Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.091exploits catalogados
35.949CVEs com exploração pública
24.695testados em laboratório
24.458 exploits
Exploit-DBVexDay Proof
Sun Solaris 2.5/2.6/7.0/8/9 AT Command - Arbitrary File Deletion
CVE-2003-1073localsolaris27 jan 2003
A race condition in the at command for Solaris 2.6 through 9 allows local users to delete arbitrary files via the -r arg
23RISCO
abrir
Exploit-DBVexDay Proof
Apache Tomcat 3.x - Null Byte Directory / File Disclosure
CVE-2003-0042remotelinux26 jan 2003
Jakarta Tomcat before 3.3.1a, when used with JDK 1.3.1 or earlier, allows remote attackers to list directories even with
35RISCO
abrir
Exploit-DBVexDay Proof
FTLS Guestbook 1.1 - Script Injection
CVE-2003-1348webappsphp25 jan 2003
Cross-site scripting (XSS) vulnerability in guestbook.cgi in ftls.org Guestbook 1.1 allows remote attackers to inject ar
23RISCO
abrir
Exploit-DBVexDay Proof
GNU Mailman 2.1 - 'email' Cross-Site Scripting
CVE-2003-0038webappscgi24 jan 2003
Cross-site scripting (XSS) vulnerability in options.py for Mailman 2.1 allows remote attackers to inject script or HTML
23RISCO
abrir
Exploit-DBVexDay Proof
slocate 2.5/2.6 - Local Buffer Overrun
CVE-2003-0056doslinux24 jan 2003
Buffer overflow in secure locate (slocate) before 2.7 allows local users to execute arbitrary code via a long (1) -c or
23RISCO
abrir
Exploit-DBVexDay Proof
GNU Mailman 2.1 - Error Page Cross-Site Scripting
CVE-2003-0038webappscgi24 jan 2003
Cross-site scripting (XSS) vulnerability in options.py for Mailman 2.1 allows remote attackers to inject script or HTML
23RISCO
abrir
Exploit-DBVexDay Proof
List Site Pro 2.0 - User Database Delimiter Injection
CVE-2003-1350remotemultiple24 jan 2003
List Site Pro 2.0 allows remote attackers to hijack user accounts by inserting a "|" (pipe), which is used as a field de
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows XP/2000/NT 4.0 - Locator Service Buffer Overflow
CVE-2003-0003remotewindows22 jan 2003
Buffer overflow in the RPC Locator service for Microsoft Windows NT 4.0, Windows NT 4.0 Terminal Server Edition, Windows
35RISCO
abrir
Exploit-DBVexDay Proof
MTink 0.9.x - Printer Status Monitor Environment Variable Buffer Overflow
CVE-2003-0034locallinux21 jan 2003
Buffer overflow in the mtink status monitor, as included in the printer-drivers package in Mandrake Linux, allows local
23RISCO
abrir
Exploit-DBVexDay Proof
CVS 1.11.x - Directory Request Double-Free Heap Corruption
CVE-2003-0015remotelinux20 jan 2003
Double-free vulnerability in CVS 1.11.4 and earlier allows remote attackers to cause a denial of service and possibly ex
28RISCO
abrir
Exploit-DBVexDay Proof
phpBB 2.0.3 - 'privmsg.php' SQL Injection
CVE-2003-1530webappsphp17 jan 2003
SQL injection vulnerability in privmsg.php in phpBB 2.0.3 and earlier allows remote attackers to execute arbitrary SQL c
23RISCO
abrir
Exploit-DBVexDay Proof
GameSpy 3D 2.62 - Packet Amplification Denial of Service
CVE-2003-1354doslinux17 jan 2003
Multiple GameSpy 3D 2.62 compatible gaming servers generate very large UDP responses to small requests, which allows rem
23RISCO
abrir
Exploit-DBVexDay Proof
Trend Micro OfficeScan 3.x - CGI Directory Insufficient Permissions
CVE-2003-1341remotewindows15 jan 2003
The default installation of Trend Micro OfficeScan 3.0 through 3.54 and 5.x allows remote attackers to bypass authentica
23RISCO
abrir
Exploit-DBVexDay Proof
Trend Micro Virus Control System 1.8 - Information Disclosure
CVE-2003-1344remotewindows15 jan 2003
Trend Micro Virus Control System (TVCS) Log Collector allows remote attackers to obtain usernames, encrypted passwords,
23RISCO
abrir
Exploit-DBVexDay Proof
GLIBC locale - Format Strings
CVE-2000-0844locallinux15 jan 2003
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which
28RISCO
abrir
Exploit-DBVexDay Proof
Trend Micro ScanMail For Exchange 3.8 - Authentication Bypass
CVE-2003-1343remotewindows15 jan 2003
Trend Micro ScanMail for Exchange (SMEX) before 3.81 and before 6.1 might install a back door account in smg_Smxcfg30.ex
23RISCO
abrir
Exploit-DBVexDay Proof
Trend Micro Virus Control System 1.8 - Denial of Service
CVE-2003-1342doswindows15 jan 2003
Trend Micro Virus Control System (TVCS) 1.8 running with IIS allows remote attackers to cause a denial of service (memor
23RISCO
abrir
Exploit-DBVexDay Proof
Geeklog 1.3.7 - 'Homepage User' HTML Injection
CVE-2003-1347webappsphp14 jan 2003
Multiple cross-site scripting (XSS) vulnerabilities in Geeklog 1.3.7 allow remote attackers to inject arbitrary web scri
23RISCO
abrir
Exploit-DBVexDay Proof
Geeklog 1.3.7 - 'profiles.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2003-1347webappsphp14 jan 2003
Multiple cross-site scripting (XSS) vulnerabilities in Geeklog 1.3.7 allow remote attackers to inject arbitrary web scri
23RISCO
abrir
Exploit-DBVexDay Proof
Geeklog 1.3.7 - 'comment.php?cid' Cross-Site Scripting
CVE-2003-1347webappsphp14 jan 2003
Multiple cross-site scripting (XSS) vulnerabilities in Geeklog 1.3.7 allow remote attackers to inject arbitrary web scri
23RISCO
abrir
Exploit-DBVexDay Proof
Geeklog 1.3.7 - 'users.php?uid' Cross-Site Scripting
CVE-2003-1347webappsphp14 jan 2003
Multiple cross-site scripting (XSS) vulnerabilities in Geeklog 1.3.7 allow remote attackers to inject arbitrary web scri
23RISCO
abrir
Exploit-DBVexDay Proof
Opera 6.0/7.0 - opera.PluginContext Native Method Denial of Service
CVE-2003-1397doswindows13 jan 2003
The PluginContext object of Opera 6.05 and 7.0 allows remote attackers to cause a denial of service (crash) via an HTTP
23RISCO
abrir
Exploit-DBVexDay Proof
PHPPass 2 - 'AccessControl.php' SQL Injection
CVE-2003-1533webappsphp13 jan 2003
SQL injection vulnerability in accesscontrol.php in PhpPass 2 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
Exploit-DBVexDay Proof
Solaris 2.x/7.0/8 - Derived 'login' Remote Buffer Overflow
CVE-2001-0797remotesolaris09 jan 2003
Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary comman
60RISCO
abrir
Exploit-DBVexDay Proof
TANne 0.6.17 - Session Manager SysLog Format String
CVE-2003-1236remotelinux07 jan 2003
Multiple format string vulnerabilities in the logger function in netzio.c for Tanne 0.6.17 allows remote attackers to ex
28RISCO
abrir
Exploit-DBVexDay Proof
E-theni - Remote File Inclusion Command Execution
CVE-2003-1256webappsphp06 jan 2003
aff_liste_langue.php in E-theni allows remote attackers to execute arbitrary PHP code by modifying the rep_include param
23RISCO
abrir
Exploit-DBVexDay Proof
S8Forum 3.0 - Remote Command Execution
CVE-2003-1252webappsphp06 jan 2003
register.php in S8Forum 3.0 allows remote attackers to execute arbitrary PHP commands by creating a user whose name ends
23RISCO
abrir
Exploit-DBVexDay Proof
H-Sphere WebShell 2.4 - Remote Command Execution
CVE-2003-1247remotelinux06 jan 2003
Multiple buffer overflows in H-Sphere WebShell 2.3 allow remote attackers to execute arbitrary code via (1) a long URL c
23RISCO
abrir
Exploit-DBVexDay Proof
AN HTTPD 1.41 e - Cross-Site Scripting
CVE-2003-1271remotemultiple06 jan 2003
Cross-site scripting vulnerability (XSS) in AN HTTP 1.41e allows remote attackers to execute arbitrary web script or HTM
23RISCO
abrir
Exploit-DBVexDay Proof
OpenTopic 2.3.1 - Private Message HTML Injection
CVE-2003-1278webappsphp06 jan 2003
Cross-site scripting vulnerability (XSS) in OpenTopic 2.3.1 allows remote attackers to execute arbitrary script as other
23RISCO
abrir
anteriorpágina 738 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.