Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

72.018exploits catalogados
32.219CVEs com exploração pública
1.932testados em laboratório
22.786 exploits
Exploit-DB
Microsoft Windows - devenum.dll!DeviceMoniker::Load() Heap Corruption Buffer Underflow (MS16-007)
CVE-2016-001513 jan 2016
DirectShow in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
35RISCO
abrir
Exploit-DB
Grassroots DICOM (GDCM) 2.6.0 and 2.6.1 - ImageRegionReader::ReadIntoBuffer Buffer Overflow
CVE-2015-839612 jan 2016
Integer overflow in the ImageRegionReader::ReadIntoBuffer function in MediaStorageAndFileFormat/gdcmImageRegionReader.cx
28RISCO
abrir
Exploit-DB
Linux Kernel 4.3.3 - 'overlayfs' Local Privilege Escalation (2)
CVE-2015-866012 jan 2016
The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr op
43RISCO
abrir
Exploit-DB
Adobe Flash (Multiple Scripts) - Use-After-Free When Rendering Displays (1)
CVE-2015-863511 jan 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and
28RISCO
abrir
Exploit-DB
Adobe Flash - Use-After-Free When Setting Stage
CVE-2015-863411 jan 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and
28RISCO
abrir
Exploit-DB
Konica Minolta FTP Utility 1.00 - CWD Command Overflow (SEH)
CVE-2015-776811 jan 2016
Buffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code via a long CWD comma
50RISCO
abrir
Exploit-DB
Trend Micro - node.js HTTP Server Listening on localhost Can Execute Commands
CVE-2016-398711 jan 2016
The HTTP server in Trend Micro Password Manager allows remote web servers to execute arbitrary commands via the url para
28RISCO
abrir
Exploit-DB
Adobe Flash BlurFilter Processing - Out-of-Bounds Memset
CVE-2015-863611 jan 2016
Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on
28RISCO
abrir
Exploit-DB
Fortinet FortiGate 4.x < 5.0.7 - SSH Backdoor Access
CVE-2016-190909 jan 2016
Fortinet FortiAnalyzer before 5.0.12 and 5.2.x before 5.2.5; FortiSwitch 3.3.x before 3.3.3; FortiCache 3.0.x before 3.0
60RISCO
abrir
Exploit-DB
OpenMRS Reporting Module 0.9.7 - Remote Code Execution
CVE-2013-728507 jan 2016
Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a rem
60RISCO
abrir
Exploit-DB
D-Link DCS-931L - Arbitrary File Upload (Metasploit)
CVE-2015-204907 jan 2016
Unrestricted file upload vulnerability in D-Link DCS-931L with firmware 1.04 and earlier allows remote authenticated use
50RISCO
abrir
Exploit-DB
Linux Kernel 4.3.3 (Ubuntu 14.04/15.10) - 'overlayfs' Local Privilege Escalation (1)
CVE-2015-866005 jan 2016
The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr op
43RISCO
abrir
Exploit-DB
Atlassian Confluence 5.2/5.8.14/5.8.15 - Multiple Vulnerabilities
CVE-2015-839805 jan 2016
Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.8.17 allows remote attackers to inject arbitra
23RISCO
abrir
Exploit-DB
Atlassian Confluence 5.2/5.8.14/5.8.15 - Multiple Vulnerabilities
CVE-2015-839905 jan 2016
Atlassian Confluence before 5.8.17 allows remote authenticated users to read configuration files via the decoratorName p
50RISCO
abrir
Exploit-DB
Ganeti - Multiple Vulnerabilities
CVE-2015-794405 jan 2016
The RESTful control interface (aka RAPI or ganeti-rapi) in Ganeti before 2.9.7, 2.10.x before 2.10.8, 2.11.x before 2.11
28RISCO
abrir
Exploit-DB
Ganeti - Multiple Vulnerabilities
CVE-2015-794505 jan 2016
The RESTful control interface (aka RAPI or ganeti-rapi) in Ganeti before 2.9.7, 2.10.x before 2.10.8, 2.11.x before 2.11
23RISCO
abrir
Exploit-DB
pdfium - CPDF_DIBSource::DownSampleScanline32Bit Heap Out-of-Bounds Read
CVE-2015-678704 jan 2016
Multiple unspecified vulnerabilities in Google Chrome before 47.0.2526.73 allow attackers to cause a denial of service o
23RISCO
abrir
Exploit-DB
pdfium - CPDF_Function::Call Stack Buffer Overflow
CVE-2015-678704 jan 2016
Multiple unspecified vulnerabilities in Google Chrome before 47.0.2526.73 allow attackers to cause a denial of service o
23RISCO
abrir
Exploit-DB
pdfium - CPDF_TextObject::CalcPositionData Heap Out-of-Bounds Read
CVE-2015-678704 jan 2016
Multiple unspecified vulnerabilities in Google Chrome before 47.0.2526.73 allow attackers to cause a denial of service o
23RISCO
abrir
Exploit-DB
Rejetto HTTP File Server (HFS) 2.3.x - Remote Command Execution (2)
CVE-2014-6287CRITICALsob ataque04 jan 2016
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c a
100RISCO
abrir
Exploit-DB
DeleGate 9.9.13 - Local Privilege Escalation
CVE-2015-755630 dez 2015
DeleGate 9.9.13 allows local users to gain privileges as demonstrated by the dgcpnod setuid program.
23RISCO
abrir
Exploit-DB
KiTTY Portable 0.65.0.2p (Windows XP/7/10) - Chat Remote Buffer Overflow (SEH)
CVE-2015-787429 dez 2015
Buffer overflow in the chat server in KiTTY Portable 0.65.0.2p and earlier allows remote attackers to execute arbitrary
28RISCO
abrir
Exploit-DB
PHP 7.0.0 - Format String
CVE-2015-861723 dez 2015
Format string vulnerability in the zend_throw_or_error function in Zend/zend_execute_API.c in PHP 7.x before 7.0.1 allow
28RISCO
abrir
Exploit-DB
Wireshark - 'AirPDcapDecryptWPABroadcastKey' Heap Out-of-Bounds Read (1)
CVE-2015-872422 dez 2015
The AirPDcapDecryptWPABroadcastKey function in epan/crypt/airpdcap.c in the 802.11 dissector in Wireshark 1.12.x before
23RISCO
abrir
Exploit-DB
Wireshark - 'infer_pkt_encap' Heap Out-of-Bounds Read
CVE-2015-873322 dez 2015
The ngsniffer_process_record function in wiretap/ngsniffer.c in the Sniffer file parser in Wireshark 1.12.x before 1.12.
23RISCO
abrir
Exploit-DB
Adobe Flash Sound.setTransform - Use-After-Free
CVE-2015-843421 dez 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RISCO
abrir
Exploit-DB
Adobe Flash TextField.text Setter - Use-After-Free
CVE-2015-843018 dez 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RISCO
abrir
Exploit-DB
Adobe Flash MovieClip.startDrag - Use-After-Free
CVE-2015-841118 dez 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RISCO
abrir
Exploit-DB
Adobe Flash Selection.SetSelection - Use-After-Free
CVE-2015-841318 dez 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RISCO
abrir
Exploit-DB
Adobe Flash MovieClip.attachBitmap - Use-After-Free
CVE-2015-841018 dez 2015
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and
35RISCO
abrir
anteriorpágina 170 / 760próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.