Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

71.957exploits catalogados
32.195CVEs com exploração pública
1.932testados em laboratório
22.786 exploits
Exploit-DB
Microsoft Windows - 'win32k.sys' TTF Processing RCVT TrueType Instruction Handler Out-of-Bounds Read (MS16-120)
CVE-2016-320920 out 2016
Graphics Device Interface (aka GDI or GDI+) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows
35RISCO
abrir
Exploit-DB
SPIP 3.1.2 - Cross-Site Request Forgery
CVE-2016-798020 out 2016
Cross-site request forgery (CSRF) vulnerability in ecrire/exec/valider_xml.php in SPIP 3.1.2 and earlier allows remote a
23RISCO
abrir
Exploit-DB
Microsoft Windows Edge/Internet Explorer - Isolated Private Namespace Insecure DACL Privilege Escalation (MS16-118)
CVE-2016-338820 out 2016
Microsoft Internet Explorer 10 and 11 and Microsoft Edge do not properly restrict access to private namespaces, which al
28RISCO
abrir
Exploit-DB
Hak5 WiFi Pineapple 2.4 - Preconfiguration Command Injection (Metasploit)
CVE-2015-462420 out 2016
Hak5 WiFi Pineapple 2.0 through 2.3 uses predictable CSRF tokens.
50RISCO
abrir
Exploit-DB
Oracle BI Publisher 11.1.1.6.0/11.1.1.7.0/11.1.1.9.0/12.2.1.0.0 - XML External Entity Injection
CVE-2016-347320 out 2016
Unspecified vulnerability in the BI Publisher (formerly XML Publisher) component in Oracle Fusion Middleware 11.1.1.7.0,
28RISCO
abrir
Exploit-DB
MiCasaVerde VeraLite - Remote Code Execution
CVE-2013-486320 out 2016
The HomeAutomationGateway service in MiCasaVerde VeraLite with firmware 1.5.408 allows (1) remote attackers to execute a
28RISCO
abrir
Exploit-DB
Linux Kernel 2.6.22 < 3.9 - 'Dirty COW' /proc/self/mem Race Condition (Write Access Method)
CVE-2016-5195HIGHsob ataque19 out 2016
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
Exploit-DB
Microsoft Windows - DeviceApi CMApi User Hive Impersonation Privilege Escalation (MS16-124)
CVE-2016-007318 out 2016
The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 160
23RISCO
abrir
Exploit-DB
Microsoft Windows - DFS Client Driver Arbitrary Drive Mapping Privilege Escalation (MS16-123)
CVE-2016-718518 out 2016
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
23RISCO
abrir
Exploit-DB
Microsoft Windows (x86) - 'afd.sys' Local Privilege Escalation (MS11-046)
CVE-2011-124918 out 2016
The Ancillary Function Driver (AFD) in afd.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vis
23RISCO
abrir
Exploit-DB
Microsoft Windows - DeviceApi CMApi PiCMOpenDeviceKey Arbitrary Registry Key Write Privilege Escalation (MS16-124)
CVE-2016-007518 out 2016
The kernel in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 160
23RISCO
abrir
Exploit-DB
Ruby on Rails - Dynamic Render File Upload / Remote Code Execution (Metasploit)
CVE-2016-0752HIGHsob ataque17 out 2016
Directory traversal vulnerability in Action View in Ruby on Rails before 3.2.22.1, 4.0.x and 4.1.x before 4.1.14.1, 4.2.
100RISCO
abrir
Exploit-DB
Microsoft Windows Diagnostics Hub - DLL Load Privilege Escalation (MS16-125)
CVE-2016-718817 out 2016
The Standard Collector Service in Windows Diagnostics Hub in Microsoft Windows 10 Gold, 1511, and 1607 mishandles librar
23RISCO
abrir
Exploit-DB
Linux Kernel < 4.5.1 - Off-By-One (PoC)
CVE-2016-618716 out 2016
The apparmor_setprocattr function in security/apparmor/lsm.c in the Linux kernel before 4.6.5 does not validate the buff
23RISCO
abrir
Exploit-DB
Cisco Webex Player T29.10 - '.WRF' Use-After-Free Memory Corruption
CVE-2016-146412 out 2016
Cisco WebEx Meetings Player T29.10, when WRF file support is enabled, allows remote attackers to execute arbitrary code
23RISCO
abrir
Exploit-DB
Cisco Webex Player T29.10 - '.ARF' Out-of-Bounds Memory Corruption
CVE-2016-141512 out 2016
Cisco WebEx Meetings Player T29.10, when WRF file support is enabled, allows remote attackers to cause a denial of servi
23RISCO
abrir
Exploit-DB
Google Android - Binder Generic ASLR Leak
CVE-2016-668912 out 2016
Binder in the kernel in Android before 2016-10-05 on Nexus devices allows attackers to obtain sensitive information via
23RISCO
abrir
Exploit-DB
Subversion 1.6.6/1.6.12 - Code Execution
CVE-2013-208812 out 2016
contrib/hook-scripts/svn-keyword-check.pl in Subversion before 1.6.23 allows remote authenticated users with commit perm
35RISCO
abrir
Exploit-DB
Adobe Flash Player 23.0.0.162 - '.SWF' ConstantPool Critical Memory Corruption
CVE-2016-427312 out 2016
Adobe Flash Player before 18.0.0.382 and 19.x through 23.x before 23.0.0.185 on Windows and OS X and before 11.2.202.637
28RISCO
abrir
Exploit-DB
Google Android - 'gpsOneXtra' Data Files Denial of Service
CVE-2016-534811 out 2016
The GPS component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 be
23RISCO
abrir
Exploit-DB
Linux Kernel 3.13.1 - 'Recvmmsg' Local Privilege Escalation (Metasploit)
CVE-2014-003811 out 2016
The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allo
50RISCO
abrir
Exploit-DB
Linux Kernel 4.6.2 (Ubuntu 16.04.1) - 'IP6T_SO_SET_REPLACE' Local Privilege Escalation
CVE-2016-499710 out 2016
The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux
38RISCO
abrir
Exploit-DB
HP Client 9.1/9.0/8.1/7.9 - Command Injection
CVE-2015-149710 out 2016
radexecd.exe in Persistent Systems Radia Client Automation (RCA) 7.9, 8.1, 9.0, and 9.1 allows remote attackers to execu
60RISCO
abrir
Exploit-DB
Apache Tomcat 8/7/6 (RedHat Based Distros) - Local Privilege Escalation
CVE-2016-542510 out 2016
The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distribu
38RISCO
abrir
Exploit-DB
Cisco Firepower Threat Management Console 6.0.1 - Local File Inclusion
CVE-2016-643505 out 2016
The web console in Cisco Firepower Management Center 6.0.1 allows remote authenticated users to read arbitrary files via
50RISCO
abrir
Exploit-DB
Cisco Firepower Threat Management Console 6.0.1 - Remote Command Execution
CVE-2016-643305 out 2016
The Threat Management Console in Cisco Firepower Management Center 5.2.0 through 6.0.1 allows remote authenticated users
60RISCO
abrir
Exploit-DB
ISC BIND 9 - Denial of Service
CVE-2016-277604 out 2016
buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly
60RISCO
abrir
Exploit-DB
Apache Tomcat 8/7/6 (Debian-Based Distros) - Local Privilege Escalation
CVE-2016-124003 out 2016
The Tomcat init script in the tomcat7 package before 7.0.56-3+deb8u4 and tomcat8 package before 8.0.14-1+deb8u3 on Debia
38RISCO
abrir
Exploit-DB
Grandsteam GXV3611_HD - SQL Injection
CVE-2015-286629 set 2016
SQL injection vulnerability on the Grandstream GXV3611_HD camera with firmware before 1.0.3.9 beta allows remote attacke
23RISCO
abrir
Exploit-DB
Symantec Messaging Gateway 10.6.1 - Directory Traversal
CVE-2016-531228 set 2016
Directory traversal vulnerability in the charting component in Symantec Messaging Gateway before 10.6.2 allows remote au
35RISCO
abrir
anteriorpágina 155 / 760próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.