Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
19.066 exploits
Exploit-DBVexDay Proof
Adobe CoolType - SING Table 'uniqueName' Local Stack Buffer Overflow (Metasploit) (2)
CVE-2010-2883HIGHsob ataquelocalwindows25 set 2010
Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows
100RISCO
abrir
Exploit-DBVexDay Proof
URSoft W32Dasm 8.93 - Disassembler Function Buffer Overflow (Metasploit)
CVE-2005-0308localwindows25 set 2010
Buffer overflow in the wsprintf function in W32Dasm 8.93 and earlier allows remote attackers to execute arbitrary code v
50RISCO
abrir
Exploit-DBVexDay Proof
Adobe - U3D CLODProgressiveMeshDeclaration Array Overrun (Metasploit) (2)
CVE-2009-3953HIGHsob ataquelocalwindows25 set 2010
The U3D implementation in Adobe Reader and Acrobat 9.x before 9.3, 8.x before 8.2 on Windows and Mac OS X, and 7.x befor
100RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Works 7 - 'WkImgSrv.dll' WKsPictureInterface() ActiveX (Metasploit)
CVE-2008-1898remotewindows25 set 2010
A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and
50RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Visual Basic - '.VBP' Local Buffer Overflow (Metasploit)
CVE-2007-4776localwindows25 set 2010
Buffer overflow in Microsoft Visual Basic 6.0 and Enterprise Edition 6.0 SP6 allows user-assisted remote attackers to ex
50RISCO
abrir
Exploit-DBVexDay Proof
Adobe - 'util.printf()' Local Buffer Overflow (Metasploit) (2)
CVE-2008-2992HIGHsob ataqueransomwarelocalwindows25 set 2010
Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary c
100RISCO
abrir
Exploit-DBVexDay Proof
Adobe - 'Doc.media.newPlayer' Use-After-Free (Metasploit) (2)
CVE-2009-4324HIGHsob ataquelocalwindows25 set 2010
Use-after-free vulnerability in the Doc.media.newPlayer method in Multimedia.api in Adobe Reader and Acrobat 9.x before
100RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Excel - Malformed FEATHEADER Record (MS09-067) (Metasploit)
CVE-2009-3129HIGHsob ataquelocalwindows25 set 2010
Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Conv
100RISCO
abrir
Exploit-DBVexDay Proof
Microsoft HTML Help Workshop 4.74 - '.hhp' Cotent Buffer Overflow (Metasploit) (2)
CVE-2006-0564localwindows25 set 2010
Stack-based buffer overflow in Microsoft HTML Help Workshop 4.74.8702.0, and possibly earlier versions, and as included
60RISCO
abrir
Exploit-DBVexDay Proof
DjVu - 'DjVu_ActiveX_MSOffice.dll' ActiveX Component Buffer Overflow (Metasploit)
CVE-2008-4922remotewindows25 set 2010
Buffer overflow in the DjVu ActiveX Control 3.0 for Microsoft Office (DjVu_ActiveX_MSOffice.dll) allows remote attackers
50RISCO
abrir
Exploit-DBVexDay Proof
ACDSee - '.XPM' File Section Buffer Overflow (Metasploit)
CVE-2007-2193localwindows25 set 2010
Stack-based buffer overflow in the ID_X.apl plugin in ACDSee 9.0 Build 108, Pro 8.1 Build 99, and Photo Editor 4.0 Build
50RISCO
abrir
Exploit-DBVexDay Proof
PointDev IDEAL Migration - Buffer Overflow (Metasploit)
CVE-2009-4265dosaix25 set 2010
Stack-based buffer overflow in Ideal Administration 2009 9.7.1, and possibly other versions, allows remote attackers to
50RISCO
abrir
Exploit-DBVexDay Proof
Adobe - FlateDecode Stream Predictor 02 Integer Overflow (Metasploit) (2)
CVE-2009-3459HIGHsob ataquelocalwindows25 set 2010
Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows rem
100RISCO
abrir
Exploit-DBVexDay Proof
Microsoft PowerPoint Viewer - TextBytesAtom Stack Buffer Overflow (MS10-004) (Metasploit)
CVE-2010-0033localwindows25 set 2010
Stack-based buffer overflow in Microsoft Office PowerPoint 2003 SP3 allows remote attackers to execute arbitrary code vi
50RISCO
abrir
Exploit-DBVexDay Proof
Adobe - 'Collab.getIcon()' Local Buffer Overflow (Metasploit) (2)
CVE-2009-0927HIGHsob ataquelocalwindows25 set 2010
Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows r
100RISCO
abrir
Exploit-DBVexDay Proof
Microsoft HTML Help Workshop 4.74 - '.hhp' compiled Buffer Overflow (Metasploit) (4)
CVE-2006-0564localwindows25 set 2010
Stack-based buffer overflow in Microsoft HTML Help Workshop 4.74.8702.0, and possibly earlier versions, and as included
60RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Excel - OBJ Record Stack Overflow
CVE-2010-0822localwindows24 set 2010
Stack-based buffer overflow in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML F
60RISCO
abrir
Exploit-DBVexDay Proof
Microsoft MPEG Layer-3 Audio Decoder - Division By Zero
CVE-2010-0480doswindows24 set 2010
Multiple stack-based buffer overflows in the MPEG Layer-3 audio codecs in Microsoft Windows 2000 SP4, XP SP2 and SP3, Se
50RISCO
abrir
Exploit-DBVexDay Proof
Linksys WRT54 Access Point - 'apply.cgi' Remote Buffer Overflow (Metasploit)
CVE-2005-2799remotehardware24 set 2010
Buffer overflow in apply.cgi in Linksys WRT54G 3.01.03, 3.03.6, and possibly other versions before 4.20.7, allows remote
60RISCO
abrir
Exploit-DBVexDay Proof
FreePBX 2.8.0 - Recordings Interface Allows Remote Code Execution
CVE-2010-3490webappsphp24 set 2010
Directory traversal vulnerability in page.recordings.php in the System Recordings component in the configuration interfa
23RISCO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat Reader and Flash - 'newfunction' Remote Code Execution
CVE-2010-2168dosmultiple23 set 2010
Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, allow attackers to execute arbi
28RISCO
abrir
Exploit-DBVexDay Proof
WAnewsletter 2.1.2 - SQL Injection
CVE-2010-4940webappsphp23 set 2010
SQL injection vulnerability in index.php in WAnewsletter 2.1.2 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
Exploit-DBVexDay Proof
Joomla! Component Joostina - SQL Injection
CVE-2010-4929webappsphp22 set 2010
SQL injection vulnerability in the Joostina (com_ezautos) component for Joomla! allows remote attackers to execute arbit
23RISCO
abrir
Exploit-DBVexDay Proof
Joomla! Component TimeTrack 1.2.4 - Multiple SQL Injections
CVE-2010-4926webappsphp22 set 2010
SQL injection vulnerability in the TimeTrack (com_timetrack) component 1.2.4 for Joomla! allows remote attackers to exec
23RISCO
abrir
Exploit-DBVexDay Proof
Adobe Shockwave Director tSAC - Chunk Memory Corruption
CVE-2010-2866doswindows22 set 2010
Integer signedness error in the DIRAPI module in Adobe Shockwave Player before 11.5.8.612 allows remote attackers to cau
28RISCO
abrir
Exploit-DBVexDay Proof
@Mail 6.1.9 - 'MailType' Cross-Site Scripting
CVE-2010-4930webappsphp21 set 2010
Cross-site scripting (XSS) vulnerability in index.php in @mail Webmail before 6.2.0 allows remote attackers to inject ar
23RISCO
abrir
Exploit-DBVexDay Proof
mountall 2.15.2 (Ubuntu 10.04/10.10) - Local Privilege Escalation
CVE-2010-2961locallinux21 set 2010
mountall.c in mountall before 2.15.2 uses 0666 permissions for the root.rules file, which allows local users to gain pri
23RISCO
abrir
Exploit-DBVexDay Proof
Novell iPrint Client - ActiveX Control ExecuteRequest debug Buffer Overflow (Metasploit)
CVE-2010-3106remotewindows21 set 2010
The ienipp.ocx ActiveX control in the browser plugin in Novell iPrint Client before 5.42 does not properly validate the
50RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - SMB Relay Code Execution (MS08-068) (Metasploit)
CVE-2008-4037remotewindows21 set 2010
Microsoft Windows 2000 Gold through SP4, XP Gold through SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 20
50RISCO
abrir
Exploit-DBVexDay Proof
wpQuiz 2.7 - Authentication Bypass
CVE-2010-3608webappsphp21 set 2010
Multiple SQL injection vulnerabilities in wpQuiz 2.7 allow remote attackers to execute arbitrary SQL commands via the (1
23RISCO
abrir
anteriorpágina 177 / 636próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.