Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.813exploits catalogados
35.788CVEs com exploração pública
24.695testados em laboratório
24.455 exploits
Exploit-DBVexDay Proof
GNU Mailutils imap4d 0.6 - 'Search' Remote Format String
CVE-2005-2878remotelinux10 set 2005
Format string vulnerability in search.c in the imap4d server in GNU Mailutils 0.6 allows remote authenticated users to e
28RISCO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.6.x - SCSI ProcFS Denial of Service
CVE-2005-2800doslinux09 set 2005
Memory leak in the seq_file implementation in the SCSI procfs interface (sg.c) in Linux kernel 2.6.13 and earlier allows
23RISCO
abrir
Exploit-DBVexDay Proof
Zebedee 2.4.1 - Remote Denial of Service
CVE-2005-2904doslinux09 set 2005
Zebedee 2.4.1, when "allowed redirection port" is not set, allows remote attackers to cause a denial of service (applica
23RISCO
abrir
Exploit-DBVexDay Proof
Stylemotion WEB//NEWS 1.4 - 'startup.php' Cookie SQL Injection
CVE-2005-2896webappsphp08 set 2005
SQL injection vulnerability in WEB//NEWS 1.4 allows remote attackers to execute arbitrary SQL commands via the (1) wn_us
23RISCO
abrir
Exploit-DBVexDay Proof
Stylemotion WEB//NEWS 1.4 - 'print.php?id' SQL Injection
CVE-2005-2896webappsphp08 set 2005
SQL injection vulnerability in WEB//NEWS 1.4 allows remote attackers to execute arbitrary SQL commands via the (1) wn_us
23RISCO
abrir
Exploit-DBVexDay Proof
Stylemotion WEB//NEWS 1.4 - 'news.php' Multiple SQL Injections
CVE-2005-2896webappsphp08 set 2005
SQL injection vulnerability in WEB//NEWS 1.4 allows remote attackers to execute arbitrary SQL commands via the (1) wn_us
23RISCO
abrir
Exploit-DBVexDay Proof
PBLang 4.65 Bulletin Board System - 'SetCookie.php' Directory Traversal
CVE-2005-2892webappsphp07 set 2005
Directory traversal vulnerability in setcookie.php in PBLang 4.65, and possibly earlier versions, allows remote attacker
23RISCO
abrir
Exploit-DBVexDay Proof
Cisco IOS 12.x - Firewall Authentication Proxy Buffer Overflow
CVE-2005-2841doshardware07 set 2005
Buffer overflow in Firewall Authentication Proxy for FTP and/or Telnet Sessions for Cisco IOS 12.2ZH and 12.2ZL, 12.3 an
28RISCO
abrir
Exploit-DBVexDay Proof
BNBT BitTorrent EasyTracker 7.7r3 - Denial of Service
CVE-2004-2029doswindows06 set 2005
The Util_DecodeHTTPAuth function in BNBT BitTorrent Tracker Beta 7.5 Release 2 and earlier allows remote attackers to ca
23RISCO
abrir
Exploit-DBVexDay Proof
Unclassified NewsBoard 1.5.3 - 'Description' HTML Injection
CVE-2005-2855webappsphp06 set 2005
Cross-site scripting (XSS) vulnerability in Unclassified NewsBoard 1.5.3 allows remote attackers to inject arbitrary web
23RISCO
abrir
Exploit-DBVexDay Proof
MAXdev MD-Pro 1.0.73 - Arbitrary File Upload
CVE-2005-2885webappsphp06 set 2005
The Downloads page in MAXdev MD-Pro 1.0.73, and possibly earlier versions, uses an incomplete blacklist to check for dan
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - CSRSS Privilege Escalation (MS05-018)
CVE-2005-0551localwindows06 set 2005
Stack-based buffer overflow in WINSRV.DLL in the Client Server Runtime System (CSRSS) process of Microsoft Windows 2000,
28RISCO
abrir
Exploit-DBVexDay Proof
man2web 0.88 - Multiple Remote Command Executions (2)
CVE-2005-2812webappscgi04 set 2005
man2web allows remote attackers to execute arbitrary commands via -P arguments.
23RISCO
abrir
Exploit-DBVexDay Proof
Free SMTP Server 2.2 - Spam Filter
CVE-2005-2857remotewindows02 set 2005
Free SMTP Server 2.2 allows remote attackers to use the server as an open mail relay (spam proxy).
23RISCO
abrir
Exploit-DBVexDay Proof
FileZilla 2.2.15 - FTP Client Hard-Coded Cipher Key
CVE-2005-2898doswindows02 set 2005
NOTE: this issue has been disputed by the vendor. FileZilla 2.2.14b and 2.2.15, and possibly earlier versions, when "Us
23RISCO
abrir
Exploit-DBVexDay Proof
WhitSoft Development SlimFTPd 3.17 - Remote Denial of Service
CVE-2005-2850doswindows02 set 2005
SlimFTPd 3.17 allows remote attackers to cause a denial of service (crash) via certain (1) USER and (2) PASS commands, p
23RISCO
abrir
Exploit-DBVexDay Proof
Frox 0.7.18 - Arbitrary Configuration File Access
CVE-2005-2807locallinux01 set 2005
frox 0.7.18, when running setuid root, does not properly drop privileges when reading a configuration file, which allows
23RISCO
abrir
Exploit-DBVexDay Proof
Simple PHP Blog 0.4.0 - Multiple Remote s
CVE-2005-2787webappsphp01 set 2005
comment_delete_cgi.php in Simple PHP Blog allows remote attackers to delete arbitrary files via the comment parameter.
23RISCO
abrir
Exploit-DBVexDay Proof
Simple PHP Blog 0.4.0 - Multiple Remote s
CVE-2005-2192webappsphp01 set 2005
SimplePHPBlog 0.4.0 stores password hashes in config/password.txt with insufficient access control, which allows remote
23RISCO
abrir
Exploit-DBVexDay Proof
Simple PHP Blog 0.4.0 - Multiple Remote s
CVE-2005-2733webappsphp01 set 2005
upload_img_cgi.php in Simple PHP Blog (SPHPBlog) does not properly restrict file extensions of uploaded files, which cou
50RISCO
abrir
Exploit-DBVexDay Proof
CMS Made Simple 0.10 - 'Lang.php' Remote File Inclusion
CVE-2005-2846webappsphp31 ago 2005
PHP remote file inclusion vulnerability in lang.php in CMS Made Simple 0.10 and earlier allows remote attackers to execu
23RISCO
abrir
Exploit-DBVexDay Proof
Indiatimes Messenger 6.0 - Remote Buffer Overflow
CVE-2005-2844doswindows31 ago 2005
Buffer overflow in MMClient.exe in Indiatimes Messenger 6.0 allows remote attackers to cause a denial of service (applic
23RISCO
abrir
Exploit-DBVexDay Proof
FlatNuke 2.5.6 - 'ID' Directory Traversal
CVE-2005-2813webappsphp31 ago 2005
Directory traversal vulnerability in FlatNuke 2.5.6 and possibly earlier allows remote attackers to read arbitrary files
23RISCO
abrir
Exploit-DBVexDay Proof
DameWare Mini Remote Control 4.0 < 4.9 - Client Agent Remote Overflow
CVE-2005-2842remotewindows31 ago 2005
Buffer overflow in dwrcs.exe in DameWare Mini Remote Control before 4.9.0 allows remote attackers to execute arbitrary c
28RISCO
abrir
Exploit-DBVexDay Proof
FlatNuke 2.5.6 - 'USR' Cross-Site Scripting
CVE-2005-2814webappsphp31 ago 2005
Cross-site scripting (XSS) vulnerability in FlatNuke 2.5.6 allows remote attackers to inject arbitrary web script or HTM
23RISCO
abrir
Exploit-DBVexDay Proof
Savant Web Server 3.1 - Remote Buffer Overflow (2)
CVE-2002-1120remotewindows30 ago 2005
Buffer overflow in Savant Web Server 3.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP G
50RISCO
abrir
Exploit-DBVexDay Proof
phpLDAPadmin 0.9.6/0.9.7 - 'welcome.php' Arbitrary File Inclusion
CVE-2005-2792webappsphp30 ago 2005
Directory traversal vulnerability in welcome.php in phpLDAPadmin 0.9.6 and 0.9.7 allows remote attackers to read arbitra
28RISCO
abrir
Exploit-DBVexDay Proof
Adobe Version Cue 1.0/1.0.1 (OSX) - '-lib' Local Privilege Escalation
CVE-2005-1843localosx30 ago 2005
VCNative for Adobe Version Cue 1.0 and 1.0.1, as used in Creative Suite 1.0 and 1.3, and when running on Mac OS X with V
23RISCO
abrir
Exploit-DBVexDay Proof
Adobe Version Cue 1.0/1.0.1 (OSX) - Local Privilege Escalation
CVE-2005-1842localosx30 ago 2005
VCNative for Adobe Version Cue 1.0 and 1.0.1, as used in Creative Suite 1.0 and 1.3, and when running on Mac OS X with V
23RISCO
abrir
Exploit-DBVexDay Proof
Gopher 3.0.9 - '+VIEWS' Client-Side Buffer Overflow
CVE-2005-2772locallinux30 ago 2005
Multiple stack-based buffer overflows in University of Minnesota gopher client 3.0.9 allow remote malicious servers to e
28RISCO
abrir
anteriorpágina 653 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.