Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.900exploits catalogados
36.847CVEs com exploração pública
24.695testados em laboratório
3.501 exploits
Metasploit600
Firefox 17.0.1 Flash Privileged Code Injection
CVE-2013-075808 jan 2013
Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderb
60RISCO
abrir
Metasploit600
Movable Type 4.2x, 4.3x Web Upgrade Remote Code Execution
CVE-2013-020907 jan 2013
lib/MT/Upgrade.pm in mt-upgrade.cgi in Movable Type 4.2x and 4.3x through 4.38 does not require authentication for reque
50RISCO
abrir
Metasploit600
Movable Type 4.2x, 4.3x Web Upgrade Remote Code Execution
CVE-2012-631507 jan 2013
35RISCO
abrir
Metasploit300
Foxit Reader Plugin URL Processing Buffer Overflow
CVE-2013-10068CRITICAL07 jan 2013
Foxit Reader <= 5.4.5.0114 Plugin URL Processing Buffer Overflow
43RISCO
abrir
Metasploit600
Ruby on Rails XML Processor YAML Deserialization Code Execution
CVE-2013-015607 jan 2013
active_support/core_ext/hash/conversions.rb in Ruby on Rails before 2.3.15, 3.0.x before 3.0.19, 3.1.x before 3.1.10, an
60RISCO
abrir
Metasploit300
WordPress Plugin Google Document Embedder Arbitrary File Disclosure
CVE-2012-491503 jan 2013
Directory traversal vulnerability in the Google Doc Embedder plugin before 2.5.4 for WordPress allows remote attackers t
50RISCO
abrir
Metasploit300
Simple Web Server 2.3-RC1 Directory Traversal
CVE-2002-186403 jan 2013
Directory traversal vulnerability in Simple Web Server (SWS) 0.0.4 through 0.1.0 allows remote attackers to read arbitra
23RISCO
abrir
Metasploit600
eXtplorer v2.1 Arbitrary File Upload Vulnerability
CVE-2012-671031 dez 2012
ext_find_user in eXtplorer through 2.1.2 allows remote attackers to bypass authentication via a password[]= (aka an empt
23RISCO
abrir
Metasploit0
MoinMoin twikidraw Action Traversal File Upload
CVE-2012-608130 dez 2012
Multiple unrestricted file upload vulnerabilities in the (1) twikidraw (action/twikidraw.py) and (2) anywikidraw (action
50RISCO
abrir
Metasploit600
Wordpress Reflex Gallery Upload Vulnerability
CVE-2015-413330 dez 2012
Unrestricted file upload vulnerability in admin/scripts/FileUploader/php.php in the ReFlex Gallery plugin before 3.1.4 f
50RISCO
abrir
Metasploit300
MS13-008 Microsoft Internet Explorer CButton Object Use-After-Free Vulnerability
CVE-2012-4792HIGHsob ataque27 dez 2012
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary cod
100RISCO
abrir
Metasploit200
Nvidia (nvsvc) Display Driver Service Local Privilege Escalation
CVE-2013-010925 dez 2012
The NVIDIA driver before 307.78, and Release 310 before 311.00, in the NVIDIA Display Driver service on Windows does not
38RISCO
abrir
Metasploit600
Android Browser and WebView addJavascriptInterface Code Execution
CVE-2013-471021 dez 2012
Android 3.0 through 4.1.x on Disney Mobile, eAccess, KDDI, NTT DOCOMO, SoftBank, and other devices does not properly imp
50RISCO
abrir
Metasploit600
Android Browser and WebView addJavascriptInterface Code Execution
CVE-2012-663621 dez 2012
The Android API before 17 does not properly restrict the WebView.addJavascriptInterface method, which allows remote atta
50RISCO
abrir
Metasploit600
TWiki MAKETEXT Remote Command Execution
CVE-2012-632915 dez 2012
The _compile function in Maketext.pm in the Locale::Maketext implementation in Perl before 5.17.7 does not properly hand
50RISCO
abrir
Metasploit300
RealPlayer RealMedia File Handling Buffer Overflow
CVE-2012-569114 dez 2012
Buffer overflow in RealNetworks RealPlayer before 16.0.0.282 and RealPlayer SP 1.0 through 1.1.5 allows remote attackers
50RISCO
abrir
Metasploit300
Novell eDirectory 8 Buffer Overflow
CVE-2012-043212 dez 2012
Stack-based buffer overflow in the Novell NCP implementation in NetIQ eDirectory 8.8.7.x before 8.8.7.2 allows remote at
50RISCO
abrir
Metasploit500
Nagios3 history.cgi Host Command Execution
CVE-2012-609609 dez 2012
Multiple stack-based buffer overflows in the get_history function in history.cgi in Nagios Core before 3.4.4, and Icinga
50RISCO
abrir
Metasploit600
FreeFloat FTP Server Arbitrary File Upload
CVE-2012-10030CRITICAL07 dez 2012
FreeFloat FTP Server Arbitrary File Upload
63RISCO
abrir
Metasploit400
Netwin SurgeFTP Remote Command Execution
CVE-2012-10028HIGH06 dez 2012
Netwin SurgeFTP <= v23c8 Authenticated RCE
36RISCO
abrir
Metasploit600
OpenSIS 'modname' PHP Code Execution
CVE-2013-134904 dez 2012
Eval injection vulnerability in ajax.php in openSIS 4.5 through 5.2 allows remote attackers to execute arbitrary PHP cod
43RISCO
abrir
Metasploit600
Foswiki MAKETEXT Remote Command Execution
CVE-2012-632903 dez 2012
The _compile function in Maketext.pm in the Locale::Maketext implementation in Perl before 5.17.7 does not properly hand
50RISCO
abrir
Metasploit600
Oracle MySQL for Microsoft Windows MOF Execution
CVE-2012-561301 dez 2012
MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the
50RISCO
abrir
Metasploit600
Tectia SSH USERAUTH Change Request Password Reset Vulnerability
CVE-2012-597501 dez 2012
The SSH USERAUTH CHANGE REQUEST feature in SSH Tectia Server 6.0.4 through 6.0.20, 6.1.0 through 6.1.12, 6.2.0 through 6
50RISCO
abrir
Metasploit300
Android Stock Browser Iframe DOS
CVE-2012-630101 dez 2012
The Browser application in Android 4.0.3 allows remote attackers to cause a denial of service (application crash) via a
18RISCO
abrir
Metasploit600
Oracle MySQL for Microsoft Windows FILE Privilege Abuse
CVE-2012-561301 dez 2012
MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the
50RISCO
abrir
Metasploit300
Symantec Messaging Gateway 9.5 Log File Download Vulnerability
CVE-2012-434730 nov 2012
Multiple directory traversal vulnerabilities in the management console in Symantec Messaging Gateway (SMG) 9.5.x allow r
50RISCO
abrir
Metasploit600
Nagios XI Network Monitor Graph Explorer Component Command Injection
CVE-2012-10029HIGH30 nov 2012
Nagios XI Network Monitor Graph Explorer Component < 1.3 Authenticated Command Injection
36RISCO
abrir
Metasploit600
MS13-005 HWND_BROADCAST Low to Medium Integrity Privilege Escalation
CVE-2013-000827 nov 2012
win32k.sys in the kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2, R2, and R2 SP1, Windows 7
43RISCO
abrir
Metasploit600
Maxthon3 about:history XCS Trusted Zone Code Execution
CVE-2012-10032HIGH26 nov 2012
Maxthon3 about:history XCS Trusted Zone Code Execution
36RISCO
abrir
anteriorpágina 69 / 117próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.