Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

72.018exploits catalogados
32.219CVEs com exploração pública
1.932testados em laboratório
22.786 exploits
Exploit-DB
Cisco AnyConnect Secure Mobility Client 3.1.08009 - Local Privilege Escalation
CVE-2015-630522 set 2015
Untrusted search path vulnerability in the CMainThread::launchDownloader function in vpndownloader.exe in Cisco AnyConne
23RISCO
abrir
Exploit-DB
Microsoft Windows Kernel - Bitmap Handling Use-After-Free (MS15-061) (2)
CVE-2015-172222 set 2015
Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista S
23RISCO
abrir
Exploit-DB
Microsoft Windows Kernel - 'DeferWindowPos' Use-After-Free (MS15-073)
CVE-2015-236622 set 2015
win32k.sys in the kernel-mode drivers in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, Wi
23RISCO
abrir
Exploit-DB
Microsoft Windows Kernel - WindowStation Use-After-Free (MS15-061)
CVE-2015-172322 set 2015
Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista S
23RISCO
abrir
Exploit-DB
Microsoft Windows Kernel - 'win32k!vSolidFillRect' Buffer Overflow (MS15-061)
CVE-2015-172522 set 2015
Buffer overflow in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows S
23RISCO
abrir
Exploit-DB
Microsoft Windows Kernel - Bitmap Handling Use-After-Free (MS15-061) (1)
CVE-2015-172222 set 2015
Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista S
23RISCO
abrir
Exploit-DB
Microsoft Windows Kernel - Use-After-Free with Printer Device Contexts (MS15-097)
CVE-2015-250722 set 2015
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
23RISCO
abrir
Exploit-DB
Microsoft Windows Kernel - 'SURFOBJ' Null Pointer Dereference (MS15-061)
CVE-2015-172522 set 2015
Buffer overflow in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows S
23RISCO
abrir
Exploit-DB
Microsoft Windows Kernel - Null Pointer Dereference with Window Station and Clipboard (MS15-061)
CVE-2015-172122 set 2015
The kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and
23RISCO
abrir
Exploit-DB
Microsoft Windows Kernel - 'HmgAllocateObjectAttr' Use-After-Free (MS15-061)
CVE-2015-172622 set 2015
Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista S
23RISCO
abrir
Exploit-DB
Microsoft Windows Kernel - 'UserCommitDesktopMemory' Use-After-Free (MS15-073)
CVE-2015-236522 set 2015
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server
23RISCO
abrir
Exploit-DB
Konica Minolta FTP Utility 1.00 - (Authenticated) CWD Command Overflow (SEH) (Metasploit)
CVE-2015-776821 set 2015
Buffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code via a long CWD comma
50RISCO
abrir
Exploit-DB
Konica Minolta FTP Utility 1.0 - Remote Command Execution
CVE-2015-776720 set 2015
Buffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code or cause a denial of
23RISCO
abrir
Exploit-DB
Google Android - libstagefright Integer Overflow Remote Code Execution
CVE-2015-386417 set 2015
Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in A
60RISCO
abrir
Exploit-DB
Microsoft Windows - Font Driver Buffer Overflow (MS15-078) (Metasploit)
CVE-2015-2426HIGHsob ataque17 set 2015
Buffer underflow in atmfd.dll in the Windows Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2
100RISCO
abrir
Exploit-DB
ManageEngine OpManager - Remote Code Execution (Metasploit)
CVE-2015-776617 set 2015
PGSQL:SubmitQuery.do in ZOHO ManageEngine OpManager 11.6, 11.5, and earlier allows remote administrators to bypass SQL q
60RISCO
abrir
Exploit-DB
ManageEngine OpManager - Remote Code Execution (Metasploit)
CVE-2015-776517 set 2015
ZOHO ManageEngine OpManager 11.5 build 11600 and earlier uses a hardcoded password of "plugin" for the IntegrationUser a
50RISCO
abrir
Exploit-DB
Microsoft Windows - Font Driver Buffer Overflow (MS15-078) (Metasploit)
CVE-2015-243317 set 2015
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
43RISCO
abrir
Exploit-DB
Microsoft Excel 2007/2010/2013 - BIFFRecord Use-After-Free
CVE-2015-252316 set 2015
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel for Mac 2011 and 2016, Office Compati
35RISCO
abrir
Exploit-DB
Microsoft Office 2007 - BIFFRecord Length Use-After-Free
CVE-2015-252016 set 2015
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel for Mac 2011 and 2016, Office Compatibility Pack SP3, and Excel Viewer a
28RISCO
abrir
Exploit-DB
Microsoft Office 2007 - OLESSDirectyEntry.CreateTime Type Confusion
CVE-2015-252116 set 2015
Microsoft Excel 2007 SP3, Excel 2010 SP2, Office Compatibility Pack SP3, and Excel Viewer allow remote attackers to exec
28RISCO
abrir
Exploit-DB
Microsoft Office 2007 - 'OGL.dll' ValidateBitmapInfo Bounds Check Failure (MS15-097)
CVE-2015-251016 set 2015
Buffer overflow in the Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2, Office 2007 S
35RISCO
abrir
Exploit-DB
FAROL - SQL Injection
CVE-2015-696216 set 2015
SQL injection vulnerability in the web application in Farol allows remote attackers to execute arbitrary SQL commands vi
23RISCO
abrir
Exploit-DB
Microsoft Windows Task Scheduler - 'DeleteExpiredTaskAfter' File Deletion Privilege Escalation
CVE-2015-252515 set 2015
Task Scheduler in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1
35RISCO
abrir
Exploit-DB
Microsoft Windows Media Center - MCL (MS15-100) (Metasploit)
CVE-2015-250915 set 2015
Windows Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, Windows 8, and Windows 8.1 allows user-assisted remo
60RISCO
abrir
Exploit-DB
Microsoft Windows - CreateObjectTask SettingsSyncDiagnostics Privilege Escalation
CVE-2015-252415 set 2015
Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 do not proper
23RISCO
abrir
Exploit-DB
Openfire 3.10.2 - Cross-Site Request Forgery
CVE-2015-697315 set 2015
Multiple cross-site request forgery (CSRF) vulnerabilities in Ignite Realtime Openfire 3.10.2 allow remote attackers to
35RISCO
abrir
Exploit-DB
WordPress Plugin CP Reservation Calendar 1.1.6 - SQL Injection
CVE-2015-723515 set 2015
Multiple SQL injection vulnerabilities in dex_reservations.php in the CP Reservation Calendar plugin before 1.1.7 for Wo
23RISCO
abrir
Exploit-DB
Microsoft Windows 10 (Build 10130) - User Mode Font Driver Thread Permissions Privilege Escalation
CVE-2015-250815 set 2015
The Adobe Type Manager Library in Microsoft Windows 10 allows local users to gain privileges via a crafted application,
23RISCO
abrir
Exploit-DB
Openfire 3.10.2 - Privilege Escalation
CVE-2015-770715 set 2015
Ignite Realtime Openfire 3.10.2 allows remote authenticated users to gain administrator access via the isadmin parameter
23RISCO
abrir
anteriorpágina 177 / 760próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.