Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.134exploits catalogados
35.960CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.657GitHub PoC 14.421VulnCheck XDB 8.773Nuclei 4.340Metasploit 3.485✓ só verificadosrecentespopularesrisco
24.458 exploits
Exploit-DB✓ VexDay Proof
Perception LiteServe 2.0 - CGI Source Disclosure
Perception LiteServe 2.0 through 2.0.1 allows remote attackers to obtain the source code of CGI scripts via an HTTP requ
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
LibHTTPD 1.2 - POST Buffer Overflow
Buffer overflow in the httpdProcessRequest function in LibHTTPD 1.2 allows remote attackers to cause a denial of service
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
phpBB Advanced Quick Reply Hack 1.0/1.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in quick_reply.php for phpBB Advanced Quick Reply Hack 1.0.0 and 1.1.0 allows re
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Key Focus KF Web Server 1.0.8 - Directory Traversal
Directory traversal vulnerability in KeyFocus web server 1.0.8 allows remote attackers to read arbitrary files for recog
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Light HTTPd 0.1 - 'GET' Buffer Overflow (2)
Buffer overflow in Light HTTPd (lhttpd) 0.1 allows remote attackers to execute arbitrary code via a long HTTP GET reques
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ISC BIND 8.3.x - OPT Record Large UDP Denial of Service
BIND 8.3.x through 8.3.3 allows remote attackers to cause a denial of service (termination due to assertion failure) via
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Light HTTPd 0.1 - 'GET' Buffer Overflow (1)
Buffer overflow in Light HTTPd (lhttpd) 0.1 allows remote attackers to execute arbitrary code via a long HTTP GET reques
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Traceroute-nanog 6 - Local Buffer Overflow
Buffer overflow in the get_origin function in traceroute-nanog allows attackers to execute arbitrary code via long WHOIS
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
W3Mail 1.0.6 - File Disclosure
Directory traversal vulnerability in viewAttachment.cgi in W3Mail 1.0.6 allows remote attackers to read arbitrary files
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
EZ Systems HTTPBench 1.1 - Information Disclosure
ezhttpbench.php in eZ httpbench 1.1 allows remote attackers to read arbitrary files via a full pathname in the AnalyseSi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Hotfoon Dialer 4.0 - Buffer Overflow (PoC)
Buffer overflow in hotfoon4.exe in Hotfoon 4.0 allows remote attackers to cause a denial of service (crash) and possibly
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Perception LiteServe 2.0.1 - Directory Query String Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Perception LiteServe 2.0.1 allows remote attackers to execute arbitrary web
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Perception LiteServe 2.0.1 - DNS Wildcard Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Perception LiteServe 2.0.1 allows remote attackers to execute arbitrary web
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Zeus Web Server 4.0/4.1 - Admin Interface Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Zeus Administration Server in Zeus Web Server 4.0 through 4.1r2 allows remot
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
QNX RTOS 6.2 - Application Packager Non-Explicit Path Execution
QNX Neutrino RTOS 6.2.0 uses the PATH environment variable to find and execute the cp program while operating at raised
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Simple Web Server 0.5.1 - File Disclosure
Peter Sandvik's Simple Web Server 0.5.1 and earlier allows remote attackers to bypass access restrictions for files via
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Lotus Domino 5.0.8-9 - Non-Existent NSF Database Banner Information Disclosure
Lotus Domino 5.0.9a and earlier, even when configured with the 'DominoNoBanner=1' option, allows remote attackers to obt
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CuteCast 1.2 - User Credential Disclosure
ArtsCore Studios CuteCast Forum 1.2 stores passwords in plaintext under the web document root, which allows remote attac
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Pine 4.x - 'From:' Heap Corruption
Pine 4.44 and earlier allows remote attackers to cause a denial of service (core dump and failed restart) via an email m
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
HP CIFS/9000 Server A.01.05/A.01.06 - Local Buffer Overflow
Buffer overflows in the cifslogin command for HP CIFS/9000 Client A.01.06 and earlier, based on the Sharity package, all
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
QNX 6.1 - 'TimeCreate' Local Denial of Service
The timer implementation in QNX RTOS 6.1.0 allows local users to cause a denial of service (hang) and possibly execute a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Northern Solutions Xeneo Web Server 2.1/2.2 - Denial of Service
Northern Solutions Xeneo Web Server 2.1.0.0, 2.0.759.6, and other versions before 2.1.5 allows remote attackers to cause
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Monkey HTTP Server 0.4/0.5 - Invalid POST Denial of Service
The Post_Method function in method.c for Monkey HTTP Daemon before 0.5.1 allows remote attackers to cause a denial of se
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Solaris 2.6/7/8 - 'TTYPROMPT in.telnet' Remote Authentication Bypass
Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary comman
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linksys BEFSR41 1.4x - 'Gozila.cgi' Denial of Service
The remote management web server for Linksys BEFSR41 EtherFast Cable/DSL Router before firmware 1.42.7 allows remote att
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP-Nuke 5.6 - 'modules.php' SQL Injection
SQL injection vulnerability in PHP-Nuke before 6.0 allows remote authenticated users to modify the database and gain pri
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linksys WAP11 1.3/1.4 / D-Link DI-804 4.68/Dl-704 2.56 b5 - Embedded HTTP Server Denial of Service
Buffer overflow in the Embedded HTTP server, as used in (1) D-Link DI-804 4.68, Dl-704 V2.56b6, and Dl-704 V2.56b5 and (
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Abuse 2.0 - Local Buffer Overflow
Buffer overflow in Abuse 2.00 and earlier allows local users to gain root privileges via a long -net command line argume
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Jason Orcutt Prometheus 3.0/4.0/6.0 - Remote File Inclusion
Prometheus 6.0 and earlier allows remote attackers to execute arbitrary PHP code via a modified PROMETHEUS_LIBRARY_BASE
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ION Script 1.4 - Remote File Disclosure
Directory traversal vulnerability in ion-p.exe (aka ion-p) allows remote attackers to read arbitrary files via (1) C: (d
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.