Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.137exploits catalogados
35.961CVEs com exploração pública
24.695testados em laboratório
24.458 exploits
Exploit-DBVexDay Proof
Cisco CatOS 5.x/6.1/7.3/7.4 - CiscoView HTTP Server Buffer Overflow
CVE-2002-1222remotehardware16 out 2002
Buffer overflow in the embedded HTTP server for Cisco Catalyst switches running CatOS 5.4 through 7.3 allows remote atta
23RISCO
abrir
Exploit-DBVexDay Proof
Ingenium Learning Management System 5.1/6.1 - Reversible Password Hash
CVE-2002-1910remotemultiple15 out 2002
Click2Learn Ingenium Learning Management System 5.1 and 6.1 uses weak encryption for passwords (reversible algorithm), w
23RISCO
abrir
Exploit-DBVexDay Proof
TelCondex SimpleWebserver 2.0.6 - Denial of Service
CVE-2002-1907doswindows15 out 2002
TelCondex SimpleWebServer 2.06.20817 allows remote attackers to cause a denial of service (crash) via a long HTTP GET re
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 5/6 - Unauthorized Document Object Model Access
CVE-2002-1217remotewindows15 out 2002
Cross-Frame scripting vulnerability in the WebBrowser control as used in Internet Explorer 5.5 and 6.0 allows remote att
35RISCO
abrir
Exploit-DBVexDay Proof
Polycom 2.2/3.0 - ViaVideo Buffer Overflow
CVE-2002-1905doswindows15 out 2002
Buffer overflow in the web server of Polycom ViaVideo 2.2 and 3.0 allows remote attackers to cause a denial of service (
23RISCO
abrir
Exploit-DBVexDay Proof
Polycom ViaVideo 2.2/3.0 - Denial of Service
CVE-2002-1906doshardware15 out 2002
The web server for Polycom ViaVideo 2.2 and 3.0 allows remote attackers to cause a denial of service (CPU consumption) b
23RISCO
abrir
Exploit-DBVexDay Proof
PHP 4 - 'PHPInfo()' Cross-Site Scripting
CVE-2002-1954webappsphp12 out 2002
Cross-site scripting (XSS) vulnerability in the phpinfo function in PHP 4.2.3 allows remote attackers to inject arbitrar
28RISCO
abrir
Exploit-DBVexDay Proof
My Web Server 1.0.1/1.0.2 - GET Denial of Service
CVE-2002-1897doswindows12 out 2002
MyWebServer LLC MyWebServer 1.0.2 allows remote attackers to cause a denial of service (crash) via a long HTTP request,
23RISCO
abrir
Exploit-DBVexDay Proof
KDE 3.0.x - KPF Icon Option File Disclosure
CVE-2002-1224remotelinux11 out 2002
Directory traversal vulnerability in kpf for KDE 3.0.1 through KDE 3.0.3a allows remote attackers to read arbitrary file
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Outlook Express 5.5/6.0 - S/MIME Buffer Overflow
CVE-2002-1179remotewindows10 out 2002
Buffer overflow in the S/MIME Parsing capability in Microsoft Outlook Express 5.5 and 6.0 allows remote attackers to exe
28RISCO
abrir
Exploit-DBVexDay Proof
PHPBBMod 1.3.3 - PHPInfo Information Disclosure
CVE-2002-2349webappsphp10 out 2002
phpinfo.php in phpBBmod 1.3.3 executes the phpinfo function, which allows remote attackers to obtain sensitive environme
23RISCO
abrir
Exploit-DBVexDay Proof
PHPRank 1.8 - 'add.php' Cross-Site Scripting
CVE-2002-1799webappsphp10 out 2002
Cross-site scripting (XSS) vulnerability in phpRank 1.8 allows remote attackers to inject arbitrary web script or HTML v
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Content Management Server 2001 - Cross-Site Scripting
CVE-2003-0002webappsasp09 out 2002
Cross-site scripting vulnerability (XSS) in ManualLogin.asp script for Microsoft Content Management Server (MCMS) 2001 a
28RISCO
abrir
Exploit-DBVexDay Proof
Authoria HR Suite - 'AthCGI.exe' Cross-Site Scripting
CVE-2002-2348webappscgi09 out 2002
Cross-site scripting (XSS) vulnerability in athcgi.exe in Authoria HR allows remote attackers to inject arbitrary web sc
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows XP/2000/NT 4.0 - NetDDE Privilege Escalation (2)
CVE-2002-1230localwindows09 out 2002
NetDDE Agent on Windows NT 4.0, 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows XP/2000/NT 4.0 - NetDDE Privilege Escalation (1)
CVE-2002-1230localwindows09 out 2002
NetDDE Agent on Windows NT 4.0, 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute
23RISCO
abrir
Exploit-DBVexDay Proof
SurfControl SuperScout Email Filter 3.5 - User Credential Disclosure
CVE-2002-1530webappsasp08 out 2002
The administrative web interface (STEMWADM) for SurfControl SuperScout Email Filter allows users to obtain usernames and
23RISCO
abrir
Exploit-DBVexDay Proof
Sendmail 8.12.6 - Compromised Source Backdoor
CVE-1999-0661remoteunix08 out 2002
A system is running a version of software that was replaced with a Trojan Horse at one of its distribution points, such
35RISCO
abrir
Exploit-DBVexDay Proof
Symantec Norton Personal Firewall 2002/Kaspersky Labs Anti-Hacker 1.0/BlackIce Server Protection 3.5/BlackICE Defender 2.9 - Auto Block Denial of Service
CVE-2002-2336doswindows08 out 2002
Norton Personal Firewall 2002 4.0, when configured to automatically block attacks, allows remote attackers to block IP a
23RISCO
abrir
Exploit-DBVexDay Proof
SurfControl SuperScout Email Filter 3.5 - 'MsgError.asp' Cross-Site Scripting
CVE-2002-1529webappsasp08 out 2002
Cross-site scripting (XSS) vulnerability in msgError.asp for the administrative web interface (STEMWADM) for SurfControl
23RISCO
abrir
Exploit-DBVexDay Proof
SSGBook 1.0 - Image Tag HTML Injection
CVE-2002-2339webappsasp08 out 2002
Cross-site scripting (XSS) vulnerability in configure.asp in Script-Shed GuestBook 1.0 allows remote attackers to inject
23RISCO
abrir
Exploit-DBVexDay Proof
ghttpd 1.4.x - 'Log()' Remote Buffer Overflow
CVE-2001-0820remotelinux07 out 2002
Buffer overflows in GazTek ghttpd 1.4 allows a remote attacker to execute arbitrary code via long arguments that are pas
28RISCO
abrir
Exploit-DBVexDay Proof
Killer Protection 1.0 - Information Disclosure
CVE-2002-2335webappsphp07 out 2002
Killer Protection 1.0 stores the vars.inc include file under the web root with insufficient access control, which allows
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows XP/2000/NT 4.0 - Help Facility ActiveX Control Buffer Overflow
CVE-2002-0693remotewindows07 out 2002
Buffer overflow in the HTML Help ActiveX Control (hhctrl.ocx) in Microsoft Windows 98, 98 Second Edition, Millennium Edi
35RISCO
abrir
Exploit-DBVexDay Proof
Oracle 9i Application Server 9.0.2 Web Cache Administration Tool - Denial of Service
CVE-2002-0386dosmultiple06 out 2002
The administration module for Oracle Web Cache in Oracle9iAS (9i Application Suite) 9.0.2 allows remote attackers to cau
28RISCO
abrir
Exploit-DBVexDay Proof
ATP HTTPd 0.4 - Single Byte Buffer Overflow
CVE-2002-1816CRITICALremotelinux05 out 2002
Off-by-one buffer overflow in the sock_gets function in sockhelp.c for ATPhttpd 0.4b and earlier allows remote attackers
48RISCO
abrir
Exploit-DBVexDay Proof
Cooolsoft PowerFTP Server 2.x - Remote Denial of Service (3)
CVE-2002-1522doswindows05 out 2002
Buffer overflow in PowerFTP FTP server 2.24, and possibly other versions, allows remote attackers to cause a denial of s
28RISCO
abrir
Exploit-DBVexDay Proof
Cooolsoft PowerFTP Server 2.x - Remote Denial of Service (1)
CVE-2002-1522doswindows05 out 2002
Buffer overflow in PowerFTP FTP server 2.24, and possibly other versions, allows remote attackers to cause a denial of s
28RISCO
abrir
Exploit-DBVexDay Proof
Cooolsoft PowerFTP Server 2.x - Remote Denial of Service (2)
CVE-2002-1522doswindows05 out 2002
Buffer overflow in PowerFTP FTP server 2.24, and possibly other versions, allows remote attackers to cause a denial of s
28RISCO
abrir
Exploit-DBVexDay Proof
phpLinkat 0.1 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2002-2321webappsphp04 out 2002
Cross-site scripting (XSS) vulnerability in (1) showcat.php and (2) addyoursite.php in phpLinkat 0.1.0 allows remote att
23RISCO
abrir
anteriorpágina 743 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.