Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.445exploits catalogados
34.432CVEs com exploração pública
24.695testados em laboratório
24.443 exploits
Exploit-DBVexDay Proof
WSO2 Carbon 4.4.5 - Local File Inclusion
CVE-2016-4314webappsjsp16 ago 2016
Directory traversal vulnerability in the LogViewer Admin Service in WSO2 Carbon 4.4.5 allows remote authenticated admini
28RISCO
abrir
Exploit-DBVexDay Proof
WSO2 Carbon 4.4.5 - Persistent Cross-Site Scripting
CVE-2016-4316webappsjsp16 ago 2016
Multiple cross-site scripting (XSS) vulnerabilities in WSO2 Carbon 4.4.5 allow remote attackers to inject arbitrary web
23RISCO
abrir
Exploit-DB
GitLab - 'impersonate' Feature Privilege Escalation
CVE-2016-4340webappsruby15 ago 2016
The impersonate feature in Gitlab 8.7.0, 8.6.0 through 8.6.7, 8.5.0 through 8.5.11, 8.4.0 through 8.4.9, 8.3.0 through 8
28RISCO
abrir
Exploit-DB
Claroline < 1.7.7 - Arbitrary File Inclusion
CVE-2006-4844webappsphp14 ago 2016
PHP remote file inclusion vulnerability in inc/claro_init_local.inc.php in Claroline 1.7.7 and earlier, as used in Dokeo
28RISCO
abrir
Exploit-DB
SquirrelMail < 1.4.7 - Arbitrary Variable Overwrite
CVE-2006-4019webappsphp11 ago 2016
Dynamic variable evaluation vulnerability in compose.php in SquirrelMail 1.4.0 to 1.4.7 allows remote attackers to overw
23RISCO
abrir
Exploit-DB
vBulletin 5.2.2 - Server-Side Request Forgery
CVE-2016-6483webappsphp10 ago 2016
The media-file upload feature in vBulletin before 3.8.7 Patch Level 6, 3.8.8 before Patch Level 2, 3.8.9 before Patch Le
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Word 2007/2010/2013/2016 - Out-of-Bounds Read Code Execution (MS16-099)
CVE-2016-3313localwindows10 ago 2016
Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, 2013 RT SP1, and 2016, Word 2016 for Mac, and Word Viewer allow remote at
35RISCO
abrir
Exploit-DB
WebNMS Framework Server 5.2/5.2 SP1 - Multiple Vulnerabilities
CVE-2016-6600webappsjsp10 ago 2016
Directory traversal vulnerability in the file upload functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remot
60RISCO
abrir
Exploit-DB
WebNMS Framework Server 5.2/5.2 SP1 - Multiple Vulnerabilities
CVE-2016-6603webappsjsp10 ago 2016
ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to bypass authentication and impersonate arbitrary users v
45RISCO
abrir
Exploit-DB
WebNMS Framework Server 5.2/5.2 SP1 - Multiple Vulnerabilities
CVE-2016-6602webappsjsp10 ago 2016
ZOHO WebNMS Framework 5.2 and 5.2 SP1 use a weak obfuscation algorithm to store passwords, which allows context-dependen
50RISCO
abrir
Exploit-DBVexDay Proof
SAP SAPCAR - Multiple Vulnerabilities
CVE-2016-5845doslinux10 ago 2016
SAP SAPCAR does not check the return value of file operations when extracting files, which allows remote attackers to ca
23RISCO
abrir
Exploit-DBVexDay Proof
SAP SAPCAR - Multiple Vulnerabilities
CVE-2016-5847doslinux10 ago 2016
SAP SAPCAR allows local users to change the permissions of arbitrary files and consequently gain privileges via a hard l
23RISCO
abrir
Exploit-DB
WebNMS Framework Server 5.2/5.2 SP1 - Multiple Vulnerabilities
CVE-2016-6601webappsjsp10 ago 2016
Directory traversal vulnerability in the file download functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows rem
60RISCO
abrir
Exploit-DB
Xfinity Gateway (Technicolor DPC3941T) - Cross-Site Request Forgery
CVE-2016-7454webappshardware09 ago 2016
CSRF vulnerability on Technicolor TC dpc3941T (formerly Cisco dpc3941T) devices with firmware dpc3941-P20-18-v303r204217
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 7 (x86/x64) - Group Policy Privilege Escalation (MS16-072)
CVE-2016-3223localwindows08 ago 2016
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold an
28RISCO
abrir
Exploit-DBVexDay Proof
VMware Host Guest Client Redirector - DLL Side Loading (Metasploit)
CVE-2016-5330localwindows06 ago 2016
Untrusted search path vulnerability in the HGFS (aka Shared Folders) feature in VMware Tools 10.0.5 in VMware ESXi 5.0 t
43RISCO
abrir
Exploit-DB
NUUO NVRmini2 / NVRsolo / Crystal Devices / NETGEAR ReadyNAS Surveillance Application - Multiple Vulnerabilities
CVE-2016-5676remotehardware05 ago 2016
cgi-bin/cgi_system in NUUO NVRmini 2 1.7.5 through 2.x, NUUO NVRsolo 1.7.5 through 2.x, and NETGEAR ReadyNAS Surveillanc
50RISCO
abrir
Exploit-DB
NUUO NVRmini2 / NVRsolo / Crystal Devices / NETGEAR ReadyNAS Surveillance Application - Multiple Vulnerabilities
CVE-2016-5679remotehardware05 ago 2016
cgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance 1.1.2 allows remote authenticat
28RISCO
abrir
Exploit-DB
NUUO NVRmini2 / NVRsolo / Crystal Devices / NETGEAR ReadyNAS Surveillance Application - Multiple Vulnerabilities
CVE-2016-5677remotehardware05 ago 2016
NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.
28RISCO
abrir
Exploit-DB
NUUO NVRmini2 / NVRsolo / Crystal Devices / NETGEAR ReadyNAS Surveillance Application - Multiple Vulnerabilities
CVE-2016-5680remotehardware05 ago 2016
Stack-based buffer overflow in cgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance
28RISCO
abrir
Exploit-DB
NUUO NVRmini2 / NVRsolo / Crystal Devices / NETGEAR ReadyNAS Surveillance Application - Multiple Vulnerabilities
CVE-2016-5678remotehardware05 ago 2016
NUUO NVRmini 2 1.0.0 through 3.0.0 and NUUO NVRsolo 1.0.0 through 3.0.0 have hardcoded root credentials, which allows re
23RISCO
abrir
Exploit-DB
NUUO NVRmini2 / NVRsolo / Crystal Devices / NETGEAR ReadyNAS Surveillance Application - Multiple Vulnerabilities
CVE-2016-5675remotehardware05 ago 2016
handle_daylightsaving.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, NUUO Crystal 2.2.1 th
60RISCO
abrir
Exploit-DB
NUUO NVRmini2 / NVRsolo / Crystal Devices / NETGEAR ReadyNAS Surveillance Application - Multiple Vulnerabilities
CVE-2016-5674remotehardware05 ago 2016
__debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR Rea
60RISCO
abrir
Exploit-DBVexDay Proof
Wireshark 2.0.0 < 2.0.4 - MMSE / WAP / WBXML / WSP Dissectors Denial of Service
CVE-2016-6512dosmultiple03 ago 2016
epan/dissectors/packet-wap.c in Wireshark 2.x before 2.0.5 omits an overflow check in the tvb_get_guintvar function, whi
23RISCO
abrir
Exploit-DBVexDay Proof
Wireshark 1.12.0 < 1.12.12 - NDS Dissector Denial of Service
CVE-2016-6504dosmultiple03 ago 2016
epan/dissectors/packet-ncp2222.inc in the NDS dissector in Wireshark 1.12.x before 1.12.13 does not properly maintain a
23RISCO
abrir
Exploit-DBVexDay Proof
Wireshark 1.12.0 < 1.12.12 / 2.0.0 < 2.0.4 - PacketBB Dissector Denial of Service
CVE-2016-6505dosmultiple03 ago 2016
epan/dissectors/packet-packetbb.c in the PacketBB dissector in Wireshark 1.12.x before 1.12.13 and 2.x before 2.0.5 allo
23RISCO
abrir
Exploit-DBVexDay Proof
Wireshark 2.0.0 < 2.0.4 - CORBA IDL Dissectors Denial of Service
CVE-2016-6503doswindows_x86-6403 ago 2016
The CORBA IDL dissectors in Wireshark 2.x before 2.0.5 on 64-bit Windows platforms do not properly interact with Visual
23RISCO
abrir
Exploit-DB
Trend Micro Deep Discovery 3.7/3.8 SP1 (3.81)/3.8 SP2 (3.82) - 'hotfix_upload.cgi' Filename Remote Code Execution
CVE-2016-5840webappslinux29 jul 2016
hotfix_upload.cgi in Trend Micro Deep Discovery Inspector (DDI) 3.7, 3.8 SP1 (3.81), and 3.8 SP2 (3.82) allows remote ad
23RISCO
abrir
Exploit-DB
phpMyAdmin 4.6.2 - (Authenticated) Remote Code Execution
CVE-2016-5734webappsphp29 jul 2016
phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not properly choose delimiters to
60RISCO
abrir
Exploit-DB
AXIS (Multiple Products) - 'devtools ' (Authenticated) Remote Command Execution
CVE-2015-8257webappslinux29 jul 2016
The devtools.sh script in AXIS network cameras allows remote authenticated users to execute arbitrary commands via shell
28RISCO
abrir
anteriorpágina 163 / 815próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.