Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.900exploits catalogados
36.847CVEs com exploração pública
24.695testados em laboratório
3.501 exploits
Metasploit500
Turbo FTP Server 1.30.823 PORT Overflow
CVE-2012-10035CRITICAL03 out 2012
Turbo FTP Server 1.30.823/826 PORT Command Buffer Overflow
43RISCO
abrir
Metasploit300
phpMyAdmin 3.5.2.2 server_sync.php Backdoor
CVE-2012-515925 set 2012
phpMyAdmin 3.5.2.2, as distributed by the cdnetworks-kr-1 mirror during an unspecified time frame in 2012, contains an e
60RISCO
abrir
Metasploit600
Kloxo Local Privilege Escalation
CVE-2012-10022HIGH18 set 2012
Kloxo <= 6.1.12 Local Privilege Escalation
36RISCO
abrir
Metasploit400
MS12-063 Microsoft Internet Explorer execCommand Use-After-Free Vulnerability
CVE-2012-4969HIGHsob ataque14 set 2012
Use-after-free vulnerability in the CMshtmlEd::Exec function in mshtml.dll in Microsoft Internet Explorer 6 through 9 al
100RISCO
abrir
Metasploit600
Auxilium RateMyPet Arbitrary File Upload Vulnerability
CVE-2012-10038CRITICAL14 set 2012
Auxilium RateMyPet Arbitrary File Upload RCE
63RISCO
abrir
Metasploit600
ZEN Load Balancer Filelog Command Execution
CVE-2012-10039CRITICAL14 set 2012
ZEN Load Balancer Filelog Command Execution
63RISCO
abrir
Metasploit300
Webmin edit_html.cgi file Parameter Traversal Arbitrary File Access
CVE-2012-298306 set 2012
file/edit_html.cgi in Webmin 1.590 and earlier does not perform an authorization check before showing a file's unedited
23RISCO
abrir
Metasploit600
Webmin /file/show.cgi Remote Command Execution
CVE-2012-298206 set 2012
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid
50RISCO
abrir
Metasploit600
Openfiler v2.x NetworkCard Command Execution
CVE-2012-10040CRITICAL04 set 2012
Openfiler v2.x NetworkCard Command Execution
63RISCO
abrir
Metasploit300
EMC Networker Format String
CVE-2012-228829 ago 2012
Format string vulnerability in the nsrd RPC service in EMC NetWorker 7.6.3 and 7.6.4 before 7.6.4.1, and 8.0 before 8.0.
50RISCO
abrir
Metasploit300
HP Intelligent Management Center UAM Buffer Overflow
CVE-2012-327429 ago 2012
Stack-based buffer overflow in uam.exe in the User Access Manager (UAM) component in HP Intelligent Management Center (I
50RISCO
abrir
Metasploit400
HP SiteScope Remote Code Execution
CVE-2012-326129 ago 2012
Unspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbit
30RISCO
abrir
Metasploit400
HP SiteScope Remote Code Execution
CVE-2012-326029 ago 2012
Unspecified vulnerability in a SOAP feature in HP SiteScope 11.10 through 11.12 allows remote attackers to execute arbit
30RISCO
abrir
Metasploit300
ActiveFax (ActFax) 4.3 Client Importer Buffer Overflow
CVE-2012-10043CRITICAL28 ago 2012
ActFax 4.32 Client Importer Buffer Overflow
43RISCO
abrir
Metasploit600
Symantec Messaging Gateway 9.5 Default SSH Password Vulnerability
CVE-2012-357927 ago 2012
Symantec Messaging Gateway (SMG) before 10.0 has a default password for an unspecified account, which makes it easier fo
50RISCO
abrir
Metasploit600
Java 7 Applet Remote Code Execution
CVE-2012-4681CRITICALsob ataqueransomware26 ago 2012
Multiple vulnerabilities in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 6 and earlier allow
100RISCO
abrir
Metasploit600
XODA 0.4.5 Arbitrary PHP File Upload Vulnerability
CVE-2012-10045CRITICAL21 ago 2012
XODA 0.4.5 Arbitrary PHP File Upload
63RISCO
abrir
Metasploit600
E-Mail Security Virtual Appliance learn-msg.cgi Command Injection
CVE-2012-10046CRITICAL16 ago 2012
E-Mail Security Virtual Appliance learn-msg.cgi Command Injection
63RISCO
abrir
Metasploit600
TestLink v1.9.3 Arbitrary File Upload Vulnerability
CVE-2012-093813 ago 2012
Multiple SQL injection vulnerabilities in TestLink 1.9.3, 1.8.5b, and earlier allow remote authenticated users with cert
18RISCO
abrir
Metasploit600
WAN Emulator v2.3 Command Execution
CVE-2012-10041CRITICAL12 ago 2012
WAN Emulator v2.3 Command Execution
63RISCO
abrir
Metasploit600
Viscosity setuid-set ViscosityHelper Privilege Escalation
CVE-2012-428412 ago 2012
A Privilege Escalation vulnerability exists in Viscosity 1.4.1 on Mac OS X due to a path name validation issue in the se
50RISCO
abrir
Metasploit600
Setuid Tunnelblick Privilege Escalation
CVE-2012-348511 ago 2012
Tunnelblick 3.3beta20 and earlier relies on argv[0] to determine the name of an appropriate (1) kernel module pathname o
38RISCO
abrir
Metasploit600
MobileCartly 1.0 Arbitrary File Creation Vulnerability
CVE-2012-10044CRITICAL10 ago 2012
MobileCartly 1.0 savepage.php Arbitrary File Creation
63RISCO
abrir
Metasploit300
Adobe Flash Player 11.3 Kern Table Parsing Integer Overflow
CVE-2012-1535HIGHsob ataque09 ago 2012
Unspecified vulnerability in Adobe Flash Player before 11.3.300.271 on Windows and Mac OS X and before 11.2.202.238 on L
100RISCO
abrir
Metasploit600
Cyclope Employee Surveillance Solution v6 SQL Injection
CVE-2012-10047CRITICAL08 ago 2012
Cyclope Employee Surveillance Solution v6.x SQL Injection
43RISCO
abrir
Metasploit400
Zenoss 3 showDaemonXMLConfig Command Execution
CVE-2012-10048HIGH30 jul 2012
Zenoss 3.x showDaemonXMLConfig Command Execution
36RISCO
abrir
Metasploit300
Ubisoft uplay 2.0.3 ActiveX Control Arbitrary Code Execution
CVE-2012-417729 jul 2012
The web browser plugin for Ubisoft Uplay PC before 2.0.4 allows remote attackers to execute arbitrary programs via the -
50RISCO
abrir
Metasploit300
Sysax Multi Server 5.64 Create Folder Buffer Overflow
CVE-2012-653029 jul 2012
Stack-based buffer overflow in Sysax Multi Server before 5.52, when HTTP is enabled, allows remote authenticated users w
50RISCO
abrir
Metasploit300
Plixer Scrutinizer NetFlow and sFlow Analyzer HTTP Authentication Bypass
CVE-2012-262627 jul 2012
cgi-bin/admin.cgi in the web console in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) before 9.5.0 does not requir
50RISCO
abrir
Metasploit600
Plixer Scrutinizer NetFlow and sFlow Analyzer 9 Default MySQL Credential
CVE-2012-395127 jul 2012
The MySQL component in Plixer Scrutinizer (aka Dell SonicWALL Scrutinizer) 9.0.1.19899 and earlier has a default passwor
50RISCO
abrir
anteriorpágina 71 / 117próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.