Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.057exploits catalogados
36.288CVEs com exploração pública
24.695testados em laboratório
19.066 exploits
Exploit-DBVexDay Proof
F5 iControl - 'iCall::Script' Root Command Execution (Metasploit)
CVE-2015-3628remotehardware19 nov 2015
The iControl API in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.0 before 11.5.3 HF2 and 11.6.
50RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'win32k.sys' Malformed TrueType Program TTF Font Processing Pool-Based Buffer Overflow (MS15-115)
CVE-2015-6104doswindows16 nov 2015
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Kernel - 'win32k.sys' Malformed OS/2 Table TTF Font Processing Pool-Based Buffer Overflow (MS15-115)
CVE-2015-6103doswindows16 nov 2015
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
35RISCO
abrir
Exploit-DBVexDay Proof
vBulletin 5.1.x - Remote Code Execution
CVE-2015-7808webappsphp05 nov 2015
The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PH
60RISCO
abrir
Exploit-DBVexDay Proof
Samsung Galaxy S6 - libQjpeg DoIntegralUpsample Crash
CVE-2015-7896dosandroid03 nov 2015
LibQJpeg in the Samsung Galaxy S6 before the October 2015 MR allows remote attackers to cause a denial of service (memor
23RISCO
abrir
Exploit-DBVexDay Proof
Samsung - libQjpeg Image Decoding Memory Corruption
CVE-2015-7894dosandroid03 nov 2015
The DCMProvider service in Samsung LibQjpeg on a Samsung SM-G925V device running build number LRX22G.G925VVRU1AOE2 allow
23RISCO
abrir
Exploit-DBVexDay Proof
Samsung Galaxy S6 Samsung Gallery - GIF Parsing Crash
CVE-2015-7898dosandroid03 nov 2015
Samsung Gallery in the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).
23RISCO
abrir
Exploit-DBVexDay Proof
Samsung Galaxy S6 Samsung Gallery - Bitmap Decoding Crash
CVE-2015-7895dosandroid03 nov 2015
Samsung Gallery on the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).
23RISCO
abrir
Exploit-DBVexDay Proof
Samsung Galaxy S6 - android.media.process Face Recognition Memory Corruption
CVE-2015-7897dosandroid03 nov 2015
The media scanning functionality in the face recognition library in android.media.process in Samsung Galaxy S6 Edge befo
23RISCO
abrir
Exploit-DBVexDay Proof
Symantec pcAnywhere 12.5.0 (Windows x86) - Remote Code Execution
CVE-2011-3478remotewindows_x8602 nov 2015
The host-services component in Symantec pcAnywhere 12.5.x through 12.5.3, and IT Management Suite pcAnywhere Solution 7.
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - NtCreateLowBoxToken Handle Capture Local Denial of Service / Privilege Escalation (MS15-111)
CVE-2015-2554doswindows30 out 2015
The kernel in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10
23RISCO
abrir
Exploit-DBVexDay Proof
Samsung - 'seiren' Kernel Driver Buffer Overflow
CVE-2015-7890dosandroid28 out 2015
Multiple buffer overflows in the esa_write function in /dev/seirenin the Exynos Seiren Audio driver, as used in Samsung
23RISCO
abrir
Exploit-DBVexDay Proof
Samsung - SecEmailComposer QUICK_REPLY_BACKGROUND Permissions
CVE-2015-7889dosandroid28 out 2015
The SecEmailComposer/EmailComposer application in the Samsung S6 Edge before the October 2015 MR uses weak permissions f
23RISCO
abrir
Exploit-DBVexDay Proof
Samsung - 'm2m1shot' Kernel Driver Buffer Overflow
CVE-2015-7892dosandroid28 out 2015
Stack-based buffer overflow in the m2m1shot_compat_ioctl32 function in the Samsung m2m1shot driver framework, as used in
23RISCO
abrir
Exploit-DBVexDay Proof
Samsung SecEmailUI - Script Injection
CVE-2015-7893remoteandroid28 out 2015
SecEmailUI in Samsung Galaxy S6 does not sanitize HTML email content, allows remote attackers to execute arbitrary JavaS
23RISCO
abrir
Exploit-DBVexDay Proof
JIRA and HipChat for JIRA Plugin - Velocity Template Injection
CVE-2015-5603webappsjava28 out 2015
The HipChat for JIRA plugin before 6.30.0 for Atlassian JIRA allows remote authenticated users to execute arbitrary Java
50RISCO
abrir
Exploit-DBVexDay Proof
Samsung fimg2d - FIMG2D_BITBLT_BLIT ioctl Concurrency Flaw
CVE-2015-7891dosandroid28 out 2015
Race condition in the ioctl implementation in the Samsung Graphics 2D driver (aka /dev/fimg2d) in Samsung devices with A
23RISCO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX 10.9.5/10.10.5 - 'rsh/libmalloc' Local Privilege Escalation (Metasploit)
CVE-2015-5889localosx27 out 2015
rsh in the remote_cmds component in Apple OS X before 10.11 allows local users to obtain root privileges via vectors inv
38RISCO
abrir
Exploit-DBVexDay Proof
Apple Safari - User-Assisted Applescript Exec Attack (Metasploit)
CVE-2015-7007remoteosx26 out 2015
Script Editor in Apple OS X before 10.11.1 allows remote attackers to bypass an intended user-confirmation requirement f
50RISCO
abrir
Exploit-DBVexDay Proof
Joomla! Component Realtyna RPL 8.9.2 - Multiple SQL Injections
CVE-2015-7714webappsphp23 out 2015
Multiple SQL injection vulnerabilities in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allow remote adm
23RISCO
abrir
Exploit-DBVexDay Proof
Joomla! Component Realtyna RPL 8.9.2 - Persistent Cross-Site Scripting / Cross-Site Request Forgery
CVE-2015-7715webappsphp23 out 2015
Cross-site request forgery (CSRF) vulnerability in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allows
23RISCO
abrir
Exploit-DBVexDay Proof
The World Browser 3.0 Final - Remote Code Execution
CVE-2014-6332HIGHsob ataqueremotewindows22 out 2015
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RISCO
abrir
Exploit-DBVexDay Proof
Zpanel - Remote Code Execution (Metasploit)
CVE-2013-2097remotephp21 out 2015
ZPanel through 10.1.0 has Remote Command Execution
43RISCO
abrir
Exploit-DBVexDay Proof
HTML Compiler - Remote Code Execution
CVE-2014-6332HIGHsob ataqueremotewindows20 out 2015
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash - 'IExternalizable.writeExternal' Type Confusion
CVE-2015-7645HIGHsob ataqueransomwaredosmultiple19 out 2015
Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535
83RISCO
abrir
Exploit-DBVexDay Proof
Nibbleblog 4.0.3 - Arbitrary File Upload (Metasploit)
CVE-2015-6967remotephp19 out 2015
Unrestricted file upload vulnerability in the My Image plugin in Nibbleblog before 4.0.5 allows remote administrators to
50RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 10 - Sandboxed Mount Reparse Point Creation Mitigation Bypass (MS15-111)
CVE-2015-2553localwindows15 out 2015
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
23RISCO
abrir
Exploit-DBVexDay Proof
TrueCrypt 7 / VeraCrypt 1.13 - Drive Letter Symbolic Link Creation Privilege Escalation
CVE-2015-7358localwindows_x8605 out 2015
The IsDriveLetterAvailable method in Driver/Ntdriver.c in TrueCrypt 7.0, VeraCrypt before 1.15, and CipherShed, when run
23RISCO
abrir
Exploit-DBVexDay Proof
Kaseya Virtual System Administrator (VSA) - 'uploader.aspx' Arbitrary File Upload (Metasploit)
CVE-2015-6922remotewindows05 out 2015
Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.33, 8.x before 8.0.0.23, 9.0 before 9.0.0.19, and 9.1 before
60RISCO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX 10.9.5/10.10.5 - 'rsh/libmalloc' Local Privilege Escalation
CVE-2015-5889localosx01 out 2015
rsh in the remote_cmds component in Apple OS X before 10.11 allows local users to obtain root privileges via vectors inv
38RISCO
abrir
anteriorpágina 68 / 636próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.