Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.056exploits catalogados
35.925CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.640GitHub PoC 14.392VulnCheck XDB 8.755Nuclei 4.333Metasploit 3.478✓ só verificadosrecentespopularesrisco
24.458 exploits
Exploit-DB✓ VexDay Proof
Apache cocoon 2.14/2.2 - Directory Traversal
Directory traversal vulnerability in the view-source sample file in Apache Software Foundation Cocoon 2.1 and 2.2 allows
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Coreutils 4.5.x - LS Width Argument Integer Overflow
An integer overflow in ls in the fileutils or coreutils packages may allow local users to cause a denial of service or e
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Sun Java Virtual Machine 1.x - Slash Path Security Model Circumvention
The loadClass method of the sun.applet.AppletClassLoader class in the Java Virtual Machine (JVM) in Sun SDK and JRE 1.4.
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Exchange Server 2000 - XEXCH50 Heap Overflow (PoC) (MS03-046)
The Internet Mail Service in Exchange Server 5.5 and Exchange 2000 allows remote attackers to cause a denial of service
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PSCS VPOP3 2.0 Email Server WebAdmin - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in PSCS VPOP3 Web Mail server 2.0e and 2.0f allows remote attackers to inject a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
DansGuardian 2.2.x - Denied URL Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in dansguardian.pl in Adelix CensorNet 3.0 through 3.2 allows remote attackers
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 6 - Scrollbar-Base-Color Partial Denial of Service
Microsoft Internet Explorer 6.0 allows remote attackers to cause a denial of service (crash) by creating a web page or H
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Sun Java Plugin 1.4 - Unauthorized Java Applet Floppy Access
Sun Java Plug-In 1.4 through 1.4.2_02 allows remote attackers to repeatedly access the floppy drive via the createXmlDoc
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Vivisimo Clustering Engine - Search Script Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Vivisimo clustering engine allows remote attackers to inject arbitrary web s
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
FuzzyMonkey 2.11 - MyClassifieds Email Variable SQL Injection
SQL injection vulnerability in FuzzyMonkey My Classifieds 2.11 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
mIRC 6.1 - 'IRC' Protocol Remote Buffer Overflow
Buffer overflow in mIRC before 6.11 allows remote attackers to execute arbitrary code via a long irc:// URL.
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Caucho Resin 2.0/2.1 - Multiple HTML Injection / Cross-Site Scripting Vulnerabilities
Multiple cross-site scripting (XSS) vulnerabilities in example scripts in Caucho Technology Resin 2.0 through 2.1.2 allo
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Opera 7.11/7.20 HREF - Malformed Server Name Heap Corruption
Heap-based buffer overflow in Opera 7.11 and 7.20 allows remote attackers to execute arbitrary code via an HREF with a l
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Bytehoard 0.7 - File Disclosure
Directory traversal vulnerability in index.php in Bytehoard 0.7 allows remote attackers to read arbitrary files via a ..
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Dansie Shopping Cart - Server Error Message Installation Full Path Disclosure
cart.pl in Dansie shopping cart allows remote attackers to obtain the installation path via an invalid db parameter, whi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Sun Java Plugin 1.4.2 _01 - Cross-Site Applet Sandbox Security Model Violation
The org.apache.xalan.processor.XSLProcessorVersion class in Java Plug-in 1.4.2_01 allows signed and unsigned applets to
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Atrium Software Mercur MailServer 3.3/4.0/4.2 - IMAP AUTH Remote Buffer Overflow
Buffer overflow in the base64 decoder in MERCUR Mailserver 4.2 before SP3a allows remote attackers to cause a denial of
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
DeskPro 1.1 - Multiple SQL Injections
NTMail does not disable the VRFY command, even if the administrator has explicitly disabled it.
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Messenger Service - Denial of Service (MS03-043)
The Messenger Service for Windows NT through Server 2003 does not properly verify the length of the message, which allow
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
GoldLink 3.0 - Cookie SQL Injection
SQL injection vulnerability in variables.php in Goldlink 3.0 allows remote attackers to execute arbitrary SQL commands v
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Bajie HTTP Server 0.95 - Example Scripts and Servlets Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Bajie Java HTTP Server 0.95 through 0.95zxv4 allows remote attackers to inje
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft ListBox/ComboBox Control - 'User32.dll' Buffer Overrun
Buffer overflow in a function in User32.dll on Windows NT through Server 2003 allows local users to execute arbitrary co
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Tomcat 4.0.x - Non-HTTP Request Denial of Service
The Catalina org.apache.catalina.connector.http package in Tomcat 4.0.x up to 4.0.3 allows remote attackers to cause a d
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WrenSoft Zoom Search Engine 2.0 Build: 1018 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in search.php for WRENSOFT Zoom Search Engine 2.0 Build 1018 and earlier allows
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WinSyslog Interactive Syslog Server 4.21 - long Message Remote Denial of Service
Adiscon WinSyslog 4.21 SP1 allows remote attackers to cause a denial of service (CPU consumption) via a long syslog mess
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
mIRC 6.1 - 'DCC SEND' Buffer Overflow (1)
Buffer overflow in mIRC 6.1 and 6.11 allows remote attackers to cause a denial of service (crash) via a long DCC SEND re
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ProFTPd 1.2.7 < 1.2.9rc2 - Remote Code Execution / Brute Force
ProFTPD 1.2.7 through 1.2.9rc2 does not properly translate newline characters when transferring files in ASCII mode, whi
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
IRCnet IRCD 2.10 - Local Buffer Overflow
Buffer overflow in m_join in channel.c for IRCnet IRCD 2.10.x to 2.10.3p3 allows remote attackers to cause a denial of s
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
mIRC 6.1 - 'DCC SEND' Buffer Overflow (2)
Buffer overflow in mIRC 6.1 and 6.11 allows remote attackers to cause a denial of service (crash) via a long DCC SEND re
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Gallery 1.4 - 'index.php' Remote File Inclusion
PHP remote file include vulnerability in index.php for Gallery 1.4 and 1.4-pl1, when running on Windows or in Configurat
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.