Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

72.018exploits catalogados
32.219CVEs com exploração pública
1.932testados em laboratório
22.786 exploits
Exploit-DB
Linux Kernel 3.10.0 (CentOS / RHEL 7.1) - 'Wacom' Multiple Nullpointer Dereferences
CVE-2016-313909 mar 2016
The wacom_probe function in drivers/input/tablet/wacom_sys.c in the Linux kernel before 3.17 allows physically proximate
23RISCO
abrir
Exploit-DB
Linux Kernel 3.10.0 (CentOS / RHEL 7.1) - visor 'treo_attach' Nullpointer Dereference
CVE-2016-278209 mar 2016
The treo_attach function in drivers/usb/serial/visor.c in the Linux kernel before 4.5 allows physically proximate attack
23RISCO
abrir
Exploit-DB
Linux Kernel 3.10.0 (CentOS / RHEL 7.1) - 'digi_acceleport' Nullpointer Dereference
CVE-2016-314009 mar 2016
The digi_port_init function in drivers/usb/serial/digi_acceleport.c in the Linux kernel before 4.5.1 allows physically p
23RISCO
abrir
Exploit-DB
Linux Kernel 3.10.0 (CentOS / RHEL 7.1) - 'aiptek' Nullpointer Dereference
CVE-2015-751509 mar 2016
The aiptek_probe function in drivers/input/tablet/aiptek.c in the Linux kernel before 4.4 allows physically proximate at
23RISCO
abrir
Exploit-DB
Linux Kernel 3.10.0 (CentOS / RHEL 7.1) - visor clie_5_attach Nullpointer Dereference
CVE-2015-756609 mar 2016
The clie_5_attach function in drivers/usb/serial/visor.c in the Linux kernel through 4.4.1 allows physically proximate a
23RISCO
abrir
Exploit-DB
Linux Kernel 3.10/3.18 /4.4 - Netfilter IPT_SO_SET_REPLACE Memory Corruption
CVE-2016-313409 mar 2016
The netfilter subsystem in the Linux kernel through 4.5.2 does not validate certain offset fields, which allows local us
23RISCO
abrir
Exploit-DB
Linux Kernel 3.10.0 (CentOS / RHEL 7.1) - 'mct_u232' Nullpointer Dereference
CVE-2016-313609 mar 2016
The mct_u232_msr_to_state function in drivers/usb/serial/mct_u232.c in the Linux kernel before 4.5.1 allows physically p
23RISCO
abrir
Exploit-DB
Linux Kernel 3.10/3.18 /4.4 - Netfilter IPT_SO_SET_REPLACE Memory Corruption
CVE-2016-313509 mar 2016
Integer overflow in the xt_alloc_table_info function in net/netfilter/x_tables.c in the Linux kernel through 4.5.2 on 32
23RISCO
abrir
Exploit-DB
ATutor LMS - '/install_modules.php' Cross-Site Request Forgery / Remote Code Execution
CVE-2016-253907 mar 2016
Cross-site request forgery (CSRF) vulnerability in install_modules.php in ATutor before 2.2.2 allows remote attackers to
23RISCO
abrir
Exploit-DB
Microsoft Windows 7 (x64) - 'afd.sys' Dangling Pointer Privilege Escalation (MS14-040)
CVE-2014-176707 mar 2016
Double free vulnerability in the Ancillary Function Driver (AFD) in afd.sys in the kernel-mode drivers in Microsoft Wind
28RISCO
abrir
Exploit-DB
Avast! - Authenticode Parsing Memory Corruption
CVE-2016-398607 mar 2016
Avast allows remote attackers to cause a denial of service (memory corruption) and possibly execute arbitrary code via a
23RISCO
abrir
Exploit-DB
McAfee VirusScan Enterprise 8.8 - Security Restrictions Bypass
CVE-2016-453407 mar 2016
The McAfee VirusScan Console (mcconsol.exe) in McAfee VirusScan Enterprise 8.8.0 before Hotfix 1123565 (8.8.0.1546) on W
23RISCO
abrir
Exploit-DB
McAfee VirusScan Enterprise 8.8 - Security Restrictions Bypass
CVE-2016-398407 mar 2016
The McAfee VirusScan Console (mcconsol.exe) in McAfee Active Response (MAR) before 1.1.0.161, Agent (MA) 5.x before 5.0.
23RISCO
abrir
Exploit-DB
PHPLib < 7.4 - SQL Injection
CVE-2006-282605 mar 2016
SQL injection vulnerability in sessions.inc in PHP Base Library (PHPLib) before 7.4a allows remote attackers to execute
23RISCO
abrir
Exploit-DB
PHPLib < 7.4 - SQL Injection
CVE-2006-088705 mar 2016
Eval injection vulnerability in sessions.inc in PHP Base Library (PHPLib) before 7.4a, when index.php3 from the PHPLib d
23RISCO
abrir
Exploit-DB
DropBearSSHD 2015.71 - Command Injection
CVE-2016-311603 mar 2016
CRLF injection vulnerability in Dropbear SSH before 2016.72 allows remote authenticated users to bypass intended shell-c
28RISCO
abrir
Exploit-DB
Schneider Electric SBO / AS - Multiple Vulnerabilities
CVE-2016-227803 mar 2016
Schneider Electric Struxureware Building Operations Automation Server AS 1.7 and earlier and AS-P 1.7 and earlier allows
28RISCO
abrir
Exploit-DB
Gallery 2 < 2.0.2 - Multiple Vulnerabilities
CVE-2006-112702 mar 2016
Cross-site scripting (XSS) vulnerability in Gallery 2 up to 2.0.2 allows remote attackers to inject arbitrary web script
23RISCO
abrir
Exploit-DB
Gallery 2 < 2.0.2 - Multiple Vulnerabilities
CVE-2006-112802 mar 2016
Directory traversal vulnerability in the session handling class (GallerySession.class) in Gallery 2 up to 2.0.2 allows r
23RISCO
abrir
Exploit-DB
Netgear NMS300 ProSafe Network Management System - Arbitrary File Upload (Metasploit)
CVE-2016-152501 mar 2016
Directory traversal vulnerability in data/config/image.do in NETGEAR Management System NMS300 1.5.0.11 and earlier allow
60RISCO
abrir
Exploit-DB
ATutor 2.2.1 - SQL Injection / Remote Code Execution (Metasploit)
CVE-2016-255501 mar 2016
SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbi
60RISCO
abrir
Exploit-DB
Microsoft Windows - 'srv2.sys' SMB Code Execution (Python) (MS09-050)
CVE-2009-253226 fev 2016
Microsoft Windows Vista Gold, SP1, and SP2, Windows Server 2008 Gold and SP2, and Windows 7 RC do not properly process t
35RISCO
abrir
Exploit-DB
Zimbra 8.0.9 GA - Cross-Site Request Forgery
CVE-2015-654126 fev 2016
Multiple cross-site request forgery (CSRF) vulnerabilities in the Mail interface in Zimbra Collaboration Server (ZCS) be
23RISCO
abrir
Exploit-DB
Microsoft Windows - 'srv2.sys' SMB Code Execution (Python) (MS09-050)
CVE-2009-310326 fev 2016
Array index error in the SMBv2 protocol implementation in srv2.sys in Microsoft Windows Vista Gold, SP1, and SP2, Window
60RISCO
abrir
Exploit-DB
Microsoft Windows - 'srv2.sys' SMB Code Execution (Python) (MS09-050)
CVE-2009-252626 fev 2016
Microsoft Windows Vista Gold, SP1, and SP2 and Server 2008 Gold and SP2 do not properly validate fields in SMBv2 packets
45RISCO
abrir
Exploit-DB
phpRPC < 0.7 - Remote Code Execution
CVE-2006-103226 fev 2016
Eval injection vulnerability in the decode function in rpc_decoder.php for phpRPC 0.7 and earlier, as used by runcms, ex
23RISCO
abrir
Exploit-DB
Microsoft Windows - 'NetAPI32.dll' Code Execution (Python) (MS08-067)
CVE-2008-4250CRITICALsob ataque26 fev 2016
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RISCO
abrir
Exploit-DB
IBM Lotus Domino R8 - Password Hash Extraction
CVE-2005-242825 fev 2016
Lotus Domino R5 and R6 WebMail, with "Generate HTML for all fields" enabled, stores sensitive data from names.nsf in hid
60RISCO
abrir
Exploit-DB
Mambo < 4.5.3h - Multiple Vulnerabilities
CVE-2006-179424 fev 2016
SQL injection vulnerability in Mambo 4.5.3, 4.5.3h, and possibly earlier versions allows remote attackers to execute arb
23RISCO
abrir
Exploit-DB
libxml2 - xmlDictAddString Heap Buffer Overread
CVE-2016-183924 fev 2016
The xmlDictAddString function in libxml2 before 2.9.4, as used in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS befo
23RISCO
abrir
anteriorpágina 166 / 760próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.