Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.900exploits catalogados
36.847CVEs com exploração pública
24.695testados em laboratório
3.501 exploits
Metasploit600
F5 BIG-IP SSH Private Key Exposure
CVE-2012-149311 jun 2012
F5 BIG-IP appliances 9.x before 9.4.8-HF5, 10.x before 10.2.4, 11.0.x before 11.0.0-HF2, and 11.1.x before 11.1.0-HF3, a
50RISCO
abrir
Metasploit300
MySQL Authentication Bypass Password Dump
CVE-2012-212209 jun 2012
sql/password.c in Oracle MySQL 5.1.x before 5.1.63, 5.5.x before 5.5.24, and 5.6.x before 5.6.6, and MariaDB 5.1.x befor
60RISCO
abrir
Metasploit400
ComSndFTP v1.3.7 Beta USER Format String (Write4) Vulnerability
CVE-2012-10055CRITICAL08 jun 2012
ComSndFTP v1.3.7 Beta USER Format String RCE
63RISCO
abrir
Metasploit300
Photodex ProShow Producer 5.0.3256 load File Handling Buffer Overflow
CVE-2012-10051HIGH06 jun 2012
Photodex ProShow Producer 5.0.3256 load File Handling Buffer Overflow
36RISCO
abrir
Metasploit600
Java Applet Field Bytecode Verifier Cache Remote Code Execution
CVE-2012-1723CRITICALsob ataqueransomware06 jun 2012
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 update 4 and earlier, 6 up
100RISCO
abrir
Metasploit600
WordPress Plugin Foxypress uploadify.php Arbitrary Code Execution
CVE-2012-10020CRITICAL05 jun 2012
FoxyPress <= 0.4.2.1 - Arbitrary File Upload
63RISCO
abrir
Metasploit300
Sielco Sistemi Winlog Buffer Overflow 2.07.14 - 2.07.16
CVE-2012-381504 jun 2012
Buffer overflow in RunTime.exe in Sielco Sistemi Winlog Pro SCADA before 2.07.18 and Winlog Lite SCADA before 2.07.18 al
50RISCO
abrir
Metasploit300
IBM Lotus iNotes dwa85W ActiveX Buffer Overflow
CVE-2012-217501 jun 2012
Buffer overflow in the Attachment_Times method in a certain ActiveX control in dwa85W.dll in IBM Lotus iNotes 8.5.x befo
43RISCO
abrir
Metasploit600
Active Collab "chat module" Remote PHP Code Injection Exploit
CVE-2012-655430 mai 2012
functions/html_to_text.php in the Chat module before 1.5.2 for activeCollab allows remote authenticated users to execute
43RISCO
abrir
Metasploit600
PHP Volunteer Management System v1.0.2 Arbitrary File Upload Vulnerability
CVE-2012-10056HIGH28 mai 2012
PHP Volunteer Management System 1.0.2 Arbitrary File Upload
36RISCO
abrir
Metasploit600
WordPress Asset-Manager PHP File Upload Vulnerability
CVE-2012-10026CRITICAL26 mai 2012
WordPress Plugin Asset-Manager <= 2.0 PHP File Upload
63RISCO
abrir
Metasploit300
IBM Lotus QuickR qp2 ActiveX Buffer Overflow
CVE-2012-217623 mai 2012
Multiple stack-based buffer overflows in a certain ActiveX control in qp2.cab in IBM Lotus Quickr 8.2 before 8.2.0.27-00
50RISCO
abrir
Metasploit300
IBM Rational ClearQuest CQOle Remote Code Execution
CVE-2012-070819 mai 2012
Heap-based buffer overflow in the Ole API in the CQOle ActiveX control in cqole.dll in IBM Rational ClearQuest 7.1.1 bef
50RISCO
abrir
Metasploit300
GIMP script-fu Server Buffer Overflow
CVE-2012-276318 mai 2012
Buffer overflow in the readstr_upto function in plug-ins/script-fu/tinyscheme/scheme.c in GIMP 2.6.12 and earlier, and p
60RISCO
abrir
Metasploit600
Symantec Web Gateway 5.0.2.8 ipchange.php Command Injection
CVE-2012-029717 mai 2012
The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts,
60RISCO
abrir
Metasploit600
Symantec Web Gateway 5.0.2.8 Arbitrary PHP File Upload Vulnerability
CVE-2012-029917 mai 2012
The file-management scripts in the management GUI in Symantec Web Gateway 5.0.x before 5.0.3 allow remote attackers to u
50RISCO
abrir
Metasploit600
Symantec Web Gateway 5.0.2.8 relfile File Inclusion Vulnerability
CVE-2012-029717 mai 2012
The management GUI in Symantec Web Gateway 5.0.x before 5.0.3 does not properly restrict access to application scripts,
60RISCO
abrir
Metasploit300
Lattice Semiconductor ispVM System XCF File Handling Overflow
CVE-2012-10057HIGH16 mai 2012
Lattice Semiconductor ispVM System 18.0.2 XCF File Handling Buffer Overflow
36RISCO
abrir
Metasploit300
Lattice Semiconductor PAC-Designer 6.21 Symbol Value Buffer Overflow
CVE-2012-291516 mai 2012
Stack-based buffer overflow in Lattice Semiconductor PAC-Designer 6.2.1344 allows remote attackers to execute arbitrary
43RISCO
abrir
Metasploit300
Apple QuickTime TeXML Style Element Stack Buffer Overflow
CVE-2012-066315 mai 2012
Multiple stack-based buffer overflows in Apple QuickTime before 7.7.2 on Windows allow remote attackers to execute arbit
43RISCO
abrir
Metasploit300
SAP NetWeaver Dispatcher DiagTraceR3Info Buffer Overflow
CVE-2012-261108 mai 2012
The DiagTraceR3Info function in the Dialog processor in disp+work.exe 7010.29.15.58313 and 7200.70.18.23869 in the Dispa
50RISCO
abrir
Metasploit300
PHP apache_request_headers Function Buffer Overflow
CVE-2012-232908 mai 2012
Buffer overflow in the apache_request_headers function in sapi/cgi/cgi_main.c in PHP 5.4.x before 5.4.3 allows remote at
50RISCO
abrir
Metasploit300
Adobe Flash Player Object Type Confusion
CVE-2012-077904 mai 2012
Adobe Flash Player before 10.3.183.19 and 11.x before 11.2.202.235 on Windows, Mac OS X, and Linux; before 11.1.111.9 on
60RISCO
abrir
Metasploit600
PHP CGI Argument Injection
CVE-2012-1823CRITICALsob ataque03 mai 2012
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RISCO
abrir
Metasploit600
McAfee Virtual Technician MVTControl 6.3.0.1911 GetObject Vulnerability
CVE-2012-459830 abr 2012
An unspecified ActiveX control in McAfee Virtual Technician (MVT) before 6.4, and ePO-MVT, allows remote attackers to ex
43RISCO
abrir
Metasploit300
InduSoft Web Studio ISSymbol.ocx InternationalSeparator() Heap Overflow
CVE-2011-034028 abr 2012
Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol v
50RISCO
abrir
Metasploit600
WebCalendar 1.2.4 Pre-Auth Remote Code Injection
CVE-2012-149523 abr 2012
install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user
60RISCO
abrir
Metasploit300
Samsung NET-i Viewer Multiple ActiveX BackupToAvi() Remote Overflow
CVE-2012-433321 abr 2012
Multiple stack-based buffer overflows in the BackupToAvi method in the (1) UMS_Ctrl 1.5.1.1 and (2) UMS_Ctrl_STW 2.0.1.0
50RISCO
abrir
Metasploit300
Oracle AutoVue ActiveX Control SetMarkupMode Buffer Overflow
CVE-2012-054918 abr 2012
Unspecified vulnerability in the Oracle AutoVue Office component in Oracle Supply Chain Products Suite 20.1.1 allows rem
50RISCO
abrir
Metasploit300
Oracle TNS Listener Checker
CVE-2012-167518 abr 2012
The TNS Listener, as used in Oracle Database 11g 11.1.0.7, 11.2.0.2, and 11.2.0.3, and 10g 10.2.0.3, 10.2.0.4, and 10.2.
40RISCO
abrir
anteriorpágina 73 / 117próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.