Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.445exploits catalogados
34.432CVEs com exploração pública
24.695testados em laboratório
24.443 exploits
Exploit-DBVexDay Proof
HP Data Protector A.09.00 - Arbitrary Command Execution
CVE-2016-2004remotewindows26 mai 2016
HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allow remote attackers to execute arbitrary cod
60RISCO
abrir
Exploit-DBVexDay Proof
Oracle Application Testing Suite (ATS) - Arbitrary File Upload (Metasploit)
CVE-2016-0492remotejava25 mai 2016
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12
60RISCO
abrir
Exploit-DBVexDay Proof
Oracle Application Testing Suite (ATS) - Arbitrary File Upload (Metasploit)
CVE-2016-0491remotejava25 mai 2016
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12
60RISCO
abrir
Exploit-DBVexDay Proof
Apple QuickTime - '.mov' Parsing Memory Corruption
CVE-2016-1848dososx19 mai 2016
QuickTime in Apple OS X before 10.11.5 allows remote attackers to execute arbitrary code or cause a denial of service (m
23RISCO
abrir
Exploit-DB
SAP NetWeaver AS JAVA 7.1 < 7.5 - Information Disclosure
CVE-2016-2388MEDIUMsob ataquewebappsxml19 mai 2016
The Universal Worklist Configuration in SAP NetWeaver AS JAVA 7.4 allows remote attackers to obtain sensitive user infor
75RISCO
abrir
Exploit-DB
SAP NetWeaver AS JAVA 7.1 < 7.5 - SQL Injection
CVE-2016-2386CRITICALsob ataquewebappsxml19 mai 2016
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbi
100RISCO
abrir
Exploit-DBVexDay Proof
Magento < 2.0.6 - Arbitrary Unserialize / Arbitrary Write File
CVE-2016-4010webappsphp18 mai 2016
Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary
60RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Overflow in Processing Raw 565 Textures
CVE-2016-1103dosmultiple17 mai 2016
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RISCO
abrir
Exploit-DB
Meteocontrol WEB’log - Admin Password Disclosure (Metasploit)
CVE-2016-2296webappsmultiple17 mai 2016
Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited does not require authentication for "post-admin" login pag
50RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash - addProperty Use-After-Free
CVE-2016-4108dosmultiple17 mai 2016
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Type Confusion in FileReference Constructor
CVE-2016-1105dosmultiple17 mai 2016
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RISCO
abrir
Exploit-DBVexDay Proof
Dell SonicWALL Scrutinizer 11.01 - methodDetail SQL Injection (Metasploit)
CVE-2014-4977remotemultiple17 mai 2016
Multiple SQL injection vulnerabilities in Dell SonicWall Scrutinizer 11.0.1 allow remote authenticated users to execute
60RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Heap Overflow in ATF Processing Image Reading
CVE-2016-1101dosmultiple17 mai 2016
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash - SetNative Use-After-Free
CVE-2016-1106dosmultiple17 mai 2016
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'gdi32.dll' Multiple 'EMF CREATECOLORSPACEW' Record Handling (MS16-055)
CVE-2016-0168doswindows17 mai 2016
GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'gdi32.dll' Multiple 'EMF COMMENT_MULTIFORMATS' Record Handling (MS16-055)
CVE-2016-0169doswindows17 mai 2016
GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012
35RISCO
abrir
Exploit-DBVexDay Proof
Symantec/Norton AntiVirus - ASPack Remote Heap/Pool Memory Corruption
CVE-2016-2208dosmultiple17 mai 2016
The kernel component in Symantec Anti-Virus Engine (AVE) 20151.1 before 20151.1.1.4 allows remote attackers to execute a
28RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash - JXR Processing Out-of-Bounds Read
CVE-2016-1102dosmultiple17 mai 2016
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash - '.MP4' Stack Corruption
CVE-2016-1096dosmultiple17 mai 2016
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RISCO
abrir
Exploit-DB
SAP xMII 15.0 - Directory Traversal
CVE-2016-2389webappsjava17 mai 2016
Directory traversal vulnerability in the GetFileList function in the SAP Manufacturing Integration and Intelligence (xMI
50RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - 'gdi32.dll' Heap Buffer Overflow in ExtEscape() Triggerable via EMR_EXTESCAPE EMF Record (MS16-055)
CVE-2016-0170dosmultiple17 mai 2016
GDI in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012
35RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Out-of-Bounds Read when Placing Object
CVE-2016-1104dosmultiple17 mai 2016
Unspecified vulnerability in Adobe Flash Player 21.0.0.213 and earlier, as used in the Adobe Flash libraries in Microsof
35RISCO
abrir
Exploit-DBVexDay Proof
Cisco ASA Software 8.x/9.x - IKEv1 / IKEv2 Buffer Overflow
CVE-2016-1287remotehardware17 mai 2016
Buffer overflow in the IKEv1 and IKEv2 implementations in Cisco ASA Software before 8.4(7.30), 8.7 before 8.7(1.18), 9.0
45RISCO
abrir
Exploit-DB
CakePHP Framework 3.2.4 - IP Spoofing
CVE-2016-4793webappsphp16 mai 2016
The clientIp function in CakePHP 3.2.4 and earlier allows remote attackers to spoof their IP via the CLIENT-IP HTTP head
23RISCO
abrir
Exploit-DBVexDay Proof
Web2py 2.14.5 - Multiple Vulnerabilities
CVE-2016-4806webappspython16 mai 2016
Web2py versions 2.14.5 and below was affected by Local File Inclusion vulnerability, which allows a malicious intended u
28RISCO
abrir
Exploit-DB
eXtplorer 2.1.9 - '.ZIP' Directory Traversal
CVE-2016-4313webappsphp16 mai 2016
Directory traversal vulnerability in unzip/extract feature in eXtplorer 2.1.9 allows remote attackers to execute arbitra
23RISCO
abrir
Exploit-DBVexDay Proof
Web2py 2.14.5 - Multiple Vulnerabilities
CVE-2016-4808webappspython16 mai 2016
Web2py versions 2.14.5 and below was affected by CSRF (Cross Site Request Forgery) vulnerability, which allows an attack
23RISCO
abrir
Exploit-DBVexDay Proof
Web2py 2.14.5 - Multiple Vulnerabilities
CVE-2016-4807webappspython16 mai 2016
Web2py versions 2.14.5 and below was affected by Reflected XSS vulnerability, which allows an attacker to perform an XSS
23RISCO
abrir
Exploit-DB
Apple OS X 10.10.5 - 'rootsh' Local Privilege Escalation
CVE-2016-1828localosx16 mai 2016
The kernel in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1, and watchOS before 2.2.1 allows attackers
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Media Center - '.MCL' File Processing Remote Code Execution (MS16-059)
CVE-2016-0185HIGHsob ataqueremotewindows12 mai 2016
Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, and Windows 8.1 allows remote attackers to execute arbitrary
83RISCO
abrir
anteriorpágina 167 / 815próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.