Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.101exploits catalogados
35.950CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.657GitHub PoC 14.406VulnCheck XDB 8.755Nuclei 4.340Metasploit 3.485✓ só verificadosrecentespopularesrisco
24.458 exploits
Exploit-DB✓ VexDay Proof
S8Forum 3.0 - Remote Command Execution
register.php in S8Forum 3.0 allows remote attackers to execute arbitrary PHP commands by creating a user whose name ends
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
EType EServ 1.9x - NNTP Remote Denial of Service
The (1) FTP, (2) POP3, (3) SMTP, and (4) NNTP servers in EServer 2.92 through 2.97, and possibly 2.98, allow remote atta
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
EType EServ 2.9x - POP3 Remote Denial of Service
The (1) FTP, (2) POP3, (3) SMTP, and (4) NNTP servers in EServer 2.92 through 2.97, and possibly 2.98, allow remote atta
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
EType EServ 2.9x - FTP Remote Denial of Service
The (1) FTP, (2) POP3, (3) SMTP, and (4) NNTP servers in EServer 2.92 through 2.97, and possibly 2.98, allow remote atta
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
EType EServ 2.9x - SMTP Remote Denial of Service
The (1) FTP, (2) POP3, (3) SMTP, and (4) NNTP servers in EServer 2.92 through 2.97, and possibly 2.98, allow remote atta
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Pocket Internet Explorer 3.0 - Denial of Service
Pocket Internet Explorer (PIE) 3.0 allows remote attackers to cause a denial of service (crash) via a Javascript functio
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
iCal 3.7 - Remote Buffer Overflow (PoC)
ICAL.EXE in iCal 3.7 allows remote attackers to cause a denial of service (crash) via a malformed HTTP request, possibly
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Server 2000 - Lanman Denial of Service (2)
LANMAN service on Microsoft Windows 2000 allows remote attackers to cause a denial of service (CPU/memory exhaustion) vi
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Sun Solaris 2.5.1/2.6/7.0/8/9 Wall - Spoofed Message Origin
rpc.walld (wall daemon) for Solaris 2.6 through 9 allows local users to send messages to logged on users that appear to
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
iCal 3.7 - HTTP Request Denial of Service
ICAL.EXE in iCal 3.7 allows remote attackers to cause a denial of service (crash) via a malformed HTTP request, possibly
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
N/X Web Content Management System 2002 Prerelease 1 - 'datasets.php?c_path' Local File Inclusion
The (1) menu.inc.php, (2) datasets.php and (3) mass_operations.inc.php (mistakenly referred to as mass_opeations.inc.php
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
N/X Web Content Management System 2002 Prerelease 1 - 'menu.inc.php?c_path' Remote File Inclusion
The (1) menu.inc.php, (2) datasets.php and (3) mass_operations.inc.php (mistakenly referred to as mass_opeations.inc.php
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PEEL 1.0b - Remote File Inclusion
haut.php in PEEL 1.0b allows remote attackers to execute arbitrary PHP code by modifying the dirroot parameter to refere
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Emacs 2.1 - Local Variable Arbitrary Command Execution
Emacs 21.2.1 does not prompt or warn the user before executing Lisp code in the local variables section of a text file,
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Melange Chat Server 1.10 - Remote Buffer Overflow
Buffer overflow in Melange Chat System 1.10 allows remote attackers to cause a denial of service (chat server crash) and
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
W-Agora 4.1.6 - 'EditForm.php' Cross-Site Scripting
Cross-site scripting vulnerability (XSS) in editform.php for w-Agora 4.1.5 allows remote attackers to execute arbitrary
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CHETCPASSWD 1.12 - Shadow File Disclosure
chetcpasswd.cgi in Pedro Lineu Orso chetcpasswd before 2.1 allows remote attackers to read the last line of the shadow f
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
RealServer 7-9 - Describe Buffer Overflow (Metasploit)
Multiple buffer overflows in RealNetworks Helix Universal Server 9.0 (9.0.2.768) allow remote attackers to execute arbit
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CUPS 1.1.x - Negative Length HTTP Header
Common Unix Printing System (CUPS) 1.1.14 through 1.1.17 allows remote attackers to cause a denial of service (crash) an
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.2 - 'mmap()' Local Denial of Service
Linux kernel 2.2.x allows local users to cause a denial of service (crash) by using the mmap() function with a PROT_READ
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
GoAhead Web Server 2.1.x - '.ASP' File Source Code Disclosure
GoAhead Web Server 2.1.7 and earlier allows remote attackers to obtain the source code of ASP files via a URL terminated
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MySQL 3.23.x/4.0.x - 'COM_CHANGE_USER' Password Length Account
The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x before 4.0.6, allows remote attackers to gain privilege
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MyPHPSoft MyPHPLinks 2.1.9/2.2 - SQL Injection Administration Bypassing
SQL injection vulnerability in admin/auth/checksession.php in MyPHPLinks 2.1.9 and 2.2.0 allows remote attackers to exec
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MySQL 3.23.x/4.0.x - COM_CHANGE_USER Password Memory Corruption
The COM_CHANGE_USER command in MySQL 3.x before 3.23.54, and 4.x to 4.0.6, allows remote attackers to execute arbitrary
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Mambo Site Server 4.0.11 - 'PHPInfo.php' Information Disclosure
The administrator/phpinfo.php script in Mambo Site Server 4.0.11 allows remote attackers to obtain sensitive information
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Mambo Site Server 4.0.11 - Full Path Disclosure
Mambo Site Server 4.0.11 allows remote attackers to obtain the physical path of the server via an HTTP request to index.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Deerfield VisNetic WebSite 3.5.13.1 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in VisNetic Website before 3.5.15 allows remote attackers to inject arbitrary w
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
HP-UX 11.0/11.11 - 'swxxx' Privilege Escalation
Buffer overflow in swverify in HP-UX 11.0, and possibly other programs, allows local users to gain privileges via a long
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
HP-UX 11 - Software Distributor Lang Environment Variable Local Buffer Overrun
Buffer overflow in the Software Distributor utilities for HP-UX B.11.00 and B.11.11 allows local users to execute arbitr
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Trend Micro PC-cillin 2000/2002/2003 - Mail Scanner Buffer Overflow
Buffer overflow in pop3trap.exe for PC-cillin 2000, 2002, and 2003 allows local users to execute arbitrary code via a lo
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.