Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.056exploits catalogados
35.925CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.640GitHub PoC 14.392VulnCheck XDB 8.755Nuclei 4.333Metasploit 3.478✓ só verificadosrecentespopularesrisco
24.458 exploits
Exploit-DB✓ VexDay Proof
Linux Kernel 2.4 - SUID 'execve()' System Call Race Condition Executable File Read
A race condition in the way env_start and env_end pointers are initialized in the execve system call and used in fs/proc
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows NT 4.0/2000 - Media Services 'nsiislog.dll' Remote Buffer Overflow
Buffer overflow in the streaming media component for logging multicast requests in the ISAPI for the logging capability
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Alt-N WebAdmin 2.0.x - 'USER' Remote Buffer Overflow (2)
Buffer overflow in WebAdmin.exe for WebAdmin allows remote attackers to execute arbitrary code via an HTTP request to We
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Gkrellmd 2.1 - Remote Buffer Overflow (1)
Buffer overflow in gkrellmd for gkrellm 2.1.x before 2.1.14 may allow remote attackers to execute arbitrary code.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Alt-N WebAdmin 2.0.x - 'USER' Remote Buffer Overflow (1)
Buffer overflow in WebAdmin.exe for WebAdmin allows remote attackers to execute arbitrary code via an HTTP request to We
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Gkrellmd 2.1 - Remote Buffer Overflow (2)
Buffer overflow in gkrellmd for gkrellm 2.1.x before 2.1.14 may allow remote attackers to execute arbitrary code.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec Security Check RuFSI - ActiveX Control Buffer Overflow
Buffer overflow in the "RuFSI Utility Class" ActiveX control (aka "RuFSI Registry Information Class"), as used for the S
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
XMB Forum 1.8 - 'member.php?member' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in member.php of XMBforum XMB 1.8.x (aka Partagium) allows remote attackers to
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
XMB Forum 1.8 - 'buddy.php?action' Cross-Site Scripting
Cross-site scripting (XSS) vulnerabilities in XMB Forum 1.8 Partagium allow remote attackers to insert arbitrary script
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Yahoo Messenger 5.5 - 'DSR-ducky.c' Remote Overflow
Buffer overflows in Yahoo! Messenger 5,0,0,1064 and earlier allows remote attackers to execute arbitrary code via a ymsg
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows XP/2000/NT 4.0 - HTML Converter HR Align Buffer Overflow
Buffer overflow in the HTML Converter (HTML32.cnv) on various Windows operating systems allows remote attackers to cause
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
XMB Forum 1.8 - 'member.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in member.php of XMBforum XMB 1.8.x (aka Partagium) allows remote attackers to
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
phpBB 2.0.5 - SQL Injection Password Disclosure
SQL injection vulnerability in viewtopic.php for phpBB 2.0.5 and earlier allows remote attackers to steal password hashe
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Tutos 1.1 - 'File_Select.php' Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in TUTOS 1.1 allow remote attackers to insert arbitrary web script,
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Tutos 1.1 - File_New Arbitrary File Upload
TUTOS 1.1 allows remote attackers to execute arbitrary code by uploading the code using file_new.php, then directly acce
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.2.x/2.4.x - '/proc' Filesystem Information Disclosure
The /proc filesystem in Linux allows local users to obtain sensitive information by opening various entries in /proc/sel
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ProFTPd 1.2.9 RC1 - 'mod_sql' SQL Injection
SQL injection vulnerability in the PostgreSQL authentication module (mod_sql_postgres) for ProFTPD before 1.2.9rc1 allow
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Kerio MailServer 5.6.3 - Web Mail DO_MAP Module Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Kerio MailServer 5.6.3 allow remote attackers to insert arbitrary
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Kerio MailServer 5.6.3 - Web Mail ADD_ACL Module Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in Kerio MailServer 5.6.3 allow remote attackers to insert arbitrary
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Kerio MailServer 5.6.3 add_acl Module - Overflow
Multiple buffer overflows in Kerio MailServer 5.6.3 allow remote authenticated users to cause a denial of service and po
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Kerio MailServer 5.6.3 subscribe Module - Overflow
Multiple buffer overflows in Kerio MailServer 5.6.3 allow remote authenticated users to cause a denial of service and po
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Kerio MailServer 5.6.3 list Module - Overflow
Multiple buffer overflows in Kerio MailServer 5.6.3 allow remote authenticated users to cause a denial of service and po
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Kerio MailServer 5.6.3 do_map Module - Overflow
Multiple buffer overflows in Kerio MailServer 5.6.3 allow remote authenticated users to cause a denial of service and po
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5/6 - MSXML XML File Parsing Cross-Site Scripting
Cross-site scripting (XSS) in Internet Explorer 5.5 and 6.0, possibly in a component that is also used by other Microsof
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5 - Custom HTTP Error HTML Injection
The Custom HTTP Errors capability in Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to execute script in th
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Snitz Forums 2000 3.4.03 - 'search.asp' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in search.asp for Snitz Forums 3.4.03 and earlier allows remote attackers to ex
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux PAM 0.77 - Pam_Wheel Module 'getlogin() Username' Spoofing Privilege Escalation
pam_wheel in Linux-PAM 0.78, with the trust option enabled and the use_uid option disabled, allows local users to spoof
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
LedNews 0.7 Post Script - Code Injection
Cross-site scripting (XSS) vulnerability in LedNews 0.7 allows remote attackers to insert arbitrary web script via a new
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PMachine 2.2.1 - '/Lib.Inc.php' Remote File Inclusion / Command Execution
PHP remote file inclusion vulnerability in pm/lib.inc.php in pMachine Free and pMachine Pro 2.2 and 2.2.1 allows remote
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Progress Database 9.1 - Environment Variable Privilege Escalation
Progress Database 9.1 to 9.1D06 trusts user input to find and load libraries using dlopen, which allows local users to g
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.