Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.124exploits catalogados
35.954CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.657GitHub PoC 14.411VulnCheck XDB 8.773Nuclei 4.340Metasploit 3.485✓ só verificadosrecentespopularesrisco
24.458 exploits
Exploit-DB✓ VexDay Proof
Mollensoft Software Enceladus Server Suite 3.9 - 'FTP' Buffer Overflow
Buffer overflow in Enceladus Server Suite 3.9 allows remote attackers to execute arbitrary code via a long CD (CWD) comm
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cobalt RaQ4 - Administrative Interface Command Execution
overflow.cgi CGI script in Sun Cobalt RaQ 4 with the SHP (Security Hardening Patch) installed allows remote attackers to
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Exim Internet Mailer 3.35/3.36/4.10 - Format String
Format string vulnerability in daemon.c for Exim 4.x through 4.10, and 3.x through 3.36, allows exim administrative user
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache 1.3.x + Tomcat 4.0.x/4.1.x mod_jk - Chunked Encoding Denial of Service
Tomcat 4.0 through 4.1.12, using mod_jk 1.2.1 module on Apache 1.3 through 1.3.27, allows remote attackers to cause a de
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SAP DB 7.3.00 - Symbolic Link
lserver in SAP DB 7.3 and earlier uses the current working directory to find and execute the lserversrv program, which a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
phpBB 2.0.3 - 'search.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in search.php in phpBB 2.0.3 and possibly earlier versions allows remote attack
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
3Com SuperStack 3 NBX 4.0/4.1 - FTPD Denial of Service
Buffer overflow in ftpd 5.4 in 3Com NBX 4.0.17 or ftpd 5.4.2 in 3Com NBX 4.1.4 allows remote attackers to cause a denial
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cyrus IMAPD 1.4/1.5.19/2.0.12/2.0.16/2.1.9/2.1.10 - Pre-Login Heap Corruption
Integer overflow in imapparse.c for Cyrus IMAP server 1.4 and 2.1.10 allows remote attackers to execute arbitrary code v
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Pserv 2.0 - HTTP Version Specifier Buffer Overflow
Buffer overflow in Pico Server (pServ) 2.0 beta 1 through beta 5 allows remote attackers to cause a denial of service (c
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Moby NetSuite 1.0/1.2 - POST Handler Buffer Overflow
Moby NetSuite allows remote attackers to cause a denial of service (crash) via an HTTP POST request with a (1) large int
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
YaBB 1 Gold SP 1 - 'YaBB.pl' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in YaBB.pl in Yet Another Bulletin Board (YaBB) 1 Gold SP 1 allows remote attac
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Lib CGI 0.1 - Include Buffer Overflow
Buffer overflow in the changevalue function in libcgi.h for Marcos Luiz Onisto Lib CGI 0.1 allows remote attackers to ex
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
BizDesign ImageFolio 2.x/3.0.1 - 'imageFolio.cgi?direct' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in BizDesign ImageFolio 3.01 and earlier allows remote attackers to execute arb
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
BizDesign ImageFolio 2.x/3.0.1 - 'nph-build.cgi' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in BizDesign ImageFolio 3.01 and earlier allows remote attackers to execute arb
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
News Evolution 1.0/2.0 - Include Undefined Variable Command Execution
PHP remote file inclusion vulnerability in News Evolution 2.0 allows remote attackers to execute arbitrary PHP commands
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
vBulletin 2.0.x/2.2.x - 'members2.php' Cross-Site Scripting
member2.php in vBulletin 2.2.9 and earlier does not properly restrict the $perpage variable to be an integer, which caus
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
XFree86 X11R6 3.3.x - Font Server Remote Buffer Overrun
Buffer overflow in Dispatch() routine for XFS font server (fs.auto) on Solaris 2.5.1 through 9 allows remote attackers t
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
acFTP 1.4 - Invalid Password Weak Authentication
acFTP 1.4 does not properly handle when an invalid password is provided by the user during authentication, which allows
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
vBulletin 2.0/2.2.x - 'memberlist.php' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Jelsoft vBulletin before 3.0 allows remote attackers to inject arbitrary web
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Rational ClearCase 4.1 - Portscan Denial of Service
Rational ClearCase 4.1, 2002.05, and possibly other versions allows remote attackers to cause a denial of service (crash
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Zeroo HTTP Server 1.5 - Directory Traversal (1)
Directory traversal vulnerability in Zeroo web server 1.5 allows remote attackers to read arbitrary files via a .. (dot
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Zeroo HTTP Server 1.5 - Directory Traversal (2)
Directory traversal vulnerability in Zeroo web server 1.5 allows remote attackers to read arbitrary files via a .. (dot
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Java Virtual Machine 3802 Series - Bytecode Verifier
The ByteCode Verifier component of Microsoft Virtual Machine (VM) build 5.0.3809 and earlier, as used in Windows and Int
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec Java! JustInTime Compiler 210.65 - Command Execution
Symantec Java! JIT (Just-In-Time) Compiler for Netscape Communicator 4.0 through 4.8 allows remote attackers to execute
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Mhonarc 2.5.x - Mail Header HTML Injection
Cross-site scripting vulnerability (XSS) in MHonArc 2.5.12 and earlier allows remote attackers to insert script or HTML
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
TFTPD32 2.50 - 'Filename' Remote Buffer Overflow
Buffer overflow in tftpd of TFTP32 2.21 and earlier allows remote attackers to execute arbitrary code via a long filenam
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
TFTPD32 2.50 - Arbitrary File Download/Upload
tftpd32 2.50 and 2.50.2 allows remote attackers to read or write arbitrary files via a full pathname in GET and PUT requ
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MailEnable 1.501x - Email Server Buffer Overflow
MailEnable 1.5 015 through 1.5 018 allows remote attackers to cause a denial of service (crash) via a long USER string,
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Lonerunner Zeroo HTTP Server 1.5 - Remote Buffer Overflow
Buffer overflow in the HttpGetRequest function in Zeroo HTTP server 1.5 allows remote attackers to execute arbitrary cod
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
IISPop 1.161/1.181 - Remote Buffer Overflow (Denial of Service) (PoC)
Buffer overflow in IISPop email server 1.161 and 1.181 allows remote attackers to cause a denial of service (crash) via
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.