Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.137exploits catalogados
35.961CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.657GitHub PoC 14.424VulnCheck XDB 8.773Nuclei 4.340Metasploit 3.485✓ só verificadosrecentespopularesrisco
24.458 exploits
Exploit-DB✓ VexDay Proof
Monkey HTTP Server 0.1.4 - File Disclosure
Directory traversal vulnerability in Monkey HTTP Daemon 0.1.4 allows remote attackers to read arbitrary files via .. (do
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Drupal 4.0 - News Message HTML Injection
Cross-site scripting (XSS) vulnerability in Drupal 4.0.0 allows remote attackers to inject arbitrary web script or HTML
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Tomcat 3/4 - 'DefaultServlet' File Disclosure
The default servlet (org.apache.catalina.servlets.DefaultServlet) in Tomcat 4.0.4 and 4.1.10 and earlier allows remote a
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
HP Procurve 4000M Switch - Device Reset Denial of Service
The HTTP administration interface for HP Procurve 4000M Switch firmware before C.09.16, with stacking features and remot
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache 2.0.39/40 - Oversized STDERR Buffer Denial of Service
mod_cgi in Apache 2.0.39 and 2.0.40 allows local users and possibly remote attackers to cause a denial of service (hang
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
XOOPS 1.0 RC3 - HTML Injection
Cross-site scripting (XSS) vulnerability in Xoops 1.0 RC3 allows remote attackers to inject arbitrary web script or HTML
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Null HTTPd 0.5 - Remote Heap Overflow
Heap-based buffer overflow in Null HTTP Server 0.5.0 and earlier allows remote attackers to execute arbitrary code via a
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Rudi Benkovic JAWMail 1.0 - Script Injection
Cross-site scripting (XSS) vulnerability in JAWmail 1.0-rc1 allows remote attackers to insert arbitrary script or HTML v
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
phpWebSite 0.8.2 - PHP File Inclusion
modsecurity.php 1.10 and earlier, in phpWebSite 0.8.2 and earlier, allows remote attackers to execute arbitrary PHP sour
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
HP Compaq Insight Manager - Web Interface Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Compaq Insight Management Agents 2.0, 2.1, 3.6.0, 4.2 and 4.3.7 allows remot
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Trillian 0.74 - IRC PART Message Denial of Service
The IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service (crash) via
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Trillian 0.74 - IRC Oversized Data Block Buffer Overflow
Multiple buffer overflows in the IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Trillian 0.74 - IRC Raw Messages Denial of Service
The IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a denial of service (crash) by
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OSX 10.2 - Terminal.APP Telnet Link Command Execution
Terminal 1.3 in Apple Mac OS X 10.2 allows remote attackers to execute arbitrary commands via shell metacharacters in a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Trillian 0.725/0.73/0.74 - IRC User Mode Numeric Remote Buffer Overflow
Multiple buffer overflows in the IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Trillian 0.73/0.74 - IRC JOIN Buffer Overflow
Multiple buffer overflows in the IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Word 95/97/98/2000/2002 - 'INCLUDEPICTURE' Document Sharing File Disclosure
Microsoft Word and Excel allow remote attackers to steal sensitive information via certain field codes that insert the i
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
AlsaPlayer 0.99.71 - Local Buffer Overflow
Buffer overflow in Alsaplayer 0.99.71, when installed setuid root, allows local users to execute arbitrary code via a lo
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Trillian 0.73/0.74 - IRC PRIVMSG Buffer Overflow
Multiple buffer overflows in the IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SquirrelMail 1.2.6/1.2.7 - Multiple Cross-Site Scripting Vulnerabilities
Cross-site scripting vulnerabilities in SquirrelMail 1.2.7 and earlier allows remote attackers to execute script as othe
43RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft VM 2000/3000/3100/3188/3200/3300/3802/3805 series - JDBC Class Code Execution
Java Database Connectivity (JDBC) classes in Microsoft Virtual Machine (VM) up to and including 5.0.3805 allow remote at
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco VPN 5000 Client - Buffer Overrun (2)
Buffer overflows in the Cisco VPN 5000 Client before 5.2.7 for Linux, and VPN 5000 Client before 5.2.8 for Solaris, allo
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco VPN 5000 Client - Buffer Overrun (1)
Buffer overflows in the Cisco VPN 5000 Client before 5.2.7 for Linux, and VPN 5000 Client before 5.2.8 for Solaris, allo
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Trillian 0.6351/0.7x - Identd Buffer Overflow
Multiple buffer overflows in the IRC component of Trillian 0.73 and 0.74 allows remote malicious IRC servers to cause a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Lycos HTMLGear - guestGear CSS HTML Injection
Cross-site scripting (XSS) vulnerability in Lycos HTMLGear guestbook allows remote attackers to inject arbitrary script
23RISCO
abrir ↗Exploit-DB
Apache mod_ssl OpenSSL < 0.9.6d / < 0.9.7-beta2 - 'openssl-too-open.c' SSL2 KEY_ARG Overflow
Buffer overflows in OpenSSL 0.9.6d and earlier, and 0.9.7-beta2 and earlier, allow remote attackers to execute arbitrary
45RISCO
abrir ↗Exploit-DB✓ VexDay Proof
DB4Web 3.4/3.6 - Connection Proxy
DB4Web server, when configured to use verbose debug messages, allows remote attackers to use DB4Web as a proxy and attem
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
TCP SYN - 'bang.c' Denial of Service
Denial of service when an attacker sends many SYN packets to create multiple connections without ever sending an ACK to
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
DB4Web 3.4/3.6 - File Disclosure
db4web_c and db4web_c.exe programs in DB4Web 3.4 and 3.6 allow remote attackers to read arbitrary files via an HTTP requ
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PlanetWeb 1.14 - GET Buffer Overflow
Buffer overflow in PlanetDNS PlanetWeb 1.14 and earlier allows remote attackers to execute arbitrary code via (1) an HTT
28RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.