Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.957exploits catalogados
32.195CVEs com exploração pública
1.932testados em laboratório
22.786 exploits
Exploit-DB
Apple macOS 10.12 - 'task_t' Local Privilege Escalation
CVE-2016-462531 out 2016
Use-after-free vulnerability in IOSurface in Apple OS X before 10.11.6 allows local users to gain privileges via unspeci
23RISCO
abrir
Exploit-DB
Apple OS X/iOS Kernel - IOSurface Use-After-Free
CVE-2016-462531 out 2016
Use-after-free vulnerability in IOSurface in Apple OS X before 10.11.6 allows local users to gain privileges via unspeci
23RISCO
abrir
Exploit-DB
NVIDIA Driver - No Bounds Checking in Escape 0x7000194
CVE-2016-739031 out 2016
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 3
23RISCO
abrir
Exploit-DB
NVIDIA Driver - No Bounds Checking in Escape 0x7000170
CVE-2016-881131 out 2016
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 3
23RISCO
abrir
Exploit-DB
Apple OS X/iOS - 'mach_ports_register' Multiple Memory Safety s
CVE-2016-466931 out 2016
An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS b
38RISCO
abrir
Exploit-DB
NVIDIA Driver - Stack Buffer Overflow in Escape 0x7000014
CVE-2016-880531 out 2016
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 3
23RISCO
abrir
Exploit-DB
Apple OS X Kernel - IOBluetoothFamily.kext Use-After-Free
CVE-2016-186331 out 2016
The kernel in Apple iOS before 9.3.3, OS X before 10.11.6, tvOS before 9.2.2, and watchOS before 2.2.2 allows local user
23RISCO
abrir
Exploit-DB
NVIDIA Driver - Stack Buffer Overflow in Escape 0x10000e9
CVE-2016-880731 out 2016
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 3
23RISCO
abrir
Exploit-DB
Rumba FTP Client 4.x - Remote Stack Buffer Overflow (SEH)
CVE-2016-576431 out 2016
Micro Focus Rumba FTP 4.X client buffer overflow makes it possible to corrupt the stack and allow arbitrary code executi
23RISCO
abrir
Exploit-DB
NVIDIA Driver - Missing Bounds Check in Escape 0x100009a
CVE-2016-881031 out 2016
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 3
23RISCO
abrir
Exploit-DB
Micro Focus Rumba 9.3 - ActiveX Stack Buffer Overflow (PoC)
CVE-2016-522831 out 2016
Stack-based buffer overflow in the PlayMacro function in ObjectXMacro.ObjectXMacro in WdMacCtl.ocx in Micro Focus Rumba
28RISCO
abrir
Exploit-DB
Joomla! 3.4.4 < 3.6.4 - Account Creation / Privilege Escalation
CVE-2016-887027 out 2016
The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before
60RISCO
abrir
Exploit-DB
Joomla! 3.4.4 < 3.6.4 - Account Creation / Privilege Escalation
CVE-2016-886927 out 2016
The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before
60RISCO
abrir
Exploit-DB
Linux Kernel 2.6.22 < 3.9 - 'Dirty COW PTRACE_POKEDATA' Race Condition (Write Access Method)
CVE-2016-5195HIGHsob ataque26 out 2016
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
Exploit-DB
Microsoft Windows (x86) - 'NDISTAPI' Local Privilege Escalation (MS11-062)
CVE-2011-197424 out 2016
NDISTAPI.sys in the NDISTAPI driver in Remote Access Service (RAS) in Microsoft Windows XP SP2 and SP3 and Windows Serve
23RISCO
abrir
Exploit-DB
TrendMicro InterScan Web Security Virtual Appliance - 'Shellshock' Remote Command Injection
CVE-2014-6271CRITICALsob ataque21 out 2016
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
Exploit-DB
Linux Kernel 2.6.22 < 3.9 (x86/x64) - 'Dirty COW /proc/self/mem' Race Condition Privilege Escalation (SUID Method)
CVE-2016-5195HIGHsob ataque21 out 2016
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
Exploit-DB
RealPlayer 18.1.5.705 - '.QCP' Crash (PoC)
CVE-2016-901821 out 2016
Improper handling of a repeating VRAT chunk in qcpfformat.dll allows attackers to cause a Null pointer dereference and c
23RISCO
abrir
Exploit-DB
Hak5 WiFi Pineapple 2.4 - Preconfiguration Command Injection (Metasploit)
CVE-2015-462420 out 2016
Hak5 WiFi Pineapple 2.0 through 2.3 uses predictable CSRF tokens.
50RISCO
abrir
Exploit-DB
Microsoft Edge - 'Array.join' Infomation Leak (MS16-119)
CVE-2016-718920 out 2016
The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code via a crafted web site,
35RISCO
abrir
Exploit-DB
Microsoft Windows Kernel - Registry Hive Loading Negative RtlMoveMemory Size in nt!CmpCheckValueList (MS16-124)
CVE-2016-007020 out 2016
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Serve
28RISCO
abrir
Exploit-DB
Oracle BI Publisher 11.1.1.6.0/11.1.1.7.0/11.1.1.9.0/12.2.1.0.0 - XML External Entity Injection
CVE-2016-347320 out 2016
Unspecified vulnerability in the BI Publisher (formerly XML Publisher) component in Oracle Fusion Middleware 11.1.1.7.0,
28RISCO
abrir
Exploit-DB
SPIP 3.1.2 - Cross-Site Request Forgery
CVE-2016-798020 out 2016
Cross-site request forgery (CSRF) vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote a
23RISCO
abrir
Exploit-DB
Microsoft Windows Edge/Internet Explorer - Isolated Private Namespace Insecure Boundary Descriptor Privilege Escalation (MS16-118)
CVE-2016-338720 out 2016
Microsoft Internet Explorer 10 and 11 and Microsoft Edge do not properly restrict access to private namespaces, which al
28RISCO
abrir
Exploit-DB
Microsoft Windows - 'win32k.sys' TTF Processing win32k!sbit_Embolden / win32k!ttfdCloseFontContext Use-After-Free (MS16-120)
CVE-2016-718220 out 2016
The Graphics component in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; W
35RISCO
abrir
Exploit-DB
Microsoft Windows Kernel - Registry Hive Loading Relative Arbitrary Read in nt!RtlValidRelativeSecurityDescriptor (MS16-123)
CVE-2016-337620 out 2016
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
28RISCO
abrir
Exploit-DB
MiCasaVerde VeraLite - Remote Code Execution
CVE-2013-486320 out 2016
The HomeAutomationGateway service in MiCasaVerde VeraLite with firmware 1.5.408 allows (1) remote attackers to execute a
28RISCO
abrir
Exploit-DB
Microsoft Edge - 'Array.map' Heap Overflow (MS16-119)
CVE-2016-719020 out 2016
The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of se
35RISCO
abrir
Exploit-DB
SPIP 3.1.2 Template Compiler/Composer - PHP Code Execution
CVE-2016-799820 out 2016
The SPIP template composer/compiler in SPIP 3.1.2 and earlier allows remote authenticated users to execute arbitrary PHP
28RISCO
abrir
Exploit-DB
Microsoft Edge - Spread Operator Stack Overflow (MS16-119)
CVE-2016-338620 out 2016
The Chakra JavaScript engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of se
35RISCO
abrir
anteriorpágina 154 / 760próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.