Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.836exploits catalogados
32.133CVEs com exploração pública
1.932testados em laboratório
3.462 exploits
Metasploit300
Apple Safari file:// Arbitrary Code Execution
CVE-2011-323012 out 2011
Apple Safari before 5.1.1 on Mac OS X does not enforce an intended policy for file: URLs, which allows remote attackers
50RISCO
abrir
Metasploit400
ScriptFTP LIST Remote Buffer Overflow
CVE-2011-397612 out 2011
Stack-based buffer overflow in AmmSoft ScriptFTP 3.3 allows remote FTP servers to execute arbitrary code via a long file
50RISCO
abrir
Metasploit600
myBB 1.6.4 Backdoor Arbitrary Command Execution
CVE-2011-10018CRITICAL06 out 2011
myBB 1.6.4 Backdoor Arbitrary Command Execution
63RISCO
abrir
Metasploit200
PcVue 10.0 SV.UIGrdCtrl.1 'LoadObject()/SaveObject()' Trusted DWORD Vulnerability
CVE-2011-404405 out 2011
An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows
43RISCO
abrir
Metasploit600
Spreecommerce 0.60.1 Arbitrary Command Execution
CVE-2011-10019CRITICAL05 out 2011
Spreecommerce < 0.60.2 Search Parameter RCE
63RISCO
abrir
Metasploit600
Plone and Zope XMLTools Remote Command Execution
CVE-2011-358704 out 2011
Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, a
60RISCO
abrir
Metasploit400
Cytel Studio 9.0 (CY3 File) Stack Buffer Overflow
CVE-2011-10015CRITICAL02 out 2011
Cytel Studio <= 9.0 .CY3 File Stack Buffer Overflow
43RISCO
abrir
Metasploit600
Apache Struts ParametersInterceptor Remote Code Execution
CVE-2011-392301 out 2011
Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class an
60RISCO
abrir
Metasploit500
Sunway Forcecontrol SNMP NetDBServer.exe Opcode 0x57
CVE-2011-10032CRITICAL22 set 2011
Sunway Forcecontrol SNMP NetDBServer.exe Opcode 0x57
63RISCO
abrir
Metasploit600
Snortreport nmap.php/nbtscan.php Remote Command Execution
CVE-2011-10017CRITICAL19 set 2011
Snort Report nmap.php/nbtscan.php RCE
63RISCO
abrir
Metasploit300
GTA SA-MP server.cfg Buffer Overflow
CVE-2011-10014HIGH18 set 2011
GTA SA-MP server.cfg Buffer Overflow
36RISCO
abrir
Metasploit600
Measuresoft ScadaPro Remote Command Execution
CVE-2011-349716 set 2011
service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary DLL functions via the
50RISCO
abrir
Metasploit300
Beckhoff TwinCAT SCADA PLC 2.11.0.2004 DoS
CVE-2011-348613 set 2011
Beckhoff TwinCAT 2.11.0.2004 and earlier allows remote attackers to cause a denial of service via a crafted request to U
50RISCO
abrir
Metasploit400
DaqFactory HMI NETB Request Overflow
CVE-2011-349213 set 2011
Stack-based buffer overflow in Azeotech DAQFactory 5.85 build 1853 and earlier allows remote attackers to cause a denial
60RISCO
abrir
Metasploit400
ScadaTEC ScadaPhone Stack Buffer Overflow
CVE-2011-453512 set 2011
Buffer overflow in TurboPower Abbrevia before 4.0, as used in ScadaTEC ScadaPhone 5.3.11.1230 and earlier, ScadaTEC Modb
43RISCO
abrir
Metasploit500
CyberLink Power2Go name Attribute (p2g) Stack Buffer Overflow Exploit
CVE-2011-517112 set 2011
Multiple stack-based buffer overflows in CyberLink Power2Go 7 (build 196) and 8 (build 1031) allow remote attackers to e
50RISCO
abrir
Metasploit400
ACDSee FotoSlate PLP File id Parameter Overflow
CVE-2011-259512 set 2011
Multiple stack-based buffer overflows in ACDSee FotoSlate 4.0 Build 146 allow remote attackers to execute arbitrary code
50RISCO
abrir
Metasploit300
Procyon Core Server HMI Coreservice.exe Stack Buffer Overflow
CVE-2011-332208 set 2011
Core Server HMI Service (Coreservice.exe) in Scadatec Limited Procyon SCADA 1.06, and other versions before 1.14, allows
50RISCO
abrir
Metasploit200
CTEK SkyRouter 4200 and 4300 Command Execution
CVE-2011-501008 set 2011
apps/a3/cfg_ethping.cgi in the Ctek SkyRouter 4200 and 4300 allows remote attackers to execute arbitrary commands via sh
50RISCO
abrir
Metasploit300
eSignal and eSignal Pro File Parsing Buffer Overflow in QUO
CVE-2011-349406 set 2011
WinSig.exe in eSignal 10.6.2425 and earlier allows remote attackers to cause a denial of service (crash) and possibly ex
50RISCO
abrir
Metasploit300
rsyslog Long Tag Off-By-Two DoS
CVE-2011-320001 set 2011
Stack-based buffer overflow in the parseLegacySyslogMsg function in tools/syslogd.c in rsyslogd in rsyslog 4.6.x before
23RISCO
abrir
Metasploit500
Free MP3 CD Ripper 1.1 WAV File Stack Buffer Overflow
CVE-2011-516527 ago 2011
Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted rem
50RISCO
abrir
Metasploit300
Apache Range Header DoS (Apache Killer)
CVE-2011-319219 ago 2011
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attac
60RISCO
abrir
Metasploit500
HP Easy Printer Care XMLSimpleAccessor Class ActiveX Control Remote Code Execution
CVE-2011-240416 ago 2011
A certain ActiveX control in HPTicketMgr.dll in HP Easy Printer Care Software 2.5 and earlier allows remote attackers to
60RISCO
abrir
Metasploit200
RealNetworks Realplayer QCP Parsing Heap Overflow
CVE-2011-295016 ago 2011
Heap-based buffer overflow in qcpfformat.dll in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5 and
43RISCO
abrir
Metasploit600
ktsuss suid Privilege Escalation
CVE-2011-292113 ago 2011
ktsuss versions 1.4 and prior has the uid set to root and does not drop privileges prior to executing user specified com
60RISCO
abrir
Metasploit300
TeeChart Professional ActiveX Control Trusted Integer Dereference
CVE-2011-403411 ago 2011
Buffer overflow in the Steema TeeChart ActiveX control, as used in Schneider Electric Vijeo Historian 4.30 and earlier,
23RISCO
abrir
Metasploit300
MS11-021 Microsoft Office 2007 Excel .xlb Buffer Overflow
CVE-2011-010509 ago 2011
Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac obtain a certain leng
60RISCO
abrir
Metasploit300
Adobe Flash Player MP4 SequenceParameterSetNALUnit Buffer Overflow
CVE-2011-214009 ago 2011
Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3 on Android, and Adob
60RISCO
abrir
Metasploit400
Apple QuickTime PICT PnSize Buffer Overflow
CVE-2011-025708 ago 2011
Integer signedness error in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a deni
50RISCO
abrir
anteriorpágina 76 / 116próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.