Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.444exploits catalogados
34.432CVEs com exploração pública
24.695testados em laboratório
24.443 exploits
Exploit-DBVexDay Proof
Linux Kernel (x86-64) - Rowhammer Privilege Escalation
CVE-2015-0565locallinux_x86-6409 mar 2015
NaCl in 2015 allowed the CLFLUSH instruction, making rowhammer attacks possible.
28RISCO
abrir
Exploit-DBVexDay Proof
Rowhammer - NaCl Sandbox Escape
CVE-2015-0565locallinux_x86-6409 mar 2015
NaCl in 2015 allowed the CLFLUSH instruction, making rowhammer attacks possible.
28RISCO
abrir
Exploit-DBVexDay Proof
Rowhammer - NaCl Sandbox Escape
CVE-2015-3693locallinux_x86-6409 mar 2015
Apple Mac EFI before 2015-001, as used in OS X before 10.10.4 and other products, does not properly set refresh rates fo
23RISCO
abrir
Exploit-DB
Elastix 2.x - Blind SQL Injection
CVE-2015-1875webappsphp07 mar 2015
SQL injection vulnerability in a2billing/customer/iridium_threed.php in Elastix 2.5.0 and earlier allows remote attacker
23RISCO
abrir
Exploit-DB
PHP Betoffice (Betster) 1.0.4 - Authentication Bypass / SQL Injection
CVE-2015-2237webappsphp06 mar 2015
Multiple SQL injection vulnerabilities in Betster (aka PHP Betoffice) 1.0.4 allow remote attackers to execute arbitrary
23RISCO
abrir
Exploit-DBVexDay Proof
HP Data Protector 8.10 - Remote Command Execution (Metasploit)
CVE-2014-2623remotewindows06 mar 2015
Unspecified vulnerability in HP Storage Data Protector 8.x allows remote attackers to execute arbitrary code via unknown
60RISCO
abrir
Exploit-DB
ProjectSend r561 - SQL Injection
CVE-2015-2564webappsphp06 mar 2015
SQL injection vulnerability in client-edit.php in ProjectSend (formerly cFTP) r561 allows remote authenticated users to
23RISCO
abrir
Exploit-DBVexDay Proof
Seagate Business NAS - Remote Command Execution (Metasploit)
CVE-2014-8687remotephp04 mar 2015
Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root
50RISCO
abrir
Exploit-DB
Linux Kernel 3.17.5 - IRET Instruction #SS Fault Handling Crash (PoC)
CVE-2014-9322doslinux_x86-6404 mar 2015
arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associated with the Stack S
23RISCO
abrir
Exploit-DBVexDay Proof
Symantec Web Gateway 5 - 'restore.php' (Authenticated) Command Injection (Metasploit)
CVE-2014-7285remotelinux04 mar 2015
The management console on the Symantec Web Gateway (SWG) appliance before 5.2.2 allows remote authenticated users to exe
50RISCO
abrir
Exploit-DB
Linux Kernel 3.16.3 - Associative Array Garbage Collection Crash (PoC)
CVE-2014-3631doslinux04 mar 2015
The assoc_array_gc function in the associative-array implementation in lib/assoc_array.c in the Linux kernel before 3.16
23RISCO
abrir
Exploit-DB
Linux Kernel 3.15.6 - PPP-over-L2TP Socket Level Handling Crash (PoC)
CVE-2014-4943doslinux04 mar 2015
The PPPoL2TP feature in net/l2tp/l2tp_ppp.c in the Linux kernel through 3.15.6 allows local users to gain privileges by
23RISCO
abrir
Exploit-DBVexDay Proof
Seagate Business NAS - Remote Command Execution (Metasploit)
CVE-2014-8686remotephp04 mar 2015
CodeIgniter before 2.2.0 makes it easier for attackers to decode session cookies by leveraging fallback to a custom XOR-
50RISCO
abrir
Exploit-DB
SolarWinds Orion Service - SQL Injection
CVE-2014-9566webappswindows04 mar 2015
Multiple SQL injection vulnerabilities in the Manage Accounts page in the AccountManagement.asmx service in the Solarwin
50RISCO
abrir
Exploit-DBVexDay Proof
Seagate Business NAS - Remote Command Execution (Metasploit)
CVE-2014-8684remotephp04 mar 2015
CodeIgniter before 3.0 and Kohana 3.2.3 and earlier and 3.3.x through 3.3.2 make it easier for remote attackers to spoof
60RISCO
abrir
Exploit-DB
PHPMoAdmin - Unauthorized Remote Code Execution
CVE-2015-2208webappsphp03 mar 2015
The saveObject function in moadmin.php in phpMoAdmin 1.1.2 allows remote attackers to execute arbitrary commands via she
50RISCO
abrir
Exploit-DB
WordPress Theme Photocrati 4.x - SQL Injection / Cross-Site Scripting
CVE-2015-2216webappsphp03 mar 2015
SQL injection vulnerability in ecomm-sizes.php in the Photocrati theme 4.x for WordPress allows remote attackers to exec
23RISCO
abrir
Exploit-DBVexDay Proof
vBulletin vBSEO 4.x - 'visitormessage.php' Remote Code Injection
CVE-2014-9463webappsphp02 mar 2015
functions_vbseo_hook.php in the VBSEO module for vBulletin allows remote authenticated users to execute arbitrary code v
28RISCO
abrir
Exploit-DBVexDay Proof
Seagate Business NAS 2014.00319 - Remote Code Execution
CVE-2014-8687webappshardware01 mar 2015
Seagate Business NAS devices with firmware before 2015.00322 allow remote attackers to execute arbitrary code with root
50RISCO
abrir
Exploit-DB
Persistent Systems Client Automation - Command Injection Remote Code Execution (Metasploit)
CVE-2015-1497remotewindows27 fev 2015
radexecd.exe in Persistent Systems Radia Client Automation (RCA) 7.9, 8.1, 9.0, and 9.1 allows remote attackers to execu
60RISCO
abrir
Exploit-DB
SQLite3 3.8.6 - Controlled Memory Corruption (PoC)
CVE-2015-5895doslinux26 fev 2015
Multiple unspecified vulnerabilities in SQLite before 3.8.10.2, as used in Apple iOS before 9, have unknown impact and a
23RISCO
abrir
Exploit-DBVexDay Proof
D-Link/TRENDnet - NCC Service Command Injection (Metasploit)
CVE-2015-1187CRITICALsob ataquewebappslinux26 fev 2015
The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr
100RISCO
abrir
Exploit-DBVexDay Proof
HP Client - Automation Command Injection (Metasploit)
CVE-2015-1497remotemultiple24 fev 2015
radexecd.exe in Persistent Systems Radia Client Automation (RCA) 7.9, 8.1, 9.0, and 9.1 allows remote attackers to execu
60RISCO
abrir
Exploit-DB
Beehive Forum 1.4.4 - Persistent Cross-Site Scripting
CVE-2015-2198webappsphp23 fev 2015
Multiple cross-site scripting (XSS) vulnerabilities in edit_prefs.php in Beehive Forum 1.4.4 allow remote attackers to i
23RISCO
abrir
Exploit-DB
Zeuscart 4.0 - Multiple Vulnerabilities
CVE-2010-5322webappsphp23 fev 2015
Cross-site scripting (XSS) vulnerability in ZeusCart 4.0 and earlier allows remote attackers to inject arbitrary web scr
23RISCO
abrir
Exploit-DB
phpBugTracker 1.6.0 - Multiple Vulnerabilities
CVE-2015-2145webappsphp23 fev 2015
Multiple cross-site scripting (XSS) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to
23RISCO
abrir
Exploit-DB
phpBugTracker 1.6.0 - Multiple Vulnerabilities
CVE-2015-2147webappsphp23 fev 2015
Multiple SQL injection vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to execute arbi
23RISCO
abrir
Exploit-DB
WordPress Plugin Easy Social Icons 1.2.2 - Cross-Site Request Forgery
CVE-2015-2084webappsphp23 fev 2015
Cross-site request forgery (CSRF) vulnerability in the Easy Social Icons plugin before 1.2.3 for WordPress allows remote
23RISCO
abrir
Exploit-DB
Clipbucket 2.7 RC3 0.9 - Blind SQL Injection
CVE-2015-2102webappsphp23 fev 2015
SQL injection vulnerability in view_item.php in ClipBucket 2.7 RC3 (2.7.0.4.v2929-rc3) allows remote attackers to execut
23RISCO
abrir
Exploit-DB
phpBugTracker 1.6.0 - Multiple Vulnerabilities
CVE-2015-2143webappsphp23 fev 2015
Multiple cross-site request forgery (CSRF) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attac
23RISCO
abrir
anteriorpágina 200 / 815próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.