Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.107exploits catalogados
36.322CVEs com exploração pública
24.695testados em laboratório
19.066 exploits
Exploit-DBVexDay Proof
OP5 5.3.5/5.4.0/5.4.2/5.5.0/5.5.1 - 'license.php' Remote Command Execution (Metasploit)
CVE-2012-0261webappsmultiple25 jan 2015
license.php in system-portal before 1.6.2 in op5 Monitor and op5 Appliance before 5.5.3 allows remote attackers to execu
60RISCO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX networkd - 'effective_audit_token' XPC Type Confusion Sandbox Escape
CVE-2014-4492localosx20 jan 2015
libnetcore in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not verify that certain
28RISCO
abrir
Exploit-DBVexDay Proof
ManageEngine (Multiple Products) - (Authenticated) Arbitrary File Upload (Metasploit)
CVE-2014-5301remotejava20 jan 2015
Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 t
60RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows < 8.1 (x86/x64) - User Profile Service Privilege Escalation (MS15-003)
CVE-2015-0004localwindows18 jan 2015
The User Profile Service (aka ProfSvc) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2
23RISCO
abrir
Exploit-DBVexDay Proof
Lexmark MarkVision Enterprise - Arbitrary File Upload (Metasploit)
CVE-2014-8741remotejava13 jan 2015
Directory traversal vulnerability in the GfdFileUploadServerlet servlet in Lexmark MarkVision Enterprise before 2.1 allo
60RISCO
abrir
Exploit-DBVexDay Proof
Oracle MySQL (Windows) - FILE Privilege Abuse (Metasploit)
CVE-2012-5613remotewindows13 jan 2015
MySQL 5.5.19 and possibly other versions, and MariaDB 5.5.28a and possibly other versions, when configured to assign the
50RISCO
abrir
Exploit-DBVexDay Proof
WordPress Plugin WP Symposium 14.11 - Arbitrary File Upload (Metasploit)
CVE-2014-10021remotephp13 jan 2015
Unrestricted file upload vulnerability in UploadHandler.php in the WP Symposium plugin 14.11 for WordPress allows remote
50RISCO
abrir
Exploit-DBVexDay Proof
Pandora FMS 3.1 - Authentication Bypass / Arbitrary File Upload (Metasploit)
CVE-2010-4279remotephp08 jan 2015
The default configuration of Pandora FMS 3.1 and earlier specifies an empty string for the loginhash_pwd field, which al
50RISCO
abrir
Exploit-DBVexDay Proof
BulletProof FTP Client - BPS Buffer Overflow (Metasploit)
CVE-2014-2973localwindows06 jan 2015
35RISCO
abrir
Exploit-DBVexDay Proof
OP5 5.3.5/5.4.0/5.4.2/5.5.0/5.5.1 - 'welcome' Remote Command Execution (Metasploit)
CVE-2012-0262webappsmultiple05 jan 2015
op5config/welcome in system-op5config before 2.0.3 in op5 Monitor and op5 Appliance before 5.5.3 allows remote attackers
60RISCO
abrir
Exploit-DBVexDay Proof
ASUSWRT 3.0.0.4.376_1071 - LAN Backdoor Command Execution
CVE-2014-9583remotehardware04 jan 2015
common.c in infosvr in ASUS WRT firmware 3.0.0.4.376_1071, 3.0.0.376.2524-g0013f52, and other versions, as used in RT-AC
60RISCO
abrir
Exploit-DBVexDay Proof
e107 2 Bootstrap CMS - Cross-Site Scripting
CVE-2015-1057webappsphp03 jan 2015
Cross-site scripting (XSS) vulnerability in usersettings.php in e107 2.0.0 allows remote attackers to inject arbitrary w
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 8.1 (x86/x64) - 'ahcache.sys' NtApphelpCacheControl Privilege Escalation
CVE-2015-0002localwindows01 jan 2015
The AhcVerifyAdminContext function in ahcache.sys in the Application Compatibility component in Microsoft Windows 7 SP1,
43RISCO
abrir
Exploit-DBVexDay Proof
ProjectSend - Arbitrary File Upload (Metasploit)
CVE-2014-9567remotephp31 dez 2014
Unrestricted file upload vulnerability in process-upload.php in ProjectSend (formerly cFTP) r100 through r561 allows rem
50RISCO
abrir
Exploit-DBVexDay Proof
Social Microblogging PRO 1.5 - Persistent Cross-Site Scripting
CVE-2014-9516webappsphp31 dez 2014
Cross-site scripting (XSS) vulnerability in Social Microblogging PRO 1.5 allows remote attackers to inject arbitrary web
23RISCO
abrir
Exploit-DBVexDay Proof
Notepad++ 6.6.9 - Buffer Overflow
CVE-2014-9456doswindows22 dez 2014
Buffer overflow in NotePad++ 6.6.9 allows remote attackers to have unspecified impact via a long Time attribute in an Ev
28RISCO
abrir
Exploit-DBVexDay Proof
Notepad++ 6.6.9 - Buffer Overflow
CVE-2014-1004doswindows22 dez 2014
20RISCO
abrir
Exploit-DBVexDay Proof
GIT 1.8.5.6/1.9.5/2.0.5/2.1.4/2.2.1 & Mercurial < 3.2.3 - Multiple Vulnerabilities (Metasploit)
CVE-2013-0757remotemultiple18 dez 2014
The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 18.0, Firefox ESR 17.x before 17.0.2, Thunderbi
50RISCO
abrir
Exploit-DBVexDay Proof
GIT 1.8.5.6/1.9.5/2.0.5/2.1.4/2.2.1 & Mercurial < 3.2.3 - Multiple Vulnerabilities (Metasploit)
CVE-2013-0758remotemultiple18 dez 2014
Mozilla Firefox before 18.0, Firefox ESR 10.x before 10.0.12 and 17.x before 17.0.2, Thunderbird before 17.0.2, Thunderb
60RISCO
abrir
Exploit-DBVexDay Proof
Malwarebytes Anti-Malware < 2.0.3 / Anti-Exploit < 1.03.1.1220 - Update Code Execution (Metasploit)
CVE-2014-4936localwindows16 dez 2014
The upgrade functionality in Malwarebytes Anti-Malware (MBAM) consumer before 2.0.3 and Malwarebytes Anti-Exploit (MBAE)
43RISCO
abrir
Exploit-DBVexDay Proof
Tuleap - PHP Unserialize Code Execution (Metasploit)
CVE-2014-8791remotephp15 dez 2014
project/register.php in Tuleap before 7.7, when sys_create_project_in_one_step is disabled, allows remote authenticated
43RISCO
abrir
Exploit-DBVexDay Proof
OpenEMR 4.1.2(7) - Multiple SQL Injections
CVE-2014-5462webappsphp10 dez 2014
Multiple SQL injection vulnerabilities in OpenEMR 4.1.2 (Patch 7) and earlier allow remote authenticated users to execut
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kerberos - Privilege Escalation (MS14-068)
CVE-2014-6324HIGHsob ataqueremotewindows05 dez 2014
The Kerberos Key Distribution Center (KDC) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008
100RISCO
abrir
Exploit-DBVexDay Proof
Tincd - (Authenticated) Remote TCP Stack Buffer Overflow (Metasploit)
CVE-2013-1428remotemultiple02 dez 2014
Stack-based buffer overflow in the receive_tcppacket function in net_packet.c in tinc before 1.0.21 and 1.1 before 1.1pr
50RISCO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX - IOKit Keyboard Driver Privilege Escalation (Metasploit)
CVE-2014-4404HIGHsob ataquelocalosx02 dez 2014
Heap-based buffer overflow in IOHIDFamily in Apple iOS before 8 and Apple TV before 7 allows attackers to execute arbitr
98RISCO
abrir
Exploit-DBVexDay Proof
WordPress Plugin DB Backup - Arbitrary File Download
CVE-2014-9119webappsphp26 nov 2014
Directory traversal vulnerability in download.php in the DB Backup plugin 4.5 and earlier for Wordpress allows remote at
43RISCO
abrir
Exploit-DBVexDay Proof
Advantech EKI-6340 - Command Injection
CVE-2014-8387webappscgi24 nov 2014
cgi/utility.cgi in Advantech EKI-6340 2.05 Wi-Fi Mesh Access Point allows remote authenticated users to execute arbitrar
35RISCO
abrir
Exploit-DBVexDay Proof
Hikvision DVR - RTSP Request Remote Code Execution (Metasploit)
CVE-2014-4880remotelinux24 nov 2014
Buffer overflow in Hikvision DVR DS-7204 Firmware 2.2.10 build 131009, and other models and versions, allows remote atta
60RISCO
abrir
Exploit-DBVexDay Proof
WordPress Plugin SP Client Document Manager 2.4.1 - SQL Injection
CVE-2014-9178webappsphp21 nov 2014
Multiple SQL injection vulnerabilities in classes/ajax.php in the Smarty Pants Plugins SP Project & Document Manager plu
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer OLE Pre-IE11 - Automation Array Remote Code Execution / PowerShell VirtualAlloc (MS14-064)
CVE-2014-6332HIGHsob ataqueremotewindows20 nov 2014
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RISCO
abrir
anteriorpágina 78 / 636próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.