Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.900exploits catalogados
35.840CVEs com exploração pública
24.695testados em laboratório
24.458 exploits
Exploit-DBVexDay Proof
S9Y Serendipity 0.x - 'exit.php' HTTP Response Splitting
CVE-2004-1620webappsphp21 out 2004
CRLF injection vulnerability in Serendipity before 0.7rc1 allows remote attackers to perform HTTP Response Splitting att
23RISCO
abrir
Exploit-DBVexDay Proof
Apache 1.3.31 mod_include - Local Buffer Overflow
CVE-2004-0940locallinux21 out 2004
Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows (x86) - Metafile '.emf' Heap Overflow (MS04-032)
CVE-2004-0209remotewindows_x8620 out 2004
Unknown vulnerability in the Graphics Rendering Engine processes of Microsoft Windows 2000, Windows XP, and Windows Serv
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 5.x - Valid File Drag and Drop Embedded Code (MS04-038)
CVE-2005-0053remotewindows20 out 2004
Internet Explorer 5.01, 5.5, and 6 allows remote attackers to execute arbitrary code via drag and drop events, aka the "
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft IIS - WebDAV XML Denial of Service (MS04-030)
CVE-2003-0718doswindows20 out 2004
The WebDAV Message Handler for Internet Information Services (IIS) 5.0, 5.1, and 6.0 allows remote attackers to cause a
45RISCO
abrir
Exploit-DBVexDay Proof
IBM Lotus Domino 6.x - Cross-Site Scripting / HTML Injection
CVE-2004-1621webappsunix18 out 2004
NOTE: this issue has been disputed by the vendor. Cross-site scripting (XSS) vulnerability in IBM Lotus Notes R6 and Do
23RISCO
abrir
Exploit-DBVexDay Proof
Apache 1.3.x mod_include - Local Buffer Overflow
CVE-2004-0940locallinux18 out 2004
Buffer overflow in the get_tag function in mod_include for Apache 1.3.x to 1.3.32 allows local users who can create SSI
23RISCO
abrir
Exploit-DBVexDay Proof
YahooPOPs 1.6 - SMTP Remote Buffer Overflow
CVE-2004-1558remotewindows18 out 2004
Multiple stack-based buffer overflows in YPOPs! (aka YahooPOPS) 0.4 through 0.6 allow remote attackers to cause a denial
60RISCO
abrir
Exploit-DBVexDay Proof
best software SalesLogix 2000.0 - Multiple Vulnerabilities
CVE-2004-1612remotewindows18 out 2004
Directory traversal vulnerability in SalesLogix 6.1 allows remote attackers to upload arbitrary files via a .. (dot dot)
23RISCO
abrir
Exploit-DBVexDay Proof
SLX Server 6.1 - Arbitrary File Creation
CVE-2004-1612remotewindows18 out 2004
Directory traversal vulnerability in SalesLogix 6.1 allows remote attackers to upload arbitrary files via a .. (dot dot)
23RISCO
abrir
Exploit-DBVexDay Proof
ProFTPd 1.2.10 - Remote Users Enumeration
CVE-2004-1602remotelinux17 out 2004
ProFTPD 1.2.x, including 1.2.8 and 1.2.10, responds in a different amount of time when a given username exists, which al
50RISCO
abrir
Exploit-DBVexDay Proof
Monit 4.2 - Basic Authentication Remote Code Execution
CVE-2004-1898remotelinux17 out 2004
Stack-based buffer overflow in the administration interface in Monit 1.4 through 4.2 allows remote attackers to execute
28RISCO
abrir
Exploit-DBVexDay Proof
CoolPHP 1.0 - Multiple Remote Input Validation Vulnerabilities
CVE-2004-1601webappsphp16 out 2004
Directory traversal vulnerability in index.php in CoolPHP 1.0-stable allows remote attackers to access arbitrary files a
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows NNTP Service (XPAT) - Denial of Service (MS04-036)
CVE-2004-0574doswindows16 out 2004
The Network News Transfer Protocol (NNTP) component of Microsoft Windows NT Server 4.0, Windows 2000 Server, Windows Ser
35RISCO
abrir
Exploit-DBVexDay Proof
Yak! Chat Client 2.x - FTP Server Directory Traversal
CVE-2004-2184doswindows15 out 2004
Directory traversal vulnerability in Digicraft Yak! server 2.0 through 2.1.2 allows remote attackers to read or write ar
23RISCO
abrir
Exploit-DBVexDay Proof
YahooPOPs 1.6 - SMTP Port Buffer Overflow
CVE-2004-1558remotewindows15 out 2004
Multiple stack-based buffer overflows in YPOPs! (aka YahooPOPS) 0.4 through 0.6 allow remote attackers to cause a denial
60RISCO
abrir
Exploit-DBVexDay Proof
ocPortal 1.0.3 - Remote File Inclusion
CVE-2004-1592webappsphp13 out 2004
PHP remote file inclusion vulnerability in index.php in ocPortal 1.0.3 and earlier allows remote attackers to execute ar
23RISCO
abrir
Exploit-DBVexDay Proof
3Com 3CRADSL72 ADSL Wireless Router - Information Disclosure / Authentication Bypass
CVE-2004-1596remotehardware13 out 2004
The 3COM Wireless router 3CRADSL72 running Boot Code 1.3d allows remote attackers to gain sensitive information such as
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows XP - Weak Default Configuration
CVE-2004-2176localwindows13 out 2004
The Internet Connection Firewall (ICF) in Microsoft Windows XP SP2 is configured by default to trust sessmgr.exe, which
23RISCO
abrir
Exploit-DBVexDay Proof
Icecast 2.0.1 (Win32) - Remote Code Execution (2)
CVE-2004-1561remotewindows12 out 2004
Buffer overflow in Icecast 2.0.1 and earlier allows remote attackers to execute arbitrary code via an HTTP request with
60RISCO
abrir
Exploit-DBVexDay Proof
DUclassmate 1.x - 'account.asp?MM-recordId' Arbitrary Password Modification
CVE-2004-2198webappsasp11 out 2004
account.asp in DUware DUclassmate 1.0 through 1.1 allows remote attackers to change the passwords for arbitrary users by
23RISCO
abrir
Exploit-DBVexDay Proof
DUforum 3.x - 'messageDetail.asp?MSG_ID' SQL Injection
CVE-2004-2201webappsasp11 out 2004
SQL injection vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
Exploit-DBVexDay Proof
DUforum 3.x - Login Form 'Password' SQL Injection
CVE-2004-2201webappsasp11 out 2004
SQL injection vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
Exploit-DBVexDay Proof
DUclassified 4.x - 'adDetail.asp' Multiple SQL Injections
CVE-2004-2202webappsasp11 out 2004
Multiple SQL injection vulnerabilities in DUware DUclassified 4.0 through 4.2 allows remote attackers to bypass authenti
23RISCO
abrir
Exploit-DBVexDay Proof
DUforum 3.x - 'messages.asp?FOR_ID' SQL Injection
CVE-2004-2201webappsasp11 out 2004
SQL injection vulnerability in DUware DUforum 3.0 through 3.1 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
Exploit-DBVexDay Proof
Monolith Games - Local Buffer Overflow (PoC)
CVE-2004-1587doswindows10 out 2004
Buffer overflow in Monolith games including (1) Alien versus Predator 2 1.0.9.6 and earlier, (2) Blood 2 2.1 and earlier
23RISCO
abrir
Exploit-DBVexDay Proof
WordPress Core 1.2 - HTTP Splitting
CVE-2004-1584webappsphp10 out 2004
CRLF injection vulnerability in wp-login.php in WordPress 1.2 allows remote attackers to perform HTTP Response Splitting
28RISCO
abrir
Exploit-DBVexDay Proof
MySQL 3.x/4.x - ALTER TABLE/RENAME Forces Old Permission Checks
CVE-2004-0835remotelinux08 out 2004
MySQL 3.x before 3.23.59, 4.x before 4.0.19, 4.1.x before 4.1.2, and 5.x before 5.0.1, checks the CREATE/INSERT rights o
28RISCO
abrir
Exploit-DBVexDay Proof
DCP-Portal 3.7/4.x/5.x - 'announcement.php?cid' Cross-Site Scripting
CVE-2004-2511webappsphp06 out 2004
Multiple cross-site scripting (XSS) vulnerabilities in DCP-Portal 5.3.2 and earlier allow remote attackers to inject arb
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft ASP.NET 1.x - URI Canonicalization Unauthorized Web Access
CVE-2004-0847webappsasp06 out 2004
The Microsoft .NET forms authentication capability for ASP.NET allows remote attackers to bypass authentication for .asp
45RISCO
abrir
anteriorpágina 691 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.