Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.184exploits catalogados
37.029CVEs com exploração pública
24.695testados em laboratório
24.476 exploits
Exploit-DBVexDay Proof
Microsoft Event Viewer 1.0 - XML External Entity Injection
CVE-2019-0948MEDIUMlocalwindows05 dez 2016
Windows Event Viewer Information Disclosure Vulnerability
38RISCO
abrir
Exploit-DBVexDay Proof
Alcatel Lucent Omnivista 8770 - Remote Code Execution
CVE-2016-9796remotewindows04 dez 2016
Alcatel-Lucent OmniVista 8770 2.0 through 3.0 exposes different ORBs interfaces, which can be queried using the GIOP pro
28RISCO
abrir
Exploit-DB
Broadcom BCM43xx Wi-Fi - 'BroadPWN' Denial of Service
CVE-2017-9417dosandroid01 dez 2016
Broadcom BCM43xx Wi-Fi chips allow remote attackers to execute arbitrary code via unspecified vectors, aka the "Broadpwn
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 10 - MSHTML 'CEdit­Adorner::Detach' Use-After-Free (MS13-047)
CVE-2013-3120doswindows28 nov 2016
Microsoft Internet Explorer 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory co
35RISCO
abrir
Exploit-DBVexDay Proof
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 - Multiple Vulnerabilities
CVE-2016-9315webappshardware28 nov 2016
Privilege Escalation Vulnerability in com.trend.iwss.gui.servlet.updateaccountadministration in Trend Micro InterScan We
23RISCO
abrir
Exploit-DBVexDay Proof
Red Hat JBoss EAP - Deserialization of Untrusted Data
CVE-2016-7065webappsjava28 nov 2016
The JMX servlet in Red Hat JBoss Enterprise Application Platform (EAP) 4 and 5 allows remote authenticated users to caus
28RISCO
abrir
Exploit-DBVexDay Proof
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 - Multiple Vulnerabilities
CVE-2016-9314webappshardware28 nov 2016
Sensitive Information Disclosure in com.trend.iwss.gui.servlet.ConfigBackup in Trend Micro InterScan Web Security Virtua
23RISCO
abrir
Exploit-DBVexDay Proof
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 - Multiple Vulnerabilities
CVE-2016-9269webappshardware28 nov 2016
Remote Command Execution in com.trend.iwss.gui.servlet.ManagePatches in Trend Micro Interscan Web Security Virtual Appli
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 8 - MSHTML 'SRun­Pointer::Span­Qualifier/Run­Type' Out-Of-Bounds Read (MS15-009)
CVE-2015-0050doswindows28 nov 2016
Microsoft Internet Explorer 8 and 9 allows remote attackers to execute arbitrary code or cause a denial of service (memo
35RISCO
abrir
Exploit-DBVexDay Proof
NTP 4.2.8p3 - Denial of Service
CVE-2015-7855doslinux28 nov 2016
The decodenetnum function in ntpd in NTP 4.2.x before 4.2.8p4, and 4.3.x before 4.3.77 allows remote attackers to cause
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 8/9/10/11 - MSHTML 'DOMImplementation' Type Confusion (MS16-009)
CVE-2016-0063doswindows28 nov 2016
Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service
35RISCO
abrir
Exploit-DBVexDay Proof
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 - Multiple Vulnerabilities
CVE-2016-9316webappshardware28 nov 2016
Multiple stored Cross-Site-Scripting (XSS) vulnerabilities in com.trend.iwss.gui.servlet.updateaccountadministration in
23RISCO
abrir
Exploit-DB
Google Android - 'BadKernel' Remote Code Execution
CVE-2016-6754remoteandroid28 nov 2016
A remote code execution vulnerability in Webview in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-
23RISCO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.6.22 < 3.9 - 'Dirty COW' 'PTRACE_POKEDATA' Race Condition Privilege Escalation (/etc/passwd Method)
CVE-2016-5195HIGHsob ataquelocallinux28 nov 2016
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.6.22 < 3.9 - 'Dirty COW /proc/self/mem' Race Condition Privilege Escalation (/etc/passwd Method)
CVE-2016-5195HIGHsob ataquelocallinux27 nov 2016
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
Exploit-DBVexDay Proof
GNU Wget < 1.18 - Access List Bypass / Race Condition
CVE-2016-7098remotemultiple24 nov 2016
Race condition in wget 1.17 and earlier, when used in recursive or mirroring mode to download a single file, might allow
23RISCO
abrir
Exploit-DB
Microsoft Windows Kernel - 'win32k.sys NtSetWindowLongPtr' Local Privilege Escalation (MS16-135) (1)
CVE-2016-7255HIGHsob ataqueransomwarelocalwindows24 nov 2016
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
93RISCO
abrir
Exploit-DB
Ubuntu 14.04/15.10 - User Namespace Overlayfs Xattr SetGID Privilege Escalation
CVE-2016-1575locallinux22 nov 2016
The overlayfs implementation in the Linux kernel through 4.5.2 does not properly maintain POSIX ACL xattr data, which al
23RISCO
abrir
Exploit-DBVexDay Proof
Crestron AM-100 - Multiple Vulnerabilities
CVE-2016-5639remotehardware22 nov 2016
Directory traversal vulnerability in cgi-bin/login.cgi on Crestron AirMedia AM-100 devices with firmware before 1.4.0.13
28RISCO
abrir
Exploit-DBVexDay Proof
Huawei UTPS - Unquoted Service Path Privilege Escalation
CVE-2016-8769localwindows22 nov 2016
Huawei UTPS earlier than UTPS-V200R003B015D16SPC00C983 has an unquoted service path vulnerability which can lead to the
23RISCO
abrir
Exploit-DB
Ubuntu 15.10 - 'USERNS ' Overlayfs Over Fuse Privilege Escalation
CVE-2016-1576locallinux22 nov 2016
The overlayfs implementation in the Linux kernel through 4.5.2 does not properly restrict the mount namespace, which all
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge Scripting Engine - Memory Corruption (MS16-129)
CVE-2016-7202doswindows21 nov 2016
The scripting engines in Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute a
45RISCO
abrir
Exploit-DBVexDay Proof
D-Link DIR-Series Routers - HNAP Login Stack Buffer Overflow (Metasploit)
CVE-2016-6563remotemultiple21 nov 2016
D-Link DIR routers contain a stack-based buffer overflow in the HNAP Login action
60RISCO
abrir
Exploit-DBVexDay Proof
NTP 4.2.8p8 - Denial of Service
CVE-2016-7434doslinux21 nov 2016
The read_mru_list function in NTP before 4.2.8p9 allows remote attackers to cause a denial of service (crash) via a craf
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 8 - jscript 'Reg­Exp­Base::FBad­Header' Use-After-Free (MS15-018)
CVE-2015-2482doswindows21 nov 2016
The Microsoft (1) VBScript 5.7 and 5.8 and (2) JScript 5.7 and 5.8 engines, as used in Internet Explorer 8 through 11 an
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge - 'CText­Extractor::Get­Block­Text' Out-of-Bounds Read (MS16-104)
CVE-2016-3247doswindows21 nov 2016
Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of
45RISCO
abrir
Exploit-DBVexDay Proof
Palo Alto Networks PanOS - appweb3 Stack Buffer Overflow
CVE-2016-9150doslinux18 nov 2016
Buffer overflow in the management web interface in Palo Alto Networks PAN-OS before 5.0.20, 5.1.x before 5.1.13, 6.0.x b
35RISCO
abrir
Exploit-DB
Moxa SoftCMS 1.5 - Denial of Service (PoC)
CVE-2016-9332doswindows18 nov 2016
An issue was discovered in Moxa SoftCMS versions prior to Version 1.6. Moxa SoftCMS Webserver does not properly validate
23RISCO
abrir
Exploit-DBVexDay Proof
Nagios 4.2.2 - Local Privilege Escalation
CVE-2016-8641MEDIUMlocallinux18 nov 2016
A privilege escalation vulnerability was found in nagios 4.2.x that occurs in daemon-init.in when creating necessary fil
33RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Edge - 'FillFromPrototypes' Type Confusion
CVE-2016-7201HIGHsob ataquedoswindows18 nov 2016
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a de
93RISCO
abrir
anteriorpágina 158 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.