Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.449exploits catalogados
35.552CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.451Referência 22.367GitHub PoC 14.225VulnCheck XDB 8.649Nuclei 4.283Metasploit 3.474✓ só verificadosrecentespopularesrisco
24.451 exploits
Exploit-DB✓ VexDay Proof
Mozilla Firefox 2.0.0.2 - Document.Cookie Path Argument Denial of Service
Mozilla Firefox 1.5.x before 1.5.0.12 and 2.x before 2.0.0.4, and SeaMonkey 1.0.9 and 1.1.2, allows remote attackers to
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
FiSH-irssi - Multiple Remote Buffer Overflow Vulnerabilities
Multiple stack-based buffer overflows in the (1) ExtractRnick and (2) decrypt_topic_332 functions in FiSH allow remote a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe Reader Plugin 'AcroPDF.dll' 8.0.0.0 - Resource Consumption
AcroPDF.DLL in Adobe Reader 8.0, when accessed from Mozilla Firefox, Netscape, or Opera, allows remote attackers to caus
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Rediff Toolbar - ActiveX Control Remote Denial of Service
The Rediff Toolbar 2.0 ActiveX control in redifftoolbar.dll allows remote attackers to cause a denial of service via uns
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
mod_security 2.1.0 - ASCIIZ byte POST Rules Bypass
Interpretation conflict in ModSecurity (mod_security) 2.1.0 and earlier allows remote attackers to bypass request rules
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
radscan conquest 8.2 - Multiple Vulnerabilities
Multiple buffer overflows in Conquest 8.2a and earlier (1) allow local users to gain privileges by querying a metaserver
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Firebug 1.03 - Rep.JS Script Code Injection
Cross-zone scripting vulnerability in the DOM templates (domplates) used by the console.log function in the Firebug exte
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Mercury/32 Mail Server 4.01b - 'check' Buffer Overflow (PoC)
Stack-based buffer overflow in Mercury/32 (aka Mercury Mail Transport System) 4.01b and earlier allows remote attackers
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Silc Server 1.0.2 - New Channel Remote Denial of Service
The SILC_SERVER_CMD_FUNC function in apps/silcd/command.c in silc-server 1.0.2 allows remote attackers to cause a denial
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WinZip 10.0.7245 - FileView ActiveX Buffer Overflow (2)
Stack-based buffer overflow in the Sky Software FileView ActiveX control, as used in WinZip 10 before build 7245 and in
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
EPortfolio 1.0 - Client-Side Input Validation
Multiple cross-site scripting (XSS) vulnerabilities in TKS Banking Solutions ePortfolio 1.0 Java allow remote attackers
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Gnome Evolution 2.x - GnuPG Arbitrary Content Injection
Evolution 2.8.1 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Evolution
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
KMail 1.x - GnuPG Arbitrary Content Injection
Enigmail 0.94.2 and earlier does not properly use the --status-fd argument when invoking GnuPG, which prevents Enigmail
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
GnuPG 1.x - Signed Message Arbitrary Content Injection
GnuPG 1.4.6 and earlier and GPGME before 1.1.4, when run from the command line, does not visually distinguish signed and
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 4.4.6 - 'mssql_[p]connect()' Local Buffer Overflow
Buffer overflow in PHP 4.4.6 and earlier, and unspecified PHP 5 versions, allows local and possibly remote attackers to
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
KDE Konqueror 3.5 - JavaScript IFrame Denial of Service
ecma/kjs_html.cpp in KDE JavaScript (KJS), as used in Konqueror in KDE 3.5.5, allows remote attackers to cause a denial
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
KDE Konqueror 3.5.7 - Assert Denial of Service
Unspecified vulnerability in KDE Konqueror 3.5.7 and earlier allows remote attackers to cause a denial of service (faile
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 4.4.3 < 4.4.6 - 'PHPinfo()' Cross-Site Scripting
A regression error in the phpinfo function in PHP 4.4.3 to 4.4.6, and PHP 6.0 in CVS, allows remote attackers to conduct
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Asterisk 1.2.15/1.4.0 - Remote Denial of Service
Asterisk 1.4 before 1.4.1 and 1.2 before 1.2.16 allows remote attackers to cause a denial of service (crash) by sending
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
RRDBrowse 1.6 - Arbitrary File Disclosure
Directory traversal vulnerability in rb.cgi in RRDBrowse 1.6 and earlier allows remote attackers to read arbitrary files
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP < 4.4.5/5.2.1 - WDDX Session Deserialization Information Leak
The WDDX deserializer in the wddx extension in PHP 5 before 5.2.1 and PHP 4 before 4.4.5 does not properly initialize th
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 5 - 'wddx_deserialize()' String Append Crash
The wddx_deserialize function in wddx.c 1.119.2.10.2.12 and 1.119.2.10.2.13 in PHP 5, as modified in CVS on 20070224 and
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Zend Platform 2.2.1 - 'PHP.INI' File Modification
ini_modifier (sgid-zendtech) in Zend Platform 2.2.3 and earlier allows local users to modify the system php.ini file by
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 4.4.4 - 'Unserialize()' ZVAL Reference Counter Overflow (PoC)
Integer overflow in PHP 4.4.4 and earlier allows remote context-dependent attackers to execute arbitrary code via a long
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Netrek 2.12.0 - 'pmessage2()' Remote Limited Format String
Format string vulnerability in the new_warning function in ntserv/warning.c for Netrek Vanilla Server 2.12.0, when EVENT
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Core 2.1.1 - '/wp-includes/theme.php?iz' Arbitrary Command Execution
WordPress 2.1.1, as downloaded from some official distribution sites during February and March 2007, contains an externa
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WordPress Core 2.1.1 - Arbitrary Command Execution
WordPress 2.1.1, as downloaded from some official distribution sites during February and March 2007, contains an externa
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 4 - Userland ZVAL Reference Counter Overflow (PoC)
Integer overflow in the 16 bit variable reference counter in PHP 4 allows context-dependent attackers to execute arbitra
53RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Built2go News Manager 1.0 Blog - 'rating.php?nid' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in built2go News Manager Blog 1.0 allow remote attackers to inject a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Built2go News Manager 1.0 Blog - 'news.php' Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in built2go News Manager Blog 1.0 allow remote attackers to inject a
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.