Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.842exploits catalogados
37.493CVEs com exploração pública
24.695testados em laboratório
9.066 exploits
VulnCheck XDB
initial-access
CVE-2015-157903 fev 2017
Directory traversal vulnerability in the Elegant Themes Divi theme for WordPress allows remote attackers to read arbitra
43RISCO
abrir
VulnCheck XDB
initial-access
CVE-2011-486202 fev 2017
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka k
60RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2015-1635CRITICALsob ataque28 jan 2017
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold an
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2016-5195HIGHsob ataque15 jan 2017
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
VulnCheck XDB
local
CVE-2016-7255HIGHsob ataqueransomware13 jan 2017
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
93RISCO
abrir
VulnCheck XDB
initial-access
CVE-2015-1427CRITICALsob ataque09 jan 2017
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the s
100RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2015-856208 jan 2017
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RISCO
abrir
VulnCheck XDB
client-side
CVE-2016-7201HIGHsob ataque04 jan 2017
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a de
93RISCO
abrir
VulnCheck XDB
client-side
CVE-2016-7200HIGHsob ataque04 jan 2017
The Chakra JavaScript scripting engine in Microsoft Edge allows remote attackers to execute arbitrary code or cause a de
93RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2015-363602 jan 2017
The ping_unhash function in net/ipv4/ping.c in the Linux kernel before 4.0.3 does not initialize a certain list data str
23RISCO
abrir
VulnCheck XDB
initial-access
CVE-2016-10033CRITICALsob ataque26 dez 2016
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISCO
abrir
VulnCheck XDB
local
CVE-2013-6282HIGHsob ataque19 dez 2016
The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not
98RISCO
abrir
VulnCheck XDB
local
CVE-2016-5195HIGHsob ataque08 dez 2016
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
VulnCheck XDB
initial-access
CVE-2014-6271CRITICALsob ataque07 dez 2016
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
VulnCheck XDB
local
CVE-2016-5195HIGHsob ataque25 nov 2016
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
VulnCheck XDB
local
CVE-2016-5195HIGHsob ataque17 nov 2016
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
VulnCheck XDB
initial-access
CVE-2015-754710 nov 2016
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RISCO
abrir
VulnCheck XDB
local
CVE-2016-5195HIGHsob ataque06 nov 2016
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
VulnCheck XDB
local
CVE-2016-5195HIGHsob ataque23 out 2016
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
VulnCheck XDB
local
CVE-2016-5195HIGHsob ataque22 out 2016
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
VulnCheck XDB
local
CVE-2016-5195HIGHsob ataque22 out 2016
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
VulnCheck XDB
local
CVE-2016-5195HIGHsob ataque21 out 2016
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
VulnCheck XDB
local
CVE-2016-5195HIGHsob ataque21 out 2016
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
VulnCheck XDB
local
CVE-2016-5195HIGHsob ataque21 out 2016
Race condition in mm/gup.c in the Linux kernel 2.x through 4.x before 4.8.3 allows local users to gain privileges by lev
93RISCO
abrir
VulnCheck XDB
initial-access
CVE-2015-7450CRITICALsob ataque18 out 2016
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2013-486312 out 2016
The HomeAutomationGateway service in MiCasaVerde VeraLite with firmware 1.5.408 allows (1) remote attackers to execute a
28RISCO
abrir
VulnCheck XDB
client-side
CVE-2016-625512 out 2016
Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to write to arbitrary files in the webroot via a P
28RISCO
abrir
VulnCheck XDB
local
CVE-2016-4655MEDIUMsob ataque02 out 2016
The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.
90RISCO
abrir
VulnCheck XDB
initial-access
CVE-2016-277630 set 2016
buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly
60RISCO
abrir
VulnCheck XDB
client-side
CVE-2012-1889HIGHsob ataque25 set 2016
Microsoft XML Core Services 3.0, 4.0, 5.0, and 6.0 accesses uninitialized memory locations, which allows remote attacker
100RISCO
abrir
anteriorpágina 298 / 303próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.