Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.056exploits catalogados
35.925CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.640GitHub PoC 14.392VulnCheck XDB 8.755Nuclei 4.333Metasploit 3.478✓ só verificadosrecentespopularesrisco
24.458 exploits
Exploit-DB✓ VexDay Proof
Sami FTP Server 1.1.3 - Library Crafted GET Remote Denial of Service
The samiftp.dll library in Sami FTP Server 1.1.3 allows remote authenticated users to cause a denial of service (pmsyste
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Sami FTP Server 1.1.3 - Invalid Command Argument Local Denial of Service
The samiftp.dll library in Sami FTP Server 1.1.3 allows local users to cause a denial of service (pmsystem.exe crash) by
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5.0.1 - ITS Protocol Zone Bypass (MS04-013)
The MHTML protocol handler in Microsoft Outlook Express 5.5 SP2 through Outlook Express 6 SP1 allows remote attackers to
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
vBulletin 3.0 - 'search.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in search.php for Jelsoft vBulletin 3.0.0 RC4 allows remote attackers to inject
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
KarjaSoft Sami HTTP Server 1.0.4 - GET Buffer Overflow
Buffer overflow in KarjaSoft Sami HTTP Server 1.0.4 allows remote attackers to cause a denial of service (crash) and pos
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Macallan Mail Solution Macallan Mail Solution 2.8.4.6 (Build 260) - Web Interface Authentication Bypass
Macallan Mail Solution 2.8.4.6 (Build 260), and possibly earlier versions, allows remote attackers to bypass authenticat
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
XFree86 4.x - CopyISOLatin1Lowered Font_Name Buffer Overflow
Buffer overflow in the ReadFontAlias function in XFree86 4.1.0 to 4.3.0, when using the CopyISOLatin1Lowered function, a
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Crob FTP Server 3.5.2 - Remote Denial of Service
Crob FTP daemon 3.5.2 allows remote attackers to cause a denial of service (crash) by repeatedly connecting to and disco
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
VisualShapers EZContents 1.x/2.0 - 'archivednews.php' Arbitrary File Inclusion
Multiple PHP remote file inclusion vulnerabilities in ezContents 2.0.2 and earlier allow remote attackers to execute arb
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
VisualShapers EZContents 1.x/2.0 - 'db.php' Arbitrary File Inclusion
Multiple PHP remote file inclusion vulnerabilities in ezContents 2.0.2 and earlier allow remote attackers to execute arb
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
BolinTech DreamFTP Server 1.2 (1.02/TryFTP 1.0.0.1) - Remote User Name Format String
Format string vulnerability in Dream FTP 1.02 allows local users to cause a denial of service (crash) via format string
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
BosDev BosDates 3.x - SQL Injection
SQL injection vulnerability in calendar_download.php in BosDates 3.2 and earlier allows remote attackers to obtain sensi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Monkey HTTP Daemon 0.x - Missing Host Field Denial of Service
The get_real_string function in Monkey HTTP Daemon (monkeyd) 0.8.1 and earlier allows remote attackers to cause a denial
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Maxwebportal 1.3x - Personal Message 'SendTo' Cross-Site Scripting
Multiple cross-site scripting vulnerabilities (XSS) in MaxWebPortal allow remote attackers to execute arbitrary web scri
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Maxwebportal 1.3x - 'down.asp' HTTP_REFERER Cross-Site Scripting
Multiple cross-site scripting vulnerabilities (XSS) in MaxWebPortal allow remote attackers to execute arbitrary web scri
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
EvolutionX - Multiple Remote Buffer Overflow Vulnerabilities
Multiple buffer overflows in EvolutionX 3921 and 3935 allow remote attackers to cause a denial of service (hang) via (1)
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows XP - HCP URI Handler Arbitrary Command Execution
Help Center (HelpCtr.exe) may allow remote attackers to read or execute arbitrary files via an "http://" or "file://" ar
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Caucho Technology Resin 2.1.12 - Directory Listings Disclosure
Caucho Technology Resin 2.1.12 allows remote attackers to gain sensitive information and view the contents of the /WEB-I
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Nadeo Game Engine - Remote Denial of Service
Nadeo Game Engine for Nadeo TrackMania and Nadeo Virtual Skipper 3 allows remote attackers to cause a denial of service
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Shaun2k2 Palmhttpd Server 3.0 - Remote Denial of Service
palmhttpd for PalmOS allows remote attackers to cause a denial of service (crash) by establishing two simultaneous HTTP
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Sambar Server 6.0 - 'results.stm' POST Buffer Overflow
Stack-based buffer overflow in results.stm for Sambar Server before the 6.0 production release allows remote attackers t
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Red-M Red-Alert 3.1 - Remote Denial of Service
Red-M Red-Alert 2.7.5 with software 3.1 build 24 allows remote attackers to cause a denial of service (reboot and loss o
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP-Nuke 6.x/7.x 'Reviews' Module - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in modules.php for Php-Nuke 6.x-7.1.0 allows remote attackers to execute arbitr
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP-Nuke 6.x/7.x - Public Message SQL Injection
SQL injection vulnerability in the "public message" capability (public_message) for Php-Nuke 6.x to 7.1.0 allows remote
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Samba 2.2.8 (Linux Kernel 2.6 / Debian / Mandrake) - Share Privilege Escalation
smbmnt in Samba 2.x and 3.x on Linux 2.6, when installed setuid, allows local users to gain root privileges by mounting
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ClamAV Daemon 0.65 - UUEncoded Message Denial of Service
libclamav in Clam AntiVirus 0.65 allows remote attackers to cause a denial of service (crash) via a uuencoded e-mail mes
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
BolinTech DreamFTP Server 1.0 - User Name Format String
Format string vulnerability in Dream FTP 1.02 allows remote attackers to cause a denial of service (crash) and possibly
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5.0.1 - LoadPicture File Enumeration
Microsoft Internet Explorer 5.0.1 through 6.0 allows remote attackers to determine the existence of arbitrary files via
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
OpenJournal 2.0 - Authentication Bypassing
oj.cgi in OpenJournal 2.0 through 2.0.5 allows remote attackers to bypass authentication and access the control panel vi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux VServer Project 1.2x - Chroot Breakout
Linux-VServer 1.24 allows local users with root privileges on a virtual server to gain access to the filesystem outside
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.