Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.057exploits catalogados
36.288CVEs com exploração pública
24.695testados em laboratório
19.066 exploits
Exploit-DBVexDay Proof
Microsoft Windows Media Center - '.MCL' File Processing Remote Code Execution (MS16-059)
CVE-2016-0185HIGHsob ataqueremotewindows12 mai 2016
Media Center in Microsoft Windows Vista SP2, Windows 7 SP1, and Windows 8.1 allows remote attackers to execute arbitrary
83RISCO
abrir
Exploit-DBVexDay Proof
Adobe Reader DC 15.010.20060 - Memory Corruption
CVE-2016-1077dosmultiple10 mai 2016
Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acro
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 7 - 'WebDAV' Local Privilege Escalation (MS16-016) (2)
CVE-2016-0051localwindows09 mai 2016
The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Window
43RISCO
abrir
Exploit-DBVexDay Proof
ImageMagick 6.9.3-9 / 7.0.1-0 - 'ImageTragick' Delegate Arbitrary Command Execution (Metasploit)
CVE-2016-3714HIGHsob ataquelocalmultiple09 mai 2016
The (1) EPHEMERAL, (2) HTTPS, (3) MVG, (4) MSL, (5) TEXT, (6) SHOW, (7) WIN, and (8) PLT coders in ImageMagick before 6.
100RISCO
abrir
Exploit-DBVexDay Proof
DotNetNuke 07.04.00 - Administration Authentication Bypass
CVE-2015-2794webappsasp06 mai 2016
The installation wizard in DotNetNuke (DNN) before 7.4.1 allows remote attackers to reinstall the application and gain S
60RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash - MovieClip.duplicateMovieClip Use-After-Free
CVE-2016-1011doswindows06 mai 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows
28RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash (Multiple Scripts) - Use-After-Free When Rendering Displays (2)
CVE-2016-1013doswindows06 mai 2016
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows
28RISCO
abrir
Exploit-DBVexDay Proof
Linux Kernel 4.4.x (Ubuntu 16.04) - 'double-fdput()' bpf(BPF_PROG_LOAD) Privilege Escalation
CVE-2016-4557locallinux04 mai 2016
The replace_map_fd_with_map_ptr function in kernel/bpf/verifier.c in the Linux kernel before 4.5.5 does not properly mai
43RISCO
abrir
Exploit-DBVexDay Proof
Linux Kernel (Ubuntu 16.04) - Reference Count Overflow Using BPF Maps
CVE-2016-4558doslinux04 mai 2016
The BPF subsystem in the Linux kernel before 4.5.5 mishandles reference counts, which allows local users to cause a deni
23RISCO
abrir
Exploit-DBVexDay Proof
OpenSSL - Padding Oracle in AES-NI CBC MAC Check
CVE-2016-2107dosmultiple04 mai 2016
The AES-NI implementation in OpenSSL before 1.0.1t and 1.0.2 before 1.0.2h does not consider memory allocation during a
45RISCO
abrir
Exploit-DBVexDay Proof
CMS Made Simple < 1.12.1 / < 2.1.3 - Web Server Cache Poisoning
CVE-2016-2784webappsphp04 mai 2016
CMS Made Simple 2.x before 2.1.3 and 1.x before 1.12.2, when Smarty Cache is activated, allow remote attackers to conduc
23RISCO
abrir
Exploit-DBVexDay Proof
McAfee LiveSafe 14.0 - Relocations Processing Memory Corruption
CVE-2016-4535doswindows04 mai 2016
Integer signedness error in the AV engine before DAT 8145, as used in McAfee LiveSafe 14.0, allows remote attackers to c
23RISCO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Ninja Forms 2.9.36 < 2.9.42 - File Upload (Metasploit)
CVE-2016-1209webappsmultiple04 mai 2016
The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via
50RISCO
abrir
Exploit-DBVexDay Proof
Apache Struts - Dynamic Method Invocation Remote Code Execution (Metasploit)
CVE-2016-3081remotelinux02 mai 2016
Apache Struts 2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28, when Dynamic Method Invocation is enabled, a
60RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'win32k.sys' TTF Processing EBLC / EBSC Tables Pool Corruption (MS16-039)
CVE-2016-0145doswindows28 abr 2016
The font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
35RISCO
abrir
Exploit-DBVexDay Proof
EMC ViPR SRM - Cross-Site Request Forgery
CVE-2016-0891webappsmultiple27 abr 2016
Multiple cross-site request forgery (CSRF) vulnerabilities in administrative pages in EMC ViPR SRM before 3.7 allow remo
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - CSRSS BaseSrvCheckVDM Session 0 Process Creation Privilege Escalation (MS16-048)
CVE-2016-0151HIGHsob ataqueransomwaredoswindows27 abr 2016
The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1,
83RISCO
abrir
Exploit-DBVexDay Proof
Advantech Webaccess Dashboard Viewer - Arbitrary File Upload (Metasploit)
CVE-2016-0854remotewindows26 abr 2016
Unrestricted file upload vulnerability in the uploadImageCommon function in the UploadAjaxAction script in the WebAccess
60RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 7 < 10 / 2008 < 2012 (x86/x64) - Local Privilege Escalation (MS16-032)
CVE-2016-0099HIGHsob ataqueransomwarelocalwindows25 abr 2016
The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8
98RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 7 < 10 / 2008 < 2012 R2 (x86/x64) - Local Privilege Escalation (MS16-032) (PowerShell)
CVE-2016-0099HIGHsob ataqueransomwarelocalwindows21 abr 2016
The Secondary Logon Service in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8
98RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - DrawMenuBarTemp Wild-Write (MS16-039)
CVE-2016-0143doswindows_x86-6420 abr 2016
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, W
23RISCO
abrir
Exploit-DBVexDay Proof
AirOS 6.x - Arbitrary File Upload
CVE-2015-9266CRITICALwebappscgi15 abr 2016
Ubiquiti airOS HTTP(S) unauthenticated arbitrary file upload
85RISCO
abrir
Exploit-DBVexDay Proof
Exim - 'perl_startup' Local Privilege Escalation (Metasploit)
CVE-2016-1531locallinux15 abr 2016
Exim before 4.86.2, when installed setuid root, allows local users to gain privileges via the perl_startup argument.
38RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Excel - Out-of-Bounds Read Code Execution (MS16-042)
CVE-2016-0122localwindows14 abr 2016
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Word 2016 for Mac, Office Compa
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 9/10/11 - 'CDOMStringDataList::InitFromString' Out-of-Bounds Read (MS15-112)
CVE-2015-6086remotewindows14 abr 2016
Microsoft Internet Explorer 9 through 11 allows remote attackers to obtain sensitive information from process memory via
28RISCO
abrir
Exploit-DBVexDay Proof
Oracle Application Testing Suite (ATS) 12.4.0.2.0 - Authentication Bypass / Arbitrary File Upload
CVE-2016-0491webappsjsp13 abr 2016
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12
60RISCO
abrir
Exploit-DBVexDay Proof
Oracle Application Testing Suite (ATS) 12.4.0.2.0 - Authentication Bypass / Arbitrary File Upload
CVE-2016-0492webappsjsp13 abr 2016
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12
60RISCO
abrir
Exploit-DBVexDay Proof
Google Android - IOMX 'getConfig'/'getParameter' Information Disclosure
CVE-2016-2417dosandroid11 abr 2016
media/libmedia/IOMX.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x befo
23RISCO
abrir
Exploit-DBVexDay Proof
Google Android - IMemory Native Interface is Insecure for IPC Use
CVE-2016-0846dosandroid11 abr 2016
libs/binder/IMemory.cpp in the IMemory Native Interface in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.
23RISCO
abrir
Exploit-DBVexDay Proof
ExaGrid - Known SSH Key and Default Password (Metasploit)
CVE-2016-1561remotelinux07 abr 2016
ExaGrid appliances with firmware before 4.8 P26 have a default SSH public key in the authorized_keys file for root, whic
60RISCO
abrir
anteriorpágina 61 / 636próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.