Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

72.018exploits catalogados
32.219CVEs com exploração pública
1.932testados em laboratório
22.786 exploits
Exploit-DB
OpenSSHd 7.2p2 - Username Enumeration
CVE-2016-6210MEDIUM18 jul 2016
sshd in OpenSSH before 7.3, when SHA256 or SHA512 are used for user password hashing, uses BLOWFISH hashing on a static
70RISCO
abrir
Exploit-DB
Meinberg NTP Time Server ELX800/GPS M4x V5.30p - Remote Command Execution / Escalate Privileges
CVE-2016-398917 jul 2016
The NTP time-server interface on Meinberg IMS-LANTIME M3000, IMS-LANTIME M1000, IMS-LANTIME M500, LANTIME M900, LANTIME
23RISCO
abrir
Exploit-DB
Meinberg NTP Time Server ELX800/GPS M4x V5.30p - Remote Command Execution / Escalate Privileges
CVE-2016-396217 jul 2016
Stack-based buffer overflow in the NTP time-server interface on Meinberg IMS-LANTIME M3000, IMS-LANTIME M1000, IMS-LANTI
23RISCO
abrir
Exploit-DB
Adobe Flash Player 22.0.0.192 - DefineBitsJPEG2 Memory Corruption
CVE-2016-417913 jul 2016
Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632
28RISCO
abrir
Exploit-DB
Adobe Flash Player 22.0.0.192 - DefineSprite Memory Corruption
CVE-2016-417513 jul 2016
Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632
28RISCO
abrir
Exploit-DB
Adobe Acrobat Reader DC 15.016.20045 - Invalid Font '.ttf' Memory Corruption (2)
CVE-2016-420413 jul 2016
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acro
28RISCO
abrir
Exploit-DB
Adobe Acrobat Reader DC 15.016.20045 - Invalid Font '.ttf' Memory Corruption (1)
CVE-2016-420513 jul 2016
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acro
28RISCO
abrir
Exploit-DB
Adobe Acrobat Reader DC 15.016.20045 - Invalid Font '.ttf' Memory Corruption (6)
CVE-2016-420613 jul 2016
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acro
28RISCO
abrir
Exploit-DB
Adobe Acrobat Reader DC 15.016.20045 - Invalid Font '.ttf' Memory Corruption (5)
CVE-2016-420713 jul 2016
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acro
28RISCO
abrir
Exploit-DB
Adobe Acrobat Reader DC 15.016.20045 - Invalid Font '.ttf' Memory Corruption (4)
CVE-2016-420813 jul 2016
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acro
28RISCO
abrir
Exploit-DB
Adobe Acrobat Reader DC 15.016.20045 - Invalid Font '.ttf' Memory Corruption (3)
CVE-2016-420313 jul 2016
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acro
28RISCO
abrir
Exploit-DB
Adobe Acrobat Reader DC 15.016.20045 - Invalid Font '.ttf' Memory Corruption (7)
CVE-2016-420113 jul 2016
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acro
28RISCO
abrir
Exploit-DB
Apache Archiva 1.3.9 - Multiple Cross-Site Request Forgery Vulnerabilities
CVE-2016-446913 jul 2016
Multiple cross-site request forgery (CSRF) vulnerabilities in Apache Archiva 1.3.9 and earlier allow remote attackers to
23RISCO
abrir
Exploit-DB
Microsoft Windows 7 < 10 / 2008 < 2012 (x86/x64) - Secondary Logon Handle Privilege Escalation (MS16-032) (Metasploit)
CVE-2016-0099HIGHsob ataqueransomware13 jul 2016
The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8
98RISCO
abrir
Exploit-DB
Adobe Flash Player 22.0.0.192 - TAG Memory Corruption
CVE-2016-417613 jul 2016
Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632
28RISCO
abrir
Exploit-DB
Adobe Flash Player 22.0.0.192 - SceneAndFrameData Memory Corruption
CVE-2016-417713 jul 2016
Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows and OS X and before 11.2.202.632
28RISCO
abrir
Exploit-DB
IPS Community Suite 4.1.12.3 - PHP Code Injection
CVE-2016-617411 jul 2016
applications/core/modules/front/system/content.php in Invision Power Services IPS Community Suite (aka Invision Power Bo
28RISCO
abrir
Exploit-DB
Adobe Flash - ATF Processing Overflow
CVE-2016-413511 jul 2016
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsof
28RISCO
abrir
Exploit-DB
Adobe Flash - ATF Image Packing Overflow
CVE-2016-413811 jul 2016
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsof
28RISCO
abrir
Exploit-DB
Adobe Flash - JXR Processing Double-Free
CVE-2016-413611 jul 2016
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsof
28RISCO
abrir
Exploit-DB
Adobe Flash - LMZA Property Decoding Heap Corruption
CVE-2016-413711 jul 2016
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsof
28RISCO
abrir
Exploit-DB
Ruby on Rails ActionPack Inline ERB - Code Execution (Metasploit)
CVE-2016-209811 jul 2016
Action Pack in Ruby on Rails before 3.2.22.2, 4.x before 4.1.14.2, and 4.2.x before 4.2.5.2 allows remote attackers to e
60RISCO
abrir
Exploit-DB
Microsoft Windows 7 SP1 - 'mrxdav.sys' WebDAV Privilege Escalation (MS16-016) (Metasploit)
CVE-2016-005111 jul 2016
The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Window
43RISCO
abrir
Exploit-DB
GNU Wget < 1.18 - Arbitrary File Upload / Remote Code Execution
CVE-2016-497106 jul 2016
GNU wget before 1.18 allows remote servers to write to arbitrary files by redirecting a request from HTTP to a crafted F
35RISCO
abrir
Exploit-DB
Python smtplib 2.7.11 / 3.4.4 / 3.5.1 - Man In The Middle StartTLS Stripping
CVE-2016-077203 jul 2016
The smtplib library in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 does not return an e
28RISCO
abrir
Exploit-DB
Ktools Photostore 4.7.5 - Blind SQL Injection
CVE-2016-433730 jun 2016
SQL injection vulnerability in the mgr.login.php file in Ktools.net Photostore before 4.7.5 allows remote attackers to e
23RISCO
abrir
Exploit-DB
Symantec AntiVirus - Unpacking RAR Multiple Remote Memory Corruptions
CVE-2016-220729 jun 2016
The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS
28RISCO
abrir
Exploit-DB
Symantec AntiVirus - Missing Bounds Checks in dec2zip ALPkOldFormatDecompressor::UnShrink
CVE-2016-364629 jun 2016
The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS
28RISCO
abrir
Exploit-DB
Symantec AntiVirus - 'dec2lha Library' Remote Stack Buffer Overflow (PoC)
CVE-2016-221029 jun 2016
Buffer overflow in Dec2LHA.dll in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec
28RISCO
abrir
Exploit-DB
Symantec Endpoint Protection Manager 12.1 - Multiple Vulnerabilities
CVE-2016-365229 jun 2016
Multiple cross-site scripting (XSS) vulnerabilities in management scripts in Symantec Endpoint Protection Manager (SEPM)
23RISCO
abrir
anteriorpágina 159 / 760próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.