Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
3.502 exploits
Metasploit400
Oracle Secure Backup NDMP_CONNECT_CLIENT_AUTH Buffer Overflow
CVE-2008-544414 jan 2009
Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.2 allows remote attackers
50RISCO
abrir
Metasploit300
Oracle Secure Backup exec_qr() Command Injection Vulnerability
CVE-2008-544814 jan 2009
Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.2 allows remote attackers
30RISCO
abrir
Metasploit400
BEA WebLogic JSESSIONID Cookie Value Overflow
CVE-2008-545713 jan 2009
Unspecified vulnerability in the Oracle BEA WebLogic Server Plugins for Apache, Sun and IIS web servers component in BEA
50RISCO
abrir
Metasploit300
Oracle DB SQL Injection in MDSYS.SDO_TOPO_DROP_FTBL Trigger
CVE-2008-397913 jan 2009
Unspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5 and 10.2.0.2 allows remote authent
50RISCO
abrir
Metasploit300
TrendMicro Data Loss Prevention 5.5 Directory Traversal
CVE-2008-293809 jan 2009
Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16,
60RISCO
abrir
Metasploit300
Tomcat UTF-8 Directory Traversal Vulnerability
CVE-2008-293809 jan 2009
Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16,
60RISCO
abrir
Metasploit500
HP OpenView Network Node Manager Toolbar.exe CGI Buffer Overflow
CVE-2008-006707 jan 2009
Multiple stack-based buffer overflows in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allow remote att
50RISCO
abrir
Metasploit400
Destiny Media Player 1.61 PLS M3U Buffer Overflow
CVE-2009-342903 jan 2009
Stack-based buffer overflow in Pirate Radio Destiny Media Player 1.61 allows remote attackers to execute arbitrary code
50RISCO
abrir
Metasploit100
SasCam Webcam Server v.2.6.5 Get() Method Buffer Overflow
CVE-2008-689829 dez 2008
Buffer overflow in the XHTTP Module 4.1.0.0 in the ActiveX control for SaschArt SasCam Webcam Server 2.6.5 allows remote
50RISCO
abrir
Metasploit400
Adobe Flash Player ActionScript Launch Command Execution Vulnerability
CVE-2008-549917 dez 2008
Unspecified vulnerability in Adobe Flash Player for Linux 10.0.12.36, and 9.0.151.0 and earlier, allows remote attackers
60RISCO
abrir
Metasploit500
Realtek Media Player Playlist Buffer Overflow
CVE-2008-566416 dez 2008
Stack-based buffer overflow in Realtek Media Player (aka Realtek Sound Manager, RtlRack, or rtlrack.exe) 1.15.0.0 allows
50RISCO
abrir
Metasploit400
MS09-004 Microsoft SQL Server sp_replwritetovarbin Memory Corruption
CVE-2008-541609 dez 2008
Heap-based buffer overflow in Microsoft SQL Server 2000 SP4, 8.00.2050, 8.00.2039, and earlier; SQL Server 2000 Desktop
60RISCO
abrir
Metasploit600
MS09-004 Microsoft SQL Server sp_replwritetovarbin Memory Corruption via SQL Injection
CVE-2008-541609 dez 2008
Heap-based buffer overflow in Microsoft SQL Server 2000 SP4, 8.00.2050, 8.00.2039, and earlier; SQL Server 2000 Desktop
60RISCO
abrir
Metasploit300
MS08-078 Microsoft Internet Explorer Data Binding Memory Corruption
CVE-2008-484407 dez 2008
Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet
50RISCO
abrir
Metasploit600
Sun Java Calendar Deserialization Privilege Escalation
CVE-2008-535303 dez 2008
The Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; a
60RISCO
abrir
Metasploit400
Cain and Abel RDP Buffer Overflow
CVE-2008-540530 nov 2008
Stack-based buffer overflow in the RDP protocol password decoder in Cain & Abel 4.9.23 and 4.9.24, and possibly earlier,
50RISCO
abrir
Metasploit100
Microsoft Works 7 WkImgSrv.dll WKsPictureInterface() ActiveX Code Execution
CVE-2008-189828 nov 2008
A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and
50RISCO
abrir
Metasploit300
Avahi Source Port 0 DoS
CVE-2008-508114 nov 2008
The originates_from_local_legacy_unicast_socket function (avahi-core/server.c) in avahi-daemon in Avahi before 0.6.24 al
50RISCO
abrir
Metasploit300
Pi3Web ISAPI DoS
CVE-2008-693813 nov 2008
Pi3Web 2.0.3 before PL2, when installed on Windows as a desktop application and without using the Pi3Web/Conf/Intenet.pi
43RISCO
abrir
Metasploit600
Openfire Admin Console Authentication Bypass
CVE-2008-650810 nov 2008
Directory traversal vulnerability in the AuthCheck filter in the Admin Console in Openfire 3.6.0a and earlier allows rem
60RISCO
abrir
Metasploit400
VLC Media Player RealText Subtitle Overflow
CVE-2008-503605 nov 2008
Stack-based buffer overflow in VideoLAN VLC media player 0.9.x before 0.9.6 might allow user-assisted attackers to execu
50RISCO
abrir
Metasploit600
Chilkat Crypt ActiveX WriteFile Unsafe Method
CVE-2008-500203 nov 2008
Insecure method vulnerability in the ChilkatCrypt2.ChilkatCrypt2.1 ActiveX control (ChilkatCrypt2.dll 4.3.2.1) in Chilka
50RISCO
abrir
Metasploit100
DjVu DjVu_ActiveX_MSOffice.dll ActiveX ComponentBuffer Overflow
CVE-2008-492230 out 2008
Buffer overflow in the DjVu ActiveX Control 3.0 for Microsoft Office (DjVu_ActiveX_MSOffice.dll) allows remote attackers
50RISCO
abrir
Metasploit300
PacketTrap TFTP Server 2.2.5459.0 DoS
CVE-2008-131129 out 2008
The TFTP server in PacketTrap pt360 Tool Suite PRO 2.0.3901.0 and earlier allows remote attackers to cause a denial of s
50RISCO
abrir
Metasploit400
TugZip 3.5 Zip File Parsing Buffer Overflow Vulnerability
CVE-2008-477928 out 2008
Stack-based buffer overflow in TUGzip 3.5.0.0 allows remote attackers to denial of service (crash) or execute arbitrary
50RISCO
abrir
Metasploit500
MS08-067 Microsoft Server Service Relative Path Stack Corruption
CVE-2008-4250CRITICALsob ataque28 out 2008
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RISCO
abrir
Metasploit300
Victory FTP Server 5.0 LIST DoS
CVE-2008-203124 out 2008
VicFTPS 5.0 allows remote attackers to cause a denial of service (crash) via a crafted LIST command, which triggers a NU
50RISCO
abrir
Metasploit300
Victory FTP Server 5.0 LIST DoS
CVE-2008-682924 out 2008
VicFTPS 5.0 allows remote attackers to cause a denial of service (crash) via a LIST command that starts with a "/\/" (fo
50RISCO
abrir
Metasploit600
Opera historysearch XSS
CVE-2008-469623 out 2008
Cross-site scripting (XSS) vulnerability in Opera.dll in Opera before 9.61 allows remote attackers to inject arbitrary w
50RISCO
abrir
Metasploit300
Oracle DB SQL Injection via SYS.DBMS_CDC_IPUBLISH.ALTER_HOTLOG_INTERNAL_CSOURCE
CVE-2008-399622 out 2008
Unspecified vulnerability in the Change Data Capture component in Oracle Database 10.1.0.5, 10.2.0.4, and 11.1.0.6 allow
18RISCO
abrir
anteriorpágina 92 / 117próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.