Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.900exploits catalogados
36.847CVEs com exploração pública
24.695testados em laboratório
3.501 exploits
Metasploit300
Apache Range Header DoS (Apache Killer)
CVE-2011-319219 ago 2011
The byterange filter in the Apache HTTP Server 1.3.x, 2.0.x through 2.0.64, and 2.2.x through 2.2.19 allows remote attac
60RISCO
abrir
Metasploit500
HP Easy Printer Care XMLSimpleAccessor Class ActiveX Control Remote Code Execution
CVE-2011-240416 ago 2011
A certain ActiveX control in HPTicketMgr.dll in HP Easy Printer Care Software 2.5 and earlier allows remote attackers to
60RISCO
abrir
Metasploit200
RealNetworks Realplayer QCP Parsing Heap Overflow
CVE-2011-295016 ago 2011
Heap-based buffer overflow in qcpfformat.dll in RealNetworks RealPlayer 11.0 through 11.1 and 14.0.0 through 14.0.5 and
43RISCO
abrir
Metasploit600
ktsuss suid Privilege Escalation
CVE-2011-292113 ago 2011
ktsuss versions 1.4 and prior has the uid set to root and does not drop privileges prior to executing user specified com
60RISCO
abrir
Metasploit300
TeeChart Professional ActiveX Control Trusted Integer Dereference
CVE-2011-403411 ago 2011
Buffer overflow in the Steema TeeChart ActiveX control, as used in Schneider Electric Vijeo Historian 4.30 and earlier,
23RISCO
abrir
Metasploit300
MS11-021 Microsoft Office 2007 Excel .xlb Buffer Overflow
CVE-2011-010509 ago 2011
Microsoft Excel 2002 SP3, Office 2004 and 2008 for Mac, and Open XML File Format Converter for Mac obtain a certain leng
60RISCO
abrir
Metasploit300
Adobe Flash Player MP4 SequenceParameterSetNALUnit Buffer Overflow
CVE-2011-214009 ago 2011
Adobe Flash Player before 10.3.183.5 on Windows, Mac OS X, Linux, and Solaris and before 10.3.186.3 on Android, and Adob
60RISCO
abrir
Metasploit400
Apple QuickTime PICT PnSize Buffer Overflow
CVE-2011-025708 ago 2011
Integer signedness error in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a deni
50RISCO
abrir
Metasploit300
BisonWare BisonFTP Server Buffer Overflow
CVE-1999-151007 ago 2011
Buffer overflows in Bisonware FTP server prior to 4.1 allow remote attackers to cause a denial of service, and possibly
50RISCO
abrir
Metasploit600
Sun/Oracle GlassFish Server Authenticated Code Execution
CVE-2011-080704 ago 2011
Unspecified vulnerability in Oracle Sun GlassFish Enterprise Server 2.1, 2.1.1, and 3.0.1, and Sun Java System Applicati
50RISCO
abrir
Metasploit600
CA Arcserve D2D GWT RPC Credential Information Disclosure
CVE-2011-301125 jul 2011
BaseServiceImpl.class in CA ARCserve D2D r15 does not properly handle sessions, which allows remote attackers to obtain
60RISCO
abrir
Metasploit600
Apple Safari Webkit libxslt Arbitrary File Creation
CVE-2011-177420 jul 2011
WebKit in Apple Safari before 5.0.6 has improper libxslt security settings, which allows remote attackers to create arbi
50RISCO
abrir
Metasploit600
Wireshark console.lua Pre-Loading Script Execution
CVE-2011-336018 jul 2011
Untrusted search path vulnerability in Wireshark 1.4.x before 1.4.9 and 1.6.x before 1.6.2 allows local users to gain pr
50RISCO
abrir
Metasploit300
Citrix Gateway ActiveX Control Stack Based Buffer Overflow Vulnerability
CVE-2011-288214 jul 2011
Stack-based buffer overflow in the NSEPA.NsepaCtrl.1 ActiveX control in nsepa.ocx in Citrix Access Gateway Enterprise Ed
50RISCO
abrir
Metasploit600
LifeSize Room Command Injection
CVE-2011-276313 jul 2011
The web interface on the LifeSize Room appliance LS_RM1_3.5.3 (11) and 4.7.18 allows remote attackers to execute arbitra
50RISCO
abrir
Metasploit600
WeBid converter.php Remote PHP Code Injection
CVE-2011-10011CRITICAL05 jul 2011
WeBid 1.0.2 converter.php Remote PHP Code Injection
63RISCO
abrir
Metasploit600
VSFTPD 2.3.4 Backdoor Command Execution
CVE-2011-252303 jul 2011
vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.
60RISCO
abrir
Metasploit300
Kaillera 0.86 Server Denial of Service
CVE-2011-10020HIGH02 jul 2011
Kaillera 0.86 Server DoS via Malformed UDP Packet
36RISCO
abrir
Metasploit400
HP OmniInet.exe Opcode 20 Buffer Overflow
CVE-2011-186529 jun 2011
Multiple stack-based buffer overflows in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allow
60RISCO
abrir
Metasploit500
HP OmniInet.exe Opcode 27 Buffer Overflow
CVE-2011-186529 jun 2011
Multiple stack-based buffer overflows in the inet service in HP OpenView Storage Data Protector 6.00 through 6.20 allow
60RISCO
abrir
Metasploit300
Mozilla Firefox Array.reduceRight() Integer Overflow
CVE-2011-237121 jun 2011
Integer overflow in the Array.reduceRight method in Mozilla Firefox before 3.6.18 and 4.x through 4.0.1, Thunderbird bef
60RISCO
abrir
Metasploit300
MS11-050 IE mshtml!CObjectElement Use After Free
CVE-2011-126016 jun 2011
Microsoft Internet Explorer 8 and 9 does not properly handle objects in memory, which allows remote attackers to execute
50RISCO
abrir
Metasploit600
Cisco AnyConnect VPN Client ActiveX URL Property Download and Execute
CVE-2011-203901 jun 2011
The helper application in Cisco AnyConnect Secure Mobility Client (formerly AnyConnect VPN Client) before 2.3.185 on Win
50RISCO
abrir
Metasploit400
IBM Tivoli Endpoint Manager POST Query Buffer Overflow
CVE-2011-122031 mai 2011
Stack-based buffer overflow in lcfd.exe in Tivoli Endpoint in IBM Tivoli Management Framework 3.7.1, 4.1, 4.1.1, and 4.3
50RISCO
abrir
Metasploit300
Sybase Easerver 6.3 Directory Traversal
CVE-2011-247425 mai 2011
Directory traversal vulnerability in the HTTP Server in Sybase EAServer 6.3.1 Developer Edition allows remote attackers
30RISCO
abrir
Metasploit300
Lotus Notes 8.0.x - 8.5.2 FP2 - Autonomy Keyview (.lzh Attachment)
CVE-2011-121324 mai 2011
Integer underflow in lzhsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers
50RISCO
abrir
Metasploit400
Lotus Notes 8.0.x - 8.5.2 FP2 - Autonomy Keyview (.lzh Attachment)
CVE-2011-121324 mai 2011
Integer underflow in lzhsr.dll in Autonomy KeyView, as used in IBM Lotus Notes before 8.5.2 FP3, allows remote attackers
50RISCO
abrir
Metasploit500
VisiWave VWR File Parsing Vulnerability
CVE-2011-238620 mai 2011
VisiWaveReport.exe in AZO Technologies, Inc. VisiWave Site Survey before 2.1.9 allows user-assisted remote attackers to
50RISCO
abrir
Metasploit300
MPlayer SAMI Subtitle File Buffer Overflow
CVE-2011-362519 mai 2011
Stack-based buffer overflow in the sub_read_line_sami function in subreader.c in MPlayer, as used in SMPlayer 0.6.9, all
43RISCO
abrir
Metasploit300
Mozilla Firefox 3.6.16 mChannel Use-After-Free
CVE-2011-006510 mai 2011
Use-after-free vulnerability in Mozilla Firefox before 3.5.19 and 3.6.x before 3.6.17, and SeaMonkey before 2.0.14, allo
60RISCO
abrir
anteriorpágina 78 / 117próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.