Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.542exploits catalogados
34.971CVEs com exploração pública
24.695testados em laboratório
24.443 exploits
Exploit-DBVexDay Proof
Chipmunk Board 1.3 - 'index.php?forumID' SQL Injection
CVE-2010-4866webappsphp01 out 2010
SQL injection vulnerability in index.php in Chipmunk Board 1.3 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft IIS 6.0 - ASP Stack Overflow Stack Exhaustion (Denial of Service) (MS10-065)
CVE-2010-1899doswindows01 out 2010
Stack consumption vulnerability in the ASP implementation in Microsoft Internet Information Services (IIS) 5.1, 6.0, 7.0
50RISCO
abrir
Exploit-DBVexDay Proof
Joomla! Component JE Directory 1.0 - SQL Injection
CVE-2010-4862webappsphp30 set 2010
SQL injection vulnerability in the JExtensions JE Directory (com_jedirectory) component 1.0 for Joomla! allows remote at
23RISCO
abrir
Exploit-DBVexDay Proof
Joomla! Component JE Guestbook 1.0 - Multiple Vulnerabilities
CVE-2010-4865webappsphp30 set 2010
SQL injection vulnerability in the JE Guestbook (com_jeguestbook) component 1.0 for Joomla! allows remote attackers to e
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Unicode Scripts Processor - Remote Code Execution (MS10-063)
CVE-2010-2738doswindows30 set 2010
The Uniscribe (aka new Unicode Script Processor) implementation in USP10.DLL in Microsoft Windows XP SP2 and SP3, Server
28RISCO
abrir
Exploit-DBVexDay Proof
MyPhpAuction 2010 - 'id' SQL Injection
CVE-2010-4860webappsphp29 set 2010
SQL injection vulnerability in product_desc.php in MyPhpAuction 2010 allows remote attackers to execute arbitrary SQL co
23RISCO
abrir
Exploit-DBVexDay Proof
Webspell 4.2.1 - 'asearch.php' SQL Injection
CVE-2010-4861webappsphp29 set 2010
SQL injection vulnerability in asearch.php in webSPELL 4.2.1 allows remote attackers to execute arbitrary SQL commands v
23RISCO
abrir
Exploit-DBVexDay Proof
XFS - Deleted Inode Local Information Disclosure
CVE-2010-2943locallinux29 set 2010
The xfs implementation in the Linux kernel before 2.6.35 does not look up inode allocation btrees before reading inode b
28RISCO
abrir
Exploit-DBVexDay Proof
Getsimple CMS 2.01 - 'changedata.php' Cross-Site Scripting
CVE-2010-4863webappsphp29 set 2010
Cross-site scripting (XSS) vulnerability in admin/changedata.php in GetSimple CMS 2.01 allows remote attackers to inject
23RISCO
abrir
Exploit-DBVexDay Proof
MODx 2.0.2-pl - '/manager/index.php?modahsh' Cross-Site Scripting
CVE-2010-4883webappsphp29 set 2010
Cross-site scripting (XSS) vulnerability in manager/index.php in MODx Revolution 2.0.2-pl allows remote attackers to inj
23RISCO
abrir
Exploit-DBVexDay Proof
MODx manager - '/controllers/default/resource/tvs.php?class_key' Traversal Local File Inclusion
CVE-2010-5278webappsphp29 set 2010
Directory traversal vulnerability in manager/controllers/default/resource/tvs.php in MODx Revolution 2.0.2-pl, and possi
43RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Excel - SxView Record Parsing Heap Memory Corruption
CVE-2010-1245doswindows29 set 2010
Unspecified vulnerability in Microsoft Office Excel 2002 SP3, Office 2004 for Mac, Office 2008 for Mac, and Open XML Fil
28RISCO
abrir
Exploit-DBVexDay Proof
Linux Kernel < 2.6.36-rc6 (RedHat / Ubuntu 10.04) - 'pktcdvd' Kernel Memory Disclosure
CVE-2010-3437locallinux29 set 2010
Integer signedness error in the pkt_find_dev_from_minor function in drivers/block/pktcdvd.c in the Linux kernel before 2
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft DNS RPC Service - 'extractQuotedChar()' Remote Overflow 'SMB' (MS07-029) (Metasploit)
CVE-2007-1748remotewindows28 set 2010
Stack-based buffer overflow in the RPC interface in the Domain Name System (DNS) Server Service in Microsoft Windows 200
60RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - 'Winhlp32.exe' MsgBox Code Execution (MS10-023) (Metasploit)
CVE-2010-0483remotewindows28 set 2010
vbscript.dll in VBScript 5.1, 5.6, 5.7, and 5.8 in Microsoft Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP2, when
60RISCO
abrir
Exploit-DBVexDay Proof
PHPMyFAQ 2.6.x - 'index.php' Cross-Site Scripting
CVE-2010-4821webappsphp28 set 2010
Cross-site scripting (XSS) vulnerability in phpMyFAQ before 2.6.9 allows remote attackers to inject arbitrary web script
23RISCO
abrir
Exploit-DBVexDay Proof
Entrans - SQL Injection
CVE-2010-4935webappsphp27 set 2010
SQL injection vulnerability in poll.php in Entrans 0.3.2 and earlier allows remote attackers to execute arbitrary SQL co
23RISCO
abrir
Exploit-DB
Allpc 2.5 osCommerce - SQL Injection / Cross-Site Scripting
CVE-2010-4946webappswindows_x8627 set 2010
SQL injection vulnerability in product_info.php in ALLPC 2.5 allows remote attackers to execute arbitrary SQL commands v
23RISCO
abrir
Exploit-DBVexDay Proof
Horde IMP Webmail 4.3.7 - 'fetchmailprefs.php' HTML Injection
CVE-2010-3695webappsphp27 set 2010
Cross-site scripting (XSS) vulnerability in fetchmailprefs.php in Horde IMP before 4.3.8, and Horde Groupware Webmail Ed
23RISCO
abrir
Exploit-DB
Allpc 2.5 osCommerce - SQL Injection / Cross-Site Scripting
CVE-2010-4947webappswindows_x8627 set 2010
Cross-site scripting (XSS) vulnerability in advanced_search_result.php in ALLPC 2.5 allows remote attackers to inject ar
23RISCO
abrir
Exploit-DBVexDay Proof
Java - RMIConnectionImpl Deserialization Privilege Escalation (Metasploit)
CVE-2010-0094remotemultiple27 set 2010
Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 18
60RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - MSHTML Findtext Processing
CVE-2010-2553doswindows27 set 2010
The Cinepak codec in Microsoft Windows XP SP2 and SP3, Windows Vista SP1 and SP2, and Windows 7 does not properly decomp
35RISCO
abrir
Exploit-DBVexDay Proof
Blue River Mura CMS - Directory Traversal
CVE-2010-3468webappscfm26 set 2010
Directory traversal vulnerability in fileManager.cfc in Mura CMS 5.1 before 5.1.498 and 5.2 before 5.2.2809, and Sava CM
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Cinepak Codec CVDecompress - Heap Overflow (MS10-055)
CVE-2010-2553doswindows26 set 2010
The Cinepak codec in Microsoft Windows XP SP2 and SP3, Windows Vista SP1 and SP2, and Windows 7 does not properly decomp
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Visual Basic - '.VBP' Local Buffer Overflow (Metasploit)
CVE-2007-4776localwindows25 set 2010
Buffer overflow in Microsoft Visual Basic 6.0 and Enterprise Edition 6.0 SP6 allows user-assisted remote attackers to ex
50RISCO
abrir
Exploit-DBVexDay Proof
ProShow Gold 4.0.2549 - '.psh' Local Stack Buffer Overflow (Metasploit)
CVE-2009-3214localwindows25 set 2010
Multiple stack-based buffer overflows in Photodex ProShow Gold 4.0.2549 allow remote attackers to execute arbitrary code
50RISCO
abrir
Exploit-DBVexDay Proof
SasCam Webcam Server 2.6.5 - 'Get()' Method Buffer Overflow (Metasploit)
CVE-2008-6898remotewindows25 set 2010
Buffer overflow in the XHTTP Module 4.1.0.0 in the ActiveX control for SaschArt SasCam Webcam Server 2.6.5 allows remote
50RISCO
abrir
Exploit-DBVexDay Proof
Microsoft HTML Help Workshop 4.74 - '.hhp' compiled Buffer Overflow (Metasploit) (4)
CVE-2006-0564localwindows25 set 2010
Stack-based buffer overflow in Microsoft HTML Help Workshop 4.74.8702.0, and possibly earlier versions, and as included
60RISCO
abrir
Exploit-DBVexDay Proof
Mozilla Firefox CSS - font-face Remote Code Execution
CVE-2010-2752doswindows25 set 2010
Integer overflow in an array class in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, Thunderbird 3.0.x befo
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft PowerPoint Viewer - TextBytesAtom Stack Buffer Overflow (MS10-004) (Metasploit)
CVE-2010-0033localwindows25 set 2010
Stack-based buffer overflow in Microsoft Office PowerPoint 2003 SP3 allows remote attackers to execute arbitrary code vi
50RISCO
abrir
anteriorpágina 346 / 815próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.