Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.900exploits catalogados
35.840CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.600GitHub PoC 14.323VulnCheck XDB 8.722Nuclei 4.320Metasploit 3.477✓ só verificadosrecentespopularesrisco
24.458 exploits
Exploit-DB✓ VexDay Proof
Citadel/UX - Remote Buffer Overflow
Buffer overflow in Citadel/UX 6.23 and earlier allows remote attackers to cause a denial of service via a long username.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Nagl XOOPS Dictionary Module 1.0 - Multiple Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS 0.94 and 1.0 allow remote attackers to execute arbitrary we
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Easy File Sharing Web Server 1.25 - Denial of Service
Easy File Sharing (EFS) Webserver 1.25 allows remote attackers to cause a denial of service (CPU consumption or crash) v
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Gaucho 1.4 - Mail Client Buffer Overflow
Stack-based buffer overflow in Gaucho 1.4 Build 145 allows remote attackers to execute arbitrary code via a POP3 email w
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Painkiller 1.3.1 - Denial of Service
Buffer overflow in Painkiller 1.3.1 and earlier allows remote attackers to cause a denial of service (crash) and possibl
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Bird Chat 1.61 - Denial of Service
Bird Chat 1.61 allows remote attackers to cause a denial of service (crash) via invalid users.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
BadBlue 2.52 Web Server - Multiple Connections Denial of Service Vulnerabilities
BadBlue 2.5 allows remote attackers to cause a denial of service (refuse HTTP connections) via a large number of connect
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Sysinternals Regmon 6.11 - Local Denial of Service
NtRegmon before 6.12 allows local users to cause a denial of service (crash), while NtRegmon is running, via invalid poi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SquirrelMail - 'chpasswd' Local Privilege Escalation (Brute Force)
Buffer overflow in the chpasswd command in the Change_passwd plugin before 4.0, as used in SquirrelMail, allows local us
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Winamp 5.04 - '.wsz' Skin File Remote Code Execution
Winamp before 5.0.4 allows remote attackers to execute arbitrary script in the Local computer zone via script in HTML fi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP Code Snippet Library 0.8 - Multiple Cross-Site Scripting Vulnerabilities
Cross-site scripting (XSS) vulnerability in index.php in PHP Code Snippet Library allows remote attackers to inject arbi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Web-APP.Org WebAPP 0.8/0.9.x - Directory Traversal
Directory traversal vulnerability in WebAPP 0.9.9 allows remote attackers to view arbitrary files via a .. (dot dot) in
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
GNU a2ps 4.13 - File Name Command Execution
a2ps 4.13 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename.
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MusicDaemon 0.0.3 - Remote Denial of Service / '/etc/shadow' Stealer (2)
Music daemon (musicd) 0.0.3 and earlier allows remote attackers to cause a denial of service (crash) by calling LOAD wit
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SWsoft Plesk Reloaded 7.1 - 'Login_name' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in login_up.php3 in Plesk 7.0 and 7.1 Reloaded allows remote attackers to injec
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Axis Network Camera 2.x And Video Server 1-3 - 'virtualinput.cgi' Arbitrary Command Execution
Axis Network Camera 2.40 and earlier, and Video Server 3.12 and earlier, allows remote attackers to execute arbitrary co
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Gadu-Gadu 6.0 - File Download Filename Obfuscation
Visual truncation vulnerability in Gadu-Gadu allows remote attackers to spoof the file extension on transmitted files vi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
IMWheel 1.0 - Predictable Temporary File Creation
Race condition in IMWheel 1.0.0pre11 and earlier, when running with the -k option, allows local users to cause a denial
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
eGroupWare 1.0 Calendar Module - 'date' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in eGroupWare 1.0.00.003 and earlier allow remote attackers to injec
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Qt - '.bmp' Parsing Bug Heap Overflow
Heap-based buffer overflow in the BMP image format parser for the QT library (qt3) before 3.3.3 allows remote attackers
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Mantis Bug Tracker 0.x - New Account Signup Mass Emailing
signup_page.php in Mantis bugtracker allows remote attackers to send e-mail bombs by creating multiple users and providi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Sympa 4.x - New List HTML Injection
Cross-site scripting (XSS) vulnerability in the create list option in Sympa 4.1.x and earlier allows remote authenticate
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
aGSM 2.35 Half-Life Server - Info Response Buffer Overflow (PoC)
Buffer overflow in aGSM Half-Life client allows remote Half-Life servers to cause a denial of service (crash) and possib
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
phpMyWebhosting - SQL Injection
SQL injection vulnerability in pmwh.php in PHPMyWebHosting 0.3.4 and earlier allows remote attackers to modify SQL state
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Mercantec SoftCart 4.00b - CGI Overflow (Metasploit)
Buffer overflow in SoftCart.exe in Mercantec SoftCart 4.00b allows remote attackers to execute arbitrary code via a long
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PlaySms 0.7 - SQL Injection
SQL injection vulnerability in the valid function in fr_left.php in PlaySMS 0.7 and earlier allows remote attackers to m
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
IPSwitch IMail Server 8.1 - Local Password Decryption Utility
Ipswitch IMail 5.0 and 6.0 uses weak encryption to store passwords in registry keys, which allows local attackers to rea
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
GV PostScript Viewer - Remote Buffer Overflow (2)
Multiple buffer overflows in the psscan function in ps.c for gv (ghostview) allow remote attackers to execute arbitrary
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
AOL Instant Messenger AIM - 'Away' Message Local Overflow
Buffer overflow in the goaway function in the aim:goaway URI handler for AOL Instant Messenger (AIM) 5.5, including 5.5.
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ProFTPd - 'ftpdctl' 'pr_ctrls_connect' Local Overflow
Stack-based buffer overflow in the pr_ctrls_recv_request function in ctrls.c in the mod_ctrls module in ProFTPD before 1
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.