Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.057exploits catalogados
36.288CVEs com exploração pública
24.695testados em laboratório
19.066 exploits
Exploit-DBVexDay Proof
Netgear Routers - Password Disclosure
CVE-2017-5521HIGHsob ataquewebappshardware30 jan 2017
An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R
100RISCO
abrir
Exploit-DBVexDay Proof
Apple macOS 10.12.1 / iOS Kernel - 'IOService::matchPassive' Use-After-Free
CVE-2017-2353dosmultiple26 jan 2017
An issue was discovered in certain Apple products. macOS before 10.12.3 is affected. The issue involves the "Bluetooth"
23RISCO
abrir
Exploit-DBVexDay Proof
Apple macOS 10.12.1 / iOS 10.2 - Kernel Userspace Pointer Memory Corruption
CVE-2017-2370dosmultiple26 jan 2017
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS
28RISCO
abrir
Exploit-DBVexDay Proof
Apple macOS 10.12.1 / iOS Kernel - 'host_self_trap' Use-After-Free
CVE-2017-2360dosmultiple26 jan 2017
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. macOS before 10.12.3 is affected. tvOS
23RISCO
abrir
Exploit-DBVexDay Proof
Palo Alto Networks Terminal Services Agent 7.0.3-13 - Integer Overflow
CVE-2017-5329localwindows26 jan 2017
Palo Alto Networks Terminal Services Agent before 7.0.7 allows local users to gain privileges via vectors that trigger a
23RISCO
abrir
Exploit-DBVexDay Proof
Mozilla Firefox < 50.0.2 - 'nsSMILTimeContainer::NotifyTimeChange()' Remote Code Execution (Metasploit)
CVE-2016-9079HIGHsob ataqueremotewindows24 jan 2017
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been dis
100RISCO
abrir
Exploit-DBVexDay Proof
Oracle OpenJDK Runtime Environment 1.8.0_112-b15 - Java Serialization Denial Of Service
CVE-2017-3241dosmultiple23 jan 2017
Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: RMI). Supported versi
35RISCO
abrir
Exploit-DBVexDay Proof
PageKit 1.0.10 - Password Reset
CVE-2017-5594webappsphp21 jan 2017
An issue was discovered in Pagekit CMS before 1.0.11. In this vulnerability the remote attacker is able to reset the reg
23RISCO
abrir
Exploit-DBVexDay Proof
Cisco Firepower Management Console 6.0 - Post Authentication UserAdd (Metasploit)
CVE-2016-6433remotelinux13 jan 2017
The Threat Management Console in Cisco Firepower Management Center 5.2.0 through 6.0.1 allows remote authenticated users
60RISCO
abrir
Exploit-DBVexDay Proof
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 SP2 - Multiple Vulnerabilities
CVE-2017-6339webappshardware12 jan 2017
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 mismanages certain key and certificate d
23RISCO
abrir
Exploit-DBVexDay Proof
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 SP2 - Multiple Vulnerabilities
CVE-2017-6340webappshardware12 jan 2017
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 does not sanitize a rest/commonlog/repor
23RISCO
abrir
Exploit-DBVexDay Proof
Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 SP2 - Multiple Vulnerabilities
CVE-2017-6338webappshardware12 jan 2017
Multiple Access Control issues in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 allow
23RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player 24.0.0.186 - 'ActionGetURL2' Out-of-Bounds Memory Corruption (1)
CVE-2017-2930dosmultiple11 jan 2017
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable memory corruption vulnerability due to a concurre
28RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player 24.0.0.186 - 'ActionGetURL2' Out-of-Bounds Memory Corruption (2)
CVE-2017-2930dosmultiple11 jan 2017
Adobe Flash Player versions 24.0.0.186 and earlier have an exploitable memory corruption vulnerability due to a concurre
28RISCO
abrir
Exploit-DBVexDay Proof
Atlassian Confluence < 5.10.6 - Persistent Cross-Site Scripting
CVE-2016-6283webappsjsp04 jan 2017
Cross-site scripting (XSS) vulnerability in Atlassian Confluence before 5.10.6 allows remote attackers to inject arbitra
23RISCO
abrir
Exploit-DBVexDay Proof
Google Android - get_user/put_user (Metasploit)
CVE-2013-6282HIGHsob ataquelocalandroid29 dez 2016
The (1) get_user and (2) put_user API functions in the Linux kernel before 3.5.5 on the v6k and v7 ARM platforms do not
98RISCO
abrir
Exploit-DBVexDay Proof
PHPMailer < 5.2.19 - Sendmail Argument Injection (Metasploit)
CVE-2016-1004webappsmultiple26 dez 2016
20RISCO
abrir
Exploit-DBVexDay Proof
Wampserver 3.0.6 - Insecure File Permissions Privilege Escalation
CVE-2016-10031localwindows26 dez 2016
WampServer 3.0.6 installs two services called 'wampapache' and 'wampmysqld' with weak file permissions, running with SYS
23RISCO
abrir
Exploit-DBVexDay Proof
Shutter 0.93.1 - Code Execution
CVE-2016-10081locallinux26 dez 2016
/usr/bin/shutter in Shutter through 0.93.1 allows user-assisted remote attackers to execute arbitrary commands via a cra
23RISCO
abrir
Exploit-DBVexDay Proof
PHPMailer < 5.2.19 - Sendmail Argument Injection (Metasploit)
CVE-2016-1003webappsmultiple26 dez 2016
20RISCO
abrir
Exploit-DBVexDay Proof
PHPMailer < 5.2.18 - Remote Code Execution
CVE-2016-10033CRITICALsob ataquewebappsphp26 dez 2016
The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra para
100RISCO
abrir
Exploit-DBVexDay Proof
OpenSSH < 7.4 - agent Protocol Arbitrary Library Loading
CVE-2016-10009HIGHremotelinux23 dez 2016
Untrusted search path vulnerability in ssh-agent.c in ssh-agent in OpenSSH before 7.4 allows remote attackers to execute
53RISCO
abrir
Exploit-DBVexDay Proof
OpenSSH < 7.4 - 'UsePrivilegeSeparation Disabled' Forwarded Unix Domain Sockets Privilege Escalation
CVE-2016-10010HIGHlocallinux23 dez 2016
sshd in OpenSSH before 7.4, when privilege separation is not used, creates forwarded Unix-domain sockets as root, which
41RISCO
abrir
Exploit-DBVexDay Proof
Apple macOS < 10.12.2 / iOS < 10.2 - Broken Kernel Mach Port Name uref Handling Privileged Port Name Replacement Privilege Escalation
CVE-2016-7637localmacos22 dez 2016
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchO
23RISCO
abrir
Exploit-DBVexDay Proof
Apple macOS < 10.12.2 / iOS < 10.2 - '_kernelrpc_mach_port_insert_right_trap' Kernel Reference Count Leak / Use-After-Free
CVE-2016-7621localmacos22 dez 2016
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchO
23RISCO
abrir
Exploit-DBVexDay Proof
Apple macOS 10.12.1 / iOS < 10.2 - powerd Arbitrary Port Replacement
CVE-2016-7661dosmultiple22 dez 2016
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. The is
23RISCO
abrir
Exploit-DBVexDay Proof
Apple macOS < 10.12.2 / iOS < 10.2 Kernel - ipc_port_t Reference Count Leak Due to Incorrect externalMethod Overrides Use-After-Free
CVE-2016-7612dosmultiple22 dez 2016
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchO
23RISCO
abrir
Exploit-DBVexDay Proof
Apple macOS 10.12.1 Kernel - Writable Privileged IOKit Registry Properties Code Execution
CVE-2016-7617dosmacos22 dez 2016
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Bluetooth"
23RISCO
abrir
Exploit-DBVexDay Proof
Apple macOS 10.12.1 / iOS < 10.2 - syslogd Arbitrary Port Replacement
CVE-2016-7660dosmultiple22 dez 2016
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchO
23RISCO
abrir
Exploit-DBVexDay Proof
Apple macOS 10.12 - Double vm_deallocate in Userspace MIG Code Use-After-Free
CVE-2016-7633dosmacos22 dez 2016
An issue was discovered in certain Apple products. macOS before 10.12.2 is affected. The issue involves the "Directory S
23RISCO
abrir
anteriorpágina 51 / 636próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.