Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.414exploits catalogados
34.907CVEs com exploração pública
24.695testados em laboratório
8.484 exploits
VulnCheck XDB
initial-access
CVE-2014-0160HIGHsob ataque30 mar 2016
The (1) TLS and (2) DTLS implementations in OpenSSL 1.0.1 before 1.0.1g do not properly handle Heartbeat Extension packe
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2014-163530 mar 2016
Buffer overflow in login.cgi in MiniHttpd in Belkin N750 Router with firmware before F9K1103_WW_1.10.17m allows remote a
50RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-822530 mar 2016
On Wireless IP Camera (P2P) WIFICAM devices, access to .ini files (containing credentials) is not correctly checked. An
28RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-14847CRITICALsob ataque30 mar 2016
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2001-053730 mar 2016
HTTP server for Cisco IOS 11.3 to 12.2 allows attackers to bypass authentication and execute arbitrary commands, when lo
50RISCO
abrir
VulnCheck XDB
initial-access
CVE-2016-20016CRITICAL30 mar 2016
MVPower CCTV DVR models, including TV-7104HE 1.8.4 115215B9 and TV7108HE, contain a web shell that is accessible via a /
85RISCO
abrir
VulnCheck XDB
initial-access
CVE-2018-999530 mar 2016
TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR L
60RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2014-6271CRITICALsob ataque30 mar 2016
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2014-6278HIGHsob ataque30 mar 2016
GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, whi
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-18368CRITICALsob ataque30 mar 2016
The ZyXEL P660HN-T1A v1 TCLinux Fw $7.3.15.0 v001 / 3.40(ULM.0)b31 router distributed by TrueOnline has a command inject
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2017-757730 mar 2016
XiongMai uc-httpd has directory traversal allowing the reading of arbitrary files via a "GET ../" HTTP request.
28RISCO
abrir
VulnCheck XDB
initial-access
CVE-2011-331530 mar 2016
Directory traversal vulnerability in Cisco Unified Communications Manager (CUCM) 5.x and 6.x before 6.1(5)SU2, 7.x befor
43RISCO
abrir
VulnCheck XDB
local
CVE-2016-072815 mar 2016
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RISCO
abrir
VulnCheck XDB
initial-access
CVE-2015-754710 mar 2016
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RISCO
abrir
VulnCheck XDB
initial-access
CVE-2015-4852CRITICALsob ataque03 mar 2016
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers
100RISCO
abrir
VulnCheck XDB
local
CVE-2016-0040HIGHsob ataque26 fev 2016
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows local users to g
91RISCO
abrir
VulnCheck XDB
initial-access
CVE-2015-754721 fev 2016
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2015-754710 fev 2016
Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C
45RISCO
abrir
VulnCheck XDB
local
CVE-2016-005109 fev 2016
The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Window
43RISCO
abrir
VulnCheck XDB
initial-access
CVE-2015-856208 fev 2016
Joomla! 1.5.x, 2.x, and 3.x before 3.4.6 allow remote attackers to conduct PHP object injection attacks and execute arbi
60RISCO
abrir
VulnCheck XDB
local
CVE-2014-4113HIGHsob ataque07 fev 2016
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
100RISCO
abrir
VulnCheck XDB
infoleak
CVE-2015-157903 fev 2016
Directory traversal vulnerability in the Elegant Themes Divi theme for WordPress allows remote attackers to read arbitra
43RISCO
abrir
VulnCheck XDB
denial-of-service
CVE-2016-072828 jan 2016
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RISCO
abrir
VulnCheck XDB
info-leak
CVE-2016-072823 jan 2016
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RISCO
abrir
VulnCheck XDB
initial-access
CVE-2016-072822 jan 2016
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RISCO
abrir
VulnCheck XDB
local
CVE-2014-4113HIGHsob ataque22 jan 2016
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 a
100RISCO
abrir
VulnCheck XDB
info-leak
CVE-2016-072820 jan 2016
The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object ref
23RISCO
abrir
VulnCheck XDB
remote-with-credentials
CVE-2015-7755CRITICALsob ataque09 jan 2016
Juniper ScreenOS 6.2.0r15 through 6.2.0r18, 6.3.0r12 before 6.3.0r12b, 6.3.0r13 before 6.3.0r13b, 6.3.0r14 before 6.3.0r
100RISCO
abrir
VulnCheck XDB
initial-access
CVE-2014-3153HIGHsob ataque08 nov 2015
The futex_requeue function in kernel/futex.c in the Linux kernel through 3.14.5 does not ensure that calls have two diff
98RISCO
abrir
VulnCheck XDB
initial-access
CVE-2015-780806 nov 2015
The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PH
60RISCO
abrir
anteriorpágina 280 / 283próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.