Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.836exploits catalogados
32.133CVEs com exploração pública
1.932testados em laboratório
3.462 exploits
Metasploit300
Scanner for Bleichenbacher Oracle in RSA PKCS #1 v1.5
CVE-2017-1237317 jun 2009
A vulnerability in the TLS protocol implementation of legacy Cisco ASA 5500 Series (ASA 5505, 5510, 5520, 5540, and 5550
23RISCO
abrir
Metasploit300
Scanner for Bleichenbacher Oracle in RSA PKCS #1 v1.5
CVE-2017-1738217 jun 2009
Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.5 before build 67.13, 11.0 before build
23RISCO
abrir
Metasploit300
Scanner for Bleichenbacher Oracle in RSA PKCS #1 v1.5
CVE-2012-508117 jun 2009
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 7 and earlier, 6 Up
30RISCO
abrir
Metasploit300
Green Dam URL Processing Buffer Overflow
CVE-2009-20008HIGH11 jun 2009
Green Dam 3.17 URL Processing Buffer Overflow
36RISCO
abrir
Metasploit600
Worldweaver DX Studio Player shell.execute() Command Execution
CVE-2009-201109 jun 2009
Worldweaver DX Studio Player 3.0.29.0, 3.0.22.0, 3.0.12.0, and probably other versions before 3.0.29.1, when used as a p
50RISCO
abrir
Metasploit600
PeaZip Zip Processing Command Injection
CVE-2009-226105 jun 2009
PeaZIP 2.6.1, 2.5.1, and earlier on Windows allows user-assisted remote attackers to execute arbitrary commands via a .z
50RISCO
abrir
Metasploit200
SafeNet SoftRemote IKE Service Buffer Overflow
CVE-2009-194301 jun 2009
Stack-based buffer overflow in the IKE service (ireIke.exe) in SafeNet SoftRemote before 10.8.6 allows remote attackers
60RISCO
abrir
Metasploit500
Apple OS X iTunes 8.1.1 ITMS Overflow
CVE-2009-095001 jun 2009
Stack-based buffer overflow in Apple iTunes before 8.2 allows remote attackers to execute arbitrary code or cause a deni
43RISCO
abrir
Metasploit300
Winamp MAKI Buffer Overflow
CVE-2009-183120 mai 2009
The Nullsoft Modern Skins Support module (gen_ff.dll) in Nullsoft Winamp before 5.552 allows remote attackers to execute
50RISCO
abrir
Metasploit300
AOL Radio AmpX ActiveX Control ConvertFile() Buffer Overflow
CVE-2007-575519 mai 2009
Multiple stack-based buffer overflows in the AOL AmpX ActiveX control in AmpX.dll 2.6.1.11 in AOL Radio allow remote att
23RISCO
abrir
Metasploit300
NetDecision 4.2 TFTP Directory Traversal
CVE-2009-173016 mai 2009
Multiple directory traversal vulnerabilities in NetMechanica NetDecision TFTP Server 4.2 allow remote attackers to read
50RISCO
abrir
Metasploit600
NetDecision 4.2 TFTP Writable Directory Traversal Execution
CVE-2009-173016 mai 2009
Multiple directory traversal vulnerabilities in NetMechanica NetDecision TFTP Server 4.2 allow remote attackers to read
50RISCO
abrir
Metasploit300
Oracle DB SQL Injection via SYS.LT.ROLLBACKWORKSPACE
CVE-2009-097804 mai 2009
Unspecified vulnerability in the Workspace Manager component in Oracle Database 10.2.0.4 and 11.1.0.6 allows remote auth
23RISCO
abrir
Metasploit300
BaoFeng Storm mps.dll ActiveX OnBeforeVideoDownload Buffer Overflow
CVE-2009-161230 abr 2009
Stack-based buffer overflow in the MPS.StormPlayer.1 ActiveX control in mps.dll 3.9.4.27 in Baofeng Storm allows remote
50RISCO
abrir
Metasploit600
Symantec System Center Alert Management System (xfr.exe) Arbitrary Command Execution
CVE-2009-142928 abr 2009
The Intel LANDesk Common Base Agent (CBA) in Symantec Alert Management System 2 (AMS2), as used in Symantec System Cente
60RISCO
abrir
Metasploit400
Symantec Alert Management System Intel Alert Originator Service Buffer Overflow
CVE-2009-143028 abr 2009
Multiple stack-based buffer overflows in IAO.EXE in the Intel Alert Originator Service in Symantec Alert Management Syst
50RISCO
abrir
Metasploit500
Linux udev Netlink Local Privilege Escalation
CVE-2009-118516 abr 2009
udev before 1.4.1 does not verify whether a NETLINK message originates from kernel space, which allows local users to ga
60RISCO
abrir
Metasploit600
EnjoySAP SAP GUI ActiveX Control Arbitrary File Download
CVE-2008-483015 abr 2009
Insecure method vulnerability in the KWEdit ActiveX control in SAP GUI 6.40 Patch 29 (KWEDIT.DLL 6400.1.1.41) and 7.10 P
43RISCO
abrir
Metasploit300
Microsoft Whale Intelligent Application Gateway ActiveX Control Buffer Overflow
CVE-2007-223815 abr 2009
Multiple stack-based buffer overflows in the Whale Client Components ActiveX control (WhlMgr.dll), as used in Microsoft
50RISCO
abrir
Metasploit500
Novell NetIdentity Agent XTIERRPCPIPE Named Pipe Buffer Overflow
CVE-2009-135006 abr 2009
Unspecified vulnerability in xtagent.exe in Novell NetIdentity Client before 1.2.4 allows remote attackers to execute ar
50RISCO
abrir
Metasploit500
UltraISO CCD File Parsing Buffer Overflow
CVE-2009-126003 abr 2009
Multiple stack-based buffer overflows in UltraISO 9.3.3.2685 and earlier allow remote attackers to cause a denial of ser
50RISCO
abrir
Metasploit300
SAP AG SAPgui EAI WebViewer3D Buffer Overflow
CVE-2007-447531 mar 2009
Stack-based buffer overflow in EAI WebViewer3D ActiveX control (webviewer3d.dll) in SAP AG SAPgui before 7.10 Patch Leve
50RISCO
abrir
Metasploit300
XM Easy Personal FTP Server 5.7.0 NLST DoS
CVE-2008-562627 mar 2009
XM Easy Personal FTP Server 5.6.0 allows remote authenticated users to cause a denial of service via a crafted argument
50RISCO
abrir
Metasploit300
IBM Access Support ActiveX Control Buffer Overflow
CVE-2009-021524 mar 2009
Stack-based buffer overflow in the GetXMLValue method in the IBM Access Support ActiveX control in IbmEgath.dll, as dist
50RISCO
abrir
Metasploit400
Adobe Collab.getIcon() Buffer Overflow
CVE-2009-0927HIGHsob ataque24 mar 2009
Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows r
100RISCO
abrir
Metasploit400
Adobe Collab.getIcon() Buffer Overflow
CVE-2009-0927HIGHsob ataque24 mar 2009
Stack-based buffer overflow in Adobe Reader and Adobe Acrobat 9 before 9.1, 8 before 8.1.3 , and 7 before 7.1.1 allows r
100RISCO
abrir
Metasploit600
phpMyAdmin Config File Code Injection
CVE-2009-128524 mar 2009
Static code injection vulnerability in the getConfigFile function in setup/lib/ConfigFile.class.php in phpMyAdmin 3.x be
23RISCO
abrir
Metasploit600
phpMyAdmin Config File Code Injection
CVE-2009-1151CRITICALsob ataque24 mar 2009
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remo
100RISCO
abrir
Metasploit300
Talkative IRC v0.4.4.16 Response Buffer Overflow
CVE-2009-20007CRITICAL17 mar 2009
Talkative IRC v0.4.4.16 Response Buffer Overflow
63RISCO
abrir
Metasploit600
IBM System Director Agent DLL Injection
CVE-2009-088010 mar 2009
Directory traversal vulnerability in the CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows rem
50RISCO
abrir
anteriorpágina 89 / 116próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.