Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.900exploits catalogados
36.847CVEs com exploração pública
24.695testados em laboratório
3.501 exploits
Metasploit300
HP OpenView Network Node Manager ov.dll _OVBuildPath Buffer Overflow
CVE-2011-316701 nov 2011
Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 allows remote attackers to execute
50RISCO
abrir
Metasploit300
NJStar Communicator 3.00 MiniSMTP Buffer Overflow
CVE-2011-404031 out 2011
Buffer overflow in MiniSmtp 3.0.11818 in NJStar Communicator allows remote attackers to execute arbitrary code via a cra
50RISCO
abrir
Metasploit600
phpLDAPadmin query_engine Remote PHP Code Injection
CVE-2011-407524 out 2011
The masort function in lib/functions.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to execute arbitrary
50RISCO
abrir
Metasploit300
HP Power Manager 'formExportDataLogs' Buffer Overflow
CVE-2009-399919 out 2011
Stack-based buffer overflow in goform/formExportDataLogs in HP Power Manager before 4.2.10 allows remote attackers to ex
60RISCO
abrir
Metasploit300
AdminStudio LaunchHelp.dll ActiveX Arbitrary Code Execution
CVE-2011-265719 out 2011
Directory traversal vulnerability in the LaunchProcess function in the LaunchHelp.HelpLauncher.1 ActiveX control in Laun
50RISCO
abrir
Metasploit600
Java Applet Rhino Script Engine Remote Code Execution
CVE-2011-3544CRITICALsob ataque18 out 2011
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7 and 6 Update 27 and
100RISCO
abrir
Metasploit600
Java RMI Server Insecure Default Configuration Java Code Execution
CVE-2011-355615 out 2011
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and ear
60RISCO
abrir
Metasploit300
Java RMI Server Insecure Endpoint Code Execution Scanner
CVE-2011-355615 out 2011
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and ear
60RISCO
abrir
Metasploit300
Apple Safari file:// Arbitrary Code Execution
CVE-2011-323012 out 2011
Apple Safari before 5.1.1 on Mac OS X does not enforce an intended policy for file: URLs, which allows remote attackers
50RISCO
abrir
Metasploit400
ScriptFTP LIST Remote Buffer Overflow
CVE-2011-397612 out 2011
Stack-based buffer overflow in AmmSoft ScriptFTP 3.3 allows remote FTP servers to execute arbitrary code via a long file
50RISCO
abrir
Metasploit600
myBB 1.6.4 Backdoor Arbitrary Command Execution
CVE-2011-10018CRITICAL06 out 2011
myBB 1.6.4 Backdoor Arbitrary Command Execution
63RISCO
abrir
Metasploit200
PcVue 10.0 SV.UIGrdCtrl.1 'LoadObject()/SaveObject()' Trusted DWORD Vulnerability
CVE-2011-404405 out 2011
An unspecified ActiveX control in SVUIGrd.ocx in ARC Informatique PcVue 6.0 through 10.0, FrontVue, and PlantVue allows
43RISCO
abrir
Metasploit600
Spreecommerce 0.60.1 Arbitrary Command Execution
CVE-2011-10019CRITICAL05 out 2011
Spreecommerce < 0.60.2 Search Parameter RCE
63RISCO
abrir
Metasploit600
Plone and Zope XMLTools Remote Command Execution
CVE-2011-358704 out 2011
Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, a
60RISCO
abrir
Metasploit400
Cytel Studio 9.0 (CY3 File) Stack Buffer Overflow
CVE-2011-10015CRITICAL02 out 2011
Cytel Studio <= 9.0 .CY3 File Stack Buffer Overflow
43RISCO
abrir
Metasploit600
Apache Struts ParametersInterceptor Remote Code Execution
CVE-2011-392301 out 2011
Apache Struts before 2.3.1.2 allows remote attackers to bypass security protections in the ParameterInterceptor class an
60RISCO
abrir
Metasploit500
Sunway Forcecontrol SNMP NetDBServer.exe Opcode 0x57
CVE-2011-10032CRITICAL22 set 2011
Sunway Forcecontrol SNMP NetDBServer.exe Opcode 0x57
63RISCO
abrir
Metasploit600
Snortreport nmap.php/nbtscan.php Remote Command Execution
CVE-2011-10017CRITICAL19 set 2011
Snort Report nmap.php/nbtscan.php RCE
63RISCO
abrir
Metasploit300
GTA SA-MP server.cfg Buffer Overflow
CVE-2011-10014HIGH18 set 2011
GTA SA-MP server.cfg Buffer Overflow
36RISCO
abrir
Metasploit600
Measuresoft ScadaPro Remote Command Execution
CVE-2011-349716 set 2011
service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary DLL functions via the
50RISCO
abrir
Metasploit300
Beckhoff TwinCAT SCADA PLC 2.11.0.2004 DoS
CVE-2011-348613 set 2011
Beckhoff TwinCAT 2.11.0.2004 and earlier allows remote attackers to cause a denial of service via a crafted request to U
50RISCO
abrir
Metasploit400
DaqFactory HMI NETB Request Overflow
CVE-2011-349213 set 2011
Stack-based buffer overflow in Azeotech DAQFactory 5.85 build 1853 and earlier allows remote attackers to cause a denial
60RISCO
abrir
Metasploit500
CyberLink Power2Go name Attribute (p2g) Stack Buffer Overflow Exploit
CVE-2011-517112 set 2011
Multiple stack-based buffer overflows in CyberLink Power2Go 7 (build 196) and 8 (build 1031) allow remote attackers to e
50RISCO
abrir
Metasploit400
ScadaTEC ScadaPhone Stack Buffer Overflow
CVE-2011-453512 set 2011
Buffer overflow in TurboPower Abbrevia before 4.0, as used in ScadaTEC ScadaPhone 5.3.11.1230 and earlier, ScadaTEC Modb
43RISCO
abrir
Metasploit400
ACDSee FotoSlate PLP File id Parameter Overflow
CVE-2011-259512 set 2011
Multiple stack-based buffer overflows in ACDSee FotoSlate 4.0 Build 146 allow remote attackers to execute arbitrary code
50RISCO
abrir
Metasploit200
CTEK SkyRouter 4200 and 4300 Command Execution
CVE-2011-501008 set 2011
apps/a3/cfg_ethping.cgi in the Ctek SkyRouter 4200 and 4300 allows remote attackers to execute arbitrary commands via sh
50RISCO
abrir
Metasploit300
Procyon Core Server HMI Coreservice.exe Stack Buffer Overflow
CVE-2011-332208 set 2011
Core Server HMI Service (Coreservice.exe) in Scadatec Limited Procyon SCADA 1.06, and other versions before 1.14, allows
50RISCO
abrir
Metasploit300
eSignal and eSignal Pro File Parsing Buffer Overflow in QUO
CVE-2011-349406 set 2011
WinSig.exe in eSignal 10.6.2425 and earlier allows remote attackers to cause a denial of service (crash) and possibly ex
50RISCO
abrir
Metasploit300
rsyslog Long Tag Off-By-Two DoS
CVE-2011-320001 set 2011
Stack-based buffer overflow in the parseLegacySyslogMsg function in tools/syslogd.c in rsyslogd in rsyslog 4.6.x before
23RISCO
abrir
Metasploit500
Free MP3 CD Ripper 1.1 WAV File Stack Buffer Overflow
CVE-2011-516527 ago 2011
Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted rem
50RISCO
abrir
anteriorpágina 77 / 117próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.