Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.056exploits catalogados
35.925CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.640GitHub PoC 14.392VulnCheck XDB 8.755Nuclei 4.333Metasploit 3.478✓ só verificadosrecentespopularesrisco
24.458 exploits
Exploit-DB✓ VexDay Proof
PJ CGI Neo Review - Directory Traversal
Directory traversal vulnerability in PJreview_Neo.cgi in PJ CGI Neo review allows remote attackers to read arbitrary fil
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
OracleAS TopLink Mapping Workbench - Weak Encryption Algorithm
Oracle toplink mapping workBench uses a weak encryption algorithm for passwords, which allows local users to decrypt the
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Loom Software SurfNow 1.x/2.x - GET Remote Denial of Service
SurfNOW 2.2 allows remote attackers to cause a denial of service (crash) via a series of long HTTP GET requests, possibl
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
BRS Webweaver 1.0.7 - 'ISAPISkeleton.dll' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in BRS WebWeaver 1.07 allows remote attackers to execute arbitrary script as ot
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
phpGroupWare 0.9.14 - 'Tables_Update.Inc.php' Remote File Inclusion
PHP remote file inclusion vulnerability in tables_update.inc.php in phpGroupWare 0.9.14.005 and earlier allows remote at
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
RhinoSoft Serv-U FTPd Server 3.x/4.x - 'SITE CHMOD' Remote Overflow
Stack-based buffer overflow in the site chmod command in Serv-U FTP Server before 4.2 allows remote attackers to execute
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
phpGroupWare 0.9.x - 'index.php' HTML Injection
Cross-site scripting (XSS) vulnerability in index.php in phpGroupWare 0.9.14.005 and earlier allows remote attackers to
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Herberlin BremsServer 1.2.4 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in BremsServer 1.2.4 allows remote attackers to inject arbitrary web script or
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
IBM Net.Data 7.0/7.2 - db2www Error Message Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in db2www CGI interpreter in IBM Net.Data 7 and 7.2 allows remote attackers to
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
InternetNow ProxyNow 2.6/2.75 - Multiple Stack / Heap Overflow Vulnerabilities
Stack-based and heap-based buffer overflows in ProxyNow! 2.75 and earlier allow remote attackers to execute arbitrary co
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Xoops 2.0.x - 'viewtopic.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in viewtopic.php in Xoops 2.x, possibly 2 through 2.0.5, allows remote attacker
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Gallery 1.3.x/1.4 - Remote Global Variable Injection
The register_globals simulation capability in Gallery 1.3.1 through 1.4.1 allows remote attackers to modify the HTTP_POS
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
herberlin bremsserver 1.2.4/3.0 - Directory Traversal
Directory traversal vulnerability in BremsServer 1.2.4 allows remote attackers to read arbitrary files via ".." (dot dot
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cherokee 0.1.x/0.2.x/0.4.x - Error Page Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Cherokee before 0.4.8 allows remote attackers to inject arbitrary web script
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
RhinoSoft Serv-U FTPd Server 3/4 - MDTM Command Stack Overflow (2)
Stack-based buffer overflow in the site chmod command in Serv-U FTP Server before 4.2 allows remote attackers to execute
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
RhinoSoft Serv-U FTPd Server 3/4 - MDTM Command Stack Overflow (1)
Stack-based buffer overflow in the site chmod command in Serv-U FTP Server before 4.2 allows remote attackers to execute
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
tinyserver 1.1 - Directory Traversal
Directory traversal vulnerability in Tiny Server 1.1 allows remote attackers to read or download arbitrary files via a .
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
TinyServer 1.1 - Denial of Service
Tiny Server 1.1 allows remote attackers to cause a denial of service (crash) via malformed HTTP requests such as (1) a G
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
borland Web server for corel paradox 1.0 b3 - Directory Traversal
Multiple directory traversal vulnerabilities in Borland Web Server (BWS) 1.0b3 and earlier allow remote attackers to rea
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
TinyServer 1.1 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Tiny Server 1.1 allows remote attackers to inject arbitrary web script or HT
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle HTTP Server 8.1.7/9.0.1/9.2 - isqlplus Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTTP Server 1.3.22, based on Apache, allow remote attacker
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Novell Netware Enterprise Web Server 5.1/6.0 - snoop.jsp Information Disclosure
Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to obtain sensitive server information, includi
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Need for Speed 2 - Remote Client Buffer Overflow (PoC)
Buffer overflow in Need for Speed Hot Pursuit 2.0 client (NFSHP2), version 242 and earlier, allows remote attackers (ser
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Novell Netware Enterprise Web Server 5.1/6.0 SnoopServlet - Information Disclosure
Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to obtain sensitive server information, includi
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Finjan SurfinGate 6.0/7.0 - FHTTP Restart Command Execution
Finjan SurfinGate 6.0 and 7.0, when running in proxy mode, does not authenticate FHTTP commands on TCP port 3141, which
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Novell Netware Enterprise Web Server 5.1/6.0 - env.bas Information Disclosure
Novell NetWare Enterprise Web Server 5.1 and 6.0 allows remote attackers to obtain sensitive server information, includi
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Reptile Web Server Reptile Web Server 20020105 - Denial of Service
Reptile Web Server allows remote attackers to cause a denial of service (CPU consumption) via multiple incomplete GET re
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Acme thttpd 1.9/2.0.x - CGI Test Script Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in FREESCO 2.05, a modified version of thttpd, allows remote attackers to injec
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
McAfee ePolicy Orchestrator 1.x/2.x/3.0 Agent - POST Buffer Mismanagement
McAfee ePolicy Orchestrator agent allows remote attackers to cause a denial of service (memory consumption and crash) an
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Darkwet Network WebcamXP 1.6.945 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in WebcamXP 1.06.945 allows remote attackers to inject arbitrary HTML or web sc
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.