Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.957exploits catalogados
32.195CVEs com exploração pública
1.932testados em laboratório
22.786 exploits
Exploit-DB
OpenSSH 6.8 < 6.9 - 'PTY' Local Privilege Escalation
CVE-2015-656526 jan 2017
sshd in OpenSSH 6.8 and 6.9 uses world-writable permissions for TTY devices, which allows local users to cause a denial
23RISCO
abrir
Exploit-DB
Apple macOS 10.12.1 / iOS Kernel - 'IOService::matchPassive' Use-After-Free
CVE-2017-235326 jan 2017
An issue was discovered in certain Apple products. macOS before 10.12.3 is affected. The issue involves the "Bluetooth"
23RISCO
abrir
Exploit-DB
OpenSSL 1.1.0 - Remote Client Denial of Service
CVE-2017-373026 jan 2017
Bad (EC)DHE parameters cause a client crash
35RISCO
abrir
Exploit-DB
Apple macOS 10.12.1 / iOS 10.2 - Kernel Userspace Pointer Memory Corruption
CVE-2017-237026 jan 2017
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS
28RISCO
abrir
Exploit-DB
Systemd 228 (SUSE 12 SP2 / Ubuntu Touch 15.04) - Local Privilege Escalation
CVE-2016-1015624 jan 2017
A flaw in systemd v228 in /src/basic/fs-util.c caused world writable suid files to be created when using the systemd tim
23RISCO
abrir
Exploit-DB
Geutebrueck GCore 1.3.8.42/1.4.2.37 - Remote Code Execution (Metasploit)
CVE-2017-1151724 jan 2017
Stack-based buffer overflow in GCoreServer.exe in the server in Geutebrueck Gcore 1.3.8.42 and 1.4.2.37 allows remote at
43RISCO
abrir
Exploit-DB
Mozilla Firefox < 50.0.2 - 'nsSMILTimeContainer::NotifyTimeChange()' Remote Code Execution (Metasploit)
CVE-2016-9079HIGHsob ataque24 jan 2017
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been dis
100RISCO
abrir
Exploit-DB
Oracle OpenJDK Runtime Environment 1.8.0_112-b15 - Java Serialization Denial Of Service
CVE-2017-324123 jan 2017
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: RMI). Supported versi
35RISCO
abrir
Exploit-DB
NTOPNG 2.4 Web Interface - Cross-Site Request Forgery
CVE-2017-547322 jan 2017
Cross-site request forgery (CSRF) vulnerability in ntopng through 2.4 allows remote attackers to hijack the authenticati
23RISCO
abrir
Exploit-DB
PageKit 1.0.10 - Password Reset
CVE-2017-559421 jan 2017
An issue was discovered in Pagekit CMS before 1.0.11. In this vulnerability the remote attacker is able to reset the reg
23RISCO
abrir
Exploit-DB
Joomla! < 2.5.2 - Admin Creation
CVE-2012-156320 jan 2017
Joomla! before 2.5.3 allows Admin Account Creation.
23RISCO
abrir
Exploit-DB
Joomla! < 3.6.4 - Admin Takeover
CVE-2016-983820 jan 2017
An issue was discovered in components/com_users/models/registration.php in Joomla! before 3.6.5. Incorrect filtering of
28RISCO
abrir
Exploit-DB
Apple macOS Sierra 10.12.1 - 'physmem' Local Privilege Escalation
CVE-2016-761716 jan 2017
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Bluetooth"
23RISCO
abrir
Exploit-DB
Apple macOS Sierra 10.12.1 - 'physmem' Local Privilege Escalation
CVE-2016-182516 jan 2017
IOHIDFamily in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a d
23RISCO
abrir
Exploit-DB
Cisco Firepower Management Console 6.0 - Post Authentication UserAdd (Metasploit)
CVE-2016-643313 jan 2017
The Threat Management Console in Cisco Firepower Management Center 5.2.0 through 6.0.1 allows remote authenticated users
60RISCO
abrir
Exploit-DB
Mozilla Firefox < 50.1.0 - Use-After-Free
CVE-2016-989913 jan 2017
Use-after-free while manipulating DOM events and removing audio elements due to errors in the handling of node adoption.
28RISCO
abrir
Exploit-DB
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 SP2 - Multiple Vulnerabilities
CVE-2017-633812 jan 2017
Multiple Access Control issues in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 allow
23RISCO
abrir
Exploit-DB
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 SP2 - Multiple Vulnerabilities
CVE-2017-633912 jan 2017
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 mismanages certain key and certificate d
23RISCO
abrir
Exploit-DB
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 SP2 - Multiple Vulnerabilities
CVE-2017-634012 jan 2017
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 does not sanitize a rest/commonlog/repor
23RISCO
abrir
Exploit-DB
Adobe Flash Player 24.0.0.186 - 'ActionGetURL2' Out-of-Bounds Memory Corruption (1)
CVE-2017-293011 jan 2017
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable memory corruption vulnerability due to a concurre
28RISCO
abrir
Exploit-DB
Adobe Flash Player 24.0.0.186 - 'ActionGetURL2' Out-of-Bounds Memory Corruption (2)
CVE-2017-293011 jan 2017
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable memory corruption vulnerability due to a concurre
28RISCO
abrir
Exploit-DB
Apple OS X Yosemite - 'flow_divert-heap-overflow' Kernel Panic
CVE-2016-182710 jan 2017
The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers
23RISCO
abrir
Exploit-DB
Ansible 2.1.4/2.2.1 - Command Execution
CVE-2016-9587MEDIUM09 jan 2017
Ansible before versions 2.1.4, 2.2.1 is vulnerable to an improper input validation in Ansible's handling of data sent fr
38RISCO
abrir
Exploit-DB
Microsoft Windows Kernel - 'win32k.sys NtSetWindowLongPtr' Local Privilege Escalation (MS16-135) (2)
CVE-2016-7255HIGHsob ataque08 jan 2017
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
93RISCO
abrir
Exploit-DB
Splunk 6.1.1 - 'Referer' Header Cross-Site Scripting
CVE-2014-838007 jan 2017
Cross-site scripting (XSS) vulnerability in Splunk 6.1.1 allows remote attackers to inject arbitrary web script or HTML
23RISCO
abrir
Exploit-DB
Microsoft Edge (Windows 10) - 'chakra.dll' Information Leak / Type Confusion Remote Code Execution
CVE-2016-7201HIGHsob ataque05 jan 2017
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a de
93RISCO
abrir
Exploit-DB
Microsoft Edge (Windows 10) - 'chakra.dll' Information Leak / Type Confusion Remote Code Execution
CVE-2016-7200HIGHsob ataque05 jan 2017
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a de
93RISCO
abrir
Exploit-DB
Atlassian Confluence < 5.10.6 - Persistent Cross-Site Scripting
CVE-2016-628304 jan 2017
Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.10.6 allows remote attackers to inject arbitra
23RISCO
abrir
Exploit-DB
PHPMailer < 5.2.20 / SwiftMailer < 5.4.5-DEV / Zend Framework / zend-mail < 2.4.11 - 'AIO' 'PwnScriptum' Remote Code Execution
CVE-2016-1003402 jan 2017
The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.
35RISCO
abrir
Exploit-DB
PHPMailer < 5.2.20 / SwiftMailer < 5.4.5-DEV / Zend Framework / zend-mail < 2.4.11 - 'AIO' 'PwnScriptum' Remote Code Execution
CVE-2016-1004502 jan 2017
The isMail transport in PHPMailer before 5.2.20 might allow remote attackers to pass extra parameters to the mail comman
60RISCO
abrir
anteriorpágina 148 / 760próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.