Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
3.502 exploits
Metasploit300
Oracle DB SQL Injection via SYS.DBMS_CDC_PUBLISH.ALTER_AUTOLOG_CHANGE_SOURCE
CVE-2008-399522 out 2008
Unspecified vulnerability in the Change Data Capture component in Oracle Database 10.1.0.5, 10.2.0.4, and 11.1.0.6 allow
18RISCO
abrir
Metasploit400
VideoLAN VLC TiVo Buffer Overflow
CVE-2008-465422 out 2008
Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player
50RISCO
abrir
Metasploit300
Oracle DB SQL Injection via SYS.LT.MERGEWORKSPACE
CVE-2008-398322 out 2008
Unspecified vulnerability in the Workspace Manager component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.3,
50RISCO
abrir
Metasploit600
Mantis manage_proj_page PHP Code Execution
CVE-2008-468716 out 2008
manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort param
50RISCO
abrir
Metasploit600
Husdawg, LLC. System Requirements Lab ActiveX Unsafe Method
CVE-2008-438516 out 2008
Husdawg, LLC Systems Requirements Lab 3, as used by Instant Expert Analysis, allows remote attackers to force the downlo
50RISCO
abrir
Metasploit500
Sun Solaris sadmind adm_build_path() Buffer Overflow
CVE-2008-455614 out 2008
Stack-based buffer overflow in the adm_build_path function in sadmind in Sun Solstice AdminSuite on Solaris 8 and 9 allo
50RISCO
abrir
Metasploit300
Titan FTP Server 6.26.630 SITE WHO DoS
CVE-2008-608214 out 2008
Titan FTP Server 6.26 build 630 allows remote attackers to cause a denial of service (CPU consumption) via the SITE WHO
50RISCO
abrir
Metasploit300
Microsoft Host Integration Server 2006 Command Execution Vulnerability
CVE-2008-346614 out 2008
Microsoft Host Integration Server (HIS) 2000, 2004, and 2006 does not limit RPC access to administrative functions, whic
40RISCO
abrir
Metasploit300
XM Easy Personal FTP Server 5.6.0 NLST DoS
CVE-2008-562613 out 2008
XM Easy Personal FTP Server 5.6.0 allows remote authenticated users to cause a denial of service via a crafted argument
50RISCO
abrir
Metasploit300
Oracle DB SQL Injection via SYS.LT.REMOVEWORKSPACE
CVE-2008-398413 out 2008
Unspecified vulnerability in the Workspace Manager component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.3,
50RISCO
abrir
Metasploit300
Oracle DB SQL Injection via SYS.LT.COMPRESSWORKSPACE
CVE-2008-398213 out 2008
Unspecified vulnerability in the Workspace Manager component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.3,
23RISCO
abrir
Metasploit300
Guild FTPd 0.999.8.11/0.999.14 Heap Corruption
CVE-2008-457212 out 2008
GuildFTPd 0.999.14, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possib
50RISCO
abrir
Metasploit200
Computer Associates ARCserve REPORTREMOTEEXECUTECML Buffer Overflow
CVE-2008-439709 out 2008
Directory traversal vulnerability in the RPC interface (asdbapi.dll) in CA ARCserve Backup (formerly BrightStor ARCserve
60RISCO
abrir
Metasploit300
iseemedia / Roxio / MGI Software LPViewer ActiveX Control Buffer Overflow
CVE-2008-438406 out 2008
Multiple stack-based buffer overflows in MGI Software LPViewer ActiveX control (LPControl.dll), as acquired by Roxio and
43RISCO
abrir
Metasploit300
mIRC PRIVMSG Handling Stack Buffer Overflow
CVE-2008-444902 out 2008
Stack-based buffer overflow in mIRC 6.34 allows remote attackers to execute arbitrary code via a long hostname in a PRIV
50RISCO
abrir
Metasploit600
phpScheduleIt PHP reserve.php start_date Parameter Arbitrary Code Injection
CVE-2008-613201 out 2008
Eval injection vulnerability in reserve.php in phpScheduleIt 1.2.10 and earlier, when magic_quotes_gpc is disabled, allo
43RISCO
abrir
Metasploit300
WinFTP 2.3.0 NLST Denial of Service
CVE-2008-566626 set 2008
WinFTP FTP Server 2.3.0, when passive (aka PASV) mode is used, allows remote authenticated users to cause a denial of se
43RISCO
abrir
Metasploit500
DATAC RealWin SCADA Server Buffer Overflow
CVE-2008-432226 set 2008
Stack-based buffer overflow in RealFlex Technologies Ltd. RealWin Server 2.0, as distributed by DATAC, allows remote att
50RISCO
abrir
Metasploit300
Windows Media Encoder 9 wmex.dll ActiveX Buffer Overflow
CVE-2008-300809 set 2008
Stack-based buffer overflow in the WMEncProfileManager ActiveX control in wmex.dll in Microsoft Windows Media Encoder 9
50RISCO
abrir
Metasploit500
BEA Weblogic Transfer-Encoding Buffer Overflow
CVE-2008-400809 set 2008
Unspecified vulnerability in the WebLogic Server Plugins for Apache component in BEA Product Suite 10.3, 10.0 MP1, 9.2 M
50RISCO
abrir
Metasploit400
Ultra Shareware Office Control ActiveX HttpUpload Buffer Overflow
CVE-2008-387827 ago 2008
Stack-based buffer overflow in the Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 in Ultra Shareware
50RISCO
abrir
Metasploit600
AWStats Totals multisort Remote Command Execution
CVE-2008-392226 ago 2008
awstatstotals.php in AWStats Totals 1.0 through 1.14 allows remote attackers to execute arbitrary code via PHP sequences
50RISCO
abrir
Metasploit100
activePDF WebGrabber ActiveX Control Buffer Overflow
CVE-2008-20001HIGH26 ago 2008
activePDF WebGrabber ActiveX Control Buffer Overflow
36RISCO
abrir
Metasploit300
SoftArtisans XFile FileManager ActiveX Control Buffer Overflow
CVE-2007-168225 ago 2008
Multiple stack-based buffer overflows in the FileManager ActiveX control in SAFmgPws.dll in SoftArtisans XFile before 2.
43RISCO
abrir
Metasploit300
Microsoft Visual Studio Mdmask32.ocx ActiveX Stack Buffer Overflow
CVE-2008-370413 ago 2008
Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions befo
50RISCO
abrir
Metasploit500
Racer v0.5.3 Beta 5 Buffer Overflow
CVE-2007-437010 ago 2008
Multiple buffer overflows in the (1) client and (2) server in Racer 0.5.3 beta 5 allow remote attackers to execute arbit
50RISCO
abrir
Metasploit300
Ruby WEBrick::HTTP::DefaultFileHandler DoS
CVE-2008-365608 ago 2008
Algorithmic complexity vulnerability in the WEBrick::HTTPUtils.split_header_value function in WEBrick::HTTP::DefaultFile
60RISCO
abrir
Metasploit400
WebEx UCF atucfobj.dll ActiveX NewObject Method Buffer Overflow
CVE-2008-355806 ago 2008
Stack-based buffer overflow in the WebexUCFObject ActiveX control in atucfobj.dll in Cisco WebEx Meeting Manager before
50RISCO
abrir
Metasploit300
DNS BailiWicked Domain Attack
CVE-2008-144721 jul 2008
The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windo
60RISCO
abrir
Metasploit300
DNS BailiWicked Host Attack
CVE-2008-144721 jul 2008
The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windo
60RISCO
abrir
anteriorpágina 93 / 117próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.