Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

72.018exploits catalogados
32.219CVEs com exploração pública
1.932testados em laboratório
22.786 exploits
Exploit-DB
Google Android 5.0 < 5.1.1 - 'Stagefright' .MP4 tx3g Integer Overflow (Metasploit)
CVE-2015-386427 set 2016
Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in A
60RISCO
abrir
Exploit-DB
Linux Kernel 4.6.3 (x86) - 'Netfilter' Local Privilege Escalation (Metasploit)
CVE-2016-499727 set 2016
The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux
38RISCO
abrir
Exploit-DB
Microsoft Windows - RegLoadAppKey Hive Enumeration Privilege Escalation (MS16-111)
CVE-2016-337326 set 2016
The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows S
28RISCO
abrir
Exploit-DB
Microsoft Windows 8.1 Update 2 / 10 10586 (x86/x64) - NtLoadKeyEx User Hive Attachment Point Privilege Escalation (MS16-111)
CVE-2016-337126 set 2016
The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows S
35RISCO
abrir
Exploit-DB
Adobe Flash - Crash When Freeing Memory After AVC decoding
CVE-2016-427523 set 2016
Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635
28RISCO
abrir
Exploit-DB
JCraft/JSch Java Secure Channel 0.1.53 - Recursive sftp-get Directory Traversal
CVE-2016-572522 set 2016
Directory traversal vulnerability in JCraft JSch before 0.1.54 on Windows, when the mode is ChannelSftp.OVERWRITE, allow
28RISCO
abrir
Exploit-DB
Exponent CMS 2.3.9 - Blind SQL Injection
CVE-2016-740022 set 2016
Multiple SQL injection vulnerabilities in Exponent CMS before 2.4.0 allow remote attackers to execute arbitrary SQL comm
23RISCO
abrir
Exploit-DB
Microsoft Windows Kerberos - Security Feature Bypass (MS16-101)
CVE-2016-323722 set 2016
Kerberos in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server
28RISCO
abrir
Exploit-DB
Symantec RAR Decomposer Engine (Multiple Products) - Out-of-Bounds Read / Out-of-Bounds Write
CVE-2016-531021 set 2016
The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP);
23RISCO
abrir
Exploit-DB
Symantec RAR Decomposer Engine (Multiple Products) - Out-of-Bounds Read / Out-of-Bounds Write
CVE-2016-530921 set 2016
The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP);
23RISCO
abrir
Exploit-DB
Microsoft Office PowerPoint 2010 - Invalid Pointer Reference
CVE-2016-335721 set 2016
Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office 2016, Word for Mac 2011, Word 20
35RISCO
abrir
Exploit-DB
VMware Workstation - 'vprintproxy.exe' TrueType NAME Tables Heap Buffer Overflow (PoC)
CVE-2016-708319 set 2016
VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, when Cortado Thin
23RISCO
abrir
Exploit-DB
VMware Workstation - 'vprintproxy.exe' JPEG2000 Images Multiple Memory Corruptions
CVE-2016-708419 set 2016
tpview.dll in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, whe
23RISCO
abrir
Exploit-DB
NetBSD - 'mail.local(8)' Local Privilege Escalation (Metasploit)
CVE-2016-625315 set 2016
mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or
38RISCO
abrir
Exploit-DB
Open-Xchange Guard 2.4.2 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2016-685413 set 2016
An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code which got injected to a mail with inline
23RISCO
abrir
Exploit-DB
Open-Xchange Guard 2.4.2 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2016-685313 set 2016
An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code and references to external websites can
23RISCO
abrir
Exploit-DB
Open-Xchange App Suite 7.8.2 - Cross-Site Scripting
CVE-2016-574013 set 2016
An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev5. JavaScript code can be used as part of ical atta
23RISCO
abrir
Exploit-DB
Open-Xchange Guard 2.4.2 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2016-685113 set 2016
An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code can be provided as parameter to the OX G
23RISCO
abrir
Exploit-DB
Cherry Music 0.35.1 - Arbitrary File Disclosure
CVE-2015-830913 set 2016
Directory traversal vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to read arbitrary file
23RISCO
abrir
Exploit-DB
MySQL / MariaDB / PerconaDB 5.5.51/5.6.32/5.7.14 - Code Execution / Privilege Escalation
CVE-2016-666212 set 2016
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.2
35RISCO
abrir
Exploit-DB
Adobe Flash - Method Calls Use-After-Free
CVE-2016-423108 set 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows
35RISCO
abrir
Exploit-DB
Google Android - libutils UTF16 to UTF8 Conversion Heap Buffer Overflow
CVE-2016-386108 set 2016
LibUtils in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-09-01, and 7.0 before 2016
28RISCO
abrir
Exploit-DB
Adobe Flash - Transform.colorTranform Getter Infomation Leak
CVE-2016-423208 set 2016
Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632
35RISCO
abrir
Exploit-DB
Adobe ColdFusion < 11 Update 10 - XML External Entity Injection
CVE-2016-426407 set 2016
The Office Open XML (OOXML) feature in Adobe ColdFusion 10 before Update 21 and 11 before Update 10 allows remote attack
35RISCO
abrir
Exploit-DB
glibc - 'getaddrinfo' Remote Stack Buffer Overflow
CVE-2015-754706 set 2016
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RISCO
abrir
Exploit-DB
Adobe Flash - Use-After-Free When Returning Rectangle
CVE-2016-422829 ago 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows
35RISCO
abrir
Exploit-DB
Adobe Flash - Stage.align Setter Use-After-Free
CVE-2016-422629 ago 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows
35RISCO
abrir
Exploit-DB
Adobe Flash - Selection.setFocus Use-After-Free
CVE-2016-422729 ago 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows
35RISCO
abrir
Exploit-DB
Adobe Flash - MovieClip Transform Getter Use-After-Free
CVE-2016-423029 ago 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows
35RISCO
abrir
Exploit-DB
Adobe Flash - BitmapData.copyPixels Use-After-Free
CVE-2016-422929 ago 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows
35RISCO
abrir
anteriorpágina 156 / 760próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.