Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

72.018exploits catalogados
32.219CVEs com exploração pública
1.932testados em laboratório
22.786 exploits
Exploit-DB
Adobe Flash - Object.unwatch Use-After-Free
CVE-2016-099829 mar 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows
28RISCO
abrir
Exploit-DB
Cogent Datahub 7.3.9 Gamma Script - Local Privilege Escalation
CVE-2016-228828 mar 2016
Cogent DataHub before 7.3.10 allows local users to gain privileges by leveraging the user or guest role to modify a file
23RISCO
abrir
Exploit-DB
Apple Mac OSX Kernel - Use-After-Free and Double Delete Due to Incorrect Locking in Intel GPU Driver
CVE-2016-174423 mar 2016
The Intel driver in the Graphics Drivers subsystem in Apple OS X before 10.11.4 allows attackers to execute arbitrary co
23RISCO
abrir
Exploit-DB
Apple Mac OSX Kernel - AppleKeyStore Use-After-Free
CVE-2016-175523 mar 2016
The kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows attackers to exe
23RISCO
abrir
Exploit-DB
Apple Mac OSX / iOS - SUID Binary Logic Error Kernel Code Execution
CVE-2016-175723 mar 2016
Race condition in the kernel in Apple iOS before 9.3 and OS X before 10.11.4 allows attackers to execute arbitrary code
28RISCO
abrir
Exploit-DB
Apple Mac OSX Kernel - Unchecked Array Index Used to Read Object Pointer Then Call Virtual Method in Nvidia Geforce Driver
CVE-2016-174123 mar 2016
The NVIDIA driver in the Graphics Drivers subsystem in Apple OS X before 10.11.4 allows attackers to execute arbitrary c
28RISCO
abrir
Exploit-DB
Adobe Flash - Shape Rendering Crash
CVE-2016-100223 mar 2016
Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows and OS X and before 11.2.202.577
28RISCO
abrir
Exploit-DB
Adobe Flash - Uninitialized Stack Parameter Access in AsBroadcaster.broadcastMessage UaF Fix
CVE-2016-099923 mar 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows
28RISCO
abrir
Exploit-DB
Adobe Flash - Sprite Creation Use-After-Free
CVE-2016-100023 mar 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows
28RISCO
abrir
Exploit-DB
Adobe Flash - Uninitialized Stack Parameter Access in MovieClip.swapDepths UaF Fix
CVE-2016-099723 mar 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows
28RISCO
abrir
Exploit-DB
Adobe Flash - Uninitialized Stack Parameter Access in Object.unwatch UaF Fix
CVE-2016-099823 mar 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows
28RISCO
abrir
Exploit-DB
Adobe Flash - Zlib Codec Heap Overflow
CVE-2016-100123 mar 2016
Heap-based buffer overflow in Adobe Flash Player before 18.0.0.333 and 19.x through 21.x before 21.0.0.182 on Windows an
28RISCO
abrir
Exploit-DB
Apple Mac OSX Kernel - Code Execution Due to Lack of Bounds Checking in AppleUSBPipe::Abort
CVE-2016-174923 mar 2016
IOUSBFamily in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a d
23RISCO
abrir
Exploit-DB
Microsoft Windows 8.1/10 (x86) - Secondary Logon Standard Handles Missing Sanitization Privilege Escalation (MS16-032)
CVE-2016-0099HIGHsob ataqueransomware21 mar 2016
The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8
98RISCO
abrir
Exploit-DB
Wildfly - 'WEB-INF' / 'META-INF' Information Disclosure via Filter Restriction Bypass
CVE-2016-079320 mar 2016
Incomplete blacklist vulnerability in the servlet filter restriction mechanism in WildFly (formerly JBoss Application Se
28RISCO
abrir
Exploit-DB
Cisco UCS Manager 2.1(1b) - Remote Command Injection (Shellshock)
CVE-2014-6278HIGHsob ataque16 mar 2016
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, whi
100RISCO
abrir
Exploit-DB
OpenSSH 7.2p1 - (Authenticated) xauth Command Injection
CVE-2016-3115MEDIUM16 mar 2016
Multiple CRLF injection vulnerabilities in session.c in sshd in OpenSSH before 7.2p2 allow remote authenticated users to
45RISCO
abrir
Exploit-DB
FreeBSD 10.2 (x64) - 'amd64_set_ldt' Heap Overflow
CVE-2016-188516 mar 2016
Integer signedness error in the amd64_set_ldt function in sys/amd64/amd64/sys_machdep.c in FreeBSD 9.3 before p39, 10.1
23RISCO
abrir
Exploit-DB
TeamPass 2.1.24 - Multiple Vulnerabilities
CVE-2015-756214 mar 2016
Multiple cross-site scripting (XSS) vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to inject arbi
23RISCO
abrir
Exploit-DB
Microsoft Windows Kernel - 'ATMFD.dll' OTF Font Processing Stack Corruption (MS16-026)
CVE-2016-012014 mar 2016
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
35RISCO
abrir
Exploit-DB
Microsoft Windows Kernel - 'ATMFD.dll' OTF Font Processing Pool-Based Buffer Overflow (MS16-026)
CVE-2016-012114 mar 2016
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
35RISCO
abrir
Exploit-DB
Linux Kernel 3.10.0-229.x (CentOS / RHEL 7.1) - 'iowarrior' Driver Crash (PoC)
CVE-2016-218814 mar 2016
The iowarrior_probe function in drivers/usb/misc/iowarrior.c in the Linux kernel before 4.5.1 allows physically proximat
23RISCO
abrir
Exploit-DB
TeamPass 2.1.24 - Multiple Vulnerabilities
CVE-2015-756414 mar 2016
Multiple SQL injection vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to execute arbitrary SQL co
23RISCO
abrir
Exploit-DB
TeamPass 2.1.24 - Multiple Vulnerabilities
CVE-2015-756314 mar 2016
Cross-site request forgery (CSRF) vulnerability in TeamPass 2.1.24 and earlier allows remote attackers to hijack the aut
23RISCO
abrir
Exploit-DB
Microsoft Internet Explorer - Read AV in MSHTML!Layout::LayoutBuilderDivider::BuildPageLayout (MS16-023)
CVE-2016-010814 mar 2016
Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory co
35RISCO
abrir
Exploit-DB
libotr 4.1.0 - Memory Corruption
CVE-2016-285110 mar 2016
Integer overflow in proto.c in libotr before 4.1.1 on 64-bit platforms allows remote attackers to cause a denial of serv
28RISCO
abrir
Exploit-DB
Exim < 4.86.2 - Local Privilege Escalation
CVE-2016-153110 mar 2016
Exim before 4.86.2, when installed setuid root, allows local users to gain privileges via the perl_startup argument.
38RISCO
abrir
Exploit-DB
Putty pscp 0.66 - Stack Buffer Overwrite
CVE-2016-256310 mar 2016
Stack-based buffer overflow in the SCP command-line utility in PuTTY before 0.67 and KiTTY 0.66.6.3 and earlier allows r
35RISCO
abrir
Exploit-DB
Linux Kernel 3.10.0 (CentOS / RHEL 7.1) - 'aiptek' Nullpointer Dereference
CVE-2015-751509 mar 2016
The aiptek_probe function in drivers/input/tablet/aiptek.c in the Linux kernel before 4.4 allows physically proximate at
23RISCO
abrir
Exploit-DB
Exim 4.84-3 - Local Privilege Escalation
CVE-2016-153109 mar 2016
Exim before 4.86.2, when installed setuid root, allows local users to gain privileges via the perl_startup argument.
38RISCO
abrir
anteriorpágina 165 / 760próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.