Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.137exploits catalogados
35.961CVEs com exploração pública
24.695testados em laboratório
24.458 exploits
Exploit-DBVexDay Proof
PlanetWeb 1.14 - GET Buffer Overflow
CVE-2002-1489doswindows16 set 2002
Buffer overflow in PlanetDNS PlanetWeb 1.14 and earlier allows remote attackers to execute arbitrary code via (1) an HTT
28RISCO
abrir
Exploit-DBVexDay Proof
WMNet2 1.0 6 - Kernel Memory File Descriptor Leakage
CVE-2002-1125localfreebsd16 set 2002
FreeBSD port programs that use libkvm for FreeBSD 4.6.2-RELEASE and earlier, including (1) asmon, (2) ascpu, (3) bubblem
23RISCO
abrir
Exploit-DBVexDay Proof
BubbleMon 1.x Kernel - Memory File Descriptor Leakage
CVE-2002-1125localunix16 set 2002
FreeBSD port programs that use libkvm for FreeBSD 4.6.2-RELEASE and earlier, including (1) asmon, (2) ascpu, (3) bubblem
23RISCO
abrir
Exploit-DBVexDay Proof
ASCPU 0.60 Kernel - Memory File Descriptor Leakage
CVE-2002-1125localunix16 set 2002
FreeBSD port programs that use libkvm for FreeBSD 4.6.2-RELEASE and earlier, including (1) asmon, (2) ascpu, (3) bubblem
23RISCO
abrir
Exploit-DBVexDay Proof
Savant Web Server 3.1 - File Disclosure
CVE-2002-2145remotewindows13 set 2002
Savant Web Server 3.1 and earlier allows remote attackers to bypass authentication for password protected user folders v
23RISCO
abrir
Exploit-DBVexDay Proof
BRU 17.0 - XBRU Insecure Temporary File
CVE-2002-1512locallinux13 set 2002
xbru in BRU Workstation 17.0 allows local users to overwrite arbitrary files and gain root privileges via a symlink atta
23RISCO
abrir
Exploit-DBVexDay Proof
Enterasys SSR8000 SmartSwitch - Port Scan Denial of Service
CVE-2002-1501doshardware13 set 2002
The MPS functionality in Enterasys SSR8000 (Smart Switch Router) before firmware 8.3.0.10 allows remote attackers to cau
23RISCO
abrir
Exploit-DBVexDay Proof
Savant Web Server 3.1 - Malformed Content-Length Denial of Service
CVE-2002-1828doswindows13 set 2002
Savant Webserver 3.1 allows remote attackers to cause a denial of service (crash) via an HTTP GET request with a negativ
23RISCO
abrir
Exploit-DBVexDay Proof
Trillian Instant Messaging 0.x - Credential Encryption
CVE-2002-2162localwindows09 set 2002
Cerulean Studios Trillian 0.73 and earlier use weak encrypttion (XOR) for storing user passwords in .ini files in the Tr
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 5 - IFrame/Frame Cross-Site/Zone Script Execution
CVE-2002-1187remotewindows09 set 2002
Cross-site scripting vulnerability (XSS) in Internet Explorer 5.01 through 6.0 allows remote attackers to read and execu
28RISCO
abrir
Exploit-DBVexDay Proof
phpGB 1.x - SQL Injection
CVE-2002-1482webappsphp09 set 2002
SQL injection vulnerability in login.php for phpGB 1.20 and earlier, when magic_quotes_gpc is not enabled, allows remote
23RISCO
abrir
Exploit-DBVexDay Proof
WoltLab Burning Board 2.0 - SQL Injection
CVE-2002-1505webappsphp09 set 2002
SQL injection vulnerability in board.php for WoltLab Burning Board (wBB) 2.0 RC 1 and earlier allows remote attackers to
23RISCO
abrir
Exploit-DBVexDay Proof
PHPGB 1.1/1.2 - PHP Code Injection
CVE-2002-1481webappsphp09 set 2002
savesettings.php in phpGB 1.20 and earlier does not require authentication, which allows remote attackers to cause a den
23RISCO
abrir
Exploit-DBVexDay Proof
Alleged Outlook Express 5/6 Link - Denial of Service
CVE-2002-2164doswindows09 set 2002
Buffer overflow in Microsoft Outlook Express 5.0, 5.5, and 6.0 allows remote attackers to cause a denial of service (cra
28RISCO
abrir
Exploit-DBVexDay Proof
phpGB 1.1 - HTML Injection
CVE-2002-1480webappsphp09 set 2002
Cross-site scripting (XSS) vulnerability in phpGB before 1.20 allows remote attackers to inject arbitrary HTML or script
23RISCO
abrir
Exploit-DBVexDay Proof
Netris 0.3/0.4/0.5 - Remote Memory Corruption
CVE-2002-1566remotelinux09 set 2002
netris 0.5, and possibly other versions before 0.52, when running with the -w (wait) option, allows remote attackers to
23RISCO
abrir
Exploit-DBVexDay Proof
AFD 1.2.x - Working Directory Local Buffer Overflow / Local Privilege Escalation
CVE-2002-1503localunix04 set 2002
Buffer overflow in Automatic File Distributor (AFD) 1.2.14 and earlier allows local users to gain privileges via a long
23RISCO
abrir
Exploit-DBVexDay Proof
Super Site Searcher - Remote Command Execution
CVE-2002-2420webappscgi03 set 2002
site_searcher.cgi in Super Site Searcher allows remote attackers to execute arbitrary commands via shell metacharacters
23RISCO
abrir
Exploit-DBVexDay Proof
Aestiva HTML/OS 2.4 - Cross-Site Scripting
CVE-2002-1494webappscgi03 set 2002
Cross-site scripting (XSS) vulnerabilities in Aestiva HTML/OS allows remote attackers to insert arbitrary HTML or script
23RISCO
abrir
Exploit-DBVexDay Proof
Cisco VPN 3000 Series Concentrator Client - Authentication Denial of Service
CVE-2002-1101doshardware03 set 2002
Cisco VPN 3000 Concentrator 2.2.x, 3.6(Rel), and 3.x before 3.5.5, allows remote attackers to cause a denial of service
23RISCO
abrir
Exploit-DBVexDay Proof
NullLogic Null HTTPd 0.5 - Error Page Cross-Site Scripting
CVE-2002-1497remotemultiple02 set 2002
Cross-site scripting (XSS) vulnerability in Null HTTP Server 0.5.0 and earlier allows remote attackers to insert arbitra
23RISCO
abrir
Exploit-DBVexDay Proof
SWS Simple Web Server 0.0.3/0.0.4/0.1 - New Line Denial of Service
CVE-2002-2370doslinux02 set 2002
SWS web server 0.0.4, 0.0.3 and 0.1.0 allows remote attackers to cause a denial of service (crash) via a URL request tha
23RISCO
abrir
Exploit-DBVexDay Proof
FactoSystem Weblog 0.9/1.0/1.1 - Multiple SQL Injections
CVE-2002-1499webappsasp31 ago 2002
Multiple SQL injection vulnerabilities in FactoSystem CMS allows remote attackers to perform unauthorized database actio
23RISCO
abrir
Exploit-DBVexDay Proof
Linuxconf 1.1.x/1.2.x - Local Environment Variable Buffer Overflow (2)
CVE-2002-1506locallinux28 ago 2002
Buffer overflow in Linuxconf before 1.28r4 allows local users to execute arbitrary code via a long LINUXCONF_LANG enviro
23RISCO
abrir
Exploit-DBVexDay Proof
Linuxconf 1.1.x/1.2.x - Local Environment Variable Buffer Overflow (1)
CVE-2002-1506locallinux28 ago 2002
Buffer overflow in Linuxconf before 1.28r4 allows local users to execute arbitrary code via a long LINUXCONF_LANG enviro
23RISCO
abrir
Exploit-DBVexDay Proof
Webmin 0.x - 'RPC' Privilege Escalation
CVE-2002-2360remotelinux28 ago 2002
The RPC module in Webmin 0.21 through 0.99, when installed without root or admin privileges, allows remote attackers to
23RISCO
abrir
Exploit-DBVexDay Proof
Linuxconf 1.1.x/1.2.x - Local Environment Variable Buffer Overflow (3)
CVE-2002-1506locallinux28 ago 2002
Buffer overflow in Linuxconf before 1.28r4 allows local users to execute arbitrary code via a long LINUXCONF_LANG enviro
23RISCO
abrir
Exploit-DBVexDay Proof
HP-UX LPD 10.20/11.00/11.11 - Command Execution (Metasploit)
CVE-2002-1473remotehp-ux28 ago 2002
Multiple buffer overflows in lp subsystem for HP-UX 10.20 through 11.11 (11i) allow local users to cause a denial of ser
38RISCO
abrir
Exploit-DBVexDay Proof
mIRC 6.0 - Scripting ASCTime Buffer Overflow
CVE-2002-1456remotewindows27 ago 2002
Buffer overflow in mIRC 6.0.2 and earlier allows remote attackers to execute arbitrary code via a long $asctime value.
28RISCO
abrir
Exploit-DBVexDay Proof
Caldera X Server 7.1/8.0 - External Program Privileged Invocation
CVE-2002-0987localunix27 ago 2002
X server (Xsco) in OpenUNIX 8.0.0 and UnixWare 7.1.1 does not drop privileges before calling programs such as xkbcomp us
23RISCO
abrir
anteriorpágina 746 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.