Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.900exploits catalogados
36.847CVEs com exploração pública
24.695testados em laboratório
3.501 exploits
Metasploit300
KingView Log File Parsing Buffer Overflow
CVE-2012-471120 nov 2012
Buffer overflow in kingMess.exe 65.20.2003.10300 in WellinTech KingView 6.52, kingMess.exe 65.20.2003.10400 in KingView
50RISCO
abrir
Metasploit300
CUPS 1.6.1 Root File Read
CVE-2012-551920 nov 2012
CUPS 1.4.4, when running in certain Linux distributions such as Debian GNU/Linux, stores the web interface administrator
18RISCO
abrir
Metasploit300
NFR Agent FSFUI Record Arbitrary Remote File Access
CVE-2012-495816 nov 2012
Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to read arbitrar
60RISCO
abrir
Metasploit300
NFR Agent SRS Record Arbitrary Remote File Access
CVE-2012-495716 nov 2012
Absolute path traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to read arbi
50RISCO
abrir
Metasploit300
NFR Agent Heap Overflow Vulnerability
CVE-2012-495616 nov 2012
Heap-based buffer overflow in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to execute arbitrary co
30RISCO
abrir
Metasploit500
NFR Agent FSFUI Record File Upload RCE
CVE-2012-495916 nov 2012
Directory traversal vulnerability in NFRAgent.exe in Novell File Reporter 1.0.2 allows remote attackers to upload and ex
60RISCO
abrir
Metasploit600
NetIQ Privileged User Manager 2.3.1 ldapagnt_eval() Remote Perl Code Execution
CVE-2012-593215 nov 2012
Eval injection vulnerability in the ldapagnt_eval function in ldapagnt.dll in unifid.exe in NetIQ Privileged User Manage
50RISCO
abrir
Metasploit600
WordPress Plugin Advanced Custom Fields Remote File Inclusion
CVE-2012-10025CRITICAL14 nov 2012
WordPress Plugin Advanced Custom Fields <= 3.5.1 Remote File Inclusion
63RISCO
abrir
Metasploit600
Narcissus Image Configuration Passthru Vulnerability
CVE-2012-10033CRITICAL14 nov 2012
Narcissus backend.php Image Configuration Command Injection
63RISCO
abrir
Metasploit300
VMWare OVF Tools Format String Vulnerability
CVE-2012-356908 nov 2012
Format string vulnerability in VMware OVF Tool 2.1 on Windows, as used in VMware Workstation 8.x before 8.0.5, VMware Pl
50RISCO
abrir
Metasploit300
VMWare OVF Tools Format String Vulnerability
CVE-2012-356908 nov 2012
Format string vulnerability in VMware OVF Tool 2.1 on Windows, as used in VMware Workstation 8.x before 8.0.5, VMware Pl
50RISCO
abrir
Metasploit300
Apple QuickTime 7.7.2 TeXML Style Element font-table Field Stack Buffer Overflow
CVE-2012-375207 nov 2012
Multiple buffer overflows in Apple QuickTime before 7.7.3 allow remote attackers to execute arbitrary code or cause a de
50RISCO
abrir
Metasploit300
Apple QuickTime 7.7.2 MIME Type Buffer Overflow
CVE-2012-375307 nov 2012
Buffer overflow in the plugin in Apple QuickTime before 7.7.3 allows remote attackers to execute arbitrary code or cause
50RISCO
abrir
Metasploit300
XBMC Web Server Directory Traversal
CVE-2012-10024HIGH04 nov 2012
XBMC ≤ 11.0 Web Server Path Traversal
36RISCO
abrir
Metasploit300
Axigen Arbitrary File Read and Delete
CVE-2012-494031 out 2012
Multiple directory traversal vulnerabilities in the View Log Files component in Axigen Free Mail Server allow remote att
60RISCO
abrir
Metasploit600
Invision IP.Board unserialize() PHP Code Execution
CVE-2012-569225 out 2012
Unspecified vulnerability in admin/sources/base/core.php in Invision Power Board (aka IPB or IP.Board) 3.1.x through 3.3
43RISCO
abrir
Metasploit300
ClanSphere 2011.3 Local File Inclusion Vulnerability
CVE-2012-10034HIGH23 out 2012
ClanSphere 2011.3 Local File Inclusion via cs_lang Cookie
36RISCO
abrir
Metasploit300
Bitweaver overlay_type Directory Traversal
CVE-2012-519223 out 2012
Directory traversal vulnerability in gmap/view_overlay.php in Bitweaver 2.8.1 and earlier allows remote attackers to rea
50RISCO
abrir
Metasploit600
Mutiny Remote Command Execution
CVE-2012-300122 out 2012
Mutiny Standard before 4.5-1.12 allows remote attackers to execute arbitrary commands via the network-interface menu, re
43RISCO
abrir
Metasploit300
Drupal OpenID External Entity Injection
CVE-2012-455417 out 2012
The OpenID module in Drupal 7.x before 7.16 allows remote OpenID servers to read arbitrary files via a crafted DOCTYPE d
23RISCO
abrir
Metasploit600
Ektron 8.02 XSLT Transform Remote Code Execution
CVE-2012-535716 out 2012
Ektron Content Management System (CMS) before 8.02 SP5 uses the XslCompiledTransform class with enablescript set to true
50RISCO
abrir
Metasploit600
Sun Java Web Start Double Quote Injection
CVE-2012-153316 out 2012
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, and
50RISCO
abrir
Metasploit600
Java Applet AverageRangeStatisticImpl Remote Code Execution
CVE-2012-5076CRITICALsob ataque16 out 2012
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allow
100RISCO
abrir
Metasploit600
Java Applet JAX-WS Remote Code Execution
CVE-2012-5076CRITICALsob ataque16 out 2012
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allow
100RISCO
abrir
Metasploit600
Java Applet Method Handle Remote Code Execution
CVE-2012-508816 out 2012
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier allow
60RISCO
abrir
Metasploit500
Windows Escalate Service Permissions Local Privilege Escalation
CVE-2025-21293HIGH15 out 2012
Active Directory Domain Services Elevation of Privilege Vulnerability
41RISCO
abrir
Metasploit300
MS11-081 Microsoft Internet Explorer Option Element Use-After-Free
CVE-2011-199611 out 2012
Microsoft Internet Explorer 6 through 8 does not properly handle objects in memory, which allows remote attackers to exe
50RISCO
abrir
Metasploit600
Project Pier Arbitrary File Upload Vulnerability
CVE-2012-10036CRITICAL08 out 2012
Project Pier <= 0.8.8 Arbitrary File Upload RCE
63RISCO
abrir
Metasploit600
PhpTax pfilez Parameter Exec Remote Code Injection
CVE-2012-10037CRITICAL08 out 2012
PhpTax pfilez Parameter Exec Remote Code Injection
63RISCO
abrir
Metasploit0
D-Link DIR-605L Captcha Handling Buffer Overflow
CVE-2012-10021CRITICAL08 out 2012
D-Link DIR-605L Captcha Handling Buffer Overflow
63RISCO
abrir
anteriorpágina 70 / 117próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.