Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.526exploits catalogados
34.478CVEs com exploração pública
24.695testados em laboratório
24.443 exploits
Exploit-DBVexDay Proof
Apple Mac OSX / iOS Kernel - iokit Registry Iterator Manipulation Double-Free
CVE-2015-7084dosmultiple28 jan 2016
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to g
23RISCO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX Kernel - no-more-senders Use-After-Free
CVE-2015-7047dososx28 jan 2016
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to g
23RISCO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX / iOS - Unsandboxable Kernel Use-After-Free in Mach Vouchers
CVE-2015-7047dosmultiple28 jan 2016
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to g
23RISCO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX Kernel - IOAccelMemoryInfoUserClient Use-After-Free
CVE-2015-7047dososx28 jan 2016
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to g
23RISCO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX Kernel - IOAccelDisplayPipeUserClient2 Use-After-Free
CVE-2015-7047dososx28 jan 2016
The kernel in Apple iOS before 9.2, OS X before 10.11.2, tvOS before 9.1, and watchOS before 2.1 allows local users to g
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Sandboxed Mount Reparse Point Creation Mitigation Bypass Redux (MS16-008) (1)
CVE-2016-0007localwindows25 jan 2016
The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8,
23RISCO
abrir
Exploit-DB
FreeBSD SCTP ICMPv6 - Error Processing
CVE-2016-1879dosfreebsd25 jan 2016
The Stream Control Transmission Protocol (SCTP) module in FreeBSD 9.3 before p33, 10.1 before p26, and 10.2 before p9, w
28RISCO
abrir
Exploit-DB
Linux Kernel 3.x/4.x - prima WLAN Driver Heap Overflow
CVE-2015-0569doslinux25 jan 2016
Heap-based buffer overflow in the private wireless extensions IOCTL implementation in wlan_hdd_wext.c in the WLAN (aka W
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Sandboxed Mount Reparse Point Creation Mitigation Bypass Redux (MS16-008) (2)
CVE-2016-0007localwindows25 jan 2016
The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8,
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Sandboxed Mount Reparse Point Creation Mitigation Bypass Redux (MS16-008) (1)
CVE-2016-0006localwindows25 jan 2016
The sandbox implementation in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8,
23RISCO
abrir
Exploit-DB
Huawei Mate 7 - '/dev/hifi_misc' Privilege Escalation
CVE-2015-8088localhardware24 jan 2016
Heap-based buffer overflow in the HIFI driver in Huawei Mate 7 phones with software MT7-UL00 before MT7-UL00C17B354, MT7
23RISCO
abrir
Exploit-DB
NTP - Local Privilege Escalation
CVE-2016-0727locallinux21 jan 2016
The crontab script in the ntp package before 1:4.2.6.p3+dfsg-1ubuntu3.11 on Ubuntu 12.04 LTS, before 1:4.2.6.p5+dfsg-3ub
23RISCO
abrir
Exploit-DBVexDay Proof
CesarFTP 0.99g - XCWD Denial of Service
CVE-2006-2961doswindows19 jan 2016
Stack-based buffer overflow in CesarFTP 0.99g and earlier allows remote attackers to cause a denial of service (applicat
50RISCO
abrir
Exploit-DB
Linux Kernel 4.4.1 - REFCOUNT Overflow Use-After-Free in Keyrings Local Privilege Escalation (1)
CVE-2016-0728locallinux19 jan 2016
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RISCO
abrir
Exploit-DB
Linux Kernel 4.4.1 - REFCOUNT Overflow Use-After-Free in Keyrings Local Privilege Escalation (2)
CVE-2016-0728locallinux19 jan 2016
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RISCO
abrir
Exploit-DB
SeaWell Networks Spectrum - Multiple Vulnerabilities
CVE-2015-8283webappsphp18 jan 2016
Directory traversal vulnerability in configure_manage.php in SeaWell Networks Spectrum SDC 02.05.00.
23RISCO
abrir
Exploit-DB
SeaWell Networks Spectrum - Multiple Vulnerabilities
CVE-2015-8284webappsphp18 jan 2016
SeaWell Networks Spectrum SDC 02.05.00 allows remote viewer users to perform administrative functions.
23RISCO
abrir
Exploit-DB
SeaWell Networks Spectrum - Multiple Vulnerabilities
CVE-2015-8282webappsphp18 jan 2016
SeaWell Networks Spectrum SDC 02.05.00 has a default password of "admin" for the "admin" account.
23RISCO
abrir
Exploit-DB
mcart.xls Bitrix Module 6.5.2 - SQL Injection
CVE-2015-8356webappsphp15 jan 2016
Multiple SQL injection vulnerabilities in the mcart.xls module 6.5.2 and earlier for Bitrix allow remote authenticated u
23RISCO
abrir
Exploit-DB
Roundcube Webmail 1.1.3 - Directory Traversal
CVE-2015-8770webappsphp15 jan 2016
Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Office / COM Object - 'WMALFXGFXDSP.dll' DLL Planting (MS16-007)
CVE-2016-0016doswindows13 jan 2016
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
35RISCO
abrir
Exploit-DB
WhatsUp Gold 16.3 - Remote Code Execution
CVE-2015-8261webappsasp13 jan 2016
The DroneDeleteOldMeasurements implementation in Ipswitch WhatsUp Gold before 16.4 does not properly validate serialized
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - devenum.dll!DeviceMoniker::Load() Heap Corruption Buffer Underflow (MS16-007)
CVE-2016-0015doswindows13 jan 2016
DirectShow in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
35RISCO
abrir
Exploit-DB
Grassroots DICOM (GDCM) 2.6.0 and 2.6.1 - ImageRegionReader::ReadIntoBuffer Buffer Overflow
CVE-2015-8396doslinux12 jan 2016
Integer overflow in the ImageRegionReader::ReadIntoBuffer function in MediaStorageAndFileFormat/gdcmImageRegionReader.cx
28RISCO
abrir
Exploit-DB
Linux Kernel 4.3.3 - 'overlayfs' Local Privilege Escalation (2)
CVE-2015-8660locallinux12 jan 2016
The ovl_setattr function in fs/overlayfs/inode.c in the Linux kernel through 4.3.3 attempts to merge distinct setattr op
43RISCO
abrir
Exploit-DBVexDay Proof
Trend Micro - node.js HTTP Server Listening on localhost Can Execute Commands
CVE-2016-3987remotewindows11 jan 2016
The HTTP server in Trend Micro Password Manager allows remote web servers to execute arbitrary commands via the url para
28RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash BlurFilter Processing - Out-of-Bounds Memset
CVE-2015-8636dosmultiple11 jan 2016
Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and OS X and before 11.2.202.559 on
28RISCO
abrir
Exploit-DBVexDay Proof
Konica Minolta FTP Utility 1.00 - CWD Command Overflow (SEH)
CVE-2015-7768remotewindows11 jan 2016
Buffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code via a long CWD comma
50RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash - Use-After-Free When Setting Stage
CVE-2015-8634doswindows_x86-6411 jan 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and
28RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash (Multiple Scripts) - Use-After-Free When Rendering Displays (1)
CVE-2015-8635doswindows11 jan 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.324 and 19.x and 20.x before 20.0.0.267 on Windows and
28RISCO
abrir
anteriorpágina 175 / 815próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.