Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.900exploits catalogados
35.840CVEs com exploração pública
24.695testados em laboratório
24.458 exploits
Exploit-DBVexDay Proof
IBM Tivoli Directory Server 3.2.2/4.1 - LDACGI Directory Traversal
CVE-2004-2526remotewindows02 ago 2004
Directory traversal vulnerability in ldacgi.exe in IBM Tivoli Directory Server 4.1 and earlier allows remote attackers t
23RISCO
abrir
Exploit-DBVexDay Proof
Citadel/UX - Remote Denial of Service (PoC)
CVE-2004-1705doslinux02 ago 2004
Buffer overflow in Citadel/UX 6.23 and earlier allows remote attackers to cause a denial of service via a long username.
23RISCO
abrir
Exploit-DBVexDay Proof
Apache - Arbitrary Long HTTP Headers Denial of Service
CVE-2004-0493doslinux02 ago 2004
The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memor
45RISCO
abrir
Exploit-DBVexDay Proof
SoX - Local Buffer Overflow
CVE-2004-0557locallinux01 ago 2004
Multiple buffer overflows in the st_wavstartread function in wav.c for Sound eXchange (SoX) 12.17.2 through 12.17.4 allo
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows XP - Task Scheduler '.job' Universal (MS04-022)
CVE-2004-0212localwindows31 jul 2004
Stack-based buffer overflow in the Task Scheduler for Windows 2000 and XP, and Internet Explorer 6 on Windows NT 4.0, al
35RISCO
abrir
Exploit-DBVexDay Proof
Fusionphp Fusion News 3.3/3.6 - Administrator Command Execution
CVE-2004-1703webappsphp30 jul 2004
Fusion News 3.6.1 allows remote attackers to add user accounts, if the administrator is logged in, via a comment that co
23RISCO
abrir
Exploit-DBVexDay Proof
Oracle9i Database - Default Library Directory Privilege Escalation
CVE-2004-1707localunix30 jul 2004
The (1) dbsnmp and (2) nmo programs in Oracle 8i, Oracle 9i, and Oracle IAS 9.0.2.0.1, on Unix systems, use a default pa
23RISCO
abrir
Exploit-DBVexDay Proof
PowerPortal 1.1/1.3 - Private Message HTML Injection
CVE-2004-2514webappsphp30 jul 2004
Cross-site scripting (XSS) vulnerability in modules/private_messages/index.php in PowerPortal 1.x allows remote attacker
23RISCO
abrir
Exploit-DBVexDay Proof
Jaws 0.2/0.3/0.4 - 'ControlPanel.php' SQL Injection
CVE-2004-2067webappsphp29 jul 2004
SQL injection vulnerability in controlpanel.php in Jaws Framework and Content Management System 0.4 allows remote attack
23RISCO
abrir
Exploit-DBVexDay Proof
Verylost LostBook 1.1 - Message Entry HTML Injection
CVE-2004-2064webappsphp29 jul 2004
Cross-site scripting (XSS) vulnerability in lostBook 1.1 and earlier allows remote attackers to inject arbitrary web scr
23RISCO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX - Panther Internet Connect Privilege Escalation
CVE-2004-0824localosx28 jul 2004
PPPDialer for Mac OS X 10.2.8 through 10.3.5 allows local users to overwrite system files via a symlink attack on PPPDia
23RISCO
abrir
Exploit-DBVexDay Proof
AntiBoard 0.6/0.7 - 'antiboard.php?feedback' Cross-Site Scripting
CVE-2004-2063webappsphp28 jul 2004
Cross-site scripting (XSS) vulnerability in antiboard.php in AntiBoard 0.7.2 and earlier allows remote attackers to inje
23RISCO
abrir
Exploit-DBVexDay Proof
AntiBoard 0.6/0.7 - 'antiboard.php' Multiple SQL Injections
CVE-2004-2062webappsphp28 jul 2004
SQL injection vulnerability in antiboard.php in AntiBoard 0.7.2 and earlier allows remote attackers to execute arbitrary
23RISCO
abrir
Exploit-DBVexDay Proof
Phorum 5.0.7 - Search Script Cross-Site Scripting
CVE-2004-2242webappsphp28 jul 2004
Cross-site scripting (XSS) vulnerability in search.php in Phorum, possibly 5.0.7 beta and earlier, allows remote attacke
23RISCO
abrir
Exploit-DBVexDay Proof
RiSearch 0.99 /RiSearch Pro 3.2.6 - show.pl Arbitrary File Access
CVE-2004-2061remotecgi27 jul 2004
RiSearch 1.0.01 and RiSearch Pro 3.2.06 allows remote attackers to use the show.pl script as an open proxy, or read arbi
23RISCO
abrir
Exploit-DBVexDay Proof
Opera Web Browser 7.53 - Location Replace URI Obfuscation
CVE-2004-2491remotemultiple27 jul 2004
A race condition in Opera web browser 7.53 Build 3850 causes Opera to fill in the address bar before the page has been l
23RISCO
abrir
Exploit-DBVexDay Proof
RiSearch 0.99 /RiSearch Pro 3.2.6 - show.pl Open Proxy Relay
CVE-2004-2061remotecgi27 jul 2004
RiSearch 1.0.01 and RiSearch Pro 3.2.06 allows remote attackers to use the show.pl script as an open proxy, or read arbi
23RISCO
abrir
Exploit-DBVexDay Proof
XLineSoft ASPRunner 1.0/2.x - '[TABLE]_list.asp?searchFor' Cross-Site Scripting
CVE-2004-2059webappsasp26 jul 2004
Multiple cross-site scripting vulnerabilities in ASPRunner 2.4 allow remote attackers to inject arbitrary web script or
23RISCO
abrir
Exploit-DBVexDay Proof
XLineSoft ASPRunner 1.0/2.x - '[TABLE-NAME]_edit.asp?SQL' Cross-Site Scripting
CVE-2004-2059webappsasp26 jul 2004
Multiple cross-site scripting vulnerabilities in ASPRunner 2.4 allow remote attackers to inject arbitrary web script or
23RISCO
abrir
Exploit-DBVexDay Proof
Mozilla Browser 0.8/0.9/1.x - Refresh Security Property Spoofing
CVE-2004-0763remotelinux26 jul 2004
Mozilla Firefox 0.9.1 and 0.9.2 allows remote web sites to spoof certificates of trusted web sites via redirects and Jav
23RISCO
abrir
Exploit-DBVexDay Proof
XLineSoft ASPRunner 1.0/2.x - '[TABLE-NAME]_search.asp?Typeen' Cross-Site Scripting
CVE-2004-2059webappsasp26 jul 2004
Multiple cross-site scripting vulnerabilities in ASPRunner 2.4 allow remote attackers to inject arbitrary web script or
23RISCO
abrir
Exploit-DBVexDay Proof
XLineSoft ASPRunner 1.0/2.x - 'export.asp?SQL' Cross-Site Scripting
CVE-2004-2059webappsasp26 jul 2004
Multiple cross-site scripting vulnerabilities in ASPRunner 2.4 allow remote attackers to inject arbitrary web script or
23RISCO
abrir
Exploit-DBVexDay Proof
XLineSoft ASPRunner 1.0/2.x - Database Direct Request Information Disclosure
CVE-2004-2060webappsasp26 jul 2004
ASPRunner 2.4 stores the database under the web root in the db directory, which may allow remote attackers to obtain the
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows SMS 2.0 - Denial of Service
CVE-2004-0728doswindows24 jul 2004
The Remote Control Client service in Microsoft's Systems Management Server (SMS) 2.50.2726.0 allows remote attackers to
28RISCO
abrir
Exploit-DBVexDay Proof
EasyIns Stadtportal 4.0 - 'Site' Remote File Inclusion
CVE-2004-2053webappsphp24 jul 2004
PHP remote file inclusion vulnerability in index.php in EasyIns Stadtportal 4 allows remote attackers to execute arbitra
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - Denial of Service
CVE-2004-0484doswindows23 jul 2004
mshtml.dll in Microsoft Internet Explorer 6.0.2800 allows remote attackers to cause a denial of service (crash) via a ta
28RISCO
abrir
Exploit-DBVexDay Proof
EasyWeb 1.0 FileManager Module - Directory Traversal
CVE-2004-2047webappsphp23 jul 2004
Directory traversal vulnerability in EasyWeb FileManager 1.0 RC-1 for PostNuke allows remote attackers to retrieve arbit
23RISCO
abrir
Exploit-DBVexDay Proof
Lexmark Multiple HTTP Servers - Denial of Service
CVE-2004-0740doshardware22 jul 2004
The HTTP server in Lexmark T522 and possibly other models allows remote attackers to cause a denial of service (server c
23RISCO
abrir
Exploit-DBVexDay Proof
Conceptronic CADSLR1 Router - Denial of Service
CVE-2004-2045doshardware22 jul 2004
The HTTP administration interface on Conceptronic CADSLR1 ADSL router running firmware 3.04n allows remote attackers to
23RISCO
abrir
Exploit-DBVexDay Proof
Apache - Arbitrary Long HTTP Headers (Denial of Service)
CVE-2004-0493dosmultiple22 jul 2004
The ap_get_mime_headers_core function in Apache httpd 2.0.49 allows remote attackers to cause a denial of service (memor
45RISCO
abrir
anteriorpágina 697 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.