Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.957exploits catalogados
32.195CVEs com exploração pública
1.932testados em laboratório
22.786 exploits
Exploit-DB
AXIS Communications - Cross-Site Scripting / Content Injection
CVE-2015-825817 mar 2017
AXIS Communications products with firmware through 5.80.x allow remote attackers to modify arbitrary files as root via v
23RISCO
abrir
Exploit-DB
Cisco IOS 12.2 < 12.4 / 15.0 < 15.6 - Security Association Negotiation Request Device Memory
CVE-2016-6415HIGHsob ataque17 mar 2017
The server IKEv1 implementation in Cisco IOS 12.2 through 12.4 and 15.0 through 15.6, IOS XE through 3.18S, IOS XR 4.3.x
100RISCO
abrir
Exploit-DB
Oracle Knowledge Management 12.1.1 < 12.2.5 - XML External Entity Leading To Remote Code Execution
CVE-2016-354217 mar 2017
Unspecified vulnerability in the Oracle Knowledge Management component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3
23RISCO
abrir
Exploit-DB
AXIS (Multiple Products) - Cross-Site Request Forgery
CVE-2015-825517 mar 2017
AXIS Communications products allow CSRF, as demonstrated by admin/pwdgrp.cgi, vaconfig.cgi, and admin/local_del.cgi.
23RISCO
abrir
Exploit-DB
Microsoft Edge 38.14393.0.0 - JavaScript Engine Use-After-Free
CVE-2017-007016 mar 2017
A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling object
45RISCO
abrir
Exploit-DB
Cerberus FTP Server 8.0.10.3 - 'MLST' Buffer Overflow (PoC)
CVE-2017-688016 mar 2017
Buffer overflow in Cerberus FTP Server 8.0.10.3 allows remote attackers to cause a denial of service (daemon crash) or p
28RISCO
abrir
Exploit-DB
Microsoft Windows DVD Maker 6.1.7 - XML External Entity Injection
CVE-2017-004516 mar 2017
Windows DVD Maker in Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, and Windows Vista SP2 does not properly parse cr
23RISCO
abrir
Exploit-DB
WordPress Plugin Membership Simplified 1.58 - Arbitrary File Download
CVE-2017-100200816 mar 2017
Vulnerability in wordpress plugin membership-simplified-for-oap-members-only v1.58, The file download code located membe
28RISCO
abrir
Exploit-DB
CommVault Edge 11 SP6 - Stack Buffer Overflow (PoC)
CVE-2017-319516 mar 2017
Commvault Edge Communication Service (cvd) prior to version 11 SP7 or version 11 SP6 with hotfix 590 is prone to a stack
28RISCO
abrir
Exploit-DB
Microsoft Windows - 'LoadUvsTable()' Heap Buffer Overflow
CVE-2016-727415 mar 2017
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
35RISCO
abrir
Exploit-DB
Adobe Flash - Metadata Parsing Out-of-Bounds Read
CVE-2017-293115 mar 2017
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable memory corruption vulnerability related to the pa
28RISCO
abrir
Exploit-DB
Sitecore CMS 8.1 Update-3 - Cross-Site Scripting
CVE-2016-885515 mar 2017
Cross-Site Scripting (XSS) in "/sitecore/client/Applications/List Manager/Taskpages/Contact list" in Sitecore Experience
23RISCO
abrir
Exploit-DB
Adobe Flash - ATF Planar Decompression Heap Overflow
CVE-2017-293415 mar 2017
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability when parsing Adobe Te
28RISCO
abrir
Exploit-DB
Adobe Flash - ATF Thumbnailing Heap Overflow
CVE-2017-293315 mar 2017
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability related to texture co
28RISCO
abrir
Exploit-DB
Adobe Flash - AVC Header Slicing Heap Overflow
CVE-2017-293515 mar 2017
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable heap overflow vulnerability when processing the F
28RISCO
abrir
Exploit-DB
IBM WebSphere - RCE Java Deserialization (Metasploit)
CVE-2015-7450CRITICALsob ataque15 mar 2017
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and
100RISCO
abrir
Exploit-DB
Adobe Flash - MovieClip Attach init Object Use-After-Free
CVE-2017-293215 mar 2017
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable use after free vulnerability in the ActionScript
28RISCO
abrir
Exploit-DB
Apache Struts 2.3.5 < 2.3.31 / 2.5 < 2.5.10 - 'Jakarta' Multipart Parser OGNL Injection (Metasploit)
CVE-2017-5638CRITICALsob ataqueransomware15 mar 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RISCO
abrir
Exploit-DB
Microsoft Windows - COM Session Moniker Privilege Escalation (MS17-012)
CVE-2017-010015 mar 2017
A DCOM object in Helppane.exe in Microsoft Windows 7 SP1; Windows Server 2008 R2; Windows 8.1; Windows Server 2012 Gold
23RISCO
abrir
Exploit-DB
APNGDis 2.8 - 'chunk size descriptor' Heap Buffer Overflow
CVE-2017-619214 mar 2017
Buffer overflow in APNGDis 2.8 and earlier allows a remote attackers to cause denial of service and possibly execute arb
23RISCO
abrir
Exploit-DB
APNGDis 2.8 - 'filename' Stack Buffer Overflow (PoC)
CVE-2017-619114 mar 2017
Buffer overflow in APNGDis 2.8 and below allows a remote attacker to execute arbitrary code via a crafted filename.
23RISCO
abrir
Exploit-DB
APNGDis 2.8 - 'image width / height chunk' Heap Buffer Overflow
CVE-2017-619314 mar 2017
Buffer overflow in APNGDis 2.8 and earlier allows remote attackers to cause a denial of service and possibly execute arb
23RISCO
abrir
Exploit-DB
Cerberus FTP Server 8.0.10.1 - Denial of Service
CVE-2017-636713 mar 2017
In Cerberus FTP Server 8.0.10.1, a crafted HTTP request causes the Windows service to crash. The attack methodology invo
23RISCO
abrir
Exploit-DB
Netgear R7000 / R6400 - 'cgi-bin' Command Injection (Metasploit)
CVE-2016-6277HIGHsob ataque13 mar 2017
NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.B
100RISCO
abrir
Exploit-DB
Nintendo Switch - WebKit Code Execution (PoC)
CVE-2016-4657HIGHsob ataque12 mar 2017
WebKit in Apple iOS before 9.3.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory
98RISCO
abrir
Exploit-DB
MobaXterm Personal Edition 9.4 - Directory Traversal
CVE-2017-680511 mar 2017
Directory traversal vulnerability in the TFTP server in MobaXterm Personal Edition 9.4 allows remote attackers to read a
23RISCO
abrir
Exploit-DB
Fiyo CMS 2.0.6.1 - Privilege Escalation
CVE-2017-682311 mar 2017
Fiyo CMS 2.0.6.1 allows remote authenticated users to gain privileges via a modified level parameter to dapur/ in an app
23RISCO
abrir
Exploit-DB
dnaLIMS DNA Sequencing - Directory Traversal / Session Hijacking / Cross-Site Scripting
CVE-2017-652810 mar 2017
An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is affected by plaintext password storage (the /home/dna/
23RISCO
abrir
Exploit-DB
Kinsey Infor/Lawson / ESBUS - SQL Injection
CVE-2017-655010 mar 2017
Multiple SQL injection vulnerabilities in Kinsey Infor-Lawson (formerly ESBUS) allow remote attackers to execute arbitra
23RISCO
abrir
Exploit-DB
dnaLIMS DNA Sequencing - Directory Traversal / Session Hijacking / Cross-Site Scripting
CVE-2017-652710 mar 2017
An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to a NUL-terminated directory traversal att
50RISCO
abrir
anteriorpágina 144 / 760próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.