Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.542exploits catalogados
34.971CVEs com exploração pública
24.695testados em laboratório
24.443 exploits
Exploit-DBVexDay Proof
Joomla! Component TimeTrack 1.2.4 - Multiple SQL Injections
CVE-2010-4926webappsphp22 set 2010
SQL injection vulnerability in the TimeTrack (com_timetrack) component 1.2.4 for Joomla! allows remote attackers to exec
23RISCO
abrir
Exploit-DBVexDay Proof
Adobe Shockwave Director tSAC - Chunk Memory Corruption
CVE-2010-2866doswindows22 set 2010
Integer signedness error in the DIRAPI module in Adobe Shockwave Player before 11.5.8.612 allows remote attackers to cau
28RISCO
abrir
Exploit-DBVexDay Proof
Novell iPrint Client - ActiveX Control call-back-url Buffer Overflow (Metasploit)
CVE-2010-1527remotewindows21 set 2010
Stack-based buffer overflow in Novell iPrint Client before 5.44 allows remote attackers to execute arbitrary code via a
50RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Excel - WOPT Record Parsing Heap Memory Corruption
CVE-2010-0824doswindows21 set 2010
Unspecified vulnerability in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute
28RISCO
abrir
Exploit-DBVexDay Proof
Novell iPrint Client - ActiveX Control ExecuteRequest debug Buffer Overflow (Metasploit)
CVE-2010-3106remotewindows21 set 2010
The ienipp.ocx ActiveX control in the browser plugin in Novell iPrint Client before 5.42 does not properly validate the
50RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - SMB Relay Code Execution (MS08-068) (Metasploit)
CVE-2008-4037remotewindows21 set 2010
Microsoft Windows 2000 Gold through SP4, XP Gold through SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 20
50RISCO
abrir
Exploit-DBVexDay Proof
wpQuiz 2.7 - Authentication Bypass
CVE-2010-3608webappsphp21 set 2010
Multiple SQL injection vulnerabilities in wpQuiz 2.7 allow remote attackers to execute arbitrary SQL commands via the (1
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Excel - WOPT Record Parsing Heap Memory Corruption
CVE-2010-1248doswindows21 set 2010
Buffer overflow in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary
28RISCO
abrir
Exploit-DBVexDay Proof
ibPhotohost 1.1.2 - SQL Injection
CVE-2010-3601webappsphp21 set 2010
SQL injection vulnerability in index.php in ibPhotohost 1.1.2 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Shell LNK Code Execution (MS10-046) (Metasploit)
CVE-2010-2568HIGHsob ataqueremotewindows21 set 2010
Windows Shell in Microsoft Windows XP SP3, Server 2003 SP2, Vista SP1 and SP2, Server 2008 SP2 and R2, and Windows 7 all
100RISCO
abrir
Exploit-DBVexDay Proof
@Mail 6.1.9 - 'MailType' Cross-Site Scripting
CVE-2010-4930webappsphp21 set 2010
Cross-site scripting (XSS) vulnerability in index.php in @mail Webmail before 6.2.0 allows remote attackers to inject ar
23RISCO
abrir
Exploit-DBVexDay Proof
Sun Java - Web Start Plugin Command Line Argument Injection (Metasploit)
CVE-2010-0886remotewindows21 set 2010
Unspecified vulnerability in the Java Deployment Toolkit component in Oracle Java SE and Java for Business JDK and JRE 6
50RISCO
abrir
Exploit-DBVexDay Proof
Novell iPrint Client - ActiveX Control ExecuteRequest Buffer Overflow (Metasploit)
CVE-2008-0935remotewindows21 set 2010
Stack-based buffer overflow in the Novell iPrint Control ActiveX control in ienipp.ocx in Novell iPrint Client before 4.
50RISCO
abrir
Exploit-DBVexDay Proof
mountall 2.15.2 (Ubuntu 10.04/10.10) - Local Privilege Escalation
CVE-2010-2961locallinux21 set 2010
mountall.c in mountall before 2.15.2 uses 0666 permissions for the root.rules file, which allows local users to gain pri
23RISCO
abrir
Exploit-DBVexDay Proof
Novell iPrint Client - ActiveX Control 'debug' Remote Buffer Overflow (Metasploit)
CVE-2010-3106remotewindows21 set 2010
The ienipp.ocx ActiveX control in the browser plugin in Novell iPrint Client before 5.42 does not properly validate the
50RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows XP/Vista/2003 - Metafile Escape() SetAbortProc Code Execution (MS06-001) (Metasploit)
CVE-2005-4560remotewindows20 set 2010
The Windows Graphical Device Interface library (GDI32.DLL) in Microsoft Windows allows remote attackers to execute arbit
60RISCO
abrir
Exploit-DBVexDay Proof
Adobe - FlateDecode Stream Predictor 02 Integer Overflow (Metasploit) (1)
CVE-2009-3459HIGHsob ataquelocalwindows20 set 2010
Heap-based buffer overflow in Adobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 allows rem
100RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player - 'newfunction' Invalid Pointer Use (Metasploit) (1)
CVE-2010-1297HIGHsob ataquelocalwindows20 set 2010
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrob
100RISCO
abrir
Exploit-DBVexDay Proof
Java 6.19 CMM readMabCurveData - Remote Stack Overflow
CVE-2010-0838remotewindows20 set 2010
Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update 18, 5.0, Update, and
28RISCO
abrir
Exploit-DBVexDay Proof
PeerCast 0.1216 (Windows x86) - URL Handling Buffer Overflow (Metasploit)
CVE-2006-1148remotewindows_x8620 set 2010
Multiple stack-based buffer overflows in the procConnectArgs function in servmgr.cpp in PeerCast before 0.1217 allow rem
60RISCO
abrir
Exploit-DBVexDay Proof
Arugizer Trojan Horse (Energizer DUO) - Code Execution (Metasploit)
CVE-2010-0103remotewindows20 set 2010
UsbCharger.dll in the Energizer DUO USB battery charger software contains a backdoor that is implemented through the Aru
43RISCO
abrir
Exploit-DBVexDay Proof
QBik WinGate WWW Proxy Server - URL Processing Overflow (Metasploit)
CVE-2006-2926remotewindows20 set 2010
Stack-based buffer overflow in the WWW Proxy Server of Qbik WinGate 6.1.1.1077 allows remote attackers to cause a denial
60RISCO
abrir
Exploit-DBVexDay Proof
OpenX - 'banner-edit.php' Arbitrary File Upload / PHP Code Execution (Metasploit)
CVE-2009-4098remotephp20 set 2010
Unrestricted file upload vulnerability in banner-edit.php in OpenX adserver 2.8.1 and earlier allows remote authenticate
43RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - 'createTextRange()' Code Execution (MS06-013) (Metasploit)
CVE-2006-1359remotewindows20 set 2010
Microsoft Internet Explorer 6 and 7 Beta 2 allows remote attackers to cause a denial of service and possibly execute arb
50RISCO
abrir
Exploit-DBVexDay Proof
Husdawg_ LLC. System Requirements Lab - ActiveX Unsafe Method (Metasploit)
CVE-2008-4385remotewindows20 set 2010
Husdawg, LLC Systems Requirements Lab 3, as used by Instant Expert Analysis, allows remote attackers to force the downlo
50RISCO
abrir
Exploit-DBVexDay Proof
Computer Associates License Client - GETCONFIG Overflow (Metasploit)
CVE-2005-0581remotewindows20 set 2010
Multiple buffer overflows in Computer Associates (CA) License Client and Server 0.1.0.15 allow remote attackers to execu
50RISCO
abrir
Exploit-DBVexDay Proof
Madwifi - SIOCGIWSCAN Buffer Overflow (Metasploit)
CVE-2006-6332remotelinux20 set 2010
Stack-based buffer overflow in net80211/ieee80211_wireless.c in MadWifi before 0.9.2.1 allows remote attackers to execut
28RISCO
abrir
Exploit-DBVexDay Proof
Novell Messenger Server 2.0 - Accept-Language Overflow (Metasploit)
CVE-2006-0992remotewindows20 set 2010
Stack-based buffer overflow in Novell GroupWise Messenger before 2.0 Public Beta 2 allows remote attackers to execute ar
60RISCO
abrir
Exploit-DBVexDay Proof
TFTPD32 < 2.21 - 'Filename' Remote Buffer Overflow (Metasploit)
CVE-2002-2226remotewindows20 set 2010
Buffer overflow in tftpd of TFTP32 2.21 and earlier allows remote attackers to execute arbitrary code via a long filenam
50RISCO
abrir
Exploit-DBVexDay Proof
Macrovision Installshield Update Service - ActiveX Unsafe Method (Metasploit)
CVE-2007-5660remotewindows20 set 2010
Unspecified vulnerability in the Update Service ActiveX control in isusweb.dll before 6.0.100.65101 in MacroVision FLEXn
50RISCO
abrir
anteriorpágina 348 / 815próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.