Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.900exploits catalogados
35.840CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.600GitHub PoC 14.323VulnCheck XDB 8.722Nuclei 4.320Metasploit 3.477✓ só verificadosrecentespopularesrisco
24.458 exploits
Exploit-DB✓ VexDay Proof
Gattaca Server 2003 POP3 - Denial of Service
POP3 protocol in Gattaca Server 2003 1.1.10.0 allows remote authenticated users to cause a denial of service (applicatio
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Gattaca Server 2003 - Null Byte Full Path Disclosure
Gattaca Server 2003 1.1.10.0 allows remote attackers to obtain sensitive information via (1) a trailing null byte ("%00"
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
BoardPower Forum - 'ICQ.cgi' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in icq.cgi in Board Power 2.04PF allows remote attackers to inject arbitrary we
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Gattaca Server 2003 - 'web.tmpl?Language' CPU Consumption (Denial of Service)
Gattaca Server 2003 1.1.10.0 allows remote attackers to cause a denial of service (CPU consumption) via directory specif
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Gattaca Server 2003 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in web.tmpl in Gattaca Server 2003 1.1.10.0 allows remote attackers to inject a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Gattaca Server 2003 - 'Language' Path Exposure
Gattaca Server 2003 1.1.10.0 allows remote attackers to obtain sensitive information via (1) a trailing null byte ("%00"
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 4.x/5.0 - 'Strip_Tags()' Function Bypass
The strip_tags function in PHP 4.x up to 4.3.7, and 5.x up to 5.0.0RC3, does not filter null (\0) characters within tag
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Server 2000 - Utility Manager Privilege Escalation (MS04-019)
Utility Manager in Windows 2000 launches winhlp32.exe while Utility Manager is running with raised privileges, which all
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
IBM Lotus Notes 6.0/6.5 - Multiple Java Applet Vulnerabilities
Buffer overflow in IBM Lotus Notes 6.5.x before 6.5.3 and 6.0.x before 6.0.5 allows remote attackers to cause a denial o
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Mozilla Browser 0.9/1.x Cache File - Multiple Vulnerabilities
Mozilla allows remote attackers to cause Mozilla to open a URI as a different MIME type than expected via a null charact
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Moodle Help Script 1.x - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in help.php in Moodle 1.3.2 and 1.4 dev allows remote attackers to inject arbit
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
IM-Switch - Insecure Temporary File Handling Symbolic Link
im-switch before 11.4-46.1 in Fedora Core 2 allows local users to overwrite arbitrary files via a symlink attack on the
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - Remote Wscript.Shell
The WebBrowser ActiveX control, or the Internet Explorer HTML rendering engine (MSHTML), as used in Internet Explorer 6,
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WebSTAR FTP Server 5.3.2 (OSX) - USER Overflow (Metasploit)
Stack-based buffer overflow in the FTP service for 4D WebSTAR 5.3.2 and earlier allows remote attackers to execute arbit
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5.0.1 - Popup.show Mouse Event Hijacking
Internet Explorer 6.x allows remote attackers to install arbitrary programs via mousedown events that call the Popup.sho
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Norton AntiVirus - Denial of Service
Symantec Norton AntiVirus 2002 and 2003 allows remote attackers to cause a denial of service (CPU consumption) via a com
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Code-Crafters Ability Mail Server 1.18 - 'errormsg' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in _error in Ability Mail Server 1.18 allows remote attackers to inject arbitra
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
phpBB 2.0.x - 'viewtopic.php' PHP Script Injection
viewtopic.php in phpBB 2.x before 2.0.11 improperly URL decodes the highlight parameter when extracting words and phrase
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5.0.1 - JavaScript Method Assignment Cross-Domain Scripting
Microsoft Internet Explorer 6.0.2800.1106 on Microsoft Windows XP SP2, and other versions including 5.01 and 5.5, allows
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MySQL 4.1/5.0 - Zero-Length Password Authentication Bypass
The check_scramble_323 function in MySQL 4.1.x before 4.1.3, and 5.0, allows remote attackers to bypass authentication v
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - Remote Application.Shell
Microsoft Windows Internet Explorer 5.5 and 6.0 allows remote attackers to execute arbitrary code via an embedded script
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Mozilla 1.7 - External Protocol Handler
Mozilla (Suite) before 1.7.1, Firefox before 0.9.2, and Thunderbird before 0.7.2 allow remote attackers to launch arbitr
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5.0.1 - Style Tag Comment Memory Corruption
Internet Explorer 6.0 SP1 and earlier, and possibly other versions, allows remote attackers to cause a denial of service
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Comersus Open Technologies Comersus 5.0 - 'comersus_message.asp' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in (1) comersus_customerAuthenticateForm.asp, (2) comersus_backoffic
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Comersus Open Technologies Comersus 5.0 - 'comersus_gatewayPayPal.asp' Price Manipulation
comersus_gatewayPayPal.asp in Comersus Cart 5.09, and possibly other versions before 5.098, allows remote attackers to c
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Jaws 0.2/0.3 - 'action' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in index.php in Jaws 0.3 allows remote attackers to inject arbitrary web script
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Jaws 0.2/0.3 - Cookie Manipulation Authentication Bypass
Jaws 0.3 allows remote attackers to bypass authentication and via an HTTP request to admin.php with the logged cookie se
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Jaws 0.2/0.3 - 'gadget' Traversal Arbitrary File Access
Directory traversal vulnerability in index.php in Jaws 0.3 BETA allows remote attackers to view arbitrary files via a ..
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec Brightmail Anti-Spam 6.0 - Unauthorized Message Disclosure
Brightmail Spamfilter 6.0 and earlier beta releases allows remote attackers to read mail from other users by modifying t
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
12Planet Chat Server 2.9 - Cross-Site Scripting
Cross-site scripting (XSS) in one2planet.infolet.InfoServlet in 12Planet Chat Server 2.9 allows remote attackers to exec
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.