Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.760exploits catalogados
32.083CVEs com exploração pública
1.932testados em laboratório
3.462 exploits
Metasploit600
SonicWALL GMS 6 Arbitrary File Upload
CVE-2013-135917 jan 2012
An Authentication Bypass Vulnerability exists in DELL SonicWALL Analyzer 7.0, Global Management System (GMS) 4.1, 5.0, 5
60RISCO
abrir
Metasploit300
Irfanview JPEG2000 jp2 Stack Buffer Overflow
CVE-2012-089716 jan 2012
Stack-based buffer overflow in the JPEG2000 plugin in IrfanView PlugIns before 4.33 allows remote attackers to execute a
50RISCO
abrir
Metasploit600
WebDAV PHP Upload
CVE-2012-10062HIGH14 jan 2012
XAMPP WebDAV PHP Upload Authentication Bypass RCE
36RISCO
abrir
Metasploit200
HP Diagnostics Server magentservice.exe Overflow
CVE-2011-478912 jan 2012
Stack-based buffer overflow in magentservice.exe in the server in HP LoadRunner 11.00 before patch 4 allows remote attac
50RISCO
abrir
Metasploit300
NTR ActiveX Control Check() Method Buffer Overflow
CVE-2012-026611 jan 2012
Multiple stack-based buffer overflows in the NTR ActiveX control before 2.0.4.8 allow remote attackers to execute arbitr
50RISCO
abrir
Metasploit300
NTR ActiveX Control StopModule() Remote Code Execution
CVE-2012-026711 jan 2012
The StopModule method in the NTR ActiveX control before 2.0.4.8 allows remote attackers to execute arbitrary code via a
50RISCO
abrir
Metasploit500
HP Easy Printer Care XMLCacheMgr Class ActiveX Control Remote Code Execution
CVE-2011-478611 jan 2012
A certain ActiveX control in HPTicketMgr.dll in HP Easy Printer Care Software 2.5 and earlier allows remote attackers to
50RISCO
abrir
Metasploit600
MS12-005 Microsoft Office ClickOnce Unsafe Object Package Handling Vulnerability
CVE-2012-001310 jan 2012
Incomplete blacklist vulnerability in the Windows Packager configuration in Microsoft Windows XP SP2 and SP3, Windows Se
60RISCO
abrir
Metasploit300
MS12-004 midiOutPlayNextPolyEvent Heap Overflow
CVE-2012-0003HIGH10 jan 2012
Unspecified vulnerability in winmm.dll in Windows Multimedia Library in Windows Media Player (WMP) in Microsoft Windows
68RISCO
abrir
Metasploit600
Apache Struts 2 Developer Mode OGNL Execution
CVE-2012-039406 jan 2012
The DebuggingInterceptor component in Apache Struts before 2.3.1.1, when developer mode is used, allows remote attackers
60RISCO
abrir
Metasploit600
Apache Struts Remote Command Execution
CVE-2012-0391CRITICALsob ataque06 jan 2012
The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during
100RISCO
abrir
Metasploit600
OP5 license.php Remote Command Execution
CVE-2012-026105 jan 2012
license.php in system-portal before 1.6.2 in op5 Monitor and op5 Appliance before 5.5.3 allows remote attackers to execu
60RISCO
abrir
Metasploit600
OP5 welcome Remote Command Execution
CVE-2012-026205 jan 2012
op5config/welcome in system-op5config before 2.0.3 in op5 Monitor and op5 Appliance before 5.5.3 allows remote attackers
60RISCO
abrir
Metasploit300
Hashtable Collisions
CVE-2011-503428 dez 2011
Apache Geronimo 2.2.1 and earlier computes hash values for form parameters without restricting the ability to trigger ha
60RISCO
abrir
Metasploit300
Hashtable Collisions
CVE-2011-485828 dez 2011
Apache Tomcat before 5.5.35, 6.x before 6.0.35, and 7.x before 7.0.23 computes hash values for form parameters without r
60RISCO
abrir
Metasploit300
Hashtable Collisions
CVE-2011-503528 dez 2011
Oracle Glassfish 2.1.1, 3.0.1, and 3.1.1, as used in Communications Server 2.0, Sun Java System Application Server 8.1 a
50RISCO
abrir
Metasploit300
Hashtable Collisions
CVE-2011-488528 dez 2011
PHP before 5.3.9 computes hash values for form parameters without restricting the ability to trigger hash collisions pre
60RISCO
abrir
Metasploit400
CoCSoft StreamDown 6.8.0 Buffer Overflow
CVE-2011-505227 dez 2011
Stack-based buffer overflow in CoCSoft Stream Down 6.8.0 allows remote web servers to execute arbitrary code via a long
50RISCO
abrir
Metasploit500
Linux BSD-derived Telnet Service Encryption Key ID Buffer Overflow
CVE-2011-486223 dez 2011
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka k
60RISCO
abrir
Metasploit500
FreeBSD Telnet Service Encryption Key ID Buffer Overflow
CVE-2011-486223 dez 2011
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka k
60RISCO
abrir
Metasploit600
HP Managed Printing Administration jobAcct Remote Command Execution
CVE-2011-416621 dez 2011
Directory traversal vulnerability in the MPAUploader.Uploader.1.UploadFiles method in HP Managed Printing Administration
50RISCO
abrir
Metasploit300
7-Technologies IGSS 9 IGSSdataServer.exe DoS
CVE-2011-405020 dez 2011
Buffer overflow in 7-Technologies (7T) Interactive Graphical SCADA System (IGSS) 9.0.0.11200 allows remote attackers to
23RISCO
abrir
Metasploit300
Enterasys NetSight nssyslogd.exe Buffer Overflow
CVE-2011-522719 dez 2011
Stack-based buffer overflow in the Syslog service (nssyslogd.exe) in Enterasys Network Management Suite (NMS) before 4.1
60RISCO
abrir
Metasploit300
MS11-093 Microsoft Windows OLE Object File Handling Remote Code Execution
CVE-2011-340013 dez 2011
Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 do not properly handle OLE objects in memory, which allows remote a
60RISCO
abrir
Metasploit300
IpSwitch WhatsUp Gold TFTP Directory Traversal
CVE-2011-472212 dez 2011
Directory traversal vulnerability in the TFTP Server 1.0.0.24 in Ipswitch WhatsUp Gold allows remote attackers to read a
50RISCO
abrir
Metasploit600
Splunk Search Remote Code Execution
CVE-2011-464212 dez 2011
mappy.py in Splunk Web in Splunk 4.2.x before 4.2.5 does not properly restrict use of the mappy command to access Python
43RISCO
abrir
Metasploit600
Traq admincp/common.php Remote Code Execution
CVE-2011-10013CRITICAL12 dez 2011
Traq 2.0–2.3 admincp/common.php RCE
63RISCO
abrir
Metasploit400
TrendMicro Control Manger CmdProcessor.exe Stack Buffer Overflow
CVE-2011-500107 dez 2011
Stack-based buffer overflow in the CGenericScheduler::AddTask function in cmdHandlerRedAlertController.dll in CmdProcess
50RISCO
abrir
Metasploit600
Solarwinds Storage Manager 5.1.0 SQL Injection
CVE-2012-257607 dez 2011
SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Prof
50RISCO
abrir
Metasploit200
Firefox nsSVGValue Out-of-Bounds Access Vulnerability
CVE-2011-365806 dez 2011
The SVG implementation in Mozilla Firefox 8.0, Thunderbird 8.0, and SeaMonkey 2.5 does not properly interact with DOMAtt
50RISCO
abrir
anteriorpágina 74 / 116próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.