Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.836exploits catalogados
32.133CVEs com exploração pública
1.932testados em laboratório
3.462 exploits
Metasploit400
Adobe Flash Player ActionScript Launch Command Execution Vulnerability
CVE-2008-549917 dez 2008
Unspecified vulnerability in Adobe Flash Player for Linux 10.0.12.36, and 9.0.151.0 and earlier, allows remote attackers
60RISCO
abrir
Metasploit500
Realtek Media Player Playlist Buffer Overflow
CVE-2008-566416 dez 2008
Stack-based buffer overflow in Realtek Media Player (aka Realtek Sound Manager, RtlRack, or rtlrack.exe) 1.15.0.0 allows
50RISCO
abrir
Metasploit400
MS09-004 Microsoft SQL Server sp_replwritetovarbin Memory Corruption
CVE-2008-541609 dez 2008
Heap-based buffer overflow in Microsoft SQL Server 2000 SP4, 8.00.2050, 8.00.2039, and earlier; SQL Server 2000 Desktop
60RISCO
abrir
Metasploit600
MS09-004 Microsoft SQL Server sp_replwritetovarbin Memory Corruption via SQL Injection
CVE-2008-541609 dez 2008
Heap-based buffer overflow in Microsoft SQL Server 2000 SP4, 8.00.2050, 8.00.2039, and earlier; SQL Server 2000 Desktop
60RISCO
abrir
Metasploit300
MS08-078 Microsoft Internet Explorer Data Binding Memory Corruption
CVE-2008-484407 dez 2008
Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet
50RISCO
abrir
Metasploit600
Sun Java Calendar Deserialization Privilege Escalation
CVE-2008-535303 dez 2008
The Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; a
60RISCO
abrir
Metasploit400
Cain and Abel RDP Buffer Overflow
CVE-2008-540530 nov 2008
Stack-based buffer overflow in the RDP protocol password decoder in Cain & Abel 4.9.23 and 4.9.24, and possibly earlier,
50RISCO
abrir
Metasploit100
Microsoft Works 7 WkImgSrv.dll WKsPictureInterface() ActiveX Code Execution
CVE-2008-189828 nov 2008
A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and
50RISCO
abrir
Metasploit300
Avahi Source Port 0 DoS
CVE-2008-508114 nov 2008
The originates_from_local_legacy_unicast_socket function (avahi-core/server.c) in avahi-daemon in Avahi before 0.6.24 al
50RISCO
abrir
Metasploit300
Pi3Web ISAPI DoS
CVE-2008-693813 nov 2008
Pi3Web 2.0.3 before PL2, when installed on Windows as a desktop application and without using the Pi3Web/Conf/Intenet.pi
43RISCO
abrir
Metasploit600
Openfire Admin Console Authentication Bypass
CVE-2008-650810 nov 2008
Directory traversal vulnerability in the AuthCheck filter in the Admin Console in Openfire 3.6.0a and earlier allows rem
60RISCO
abrir
Metasploit400
VLC Media Player RealText Subtitle Overflow
CVE-2008-503605 nov 2008
Stack-based buffer overflow in VideoLAN VLC media player 0.9.x before 0.9.6 might allow user-assisted attackers to execu
50RISCO
abrir
Metasploit600
Chilkat Crypt ActiveX WriteFile Unsafe Method
CVE-2008-500203 nov 2008
Insecure method vulnerability in the ChilkatCrypt2.ChilkatCrypt2.1 ActiveX control (ChilkatCrypt2.dll 4.3.2.1) in Chilka
50RISCO
abrir
Metasploit100
DjVu DjVu_ActiveX_MSOffice.dll ActiveX ComponentBuffer Overflow
CVE-2008-492230 out 2008
Buffer overflow in the DjVu ActiveX Control 3.0 for Microsoft Office (DjVu_ActiveX_MSOffice.dll) allows remote attackers
50RISCO
abrir
Metasploit300
PacketTrap TFTP Server 2.2.5459.0 DoS
CVE-2008-131129 out 2008
The TFTP server in PacketTrap pt360 Tool Suite PRO 2.0.3901.0 and earlier allows remote attackers to cause a denial of s
50RISCO
abrir
Metasploit500
MS08-067 Microsoft Server Service Relative Path Stack Corruption
CVE-2008-4250CRITICALsob ataque28 out 2008
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RISCO
abrir
Metasploit400
TugZip 3.5 Zip File Parsing Buffer Overflow Vulnerability
CVE-2008-477928 out 2008
Stack-based buffer overflow in TUGzip 3.5.0.0 allows remote attackers to denial of service (crash) or execute arbitrary
50RISCO
abrir
Metasploit300
Victory FTP Server 5.0 LIST DoS
CVE-2008-682924 out 2008
VicFTPS 5.0 allows remote attackers to cause a denial of service (crash) via a LIST command that starts with a "/\/" (fo
50RISCO
abrir
Metasploit300
Victory FTP Server 5.0 LIST DoS
CVE-2008-203124 out 2008
VicFTPS 5.0 allows remote attackers to cause a denial of service (crash) via a crafted LIST command, which triggers a NU
50RISCO
abrir
Metasploit600
Opera historysearch XSS
CVE-2008-469623 out 2008
Cross-site scripting (XSS) vulnerability in Opera.dll in Opera before 9.61 allows remote attackers to inject arbitrary w
50RISCO
abrir
Metasploit300
Oracle DB SQL Injection via SYS.LT.MERGEWORKSPACE
CVE-2008-398322 out 2008
Unspecified vulnerability in the Workspace Manager component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.3,
50RISCO
abrir
Metasploit300
Oracle DB SQL Injection via SYS.DBMS_CDC_IPUBLISH.ALTER_HOTLOG_INTERNAL_CSOURCE
CVE-2008-399622 out 2008
Unspecified vulnerability in the Change Data Capture component in Oracle Database 10.1.0.5, 10.2.0.4, and 11.1.0.6 allow
18RISCO
abrir
Metasploit300
Oracle DB SQL Injection via SYS.DBMS_CDC_PUBLISH.ALTER_AUTOLOG_CHANGE_SOURCE
CVE-2008-399522 out 2008
Unspecified vulnerability in the Change Data Capture component in Oracle Database 10.1.0.5, 10.2.0.4, and 11.1.0.6 allow
18RISCO
abrir
Metasploit400
VideoLAN VLC TiVo Buffer Overflow
CVE-2008-465422 out 2008
Stack-based buffer overflow in the parse_master function in the Ty demux plugin (modules/demux/ty.c) in VLC Media Player
50RISCO
abrir
Metasploit600
Husdawg, LLC. System Requirements Lab ActiveX Unsafe Method
CVE-2008-438516 out 2008
Husdawg, LLC Systems Requirements Lab 3, as used by Instant Expert Analysis, allows remote attackers to force the downlo
50RISCO
abrir
Metasploit600
Mantis manage_proj_page PHP Code Execution
CVE-2008-468716 out 2008
manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort param
50RISCO
abrir
Metasploit300
Titan FTP Server 6.26.630 SITE WHO DoS
CVE-2008-608214 out 2008
Titan FTP Server 6.26 build 630 allows remote attackers to cause a denial of service (CPU consumption) via the SITE WHO
50RISCO
abrir
Metasploit300
Microsoft Host Integration Server 2006 Command Execution Vulnerability
CVE-2008-346614 out 2008
Microsoft Host Integration Server (HIS) 2000, 2004, and 2006 does not limit RPC access to administrative functions, whic
40RISCO
abrir
Metasploit500
Sun Solaris sadmind adm_build_path() Buffer Overflow
CVE-2008-455614 out 2008
Stack-based buffer overflow in the adm_build_path function in sadmind in Sun Solstice AdminSuite on Solaris 8 and 9 allo
50RISCO
abrir
Metasploit300
XM Easy Personal FTP Server 5.6.0 NLST DoS
CVE-2008-562613 out 2008
XM Easy Personal FTP Server 5.6.0 allows remote authenticated users to cause a denial of service via a crafted argument
50RISCO
abrir
anteriorpágina 91 / 116próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.