Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.107exploits catalogados
36.322CVEs com exploração pública
24.695testados em laboratório
19.066 exploits
Exploit-DBVexDay Proof
Abrt (Fedora 21) - Race Condition
CVE-2015-1862locallinux14 abr 2015
The crash reporting feature in Abrt allows local users to gain privileges by leveraging an execve by root after a chroot
23RISCO
abrir
Exploit-DBVexDay Proof
Apport/Abrt (Ubuntu / Fedora) - Local Privilege Escalation
CVE-2015-1862locallinux14 abr 2015
The crash reporting feature in Abrt allows local users to gain privileges by leveraging an execve by root after a chroot
23RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player - casi32 Integer Overflow (Metasploit)
CVE-2014-0569remotewindows13 abr 2015
Integer overflow in Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and bef
60RISCO
abrir
Exploit-DBVexDay Proof
ProFTPd 1.3.5 - File Copy
CVE-2015-3306remotelinux13 abr 2015
The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and
60RISCO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX - 'Rootpipe' Local Privilege Escalation (Metasploit)
CVE-2015-1130HIGHsob ataquelocalosx13 abr 2015
The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and o
86RISCO
abrir
Exploit-DBVexDay Proof
Lenovo System Update - Local Privilege Escalation (Metasploit)
CVE-2015-2219localwindows12 abr 2015
Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses predictable security tokens, which allo
38RISCO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX < 10.7.5/10.8.2/10.9.5/10.10.2 - 'Rootpipe' Local Privilege Escalation
CVE-2015-1130HIGHsob ataquelocalosx09 abr 2015
The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and o
86RISCO
abrir
Exploit-DBVexDay Proof
Novell ZENworks Configuration Management 11.3.1 - Remote Code Execution
CVE-2015-0779webappsjsp08 abr 2015
Directory traversal vulnerability in UploadServlet in Novell ZENworks Configuration Management (ZCM) 10 and 11 before 11
60RISCO
abrir
Exploit-DBVexDay Proof
SolarWinds Firewall Security Manager 6.6.5 - Client Session Handling (Metasploit)
CVE-2015-2284remotewindows08 abr 2015
userlogin.jsp in SolarWinds Firewall Security Manager (FSM) before 6.6.5 HotFix1 allows remote attackers to gain privile
60RISCO
abrir
Exploit-DBVexDay Proof
JBoss Seam 2 - Arbitrary File Upload / Execution (Metasploit)
CVE-2010-1871HIGHsob ataqueremotejsp06 abr 2015
JBoss Seam 2 (jboss-seam2), as used in JBoss Enterprise Application Platform 4.3.0 for Red Hat Linux, does not properly
100RISCO
abrir
Exploit-DBVexDay Proof
WebGate eDVR Manager 2.6.4 - Connect Method Stack Buffer Overflow
CVE-2015-2097remotewindows02 abr 2015
Multiple buffer overflows in WebGate Embedded Standard Protocol (WESP) SDK allow remote attackers to execute arbitrary c
28RISCO
abrir
Exploit-DBVexDay Proof
WordPress Plugin Simple Ads Manager - Multiple SQL Injections
CVE-2015-2824webappsphp02 abr 2015
Multiple SQL injection vulnerabilities in the Simple Ads Manager plugin before 2.7.97 for WordPress allow remote attacke
23RISCO
abrir
Exploit-DBVexDay Proof
WebGate eDVR Manager 2.6.4 - AudioOnlySiteChannel Stack Buffer Overflow
CVE-2015-2098remotewindows02 abr 2015
Multiple stack-based buffer overflows in WebGate eDVR Manager allow remote attackers to execute arbitrary code via unspe
28RISCO
abrir
Exploit-DBVexDay Proof
WebGate eDVR Manager 2.6.4 - SiteChannel Property Stack Buffer Overflow
CVE-2015-2098remotewindows02 abr 2015
Multiple stack-based buffer overflows in WebGate eDVR Manager allow remote attackers to execute arbitrary code via unspe
28RISCO
abrir
Exploit-DBVexDay Proof
Ceragon FibeAir IP-10 - SSH Private Key Exposure (Metasploit)
CVE-2015-0936remotelinux01 abr 2015
Ceragon FibeAir IP-10 have a default SSH public key in the authorized_keys file for the mateidu user, which allows remot
60RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player - ByteArray With Workers Use-After-Free (Metasploit)
CVE-2015-0313HIGHsob ataqueremotewindows31 mar 2015
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows
100RISCO
abrir
Exploit-DBVexDay Proof
Acunetix 9.5 - OLE Automation Array Remote Code Execution
CVE-2014-6332HIGHsob ataqueremotewindows27 mar 2015
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RISCO
abrir
Exploit-DBVexDay Proof
Mozilla Firefox - Proxy Prototype Privileged JavaScript Injection (Metasploit)
CVE-2014-8636remotemultiple24 mar 2015
The XrayWrapper implementation in Mozilla Firefox before 35.0 and SeaMonkey before 2.32 does not properly interact with
50RISCO
abrir
Exploit-DBVexDay Proof
Free MP3 CD Ripper 2.6 - '.wav' Local Buffer Overflow
CVE-2011-5165localwindows22 mar 2015
Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted rem
50RISCO
abrir
Exploit-DBVexDay Proof
Publish-It - '.PUI' Local Buffer Overflow (SEH) (Metasploit)
CVE-2014-0980localwindows19 mar 2015
Buffer overflow in Poster Software PUBLISH-iT 3.6d allows remote attackers to execute arbitrary code via a crafted PUI f
50RISCO
abrir
Exploit-DBVexDay Proof
TWiki Debugenableplugins - Remote Code Execution (Metasploit)
CVE-2014-7236remotephp19 mar 2015
Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary
50RISCO
abrir
Exploit-DBVexDay Proof
Exim - 'GHOST' glibc gethostbyname Buffer Overflow (Metasploit)
CVE-2015-0235remotelinux18 mar 2015
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18,
60RISCO
abrir
Exploit-DBVexDay Proof
Fortinet Single Sign On - Stack Overflow
CVE-2015-2281doswindows18 mar 2015
Stack-based buffer overflow in collectoragent.exe in Fortinet Single Sign On (FSSO) before build 164 allows remote attac
28RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player - PCRE Regex (Metasploit)
CVE-2015-0318remotewindows17 mar 2015
Adobe Flash Player before 13.0.0.269 and 14.x through 16.x before 16.0.0.305 on Windows and OS X and before 11.2.202.442
60RISCO
abrir
Exploit-DBVexDay Proof
ElasticSearch - Search Groovy Sandbox Bypass (Metasploit)
CVE-2015-1427CRITICALsob ataqueremotejava16 mar 2015
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the s
100RISCO
abrir
Exploit-DBVexDay Proof
WordPress Plugin SEO by Yoast 1.7.3.3 - Blind SQL Injection
CVE-2015-2292webappsphp16 mar 2015
Multiple SQL injection vulnerabilities in admin/class-bulk-editor-list-table.php in the WordPress SEO by Yoast plugin be
23RISCO
abrir
Exploit-DBVexDay Proof
IPass Control Pipe - Remote Command Execution (Metasploit)
CVE-2015-0925remotewindows16 mar 2015
The client in iPass Open Mobile before 2.4.5 on Windows allows remote authenticated users to execute arbitrary code via
50RISCO
abrir
Exploit-DBVexDay Proof
Adobe Flash Player - ByteArray UncompressViaZlibVariant Use-After-Free (Metasploit)
CVE-2015-0311HIGHsob ataqueremotewindows12 mar 2015
Unspecified vulnerability in Adobe Flash Player through 13.0.0.262 and 14.x, 15.x, and 16.x through 16.0.0.287 on Window
100RISCO
abrir
Exploit-DBVexDay Proof
ElasticSearch - Remote Code Execution
CVE-2015-1427CRITICALsob ataqueremotelinux11 mar 2015
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the s
100RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Text Services Memory Corruption (MS15-020)
CVE-2015-0081doswindows11 mar 2015
Windows Text Services (WTS) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,
28RISCO
abrir
anteriorpágina 76 / 636próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.