Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.445exploits catalogados
34.432CVEs com exploração pública
24.695testados em laboratório
24.443 exploits
Exploit-DBVexDay Proof
Microsoft Windows 7 - win32k Bitmap Use-After-Free (MS16-062) (2)
CVE-2016-0173doswindows15 jun 2016
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
23RISCO
abrir
Exploit-DB
Bomgar Remote Support - Code Execution (Metasploit)
CVE-2015-0935remotelinux15 jun 2016
Bomgar Remote Support before 15.1.1 allows remote attackers to execute arbitrary PHP code via crafted serialized data to
23RISCO
abrir
Exploit-DBVexDay Proof
Easy RM to MP3 Converter 2.7.3.700 - '.m3u' File (Universal ASLR + DEP Bypass)
CVE-2009-1330localwindows13 jun 2016
Stack-based buffer overflow in Easy RM to MP3 Converter allows remote attackers to execute arbitrary code via a long fil
28RISCO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX Kernel - NULL Dereference in CoreCaptureResponder Due to Unchecked Return Value
CVE-2016-1803dososx10 jun 2016
CoreCapture in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers
23RISCO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX Kernel - GeForce GPU Driver Stack Buffer Overflow
CVE-2016-1861dososx10 jun 2016
The NVIDIA Graphics Drivers subsystem in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privi
23RISCO
abrir
Exploit-DBVexDay Proof
IPFire - 'Shellshock' Bash Environment Variable Command Injection (Metasploit)
CVE-2014-6271CRITICALsob ataqueremotecgi10 jun 2016
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX Kernel - Use-After-Free Due to Bad Locking in IOAcceleratorFamily2
CVE-2016-1819dososx10 jun 2016
Use-after-free vulnerability in the IOAccelContext2::clientMemoryForType method in Apple iOS before 9.3.2, OS X before 1
23RISCO
abrir
Exploit-DBVexDay Proof
Apache Struts - REST Plugin With Dynamic Method Invocation Remote Code Execution (Metasploit)
CVE-2016-3087remotemultiple10 jun 2016
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, a
60RISCO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX Kernel - Out-of-Bounds Read of Object Pointer Due to Insufficient Checks in Raw Cast to enum Type
CVE-2016-1823dososx10 jun 2016
The IOHIDDevice::handleReportWithTime function in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and wa
23RISCO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX Kernel - Null Pointer Dereference in IOAudioEngine
CVE-2016-1821dososx10 jun 2016
IOAudioFamily in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged context or cause a
23RISCO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX Kernel - Null Pointer Dereference in AppleGraphicsDeviceControl
CVE-2016-1793dososx10 jun 2016
AppleGraphicsDeviceControlClient in Apple OS X before 10.11.5 allows attackers to execute arbitrary code in a privileged
23RISCO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX Kernel - Null Pointer Dereference in AppleMuxControl.kext
CVE-2016-1794dososx10 jun 2016
The AppleGraphicsControlClient::checkArguments method in AppleGraphicsControl in Apple OS X before 10.11.5 allows attack
23RISCO
abrir
Exploit-DBVexDay Proof
Google Android - '/system/bin/sdcard' Stack Buffer Overflow (PoC)
CVE-2016-2494dosandroid10 jun 2016
Off-by-one error in sdcard/sdcard.c in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before
23RISCO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX / iOS Kernel - UAF Racing getProperty on IOHDIXController and testNetBootMethod on IOHDIXControllerUserClient
CVE-2016-1807dosmultiple10 jun 2016
Race condition in the Disk Images subsystem in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watch
23RISCO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX Kernel - Null Pointer Dereference in nvCommandQueue::GetHandleIndex in GeForce.kext
CVE-2016-1846dososx10 jun 2016
The nvCommandQueue::GetHandleIndex method in the NVIDIA Graphics Drivers subsystem in Apple OS X before 10.11.5 allows a
23RISCO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX Kernel - NULL Dereference in IOAccelSharedUserClient2::page_off_resource
CVE-2016-1813dososx10 jun 2016
The IOAccelSharedUserClient2::page_off_resource method in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1
23RISCO
abrir
Exploit-DB
Cisco EPC 3928 - Multiple Vulnerabilities
CVE-2016-1337webappsasp07 jun 2016
Cisco EPC3928 devices allow remote attackers to obtain sensitive configuration and credential information by making requ
23RISCO
abrir
Exploit-DB
Cisco EPC 3928 - Multiple Vulnerabilities
CVE-2016-1336webappsasp07 jun 2016
goform/Docsis_system on Cisco EPC3928 devices allows remote attackers to cause a denial of service (device crash) via a
23RISCO
abrir
Exploit-DB
Cisco EPC 3928 - Multiple Vulnerabilities
CVE-2015-6402webappsasp07 jun 2016
Cross-site scripting (XSS) vulnerability in the management interface on Cisco EPC3928 devices with EDVA 5.5.10, 5.5.11,
23RISCO
abrir
Exploit-DB
Cisco EPC 3928 - Multiple Vulnerabilities
CVE-2016-1328webappsasp07 jun 2016
goform/WClientMACList on Cisco EPC3928 devices allows remote attackers to cause a denial of service (device crash) via a
23RISCO
abrir
Exploit-DB
Cisco EPC 3928 - Multiple Vulnerabilities
CVE-2015-6401webappsasp07 jun 2016
Cisco EPC3928 devices with EDVA 5.5.10, 5.5.11, and 5.7.1 allow remote attackers to bypass an intended authentication re
23RISCO
abrir
Exploit-DB
Valve Steam 3.42.16.13 - Local Privilege Escalation
CVE-2016-5237localwindows06 jun 2016
Valve Steam 3.42.16.13 uses weak permissions for the files in the Steam program directory, which allows local users to m
23RISCO
abrir
Exploit-DB
Sun Secure Global Desktop and Oracle Global Desktop 4.61.915 - Command Injection (Shellshock)
CVE-2014-6278HIGHsob ataquewebappscgi06 jun 2016
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, whi
100RISCO
abrir
Exploit-DB
Liferay CE < 6.2 CE GA6 - Persistent Cross-Site Scripting
CVE-2016-3670webappsjsp02 jun 2016
Cross-site scripting (XSS) vulnerability in users.jsp in the Profile Search functionality in Liferay before 7.0.0 CE RC1
23RISCO
abrir
Exploit-DBVexDay Proof
HP Data Protector A.09.00 - Encrypted Communications Arbitrary Command Execution (Metasploit)
CVE-2016-2004remotewindows31 mai 2016
HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary cod
60RISCO
abrir
Exploit-DB
MySQL 5.5.45 - procedure analyse Function Denial of Service
CVE-2015-4870dosmultiple30 mai 2016
Unspecified vulnerability in Oracle MySQL Server 5.5.45 and earlier, and 5.6.26 and earlier, allows remote authenticated
35RISCO
abrir
Exploit-DB
FreeBSD Kernel (FreeBSD 10.2 < 10.3 x64) - 'SETFKEY' (PoC)
CVE-2016-1886dosfreebsd_x86-6429 mai 2016
Integer signedness error in the genkbd_commonioctl function in sys/dev/kbd/kbd.c in FreeBSD 9.3 before p42, 10.1 before
23RISCO
abrir
Exploit-DB
FreeBSD Kernel (FreeBSD 10.2 x64) - 'sendmsg' Kernel Heap Overflow (PoC)
CVE-2016-1887dosfreebsd_x86-6429 mai 2016
Integer signedness error in the sockargs function in sys/kern/uipc_syscalls.c in FreeBSD 10.1 before p34, 10.2 before p1
23RISCO
abrir
Exploit-DBVexDay Proof
VideoLAN VLC Media Player 2.2.1 - 'DecodeAdpcmImaQT' Buffer Overflow
CVE-2016-5108doswindows27 mai 2016
Buffer overflow in the DecodeAdpcmImaQT function in modules/codec/adpcm.c in VideoLAN VLC media player before 2.2.4 allo
28RISCO
abrir
Exploit-DB
Micro Focus Rumba+ 9.4 - Multiple Stack Buffer Overflow Vulnerabilities
CVE-2016-1606doswindows26 mai 2016
Multiple stack-based buffer overflows in COM objects in Micro Focus Rumba 9.4.x before 9.4 HF 13960 allow remote attacke
35RISCO
abrir
anteriorpágina 166 / 815próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.