Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.542exploits catalogados
34.971CVEs com exploração pública
24.695testados em laboratório
24.443 exploits
Exploit-DBVexDay Proof
Lyris ListManager - MSDE Weak sa Password (Metasploit)
CVE-2005-4145remotewindows20 set 2010
The MSDE version of Lyris ListManager 5.0 through 8.9b configures the sa account in the database to use a password with
50RISCO
abrir
Exploit-DBVexDay Proof
Computer Associates License Client - GETCONFIG Overflow (Metasploit)
CVE-2005-0581remotewindows20 set 2010
Multiple buffer overflows in Computer Associates (CA) License Client and Server 0.1.0.15 allow remote attackers to execu
50RISCO
abrir
Exploit-DBVexDay Proof
Mercantec SoftCart - CGI Overflow (Metasploit)
CVE-2004-2221remotewindows20 set 2010
Buffer overflow in SoftCart.exe in Mercantec SoftCart 4.00b allows remote attackers to execute arbitrary code via a long
50RISCO
abrir
Exploit-DBVexDay Proof
3Com 3CDaemon 2.0 FTP Server - 'Username' Remote Overflow (Metasploit)
CVE-2005-0277remotewindows20 set 2010
Buffer overflow in the FTP service in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to cause a denial of service
50RISCO
abrir
Exploit-DBVexDay Proof
eIQNetworks ESA - Topology DELETEDEVICE Overflow (Metasploit)
CVE-2006-3838remotewindows20 set 2010
Multiple stack-based buffer overflows in eIQnetworks Enterprise Security Analyzer (ESA) before 2.5.0, as used in product
60RISCO
abrir
Exploit-DBVexDay Proof
eIQNetworks ESA - License Manager LICMGR_ADDLICENSE Overflow (Metasploit)
CVE-2006-3838remotewindows20 set 2010
Multiple stack-based buffer overflows in eIQnetworks Enterprise Security Analyzer (ESA) before 2.5.0, as used in product
60RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Private Communications Transport - Remote Overflow (MS04-011) (Metasploit)
CVE-2003-0719remotewindows20 set 2010
Buffer overflow in the Private Communications Transport (PCT) protocol implementation in the Microsoft SSL library, as u
60RISCO
abrir
Exploit-DBVexDay Proof
Hummingbird Connectivity 10 SP5 - LPD Buffer Overflow (Metasploit)
CVE-2005-1815remotewindows20 set 2010
Multiple buffer overflows in Hummingbird Connectivity inetD 10.0.0.1 and 9.0.0.4 allows attackers to cause a denial of s
50RISCO
abrir
Exploit-DBVexDay Proof
Racer 0.5.3 Beta 5 - Remote Buffer Overflow (Metasploit)
CVE-2007-4370remotewindows20 set 2010
Multiple buffer overflows in the (1) client and (2) server in Racer 0.5.3 beta 5 allow remote attackers to execute arbit
50RISCO
abrir
Exploit-DBVexDay Proof
Java 6.19 CMM readMabCurveData - Remote Stack Overflow
CVE-2010-0838remotewindows20 set 2010
Unspecified vulnerability in the Java 2D component in Oracle Java SE and Java for Business 6 Update 18, 5.0, Update, and
28RISCO
abrir
Exploit-DBVexDay Proof
OpenX - 'banner-edit.php' Arbitrary File Upload / PHP Code Execution (Metasploit)
CVE-2009-4098remotephp20 set 2010
Unrestricted file upload vulnerability in banner-edit.php in OpenX adserver 2.8.1 and earlier allows remote authenticate
43RISCO
abrir
Exploit-DBVexDay Proof
VeryPDF PDFView - OCX ActiveX OpenPDF Heap Overflow (Metasploit)
CVE-2008-5492remotewindows20 set 2010
Heap-based buffer overflow in the PDFVIEW.PdfviewCtrl.1 ActiveX control in pdfview.ocx 2.0.0.1 in VeryDOC PDF Viewer OCX
50RISCO
abrir
Exploit-DBVexDay Proof
Adobe CoolType - SING Table 'uniqueName' Remote Stack Buffer Overflow (Metasploit) (1)
CVE-2010-2883HIGHsob ataqueremotewindows20 set 2010
Stack-based buffer overflow in CoolType.dll in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows
100RISCO
abrir
Exploit-DBVexDay Proof
Adobe - U3D CLODProgressiveMeshDeclaration Array Overrun (Metasploit) (1)
CVE-2009-2990remotemultiple20 set 2010
Array index error in Adobe Reader and Acrobat 9.x before 9.2, 8.x before 8.1.7, and possibly 7.x through 7.1.4 might all
50RISCO
abrir
Exploit-DBVexDay Proof
Novell iPrint Client Browser Plugin - 'call-back-url' Remote Stack Overflow
CVE-2010-1527remotewindows19 set 2010
Stack-based buffer overflow in Novell iPrint Client before 5.44 allows remote attackers to execute arbitrary code via a
50RISCO
abrir
Exploit-DBVexDay Proof
BoutikOne 1.0 - SQL Injection
CVE-2010-3479webappsphp19 set 2010
SQL injection vulnerability in list.php in BoutikOne 1.0 allows remote attackers to execute arbitrary SQL commands via t
23RISCO
abrir
Exploit-DBVexDay Proof
SmarterMail 7.1.3876 - Directory Traversal
CVE-2010-3486remotewindows19 set 2010
Directory traversal vulnerability in FileStorageUpload.ashx in SmarterMail 7.1.3876 allows remote attackers to read arbi
23RISCO
abrir
Exploit-DBVexDay Proof
Joomla! Component Restaurant Guide 1.0.0 - Multiple Vulnerabilities
CVE-2010-4928webappsphp18 set 2010
Cross-site scripting (XSS) vulnerability in the Restaurant Guide (com_restaurantguide) component 1.0.0 for Joomla! allow
23RISCO
abrir
Exploit-DBVexDay Proof
Joomla! Component Restaurant Guide 1.0.0 - Multiple Vulnerabilities
CVE-2010-4927webappsphp18 set 2010
SQL injection vulnerability in the Restaurant Guide (com_restaurantguide) component 1.0.0 for Joomla! allows remote atta
23RISCO
abrir
Exploit-DBVexDay Proof
Apple QuickTime FLI LinePacket - Remote Code Execution
CVE-2010-0520doswindows18 set 2010
Heap-based buffer overflow in QuickTimeAuthoring.qtx in QuickTime in Apple Mac OS X before 10.6.3 allows remote attacker
28RISCO
abrir
Exploit-DBVexDay Proof
xt:Commerce Gambio 2008 < 2010 - 'reviews.php' Error-Based SQL Injection
CVE-2010-4954webappsphp18 set 2010
SQL injection vulnerability in product_reviews_info.php in xt:Commerce Gambio 2008 allows remote attackers to execute ar
23RISCO
abrir
Exploit-DBVexDay Proof
Netautor Professional 5.5 - 'login2.php' Cross-Site Scripting
CVE-2010-3489webappsphp17 set 2010
Cross-site scripting (XSS) vulnerability in netautor/napro4/home/login2.php in CMS Digital Workroom (formerly Netautor P
23RISCO
abrir
Exploit-DBVexDay Proof
Mozilla Firefox 3.6.4 - 'Plugin' EnsureCachedAttrParamArrays Remote Code Execution
CVE-2010-1214doswindows17 set 2010
Integer overflow in Mozilla Firefox 3.5.x before 3.5.11 and 3.6.x before 3.6.7, and SeaMonkey before 2.0.6, allows remot
23RISCO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.6.27 < 2.6.36 (RedHat x86-64) - 'compat' Local Privilege Escalation
CVE-2010-3081locallinux_x86-6416 set 2010
The compat_alloc_user_space functions in include/asm/compat.h files in the Linux kernel before 2.6.36-rc4-git2 on 64-bit
23RISCO
abrir
Exploit-DBVexDay Proof
mojoportal - Multiple Vulnerabilities
CVE-2010-3603webappsasp16 set 2010
Cross-site request forgery (CSRF) vulnerability in the file manager service (Services/FileService.ashx) in mojoPortal 2.
23RISCO
abrir
Exploit-DBVexDay Proof
mojoportal - Multiple Vulnerabilities
CVE-2010-3602webappsasp16 set 2010
Cross-site scripting (XSS) vulnerability in ProfileView.aspx in mojoPortal 2.3.4.3 and 2.3.5.1 allows remote attackers t
23RISCO
abrir
Exploit-DBVexDay Proof
Linux Kernel < 2.6.36-rc4-git2 (x86-64) - 'ia32syscall' Emulation Privilege Escalation
CVE-2010-3301locallinux_x86-6416 set 2010
The IA32 system call emulation functionality in arch/x86/ia32/ia32entry.S in the Linux kernel before 2.6.36-rc4-git2 on
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Excel - HFPicture Record Parsing Remote Code Execution
CVE-2010-1248doswindows16 set 2010
Buffer overflow in Microsoft Office Excel 2002 SP3 and Office 2004 for Mac allows remote attackers to execute arbitrary
28RISCO
abrir
Exploit-DBVexDay Proof
BACnet OPC Client - Local Buffer Overflow (1)
CVE-2010-4740localwindows16 set 2010
Stack-based buffer overflow in WTclient.dll in SCADA Engine BACnet OPC Client before 1.0.25 allows user-assisted remote
50RISCO
abrir
Exploit-DBVexDay Proof
PHP microcms 1.0.1 - Multiple Vulnerabilities
CVE-2010-3481webappsphp15 set 2010
Multiple SQL injection vulnerabilities in login.php in ApPHP PHP MicroCMS 1.0.1, when magic_quotes_gpc is disabled, allo
23RISCO
abrir
anteriorpágina 351 / 815próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.