Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.858exploits catalogados
36.825CVEs com exploração pública
24.695testados em laboratório
3.501 exploits
Metasploit600
Sophos Web Protection Appliance Interface Authenticated Arbitrary Command Execution
CVE-2014-285008 abr 2014
The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrator
50RISCO
abrir
Metasploit600
Sophos Web Protection Appliance Interface Authenticated Arbitrary Command Execution
CVE-2014-284908 abr 2014
The Change Password dialog box (change_password) in Sophos Web Appliance before 3.8.2 allows remote authenticated users
50RISCO
abrir
Metasploit300
OpenSSL Heartbeat (Heartbleed) Client Memory Exposure
CVE-2014-0160HIGHsob ataque07 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
Metasploit300
OpenSSL Heartbeat (Heartbleed) Information Leak
CVE-2014-0160HIGHsob ataque07 abr 2014
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
Metasploit600
Belkin Wemo UPnP Remote Code Execution
CVE-2019-1278004 abr 2014
The Belkin Wemo Enabled Crock-Pot allows command injection in the Wemo UPnP API via the SmartDevURL argument to the SetS
40RISCO
abrir
Metasploit600
eScan Web Management Console Command Injection
CVE-2014-125118CRITICAL04 abr 2014
eScan 5.5-2 Web Management Console Command Injection
63RISCO
abrir
Metasploit300
MS14-017 Microsoft Word RTF Object Confusion
CVE-2014-1761HIGHsob ataque01 abr 2014
Microsoft Word 2003 SP3, 2007 SP3, 2010 SP1 and SP2, 2013, and 2013 RT; Word Viewer; Office Compatibility Pack SP3; Offi
100RISCO
abrir
Metasploit300
EMC CTA v10.0 Unauthenticated XXE Arbitrary File Read
CVE-2014-064431 mar 2014
EMC Cloud Tiering Appliance (CTA) 10 through SP1 allows remote attackers to read arbitrary files via an api/login reques
50RISCO
abrir
Metasploit300
AlienVault Authenticated SQL Injection Arbitrary File Read
CVE-2013-596730 mar 2014
Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.3 and earlier
43RISCO
abrir
Metasploit300
Katello (Red Hat Satellite) users/update_roles Missing Authorization
CVE-2013-214324 mar 2014
The users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update
50RISCO
abrir
Metasploit600
FreePBX config.php Remote Code Execution
CVE-2014-190321 mar 2014
admin/libraries/view.functions.php in FreePBX 2.9 before 2.9.0.14, 2.10 before 2.10.1.15, 2.11 before 2.11.0.23, and 12
50RISCO
abrir
Metasploit600
SePortal SQLi Remote Code Execution
CVE-2008-519120 mar 2014
Multiple SQL injection vulnerabilities in SePortal 2.4 allow remote attackers to execute arbitrary SQL commands via the
43RISCO
abrir
Metasploit400
Wireshark wiretap/mpeg.c Stack Buffer Overflow
CVE-2014-229920 mar 2014
Buffer overflow in the mpeg_read function in wiretap/mpeg.c in the MPEG parser in Wireshark 1.8.x before 1.8.13 and 1.10
50RISCO
abrir
Metasploit600
Firefox WebIDL Privileged Javascript Injection
CVE-2014-151017 mar 2014
The Web IDL implementation in Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and Se
60RISCO
abrir
Metasploit600
Firefox WebIDL Privileged Javascript Injection
CVE-2014-151117 mar 2014
Mozilla Firefox before 28.0, Firefox ESR 24.x before 24.4, Thunderbird before 24.4, and SeaMonkey before 2.25 allow remo
60RISCO
abrir
Metasploit300
MS14-012 Microsoft Internet Explorer TextRange Use-After-Free
CVE-2014-030711 mar 2014
Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause
60RISCO
abrir
Metasploit200
VirtualBox 3D Acceleration Virtual Machine Escape
CVE-2014-098311 mar 2014
Multiple array index errors in programs that are automatically generated by VBox/HostServices/SharedOpenGL/crserverlib/s
38RISCO
abrir
Metasploit300
Yokogawa CENTUM CS 3000 BKCLogSvr.exe Heap Buffer Overflow
CVE-2014-078110 mar 2014
Yokogawa CENTUM CS 3000 Heap-based Buffer Overflow
48RISCO
abrir
Metasploit600
ifwatchd Privilege Escalation
CVE-2014-253310 mar 2014
/sbin/ifwatchd in BlackBerry QNX Neutrino RTOS 6.4.x and 6.5.x allows local users to gain privileges by providing an arb
38RISCO
abrir
Metasploit200
Yokogawa CENTUM CS 3000 BKHOdeq.exe Buffer Overflow
CVE-2014-078310 mar 2014
Yokogawa CENTUM CS 3000 Stack-based Buffer Overflow
75RISCO
abrir
Metasploit300
Yokogawa CENTUM CS 3000 BKBCopyD.exe Buffer Overflow
CVE-2014-078410 mar 2014
Yokogawa CENTUM CS 3000 Stack-based Buffer Overflow
68RISCO
abrir
Metasploit300
Yokogawa CS3000 BKESimmgr.exe Buffer Overflow
CVE-2014-078210 mar 2014
Yokogawa CENTUM CS 3000 Stack-based Buffer Overflow
68RISCO
abrir
Metasploit300
GetGo Download Manager HTTP Response Buffer Overflow
CVE-2014-220609 mar 2014
Stack-based buffer overflow in GetGo Download Manager 4.9.0.1982, 4.8.2.1346, 4.4.5.502, and earlier allows remote attac
50RISCO
abrir
Metasploit600
Dell KACE K1000 File Upload
CVE-2014-125113CRITICAL07 mar 2014
Dell/Quest KACE K1000 Unauthenticated File Upload RCE
43RISCO
abrir
Metasploit0
Apache Struts ClassLoader Manipulation Remote Code Execution
CVE-2014-011206 mar 2014
ParametersInterceptor in Apache Struts before 2.3.20 does not properly restrict access to the getClass method, which all
60RISCO
abrir
Metasploit0
Apache Struts ClassLoader Manipulation Remote Code Execution
CVE-2014-009406 mar 2014
The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via t
60RISCO
abrir
Metasploit0
Apache Struts ClassLoader Manipulation Remote Code Execution
CVE-2014-011406 mar 2014
Apache Commons BeanUtils, as distributed in lib/commons-beanutils-1.8.0.jar in Apache Struts 1.x through 1.3.10 and in o
60RISCO
abrir
Metasploit0
Vtiger Install Unauthenticated Remote Command Execution
CVE-2014-226805 mar 2014
views/Index.php in the Install module in vTiger 6.0 before Security Patch 2 does not properly restrict access, which all
50RISCO
abrir
Metasploit300
Joomla weblinks-categories Unauthenticated SQL Injection Arbitrary File Read
CVE-2014-798102 mar 2014
SQL injection vulnerability in Joomla! CMS 3.1.x and 3.2.x before 3.2.3 allows remote attackers to execute arbitrary SQL
18RISCO
abrir
Metasploit300
Oracle Demantra Arbitrary File Retrieval with Authentication Bypass
CVE-2013-587728 fev 2014
Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0
50RISCO
abrir
anteriorpágina 59 / 117próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.