Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.900exploits catalogados
36.847CVEs com exploração pública
24.695testados em laboratório
3.501 exploits
Metasploit500
PointDev IDEAL Migration Buffer Overflow
CVE-2009-426505 dez 2009
Stack-based buffer overflow in Ideal Administration 2009 9.7.1, and possibly other versions, allows remote attackers to
50RISCO
abrir
Metasploit500
Adobe Illustrator CS4 v14.0.0
CVE-2009-419503 dez 2009
Buffer overflow in Adobe Illustrator CS4 14.0.0, CS3 13.0.3 and earlier, and CS3 13.0.0 allows remote attackers to execu
60RISCO
abrir
Metasploit600
FreeBSD rtld execl() Privilege Escalation
CVE-2009-414630 nov 2009
The _rtld function in the Run-Time Link-Editor (rtld) in libexec/rtld-elf/rtld.c in FreeBSD 7.1, 7.2, and 8.0 does not c
38RISCO
abrir
Metasploit600
FreeBSD rtld execl() Privilege Escalation
CVE-2009-414730 nov 2009
The _rtld function in the Run-Time Link-Editor (rtld) in libexec/rtld-elf/rtld.c in FreeBSD 7.1 and 8.0 does not clear t
38RISCO
abrir
Metasploit600
OpenX banner-edit.php File Upload PHP Code Execution
CVE-2009-409824 nov 2009
Unrestricted file upload vulnerability in banner-edit.php in OpenX adserver 2.8.1 and earlier allows remote authenticate
43RISCO
abrir
Metasploit300
MS09-072 Microsoft Internet Explorer Style getElementsByTagName Memory Corruption
CVE-2009-367220 nov 2009
Microsoft Internet Explorer 6 and 7 does not properly handle objects in memory that (1) were not properly initialized or
60RISCO
abrir
Metasploit500
Erlang Port Mapper Daemon Cookie RCE
CVE-2020-2471920 nov 2009
Exposed Erlang Cookie could lead to Remote Command Execution (RCE) attack. Communication between Erlang nodes is done by
23RISCO
abrir
Metasploit500
HTTPDX tolog() Function Format String Vulnerability
CVE-2009-476917 nov 2009
Multiple format string vulnerabilities in the tolog function in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 allow (1) remo
50RISCO
abrir
Metasploit500
HTTPDX tolog() Function Format String Vulnerability
CVE-2009-476917 nov 2009
Multiple format string vulnerabilities in the tolog function in httpdx 1.4, 1.4.5, 1.4.6, 1.4.6b, and 1.5 allow (1) remo
50RISCO
abrir
Metasploit600
AwingSoft Winds3D Player 3.5 SceneURL Download and Execute
CVE-2009-485014 nov 2009
The Awingsoft Awakening Winds3D Viewer plugin 3.5.0.9 allows remote attackers to execute arbitrary programs via a SceneU
43RISCO
abrir
Metasploit400
MS09-067 Microsoft Excel Malformed FEATHEADER Record Vulnerability
CVE-2009-3129HIGHsob ataque10 nov 2009
Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Conv
100RISCO
abrir
Metasploit300
Microsoft Windows EOT Font Table Directory Integer Overflow
CVE-2009-251410 nov 2009
win32k.sys in the kernel in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2 does not correctly parse fon
50RISCO
abrir
Metasploit600
Apache Tomcat Manager Application Deployer Authenticated Code Execution
CVE-2010-055709 nov 2009
IBM Cognos Express 9.0 allows attackers to obtain unspecified access to the Tomcat Manager component, and cause a denial
50RISCO
abrir
Metasploit600
Apache Tomcat Manager Application Deployer Authenticated Code Execution
CVE-2009-354809 nov 2009
The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a
60RISCO
abrir
Metasploit600
Apache Tomcat Manager Application Deployer Authenticated Code Execution
CVE-2009-418909 nov 2009
HP Operations Manager has a default password of OvW*busr1 for the ovwebusr account, which allows remote attackers to exe
60RISCO
abrir
Metasploit600
Apache Tomcat Manager Application Deployer Authenticated Code Execution
CVE-2009-384309 nov 2009
HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which all
60RISCO
abrir
Metasploit600
Apache Tomcat Manager Authenticated Upload Code Execution
CVE-2009-418809 nov 2009
HP Operations Dashboard has a default password of j2deployer for the j2deployer account, which allows remote attackers t
50RISCO
abrir
Metasploit600
Apache Tomcat Manager Application Deployer Authenticated Code Execution
CVE-2010-409409 nov 2009
The Tomcat server in IBM Rational Quality Manager and Rational Test Lab Manager has a default password for the ADMIN acc
50RISCO
abrir
Metasploit600
Apache Tomcat Manager Application Deployer Authenticated Code Execution
CVE-2009-418809 nov 2009
HP Operations Dashboard has a default password of j2deployer for the j2deployer account, which allows remote attackers t
50RISCO
abrir
Metasploit600
Apache Tomcat Manager Authenticated Upload Code Execution
CVE-2010-409409 nov 2009
The Tomcat server in IBM Rational Quality Manager and Rational Test Lab Manager has a default password for the ADMIN acc
50RISCO
abrir
Metasploit600
Apache Tomcat Manager Authenticated Upload Code Execution
CVE-2009-384309 nov 2009
HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which all
60RISCO
abrir
Metasploit600
Apache Tomcat Manager Authenticated Upload Code Execution
CVE-2010-055709 nov 2009
IBM Cognos Express 9.0 allows attackers to obtain unspecified access to the Tomcat Manager component, and cause a denial
50RISCO
abrir
Metasploit600
Apache Tomcat Manager Authenticated Upload Code Execution
CVE-2009-418909 nov 2009
HP Operations Manager has a default password of OvW*busr1 for the ovwebusr account, which allows remote attackers to exe
60RISCO
abrir
Metasploit600
Apache Tomcat Manager Authenticated Upload Code Execution
CVE-2009-354809 nov 2009
The Windows installer for Apache Tomcat 6.0.0 through 6.0.20, 5.5.0 through 5.5.28, and possibly earlier versions uses a
60RISCO
abrir
Metasploit500
Sun Java JRE getSoundbank file:// URI Buffer Overflow
CVE-2009-386704 nov 2009
Stack-based buffer overflow in the HsbParser.getSoundBank function in Sun Java SE in JDK and JRE 5.0 before Update 22, J
60RISCO
abrir
Metasploit500
Sun Java JRE AWT setDiffICM Buffer Overflow
CVE-2009-386904 nov 2009
Stack-based buffer overflow in the setDiffICM function in the Abstract Window Toolkit (AWT) in Java Runtime Environment
50RISCO
abrir
Metasploit200
Hewlett-Packard Power Manager Administration Buffer Overflow
CVE-2009-268504 nov 2009
Stack-based buffer overflow in the login form in the management web server in HP Power Manager allows remote attackers t
60RISCO
abrir
Metasploit300
Symantec Altiris Deployment Solution ActiveX Control Buffer Overflow
CVE-2009-303304 nov 2009
Buffer overflow in the RunCmd method in the Altiris eXpress NS Console Utilities ActiveX control in AeXNSConsoleUtilitie
50RISCO
abrir
Metasploit400
IBM Tivoli Storage Manager Express CAD Service Buffer Overflow
CVE-2009-385304 nov 2009
Stack-based buffer overflow in the client acceptor daemon (CAD) scheduler in the client in IBM Tivoli Storage Manager (T
50RISCO
abrir
Metasploit500
IBM Tivoli Storage Manager Express RCA Service Buffer Overflow
CVE-2008-482804 nov 2009
Multiple stack-based buffer overflows in dsmagent.exe in the Remote Agent Service in the IBM Tivoli Storage Manager (TSM
60RISCO
abrir
anteriorpágina 87 / 117próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.