Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.836exploits catalogados
32.133CVEs com exploração pública
1.932testados em laboratório
3.462 exploits
Metasploit300
Oracle Secure Backup Authentication Bypass/Command Injection Vulnerability
CVE-2009-197718 ago 2009
Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.2.0.3 allows remote attackers
60RISCO
abrir
Metasploit500
Linux Kernel Sendpage Local Privilege Escalation
CVE-2009-269213 ago 2009
The Linux kernel 2.6.0 through 2.6.30.4, and 2.4.4 through 2.4.37.4, does not initialize all function pointers for socke
43RISCO
abrir
Metasploit300
Microsoft OWC Spreadsheet HTMLURL Buffer Overflow
CVE-2009-153411 ago 2009
Buffer overflow in the Office Web Components ActiveX Control in Microsoft Office XP SP3, Office 2000 Web Components SP3,
50RISCO
abrir
Metasploit400
BlazeDVD 6.1 PLF Buffer Overflow
CVE-2006-619903 ago 2009
Stack-based buffer overflow in BlazeVideo BlazeDVD Standard and Professional 5.0, and possibly earlier, allows remote at
50RISCO
abrir
Metasploit500
SAP Business One License Manager 2005 Buffer Overflow
CVE-2009-498801 ago 2009
Stack-based buffer overflow in NT_Naming_Service.exe in SAP Business One 2005 A 6.80.123 and 6.80.320 allows remote atta
50RISCO
abrir
Metasploit500
Millenium MP3 Studio 2.0 (PLS File) Stack Buffer Overflow
CVE-2009-20002HIGH30 jul 2009
Millenium MP3 Studio <= 2.0 .pls File Stack-Based Buffer Overflow
36RISCO
abrir
Metasploit600
Joomla 1.5.12 TinyBrowser File Upload Code Execution
CVE-2011-490822 jul 2009
TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php.
50RISCO
abrir
Metasploit600
DD-WRT HTTP Daemon Arbitrary Command Execution
CVE-2009-276520 jul 2009
httpd.c in httpd in the management GUI in DD-WRT 24 sp1, and other versions before build 12533, allows remote attackers
60RISCO
abrir
Metasploit300
Microsoft OWC Spreadsheet msDataSourceObject Memory Corruption
CVE-2009-113613 jul 2009
The Microsoft Office Web Components Spreadsheet ActiveX control (aka OWC10 or OWC11), as distributed in Office XP SP3 an
50RISCO
abrir
Metasploit300
Firefox 3.5 escape() Return Value Memory Corruption
CVE-2009-247713 jul 2009
js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firefox 3.5 before 3.5.1
50RISCO
abrir
Metasploit200
AwingSoft Winds3D Player SceneURL Buffer Overflow
CVE-2009-458810 jul 2009
Heap-based buffer overflow in the WindsPlayerIE.View.1 ActiveX control in WindsPly.ocx 3.5.0.0 Beta, 3.0.0.5, and earlie
50RISCO
abrir
Metasploit600
Wyse Rapport Hagent Fake Hserver Command Execution
CVE-2009-069510 jul 2009
hagent.exe in Wyse Device Manager (WDM) 4.7.x does not require authentication for commands, which allows remote attacker
50RISCO
abrir
Metasploit300
Microsoft DirectShow (msvidctl.dll) MPEG-2 Memory Corruption
CVE-2008-0015HIGHsob ataque05 jul 2009
Stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL), as used in
100RISCO
abrir
Metasploit600
ColdFusion 8.0.1 Arbitrary File Upload and Execute
CVE-2009-226503 jul 2009
Multiple directory traversal vulnerabilities in FCKeditor before 2.6.4.1 allow remote attackers to create executable fil
60RISCO
abrir
Metasploit300
Media Jukebox 8.0.400 Buffer Overflow (SEH)
CVE-2009-265001 jul 2009
Heap-based buffer overflow in Sorcerer Software MultiMedia Jukebox 4.0 Build 020124 allows remote attackers to cause a d
50RISCO
abrir
Metasploit400
HT-MP3Player 1.0 HT3 File Parsing Buffer Overflow
CVE-2009-248529 jun 2009
Stack-based buffer overflow in HT-MP3Player 1.0 allows remote attackers to execute arbitrary code via a long string in a
50RISCO
abrir
Metasploit500
Timbuktu PlughNTCommand Named Pipe Buffer Overflow
CVE-2009-139425 jun 2009
Stack-based buffer overflow in Motorola Timbuktu Pro 8.6.5 on Windows allows remote attackers to execute arbitrary code
50RISCO
abrir
Metasploit500
VideoLAN Client (VLC) Win32 smb:// URI Buffer Overflow
CVE-2009-248424 jun 2009
Stack-based buffer overflow in the Win32AddConnection function in modules/access/smb.c in VideoLAN VLC media player 0.9.
50RISCO
abrir
Metasploit600
Nagios3 statuswml.cgi Ping Command Execution
CVE-2009-228822 jun 2009
statuswml.cgi in Nagios before 3.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in t
60RISCO
abrir
Metasploit400
Bopup Communications Server Buffer Overflow
CVE-2009-222718 jun 2009
Stack-based buffer overflow in B Labs Bopup Communication Server 3.2.26.5460 allows remote attackers to execute arbitrar
50RISCO
abrir
Metasploit300
Slowloris Denial of Service Attack
CVE-2007-675017 jun 2009
The Apache HTTP Server 1.x and 2.x allows remote attackers to cause a denial of service (daemon outage) via partial HTTP
40RISCO
abrir
Metasploit300
Slowloris Denial of Service Attack
CVE-2010-222717 jun 2009
Apache Tomcat 5.5.0 through 5.5.29, 6.0.0 through 6.0.27, and 7.0.0 beta does not properly handle an invalid Transfer-En
30RISCO
abrir
Metasploit300
Scanner for Bleichenbacher Oracle in RSA PKCS #1 v1.5
CVE-2012-508117 jun 2009
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Up
30RISCO
abrir
Metasploit300
Scanner for Bleichenbacher Oracle in RSA PKCS #1 v1.5
CVE-2017-1738217 jun 2009
Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.5 before build 67.13, 11.0 before build
23RISCO
abrir
Metasploit300
Scanner for Bleichenbacher Oracle in RSA PKCS #1 v1.5
CVE-2017-13099HIGH17 jun 2009
wolfSSL Bleichenbacher/ROBOT
41RISCO
abrir
Metasploit300
Scanner for Bleichenbacher Oracle in RSA PKCS #1 v1.5
CVE-2016-688317 jun 2009
MatrixSSL before 3.8.3 configured with RSA Cipher Suites allows remote attackers to obtain sensitive information via a B
23RISCO
abrir
Metasploit300
Scanner for Bleichenbacher Oracle in RSA PKCS #1 v1.5
CVE-2017-1742817 jun 2009
Cavium Nitrox SSL, Nitrox V SSL, and TurboSSL software development kits (SDKs) allow remote attackers to decrypt TLS cip
23RISCO
abrir
Metasploit300
Scanner for Bleichenbacher Oracle in RSA PKCS #1 v1.5
CVE-2017-1742717 jun 2009
Radware Alteon devices with a firmware version between 31.0.0.0-31.0.3.0 are vulnerable to an adaptive-chosen ciphertext
23RISCO
abrir
Metasploit300
Scanner for Bleichenbacher Oracle in RSA PKCS #1 v1.5
CVE-2017-616817 jun 2009
On BIG-IP versions 11.6.0-11.6.2 (fixed in 11.6.2 HF1), 12.0.0-12.1.2 HF1 (fixed in 12.1.2 HF2), or 13.0.0-13.0.0 HF2 (f
23RISCO
abrir
Metasploit300
Scanner for Bleichenbacher Oracle in RSA PKCS #1 v1.5
CVE-2017-1237317 jun 2009
A vulnerability in the TLS protocol implementation of legacy Cisco ASA 5500 Series (ASA 5505, 5510, 5520, 5540, and 5550
23RISCO
abrir
anteriorpágina 88 / 116próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.