Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.858exploits catalogados
36.825CVEs com exploração pública
24.695testados em laboratório
3.501 exploits
Metasploit300
DHCP Client Bash Environment Variable Code Injection (Shellshock)
CVE-2014-6271CRITICALsob ataque24 set 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
Metasploit600
Dhclient Bash Environment Variable Injection (Shellshock)
CVE-2014-6271CRITICALsob ataque24 set 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
Metasploit0
Mac OS X IOKit Keyboard Driver Root Privilege Escalation
CVE-2014-4404HIGHsob ataque24 set 2014
Heap-based buffer overflow in IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitr
98RISCO
abrir
Metasploit300
Apache mod_cgi Bash Environment Variable Injection (Shellshock) Scanner
CVE-2014-6271CRITICALsob ataque24 set 2014
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
Metasploit500
Adobe Flash Player copyPixelsToByteArray Method Integer Overflow
CVE-2014-055623 set 2014
Heap-based buffer overflow in Adobe Flash Player before 13.0.0.244 and 14.x and 15.x before 15.0.0.152 on Windows and OS
60RISCO
abrir
Metasploit600
Phpwiki Ploticus Remote Code Execution
CVE-2014-551911 set 2014
The Ploticus module in PhpWiki 1.5.0 allows remote attackers to execute arbitrary code via shell metacharacters in a dev
50RISCO
abrir
Metasploit600
Rejetto HttpFileServer Remote Command Execution
CVE-2014-6287CRITICALsob ataque11 set 2014
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISCO
abrir
Metasploit300
MS14-052 Microsoft Internet Explorer XMLDOM Filename Disclosure
CVE-2013-7331MEDIUMsob ataque09 set 2014
The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the exist
70RISCO
abrir
Metasploit300
HP Network Node Manager I PMD Buffer Overflow
CVE-2014-262409 set 2014
Unspecified vulnerability in HP Network Node Manager i (NNMi) 9.0x, 9.1x, and 9.2x allows remote attackers to execute ar
50RISCO
abrir
Metasploit600
ManageEngine Desktop Central StatusUpdate Arbitrary File Upload
CVE-2014-500531 ago 2014
Directory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers
60RISCO
abrir
Metasploit600
ManageEngine Eventlog Analyzer Arbitrary File Upload
CVE-2014-603731 ago 2014
Directory traversal vulnerability in the agentUpload servlet in ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8
60RISCO
abrir
Metasploit600
Wordpress SlideShow Gallery Authenticated File Upload
CVE-2014-546028 ago 2014
Unrestricted file upload vulnerability in the Tribulant Slideshow Gallery plugin before 1.4.7 for WordPress allows remot
60RISCO
abrir
Metasploit300
ManageEngine DeviceExpert User Credentials
CVE-2014-537728 ago 2014
ReadUsersFromMasterServlet in ManageEngine DeviceExpert before 5.9 build 5981 allows remote attackers to obtain user acc
50RISCO
abrir
Metasploit600
ActualAnalyzer 'ant' Cookie Command Execution
CVE-2014-5470CRITICAL28 ago 2014
Actual Analyzer through 2014-08-29 allows code execution via shell metacharacters because untrusted input is used for pa
68RISCO
abrir
Metasploit600
Railo Remote File Include
CVE-2014-546826 ago 2014
A File Inclusion vulnerability exists in Railo 4.2.1 and earlier via a specially-crafted URL request to the thumbnail.cf
50RISCO
abrir
Metasploit300
Netcore Router Udp 53413 Backdoor
CVE-2025-34117CRITICAL25 ago 2014
Netcore / Netis Routers RCE via UDP Port 53413 Backdoor
68RISCO
abrir
Metasploit300
NTP Mode 6 UNSETTRAP DRDoS Scanner
CVE-2013-521125 ago 2014
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RISCO
abrir
Metasploit300
NTP Mode 6 REQ_NONCE DRDoS Scanner
CVE-2013-521125 ago 2014
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RISCO
abrir
Metasploit300
NTP Mode 7 PEER_LIST_SUM DoS Scanner
CVE-2013-521125 ago 2014
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RISCO
abrir
Metasploit300
NTP Mode 7 GET_RESTRICT DRDoS Scanner
CVE-2013-521125 ago 2014
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RISCO
abrir
Metasploit300
NTP Mode 7 PEER_LIST DoS Scanner
CVE-2013-521125 ago 2014
The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service
60RISCO
abrir
Metasploit600
SolarWinds Storage Manager Authentication Bypass
CVE-2015-537119 ago 2014
The AuthenticationFilter class in SolarWinds Storage Manager allows remote attackers to upload and execute arbitrary scr
40RISCO
abrir
Metasploit300
Yokogawa BKBCopyD.exe Client
CVE-2014-520809 ago 2014
BKBCopyD.exe in the Batch Management Packages in Yokogawa CENTUM CS 3000 through R3.09.50 and CENTUM VP through R4.03.00
23RISCO
abrir
Metasploit300
Wordpress XMLRPC DoS
CVE-2014-526606 ago 2014
The Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, doe
23RISCO
abrir
Metasploit0
HybridAuth install.php PHP Code Execution
CVE-2014-125116CRITICAL04 ago 2014
HybridAuth 2.0.9 - 2.2.2 Unauthenticated RCE via install.php Configuration Injection
63RISCO
abrir
Metasploit300
BulletProof FTP Client BPS Buffer Overflow
CVE-2014-297324 jul 2014
35RISCO
abrir
Metasploit600
Dell SonicWALL Scrutinizer 11.01 methodDetail SQL Injection
CVE-2014-497724 jul 2014
Multiple SQL injection vulnerabilities in Dell SonicWall Scrutinizer 11.0.1 allow remote authenticated users to execute
60RISCO
abrir
Metasploit200
MQAC.sys Arbitrary Write Privilege Escalation
CVE-2014-497122 jul 2014
Microsoft Windows XP SP3 does not validate addresses in certain IRP handler routines, which allows local users to write
43RISCO
abrir
Metasploit200
MS14-062 Microsoft Bluetooth Personal Area Networking (BthPan.sys) Privilege Escalation
CVE-2014-497118 jul 2014
Microsoft Windows XP SP3 does not validate addresses in certain IRP handler routines, which allows local users to write
43RISCO
abrir
Metasploit300
Advantech WebAccess dvs.ocx GetColor Buffer Overflow
CVE-2014-236417 jul 2014
Advantech WebAccess Stack-Based Buffer Overflow
68RISCO
abrir
anteriorpágina 57 / 117próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.