Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.008exploits catalogados
34.638CVEs com exploração pública
24.695testados em laboratório
8.460 exploits
VulnCheck XDB
local
CVE-2014-4113HIGHsob ataque22 jan 2016
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2016-072822 jan 2016
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RISCO
abrir
VulnCheck XDB
info-leak
CVE-2016-072820 jan 2016
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2015-7755CRITICALsob ataque09 jan 2016
Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2014-3153HIGHsob ataque08 nov 2015
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RISCO
abrir
VulnCheck XDB
initial-access
CVE-2015-780806 nov 2015
The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PH
60RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2015-1635CRITICALsob ataque14 out 2015
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISCO
abrir
VulnCheck XDB
local
CVE-2015-363607 out 2015
The ping_unhash function in net/ipv4/ping.c in the Linux kernel before 4.0.3 does not initialize a certain list data str
23RISCO
abrir
VulnCheck XDB
initial-access
CVE-2014-7169CRITICALsob ataque30 set 2015
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2014-0160HIGHsob ataque24 set 2015
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2015-363612 set 2015
The ping_unhash function in net/ipv4/ping.c in the Linux kernel before 4.0.3 does not initialize a certain list data str
23RISCO
abrir
VulnCheck XDB
client-side
CVE-2015-5119HIGHsob ataque10 set 2015
Use-after-free vulnerability in the ByteArray class in the ActionScript 3 (AS3) implementation in Adobe Flash Player 13.
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2012-1823CRITICALsob ataque08 set 2015
sapi/cgi/cgi_main.c in PHP before 5.3.12 and 5.4.x before 5.4.2, when configured as a CGI script (aka php-cgi), does not
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2015-363621 ago 2015
The ping_unhash function in net/ipv4/ping.c in the Linux kernel before 4.0.3 does not initialize a certain list data str
23RISCO
abrir
VulnCheck XDB
client-side
CVE-2015-4495HIGHsob ataque10 ago 2015
The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote
98RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2015-547709 ago 2015
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2015-547731 jul 2015
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RISCO
abrir
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALsob ataque26 jun 2015
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2014-0160HIGHsob ataque09 jun 2015
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
VulnCheck XDB
local
CVE-2010-3904HIGHsob ataque09 jun 2015
The rds_page_copy_user function in net/rds/page.c in the Reliable Datagram Sockets (RDS) protocol implementation in the
91RISCO
abrir
VulnCheck XDB
local
CVE-2015-1701HIGHsob ataqueransomware12 mai 2015
Win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Vista SP2, and Server 2008 SP2 allows local
98RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2015-1635CRITICALsob ataque16 abr 2015
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISCO
abrir
VulnCheck XDB
local
CVE-2015-1130HIGHsob ataque15 abr 2015
The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and o
86RISCO
abrir
VulnCheck XDB
local
CVE-2015-1130HIGHsob ataque10 abr 2015
The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and o
86RISCO
abrir
VulnCheck XDB
local
CVE-2013-2094HIGHsob ataque29 mar 2015
The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data t
83RISCO
abrir
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALsob ataque20 mar 2015
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2014-0160HIGHsob ataque08 mar 2015
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALsob ataque22 fev 2015
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
VulnCheck XDB
client-side
CVE-2015-007221 fev 2015
Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass t
60RISCO
abrir
VulnCheck XDB
local
CVE-2014-3153HIGHsob ataque12 jan 2015
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RISCO
abrir
anteriorpágina 280 / 282próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.