Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.526exploits catalogados
34.478CVEs com exploração pública
24.695testados em laboratório
24.443 exploits
Exploit-DB
Geeklog < 1.4.0 - Multiple Vulnerabilities
CVE-2006-0823webappsphp19 fev 2016
Multiple SQL injection vulnerabilities in Geeklog 1.4.0 before 1.4.0sr1 and 1.3.11 before 1.3.11sr4 allow remote attacke
23RISCO
abrir
Exploit-DB
ADOdb < 4.71 - Cross Site Scripting
CVE-2006-0806webappsphp18 fev 2016
Multiple cross-site scripting (XSS) vulnerabilities in ADOdb 4.71, as used in multiple packages such as phpESP, allow re
23RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Out-of-Bounds Image Read
CVE-2016-0965dosmultiple17 fev 2016
Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on
28RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Sound.loadPCMFromByteArray Dangling Pointer
CVE-2016-0984HIGHsob ataquedosmultiple17 fev 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and
83RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash - textfield Constructor Type Confusion
CVE-2016-0985dosmultiple17 fev 2016
Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on
28RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash - BitmapData.drawWithQuality Heap Overflow
CVE-2016-0964dosmultiple17 fev 2016
Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on
28RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash - H264 File Stack Corruption
CVE-2016-0967dosmultiple17 fev 2016
Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS X and before 11.2.202.569 on
28RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash - LoadVars.decode Use-After-Free
CVE-2016-0974dosmultiple17 fev 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and
35RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash - ATF Processing Heap Overflow
CVE-2016-0971dosmultiple17 fev 2016
Heap-based buffer overflow in Adobe Flash Player before 18.0.0.329 and 19.x and 20.x before 20.0.0.306 on Windows and OS
35RISCO
abrir
Exploit-DB
Inductive Automation Ignition 7.8.1 - Remote Leakage Of Shared Buffers
CVE-2015-2080remotemultiple17 fev 2016
The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive informat
60RISCO
abrir
Exploit-DBVexDay Proof
glibc - 'getaddrinfo' Stack Buffer Overflow (PoC)
CVE-2015-7547doslinux16 fev 2016
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RISCO
abrir
Exploit-DB
Flash ActiveX 28.0.0.137 - Code Execution (1)
CVE-2018-4878HIGHsob ataqueransomwarelocalwindows16 fev 2016
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RISCO
abrir
Exploit-DB
Microsoft Windows 7 (x86) - 'afd.sys' Dangling Pointer Privilege Escalation (MS14-040)
CVE-2014-1767localwindows_x8615 fev 2016
Double free vulnerability in the Ancillary Function Driver (AFD) in afd.sys in the kernel-mode drivers in Microsoft Wind
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Kerberos Security Feature Bypass (MS16-014)
CVE-2016-0049localwindows15 fev 2016
Kerberos in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
28RISCO
abrir
Exploit-DB
Flash ActiveX 28.0.0.137 - Code Execution (2)
CVE-2018-4878HIGHsob ataqueransomwarelocalwindows13 fev 2016
A use-after-free vulnerability was discovered in Adobe Flash Player before 28.0.0.161. This vulnerability occurs due to
93RISCO
abrir
Exploit-DB
Yeager CMS 1.2.1 - Multiple Vulnerabilities
CVE-2015-7568webappsphp10 fev 2016
SQL injection vulnerability in the password recovery feature in Yeager CMS 1.2.1 allows remote attackers to change the a
23RISCO
abrir
Exploit-DB
Yeager CMS 1.2.1 - Multiple Vulnerabilities
CVE-2015-7572webappsphp10 fev 2016
20RISCO
abrir
Exploit-DB
Yeager CMS 1.2.1 - Multiple Vulnerabilities
CVE-2015-7569webappsphp10 fev 2016
SQL injection vulnerability in "yeager/y.php/tab_USERLIST" in Yeager CMS 1.2.1 allows local users to execute arbitrary S
23RISCO
abrir
Exploit-DBVexDay Proof
Apache Sling Framework (Adobe AEM) 2.3.6 - Information Disclosure
CVE-2016-0956webappsmultiple10 fev 2016
The Servlets Post component 2.3.6 in Apache Sling, as used in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0, allows r
35RISCO
abrir
Exploit-DB
Yeager CMS 1.2.1 - Multiple Vulnerabilities
CVE-2015-7567webappsphp10 fev 2016
SQL injection vulnerability in Yeager CMS 1.2.1 allows remote attackers to execute arbitrary SQL commands via the "passw
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 7 SP1 (x86) - 'WebDAV' Local Privilege Escalation (MS16-016) (1)
CVE-2016-0051localwindows_x8610 fev 2016
The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Window
43RISCO
abrir
Exploit-DB
Yeager CMS 1.2.1 - Multiple Vulnerabilities
CVE-2015-7571webappsphp10 fev 2016
Unrestricted file upload vulnerability in Yeager CMS 1.2.1 allows remote attackers to execute arbitrary code by uploadin
23RISCO
abrir
Exploit-DB
Yeager CMS 1.2.1 - Multiple Vulnerabilities
CVE-2015-7570webappsphp10 fev 2016
Multiple server-side request forgery (SSRF) vulnerabilities in Yeager CMS 1.2.1 allow remote attackers to trigger outbou
23RISCO
abrir
Exploit-DBVexDay Proof
Adobe Photoshop CC / Bridge CC - '.png' Parsing Memory Corruption (1)
CVE-2016-0951doswindows09 fev 2016
Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to exec
28RISCO
abrir
Exploit-DBVexDay Proof
Adobe Photoshop CC / Bridge CC - '.png' Parsing Memory Corruption (2)
CVE-2016-0952doswindows09 fev 2016
Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to exec
28RISCO
abrir
Exploit-DBVexDay Proof
Adobe Photoshop CC / Bridge CC - '.iff' Parsing Memory Corruption
CVE-2016-0953doswindows09 fev 2016
Adobe Photoshop CC 2014 before 15.2.4, Photoshop CC 2015 before 16.1.2, and Bridge CC before 6.2 allow attackers to exec
28RISCO
abrir
Exploit-DB
D-Link DVG­N5402SP - Multiple Vulnerabilities
CVE-2015-7247webappshardware04 fev 2016
D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 discloses usernames, passwords, keys, values, and
28RISCO
abrir
Exploit-DBVexDay Proof
GE Industrial Solutions UPS SNMP Adapter < 4.8 - Multiple Vulnerabilities
CVE-2016-0862webappshardware04 fev 2016
General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authentica
23RISCO
abrir
Exploit-DB
D-Link DVG­N5402SP - Multiple Vulnerabilities
CVE-2015-7246webappshardware04 fev 2016
D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 has a default password of root for the root accou
28RISCO
abrir
Exploit-DB
D-Link DVG­N5402SP - Multiple Vulnerabilities
CVE-2015-7245webappshardware04 fev 2016
Directory traversal vulnerability in D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 allows remot
50RISCO
abrir
anteriorpágina 173 / 815próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.