Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.442exploits catalogados
34.431CVEs com exploração pública
24.695testados em laboratório
24.443 exploits
Exploit-DBVexDay Proof
Google Android - 'gpsOneXtra' Data Files Denial of Service
CVE-2016-5348dosandroid11 out 2016
The GPS component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 be
23RISCO
abrir
Exploit-DB
Linux Kernel 4.6.2 (Ubuntu 16.04.1) - 'IP6T_SO_SET_REPLACE' Local Privilege Escalation
CVE-2016-4997locallinux10 out 2016
The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux
38RISCO
abrir
Exploit-DB
Apache Tomcat 8/7/6 (RedHat Based Distros) - Local Privilege Escalation
CVE-2016-5425locallinux10 out 2016
The Tomcat package on Red Hat Enterprise Linux (RHEL) 7, Fedora, CentOS, Oracle Linux, and possibly other Linux distribu
38RISCO
abrir
Exploit-DB
HP Client 9.1/9.0/8.1/7.9 - Command Injection
CVE-2015-1497remotemultiple10 out 2016
radexecd.exe in Persistent Systems Radia Client Automation (RCA) 7.9, 8.1, 9.0, and 9.1 allows remote attackers to execu
60RISCO
abrir
Exploit-DBVexDay Proof
Cisco Firepower Threat Management Console 6.0.1 - Remote Command Execution
CVE-2016-6433webappscgi05 out 2016
The Threat Management Console in Cisco Firepower Management Center 5.2.0 through 6.0.1 allows remote authenticated users
60RISCO
abrir
Exploit-DB
Cisco Firepower Threat Management Console 6.0.1 - Local File Inclusion
CVE-2016-6435webappscgi05 out 2016
The web console in Cisco Firepower Management Center 6.0.1 allows remote authenticated users to read arbitrary files via
50RISCO
abrir
Exploit-DB
Cisco Firepower Threat Management Console 6.0.1 - Hard-Coded MySQL Credentials
CVE-2016-6434locallinux05 out 2016
Cisco Firepower Management Center 6.0.1 has hardcoded database credentials, which allows local users to obtain sensitive
23RISCO
abrir
Exploit-DB
ISC BIND 9 - Denial of Service
CVE-2016-2776dosmultiple04 out 2016
buffer.c in named in ISC BIND 9 before 9.9.9-P3, 9.10.x before 9.10.4-P3, and 9.11.x before 9.11.0rc3 does not properly
60RISCO
abrir
Exploit-DBVexDay Proof
Apache Tomcat 8/7/6 (Debian-Based Distros) - Local Privilege Escalation
CVE-2016-1240locallinux03 out 2016
The Tomcat init script in the tomcat7 package before 7.0.56-3+deb8u4 and tomcat8 package before 8.0.14-1+deb8u3 on Debia
38RISCO
abrir
Exploit-DB
Grandsteam GXV3611_HD - SQL Injection
CVE-2015-2866remotehardware29 set 2016
SQL injection vulnerability on the Grandstream GXV3611_HD camera with firmware before 1.0.3.9 beta allows remote attacke
23RISCO
abrir
Exploit-DB
Symantec Messaging Gateway 10.6.1 - Directory Traversal
CVE-2016-5312webappsjava28 set 2016
Directory traversal vulnerability in the charting component in Symantec Messaging Gateway before 10.6.2 allows remote au
35RISCO
abrir
Exploit-DBVexDay Proof
Google Android 5.0 < 5.1.1 - 'Stagefright' .MP4 tx3g Integer Overflow (Metasploit)
CVE-2015-3864remoteandroid27 set 2016
Integer underflow in the MPEG4Extractor::parseChunk function in MPEG4Extractor.cpp in libstagefright in mediaserver in A
60RISCO
abrir
Exploit-DBVexDay Proof
Linux Kernel 4.6.3 (x86) - 'Netfilter' Local Privilege Escalation (Metasploit)
CVE-2016-4997locallinux_x8627 set 2016
The compat IPT_SO_SET_REPLACE and IP6T_SO_SET_REPLACE setsockopt implementations in the netfilter subsystem in the Linux
38RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - RegLoadAppKey Hive Enumeration Privilege Escalation (MS16-111)
CVE-2016-3373localwindows26 set 2016
The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows S
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 8.1 Update 2 / 10 10586 (x86/x64) - NtLoadKeyEx User Hive Attachment Point Privilege Escalation (MS16-111)
CVE-2016-3371localwindows26 set 2016
The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows S
35RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Crash When Freeing Memory After AVC decoding
CVE-2016-4275dosmultiple23 set 2016
Adobe Flash Player before 18.0.0.375 and 19.x through 23.x before 23.0.0.162 on Windows and OS X and before 11.2.202.635
28RISCO
abrir
Exploit-DB
Exponent CMS 2.3.9 - Blind SQL Injection
CVE-2016-7400webappsphp22 set 2016
Multiple SQL injection vulnerabilities in Exponent CMS before 2.4.0 allow remote attackers to execute arbitrary SQL comm
23RISCO
abrir
Exploit-DBVexDay Proof
JCraft/JSch Java Secure Channel 0.1.53 - Recursive sftp-get Directory Traversal
CVE-2016-5725doswindows22 set 2016
Directory traversal vulnerability in JCraft JSch before 0.1.54 on Windows, when the mode is ChannelSftp.OVERWRITE, allow
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kerberos - Security Feature Bypass (MS16-101)
CVE-2016-3237localwindows22 set 2016
Kerberos in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server
28RISCO
abrir
Exploit-DBVexDay Proof
Symantec RAR Decomposer Engine (Multiple Products) - Out-of-Bounds Read / Out-of-Bounds Write
CVE-2016-5310dosmultiple21 set 2016
The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP);
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Office PowerPoint 2010 - Invalid Pointer Reference
CVE-2016-3357doswindows21 set 2016
Microsoft Office 2007 SP3, Office 2010 SP2, Office 2013 SP1, Office 2013 RT SP1, Office 2016, Word for Mac 2011, Word 20
35RISCO
abrir
Exploit-DBVexDay Proof
Symantec RAR Decomposer Engine (Multiple Products) - Out-of-Bounds Read / Out-of-Bounds Write
CVE-2016-5309dosmultiple21 set 2016
The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP);
23RISCO
abrir
Exploit-DBVexDay Proof
VMware Workstation - 'vprintproxy.exe' TrueType NAME Tables Heap Buffer Overflow (PoC)
CVE-2016-7083doswindows19 set 2016
VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, when Cortado Thin
23RISCO
abrir
Exploit-DBVexDay Proof
VMware Workstation - 'vprintproxy.exe' JPEG2000 Images Multiple Memory Corruptions
CVE-2016-7084doswindows19 set 2016
tpview.dll in VMware Workstation Pro 12.x before 12.5.0 and VMware Workstation Player 12.x before 12.5.0 on Windows, whe
23RISCO
abrir
Exploit-DBVexDay Proof
NetBSD - 'mail.local(8)' Local Privilege Escalation (Metasploit)
CVE-2016-6253localnetbsd_x8615 set 2016
mail.local in NetBSD versions 6.0 through 6.0.6, 6.1 through 6.1.5, and 7.0 allows local users to change ownership of or
38RISCO
abrir
Exploit-DB
Open-Xchange Guard 2.4.2 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2016-6853webappslinux13 set 2016
An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code and references to external websites can
23RISCO
abrir
Exploit-DB
Open-Xchange Guard 2.4.2 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2016-6851webappslinux13 set 2016
An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code can be provided as parameter to the OX G
23RISCO
abrir
Exploit-DB
Open-Xchange Guard 2.4.2 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2016-6854webappslinux13 set 2016
An issue was discovered in Open-Xchange OX Guard before 2.4.2-rev5. Script code which got injected to a mail with inline
23RISCO
abrir
Exploit-DB
Open-Xchange App Suite 7.8.2 - Cross-Site Scripting
CVE-2016-5740webappslinux13 set 2016
An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev5. JavaScript code can be used as part of ical atta
23RISCO
abrir
Exploit-DBVexDay Proof
Cherry Music 0.35.1 - Arbitrary File Disclosure
CVE-2015-8309webappsphp13 set 2016
Directory traversal vulnerability in Cherry Music before 0.36.0 allows remote authenticated users to read arbitrary file
23RISCO
abrir
anteriorpágina 161 / 815próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.