Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.184exploits catalogados
37.029CVEs com exploração pública
24.695testados em laboratório
24.476 exploits
Exploit-DBVexDay Proof
Apple macOS 10.12.1 / iOS < 10.2 - powerd Arbitrary Port Replacement
CVE-2016-7661dosmultiple22 dez 2016
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. The is
23RISCO
abrir
Exploit-DBVexDay Proof
Apple macOS < 10.12.2 / iOS < 10.2 - Broken Kernel Mach Port Name uref Handling Privileged Port Name Replacement Privilege Escalation
CVE-2016-7637localmacos22 dez 2016
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchO
23RISCO
abrir
Exploit-DB
IBM AIX 6.1/7.1/7.2 - 'Bellmail' Local Privilege Escalation
CVE-2016-8972localaix22 dez 2016
IBM AIX 6.1, 7.1, and 7.2 could allow a local user to gain root privileges using a specially crafted command within the
23RISCO
abrir
Exploit-DBVexDay Proof
Apple macOS 10.12.1 Kernel - Writable Privileged IOKit Registry Properties Code Execution
CVE-2016-7617dosmacos22 dez 2016
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Bluetooth"
23RISCO
abrir
Exploit-DBVexDay Proof
Apple macOS 10.12 - Double vm_deallocate in Userspace MIG Code Use-After-Free
CVE-2016-7633dosmacos22 dez 2016
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Directory S
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 11 - MSHTML CPaste­Command::Convert­Bitmapto­Png Heap Buffer Overflow (MS14-056)
CVE-2014-4138doswindows22 dez 2016
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory co
35RISCO
abrir
Exploit-DBVexDay Proof
Apple macOS < 10.12.2 / iOS < 10.2 - '_kernelrpc_mach_port_insert_right_trap' Kernel Reference Count Leak / Use-After-Free
CVE-2016-7621localmacos22 dez 2016
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchO
23RISCO
abrir
Exploit-DBVexDay Proof
Apple macOS < 10.12.2 / iOS < 10.2 Kernel - ipc_port_t Reference Count Leak Due to Incorrect externalMethod Overrides Use-After-Free
CVE-2016-7612dosmultiple22 dez 2016
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchO
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge - Internationalization Initialization Type Confusion (MS16-144)
CVE-2016-7287doswindows21 dez 2016
The scripting engines in Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary c
35RISCO
abrir
Exploit-DB
Netgear WNR2000v5 - Remote Code Execution
CVE-2016-10174CRITICALsob ataqueremotecgi21 dez 2016
The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cg
100RISCO
abrir
Exploit-DB
Netgear WNR2000v5 - Remote Code Execution
CVE-2016-10176remotecgi21 dez 2016
The NETGEAR WNR2000v5 router allows an administrator to perform sensitive actions by invoking the apply.cgi URL on the w
60RISCO
abrir
Exploit-DB
Netgear WNR2000v5 - Remote Code Execution
CVE-2016-10175remotecgi21 dez 2016
The NETGEAR WNR2000v5 router leaks its serial number when performing a request to the /BRS_netgear_success.html URI. Thi
50RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge - SIMD.toLocaleString Uninitialized Memory (MS16-145)
CVE-2016-7286doswindows21 dez 2016
The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (m
35RISCO
abrir
Exploit-DBVexDay Proof
Google Android - WifiNative::setHotlist Stack Overflow
CVE-2016-6772dosandroid20 dez 2016
An elevation of privilege vulnerability in Wi-Fi could enable a local malicious application to execute arbitrary code wi
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 11 - MSHTML CSplice­Tree­Engine::Remove­Splice Use-After-Free (MS14-035)
CVE-2014-1785doswindows20 dez 2016
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory co
35RISCO
abrir
Exploit-DBVexDay Proof
Google Chrome < 31.0.1650.48 - HTTP 1xx base::String­Tokenizer­T<...>::Quick­Get­Next Out-of-Bounds Read
CVE-2013-6627dosmultiple19 dez 2016
net/http/http_stream_parser.cc in Google Chrome before 31.0.1650.48 does not properly process HTTP Informational (aka 1x
23RISCO
abrir
Exploit-DBVexDay Proof
Naenara Browser 3.5 (RedStar 3.0 Desktop) - 'JACKRABBIT' Client-Side Command Execution
CVE-2009-2477locallinux18 dez 2016
js/src/jstracer.cpp in the Just-in-time (JIT) JavaScript compiler (aka TraceMonkey) in Mozilla Firefox 3.5 before 3.5.1
50RISCO
abrir
Exploit-DBVexDay Proof
RedStar 3.0 Server - 'Shellshock' 'BEAM' / 'RSSMON' Command Injection
CVE-2014-6271CRITICALsob ataquelocallinux18 dez 2016
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
Exploit-DBVexDay Proof
Apple macOS 10.12 16A323 XNU Kernel / iOS 10.1.1 - 'set_dp_control_port' Lack of Locking Use-After-Free
CVE-2016-7661localmultiple16 dez 2016
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. The is
23RISCO
abrir
Exploit-DBVexDay Proof
Apple macOS 10.12 16A323 XNU Kernel / iOS 10.1.1 - 'set_dp_control_port' Lack of Locking Use-After-Free
CVE-2016-7637localmultiple16 dez 2016
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchO
23RISCO
abrir
Exploit-DBVexDay Proof
Apple macOS 10.12 16A323 XNU Kernel / iOS 10.1.1 - 'set_dp_control_port' Lack of Locking Use-After-Free
CVE-2016-7644localmultiple16 dez 2016
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchO
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 9 - IEFRAME CView::Ensure­Size Use-After-Free (MS13-021)
CVE-2013-0090HIGHdoswindows16 dez 2016
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary co
53RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 9 - IEFRAME CMarkup::Remove­Pointer­Pos Use-After-Free (MS13-055)
CVE-2013-3143doswindows15 dez 2016
Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code or cause a denial of service (mem
35RISCO
abrir
Exploit-DBVexDay Proof
Nagios < 4.2.4 - Local Privilege Escalation
CVE-2016-9566locallinux15 dez 2016
base/logging.c in Nagios Core before 4.2.4 allows local users with access to an account in the nagios group to gain root
23RISCO
abrir
Exploit-DBVexDay Proof
Nagios < 4.2.2 - Arbitrary Code Execution
CVE-2016-9565remotelinux15 dez 2016
MagpieRSS, as used in the front-end component in Nagios Core before 4.2.2 might allow remote attackers to read or write
28RISCO
abrir
Exploit-DBVexDay Proof
Adobe Animate 15.2.1.95 - Memory Corruption
CVE-2016-7866doswindows14 dez 2016
Adobe Animate versions 15.2.1.95 and earlier have an exploitable memory corruption vulnerability. Successful exploitatio
28RISCO
abrir
Exploit-DB
Apport 2.x (Ubuntu Desktop 12.10 < 16.04) - Local Code Execution
CVE-2016-9951locallinux14 dez 2016
An issue was discovered in Apport before 2.20.4. A malicious Apport crash file can contain a restart command in `Respawn
23RISCO
abrir
Exploit-DB
Apport 2.x (Ubuntu Desktop 12.10 < 16.04) - Local Code Execution
CVE-2016-9950locallinux14 dez 2016
An issue was discovered in Apport before 2.20.4. There is a path traversal issue in the Apport crash file "Package" and
23RISCO
abrir
Exploit-DB
Apport 2.x (Ubuntu Desktop 12.10 < 16.04) - Local Code Execution
CVE-2016-9949locallinux14 dez 2016
An issue was discovered in Apport before 2.20.4. In apport/ui.py, Apport reads the CrashDB field and it then evaluates t
28RISCO
abrir
Exploit-DBVexDay Proof
APT - Repository Signing Bypass via Memory Allocation Failure
CVE-2016-1252remotelinux14 dez 2016
The apt package in Debian jessie before 1.0.9.8.4, in Debian unstable before 1.4~beta2, in Ubuntu 14.04 LTS before 1.0.1
23RISCO
abrir
anteriorpágina 156 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.