Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.900exploits catalogados
36.847CVEs com exploração pública
24.695testados em laboratório
3.501 exploits
Metasploit400
Kolibri HTTP Server HEAD Buffer Overflow
CVE-2002-226826 dez 2010
Buffer overflow in Webster HTTP Server allows remote attackers to execute arbitrary code via a long URL.
50RISCO
abrir
Metasploit500
Microsoft WMI Administration Tools ActiveX Buffer Overflow
CVE-2010-397321 dez 2010
The WMITools ActiveX control in WBEMSingleView.ocx 1.50.1131.0 in Microsoft WMI Administrative Tools 1.1 and earlier in
60RISCO
abrir
Metasploit600
Citrix Access Gateway Command Execution
CVE-2010-456621 dez 2010
The web authentication form in the NT4 authentication component in Citrix Access Gateway Enterprise Edition 9.2-49.8 and
43RISCO
abrir
Metasploit300
Microsoft IIS FTP Server Encoded Response Overflow Trigger
CVE-2010-397221 dez 2010
Heap-based buffer overflow in the TELNET_STREAM_CONTEXT::OnSendData function in ftpsvc.dll in Microsoft FTP Service 7.0
60RISCO
abrir
Metasploit600
Redmine SCM Repository Arbitrary Command Execution
CVE-2011-492919 dez 2010
Unspecified vulnerability in the bazaar repository adapter in Redmine 0.9.x and 1.0.x before 1.0.5 allows remote attacke
50RISCO
abrir
Metasploit500
MS11-006 Microsoft Windows CreateSizedDIBSECTION Stack Buffer Overflow
CVE-2010-397015 dez 2010
Stack-based buffer overflow in the CreateSizedDIBSECTION function in shimgvw.dll in the Windows Shell graphics processor
50RISCO
abrir
Metasploit300
Crystal Reports CrystalPrintControl ActiveX ServerResourceVersion Property Overflow
CVE-2010-259014 dez 2010
Heap-based buffer overflow in the CrystalReports12.CrystalPrintControl.1 ActiveX control in PrintControl.dll 12.3.2.753
50RISCO
abrir
Metasploit600
MS10-104 Microsoft Office SharePoint Server 2007 Remote Code Execution
CVE-2010-396414 dez 2010
Unrestricted file upload vulnerability in the Document Conversions Launcher Service in Microsoft Office SharePoint Serve
60RISCO
abrir
Metasploit600
Exim4 string_format Function Heap Buffer Overflow
CVE-2010-4345HIGHsob ataque07 dez 2010
Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specif
91RISCO
abrir
Metasploit600
Exim4 string_format Function Heap Buffer Overflow
CVE-2010-4344CRITICALsob ataque07 dez 2010
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to exe
100RISCO
abrir
Metasploit600
ProFTPD 1.3.3c Backdoor Command Execution
CVE-2010-20103CRITICAL02 dez 2010
ProFTPD 1.3.3c Backdoor Command Execution
63RISCO
abrir
Metasploit600
Pandora FMS v3.1 Auth Bypass and Arbitrary File Upload Vulnerability
CVE-2010-427930 nov 2010
The default configuration of Pandora FMS 3.1 and earlier specifies an empty string for the loginhash_pwd field, which al
50RISCO
abrir
Metasploit400
MS11-003 Microsoft Internet Explorer CSS Recursive Import Use After Free
CVE-2010-397129 nov 2010
Use-after-free vulnerability in the CSharedStyleSheet::Notify function in the Cascading Style Sheets (CSS) parser in msh
60RISCO
abrir
Metasploit500
Xion Audio Player 1.0.126 Unicode Stack Buffer Overflow
CVE-2010-20042HIGH23 nov 2010
Xion Audio Player ≤ 1.0.126 Unicode Stack Buffer Overflow
36RISCO
abrir
Metasploit500
DATAC RealWin SCADA Server SCPC_TXTEVENT Buffer Overflow
CVE-2010-414218 nov 2010
Multiple stack-based buffer overflows in DATAC RealWin 2.0 Build 6.1.8.10 and earlier allow remote attackers to cause a
50RISCO
abrir
Metasploit600
SystemTap MODPROBE_OPTIONS Privilege Escalation
CVE-2010-417017 nov 2010
The staprun runtime tool in SystemTap 1.3 does not properly clear the environment before executing modprobe, which allow
38RISCO
abrir
Metasploit600
CakePHP Cache Corruption Code Execution
CVE-2010-433515 nov 2010
The _validatePost function in libs/controller/components/security.php in CakePHP 1.3.x through 1.3.5 and 1.2.8 allows re
50RISCO
abrir
Metasploit300
RealNetworks RealPlayer CDDA URI Initialization Vulnerability
CVE-2010-374715 nov 2010
An ActiveX control in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.4, and RealPlayer Enterpr
50RISCO
abrir
Metasploit300
Novell iPrint Client ActiveX Control Buffer Overflow
CVE-2010-432115 nov 2010
Stack-based buffer overflow in an ActiveX control in ienipp.ocx in Novell iPrint Client 5.52 allows remote attackers to
50RISCO
abrir
Metasploit500
Foxit PDF Reader v4.1.1 Title Stack Buffer Overflow
CVE-2010-20010HIGH13 nov 2010
Foxit PDF Reader < 4.2.0.0928 Title Stack Buffer Overflow
36RISCO
abrir
Metasploit500
MS10-087 Microsoft Word RTF pFragments Stack Buffer Overflow (File Format)
CVE-2010-3333HIGHsob ataque09 nov 2010
Stack-based buffer overflow in Microsoft Office XP SP3, Office 2003 SP3, Office 2007 SP2, Office 2010, Office 2004 and 2
100RISCO
abrir
Metasploit500
FreeNAS exec_raw.php Arbitrary Command Execution
CVE-2010-20059CRITICAL06 nov 2010
FreeNAS < 0.7.2 rev 5543 exec_raw.php Arbitrary Command Execution
43RISCO
abrir
Metasploit400
MS10-090 Microsoft Internet Explorer CSS SetUserClip Memory Corruption
CVE-2010-3962HIGHsob ataque03 nov 2010
Use-after-free vulnerability in Microsoft Internet Explorer 6, 7, and 8 allows remote attackers to execute arbitrary cod
100RISCO
abrir
Metasploit500
ProFTPD 1.3.2rc3 - 1.3.3b Telnet IAC Buffer Overflow (Linux)
CVE-2010-422101 nov 2010
Multiple stack-based buffer overflows in the pr_netio_telnet_gets function in netio.c in ProFTPD before 1.3.3c allow rem
60RISCO
abrir
Metasploit500
ProFTPD 1.3.2rc3 - 1.3.3b Telnet IAC Buffer Overflow (FreeBSD)
CVE-2010-422101 nov 2010
Multiple stack-based buffer overflows in the pr_netio_telnet_gets function in netio.c in ProFTPD before 1.3.3c allow rem
60RISCO
abrir
Metasploit300
Adobe Flash Player "Button" Remote Code Execution
CVE-2010-365428 out 2010
Adobe Flash Player before 9.0.289.0 and 10.x before 10.1.102.64 on Windows, Mac OS X, Linux, and Solaris and 10.1.95.1 o
50RISCO
abrir
Metasploit300
Mozilla Firefox Interleaved document.write/appendChild Memory Corruption
CVE-2010-3765CRITICALsob ataque25 out 2010
Mozilla Firefox 3.5.x through 3.5.14 and 3.6.x through 3.6.11, Thunderbird 3.1.6 before 3.1.6 and 3.0.x before 3.0.10, a
100RISCO
abrir
Metasploit300
Adobe Shockwave rcsL Memory Corruption
CVE-2010-365321 out 2010
The Director module (dirapi.dll) in Adobe Shockwave Player before 11.5.9.615 allows remote attackers to execute arbitrar
60RISCO
abrir
Metasploit500
MOXA Device Manager Tool 2.1 Buffer Overflow
CVE-2010-474120 out 2010
Stack-based buffer overflow in MDMUtil.dll in MDMTool.exe in MDM Tool before 2.3 in Moxa Device Manager allows remote MD
43RISCO
abrir
Metasploit500
Reliable Datagram Sockets (RDS) rds_page_copy_user Privilege Escalation
CVE-2010-3904HIGHsob ataque20 out 2010
The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the
91RISCO
abrir
anteriorpágina 81 / 117próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.