
Mercury/32 Mail Server < 4.01b - LOGIN Buffer Overflow (Metasploit)
CVE-2007-1373remotewindows22 jun 2010
Stack-based buffer overflow in Mercury/32 (aka Mercury Mail Transport System) 4.01b and earlier allows remote attackers
50RISCO
abrir
Exploit-DBVexDay Proof
Samba 2.2.8 (OSX/PPC) - 'trans2open' Remote Overflow (Metasploit)
CVE-2003-0201remoteosx_ppc21 jun 2010
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x vers
60RISCO
abrir
Exploit-DBVexDay Proof
Jamroom 4.0.2/4.1.x - 'forum.php' Cross-Site Scripting
CVE-2010-2463webappsphp21 jun 2010
Cross-site scripting (XSS) vulnerability in forum.php in Jamroom before 4.1.9 allows remote attackers to inject arbitrar
23RISCO
abrir
Exploit-DBVexDay Proof
IBM Websphere ILOG JRules 6.7 - Cross-Site Scripting
CVE-2010-2433webappsjsp21 jun 2010
Multiple cross-site scripting (XSS) vulnerabilities in content/internalError.jsp in IBM WebSphere ILOG JRules 6.7 allow
23RISCO
abrir
Exploit-DB
Linker IMG 1.0 - Remote File Inclusion
CVE-2010-2456webappsphp21 jun 2010
Multiple directory traversal vulnerabilities in index.php in Linker IMG 1.0 and earlier allow remote attackers to read a
23RISCO
abrir
Exploit-DBVexDay Proof
G.CMS Generator - SQL Injection
CVE-2010-2438webappsphp21 jun 2010
SQL injection vulnerability in G.CMS generator allows remote attackers to execute arbitrary SQL commands via the lang pa
23RISCO
abrir
Exploit-DBVexDay Proof
Samba 2.2.8 (Solaris SPARC) - 'trans2open' Remote Overflow (Metasploit)
CVE-2003-0201remotesolaris_sparc21 jun 2010
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x vers
60RISCO
abrir
Exploit-DBVexDay Proof
Overstock Script - SQL Injection
CVE-2010-2461webappsphp20 jun 2010
SQL injection vulnerability in storecat.php in JCE-Tech Overstock 1 allows remote attackers to execute arbitrary SQL com
23RISCO
abrir
Exploit-DBVexDay Proof
MoreAmp - '.maf' Local Stack Buffer Overflow (SEH)
CVE-2010-2439localwindows20 jun 2010
Stack-based buffer overflow in MoreAmp allows remote attackers to execute arbitrary code via a long line in a song list
23RISCO
abrir
Exploit-DBVexDay Proof
Shareasale Script - SQL Injection
CVE-2010-2460webappsphp20 jun 2010
SQL injection vulnerability in merchant_product_list.php in JCE-Tech Shareasale Script (SASS) 1 allows remote attackers
23RISCO
abrir
Exploit-DBVexDay Proof
iBoutique - 'page' SQL Injection / Cross-Site Scripting
CVE-2010-5020webappsphp20 jun 2010
SQL injection vulnerability in index.php in NetArt Media iBoutique 4.0 allows remote attackers to execute arbitrary SQL
23RISCO
abrir
Exploit-DBVexDay Proof
iBoutique - 'page' SQL Injection / Cross-Site Scripting
CVE-2010-0804webappsphp20 jun 2010
Cross-site scripting (XSS) vulnerability in index.php in iBoutique 4.0 allows remote attackers to inject arbitrary web s
23RISCO
abrir
Exploit-DBVexDay Proof
OroHYIP - SQL Injection
CVE-2010-2462webappsphp20 jun 2010
SQL injection vulnerability in withdraw_money.php in Toma Cero OroHYIP allows remote attackers to execute arbitrary SQL
23RISCO
abrir
Exploit-DBVexDay Proof
MoreAmp - '.maf' Buffer Overflow (PoC)
CVE-2010-2439doswindows19 jun 2010
Stack-based buffer overflow in MoreAmp allows remote attackers to execute arbitrary code via a long line in a song list
23RISCO
abrir
Exploit-DBVexDay Proof
Orbital Viewer 1.04 - '.ov' Local Universal Stack Overflow (SEH)
CVE-2010-0688localwindows19 jun 2010
Stack-based buffer overflow in Orbital Viewer 1.04 allows user-assisted remote attackers to execute arbitrary code via a
50RISCO
abrir
Exploit-DBVexDay Proof
Joomla! Component RSComments 1.0.0 - Persistent Cross-Site Scripting
CVE-2010-2464webappsphp19 jun 2010
Multiple cross-site scripting (XSS) vulnerabilities in the RSComments (com_rscomments) component 1.0.0 Rev 2 for Joomla!
23RISCO
abrir
Exploit-DBVexDay Proof
Elite Gaming Ladders 3.5 - 'ladder[id]' SQL Injection
CVE-2010-5014webappsphp19 jun 2010
SQL injection vulnerability in standings.php in Elite Gaming Ladders 3.5 allows remote attackers to execute arbitrary SQ
23RISCO
abrir
Exploit-DBVexDay Proof
Spring Framework - Arbitrary code Execution
CVE-2010-1622webappsmultiple18 jun 2010
SpringSource Spring Framework 2.5.x before 2.5.6.SEC02, 2.5.7 before 2.5.7.SR01, and 3.0.x before 3.0.3 allows remote at
35RISCO
abrir
anteriorpágina 369 / 815próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.