Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.760exploits catalogados
32.083CVEs com exploração pública
1.932testados em laboratório
3.462 exploits
Metasploit600
WordPress WP-Property PHP File Upload Vulnerability
CVE-2012-10027CRITICAL26 mar 2012
WordPress Plugin WP-Property <= 1.35.0 PHP File Upload
63RISCO
abrir
Metasploit400
TFM MMPlayer (m3u/ppl File) Buffer Overflow
CVE-2009-256623 mar 2012
Stack-based buffer overflow in TFM MMPlayer 2.0, and possibly 2.0.0.30, allows remote attackers to execute arbitrary cod
50RISCO
abrir
Metasploit300
FlexNet License Server Manager lmgrd Buffer Overflow
CVE-2011-413523 mar 2012
Multiple directory traversal vulnerabilities in lmgrd in Flexera FlexNet Publisher 11.10 (aka FlexNet License Server Man
30RISCO
abrir
Metasploit300
Cisco Linksys PlayerPT ActiveX Control Buffer Overflow
CVE-2012-028422 mar 2012
Stack-based buffer overflow in the SetSource method in the Cisco Linksys PlayerPT ActiveX control 1.0.0.15 in PlayerPT.o
50RISCO
abrir
Metasploit0
FreePBX 2.10.0 / 2.9.0 callmenum Remote Code Execution
CVE-2012-486920 mar 2012
The callme_startcall function in recordings/misc/callme_page.php in FreePBX 2.9, 2.10, and earlier allows remote attacke
60RISCO
abrir
Metasploit300
MS12-020 Microsoft Remote Desktop Use-After-Free DoS
CVE-2012-000216 mar 2012
The Remote Desktop Protocol (RDP) implementation in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows V
60RISCO
abrir
Metasploit300
VLC MMS Stream Handling Buffer Overflow
CVE-2012-177515 mar 2012
Stack-based buffer overflow in VideoLAN VLC media player before 2.0.1 allows remote attackers to execute arbitrary code
50RISCO
abrir
Metasploit300
Sockso Music Host Server 1.5 Directory Traversal
CVE-2012-10061HIGH14 mar 2012
Sockso Music Host Server <= 1.5 Path Traversal
36RISCO
abrir
Metasploit300
HP Data Protector Create New Folder Buffer Overflow
CVE-2012-012412 mar 2012
Unspecified vulnerability in HP Data Protector Express (aka DPX) 5.0.00 before build 59287 and 6.0.00 before build 11974
50RISCO
abrir
Metasploit300
NetDecision NOCVision Server Directory Traversal
CVE-2012-146507 mar 2012
Stack-based buffer overflow in the HTTP Server in NetMechanica NetDecision before 4.6.1 allows remote attackers to cause
43RISCO
abrir
Metasploit300
IBM Tivoli Provisioning Manager Express for Software Distribution Isig.isigCtl.1 ActiveX RunAndUploadFile() Method Overflow
CVE-2012-019801 mar 2012
Stack-based buffer overflow in the RunAndUploadFile method in the Isig.isigCtl.1 ActiveX control in IBM Tivoli Provision
50RISCO
abrir
Metasploit300
Ricoh DC DL-10 SR10 FTP USER Command Buffer Overflow
CVE-2012-500201 mar 2012
Stack-based buffer overflow in SR10 FTP server (SR10.exe) 1.1.0.6 in Ricoh DC Software DL-10 4.5.0.1, when the Log file
50RISCO
abrir
Metasploit500
IBM Personal Communications iSeries Access WorkStation 5.9 Profile
CVE-2012-020128 fev 2012
Stack-based buffer overflow in pcspref.dll in pcsws.exe in IBM Personal Communications 5.9.x before 5.9.8 and 6.0.x befo
50RISCO
abrir
Metasploit300
Sysax 5.53 SSH Username Buffer Overflow
CVE-2012-10060CRITICAL27 fev 2012
Sysax Multi Server < 5.55 SSH Username Buffer Overflow
63RISCO
abrir
Metasploit300
NetDecision 4.5.1 HTTP Server Buffer Overflow
CVE-2012-146524 fev 2012
Stack-based buffer overflow in the HTTP Server in NetMechanica NetDecision before 4.6.1 allows remote attackers to cause
43RISCO
abrir
Metasploit300
Csound hetro File Handling Stack Buffer Overflow
CVE-2012-027023 fev 2012
Multiple stack-based buffer overflows in Csound before 5.16.6 allow remote attackers to execute arbitrary code via a cra
50RISCO
abrir
Metasploit300
Novell ZENworks Configuration Management Preboot Service 0x6c Buffer Overflow
CVE-2011-317522 fev 2012
Stack-based buffer overflow in the Preboot Service in Novell ZENworks Configuration Management (ZCM) 11.1 and 11.1a allo
50RISCO
abrir
Metasploit300
Novell ZENworks Configuration Management Preboot Service 0x4c Buffer Overflow
CVE-2011-317622 fev 2012
Stack-based buffer overflow in the Preboot Service in Novell ZENworks Configuration Management (ZCM) 11.1 and 11.1a allo
50RISCO
abrir
Metasploit300
ASUS Net4Switch ipswcom.dll ActiveX Stack Buffer Overflow
CVE-2012-492417 fev 2012
Buffer overflow in the CxDbgPrint function in the ipswcom.dll ActiveX component 1.0.0.1 for ASUS Net4Switch 1.0.0020 all
50RISCO
abrir
Metasploit300
Adobe Flash Player MP4 'cprt' Overflow
CVE-2012-0754HIGHsob ataque15 fev 2012
Adobe Flash Player before 10.3.183.15 and 11.x before 11.1.102.62 on Windows, Mac OS X, Linux, and Solaris; before 11.1.
100RISCO
abrir
Metasploit600
LANDesk Lenovo ThinkManagement Console Remote Command Execution
CVE-2012-119515 fev 2012
Unrestricted file upload vulnerability in andesk/managementsuite/core/core.anonymous/ServerSetup.asmx in the ServerSetup
50RISCO
abrir
Metasploit600
LANDesk Lenovo ThinkManagement Console Remote Command Execution
CVE-2012-119615 fev 2012
Directory traversal vulnerability in the VulCore web service (WSVulnerabilityCore/VulCore.asmx) in Lenovo ThinkManagemen
50RISCO
abrir
Metasploit600
Java AtomicReferenceArray Type Violation Vulnerability
CVE-2012-0507CRITICALsob ataqueransomware14 fev 2012
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Up
100RISCO
abrir
Metasploit600
Sun Java Web Start Plugin Command Line Argument Injection
CVE-2012-050014 fev 2012
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 2 and earlier, 6 Up
50RISCO
abrir
Metasploit600
Horde 3.3.12 Backdoor Arbitrary PHP Code Execution
CVE-2012-020913 fev 2012
Horde 3.3.12, Horde Groupware 1.2.10, and Horde Groupware Webmail Edition 1.2.10, as distributed by FTP between November
60RISCO
abrir
Metasploit300
RabidHamster R4 Log Entry sprintf() Buffer Overflow
CVE-2012-10058CRITICAL09 fev 2012
RabidHamster R4 Log Entry sprintf() Buffer Overflow
63RISCO
abrir
Metasploit600
vBSEO proc_deutf() Remote PHP Code Injection
CVE-2012-522323 jan 2012
The proc_deutf function in includes/functions_vbseocp_abstract.php in vBSEO 3.5.0, 3.5.1, 3.5.2, 3.6.0, and earlier allo
50RISCO
abrir
Metasploit600
PolarBear CMS PHP File Upload Vulnerability
CVE-2013-080321 jan 2012
A PHP File Upload Vulnerability exists in PolarBear CMS 2.5 via upload.php, which could let a malicious user execute arb
60RISCO
abrir
Metasploit600
appRain CMF Arbitrary PHP File Upload Vulnerability
CVE-2012-115319 jan 2012
Unrestricted file upload vulnerability in addons/uploadify/uploadify.php in appRain CMF 0.1.5 and earlier allows remote
50RISCO
abrir
Metasploit300
General Electric D20 Password Recovery
CVE-2012-666319 jan 2012
General Electric D20ME devices are not properly configured and reveal plaintext passwords.
18RISCO
abrir
anteriorpágina 73 / 116próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.