Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.137exploits catalogados
35.961CVEs com exploração pública
24.695testados em laboratório
24.458 exploits
Exploit-DBVexDay Proof
Cacheflow CacheOS 3.1.x/4.0.x/4.1 - Unresolved Domain Cross-Site Scripting
CVE-2002-1060remotemultiple24 jul 2002
Cross-site scripting (XSS) vulnerability in Blue Coat Systems (formerly CacheFlow) CacheOS on Client Accelerator 4.1.06,
23RISCO
abrir
Exploit-DBVexDay Proof
GNU Mailman 2.0.x - Admin Login Variant Cross-Site Scripting
CVE-2002-0855remotecgi24 jul 2002
Cross-site scripting vulnerability in Mailman before 2.0.12 allows remote attackers to execute script as other users via
23RISCO
abrir
Exploit-DBVexDay Proof
CodeBlue 5.1 - SMTP Response Buffer Overflow
CVE-2002-0280remotewindows24 jul 2002
Buffer overflow in CodeBlue 4 and earlier, and possibly other versions, allows remote attackers to execute arbitrary cod
23RISCO
abrir
Exploit-DBVexDay Proof
Pegasus Mail 4.0 1 - Message Header Buffer Overflow
CVE-2002-1075remotewindows24 jul 2002
Buffer overflow in Pegasus mail client 4.01 and earlier allows remote attackers to cause a denial of service (crash) and
23RISCO
abrir
Exploit-DBVexDay Proof
Pine 4.x - Empty MIME Boundary Denial of Service
CVE-2002-2325dosunix24 jul 2002
The c-client library in Internet Message Access Protocol (IMAP) dated before 2002 RC2, as used by Pine 4.20 through 4.44
23RISCO
abrir
Exploit-DBVexDay Proof
VMware GSX Server 2.0 - Authentication Server Buffer Overflow
CVE-2002-0814remotewindows24 jul 2002
Buffer overflow in VMware Authorization Service for VMware GSX Server 2.0.0 build-2050 allows remote authenticated users
28RISCO
abrir
Exploit-DBVexDay Proof
Cobalt Qube 3.0 - Authentication Bypass
CVE-2002-1058webappsphp24 jul 2002
Directory traversal vulnerability in splashAdmin.php for Cobalt Qube 3.0 allows local users and remote attackers, to gai
23RISCO
abrir
Exploit-DBVexDay Proof
GNU Mailman 2.0.x - Subscribe Cross-Site Scripting
CVE-2002-0855remotecgi24 jul 2002
Cross-site scripting vulnerability in Mailman before 2.0.12 allows remote attackers to execute script as other users via
23RISCO
abrir
Exploit-DBVexDay Proof
SecureCRT 2.4/3.x/4.0 - SSH1 Identifier String Buffer Overflow (2)
CVE-2002-1059remotewindows23 jul 2002
Buffer overflow in Van Dyke SecureCRT SSH client before 3.4.6, and 4.x before 4.0 beta 3, allows an SSH server to execut
50RISCO
abrir
Exploit-DBVexDay Proof
SecureCRT 2.4/3.x/4.0 - SSH1 Identifier String Buffer Overflow (1)
CVE-2002-1059doswindows23 jul 2002
Buffer overflow in Van Dyke SecureCRT SSH client before 3.4.6, and 4.x before 4.0 beta 3, allows an SSH server to execut
50RISCO
abrir
Exploit-DBVexDay Proof
Opera 6.0.1 / Microsoft Internet Explorer 5/6 - JavaScript Modifier Keypress Event Subversion
CVE-2002-2312remotewindows23 jul 2002
Opera 6.0.1 allows remote attackers to upload arbitrary file contents when users press a key corresponding to the JavaSc
23RISCO
abrir
Exploit-DBVexDay Proof
PHP Interpreter 3.0.x/4.0.x/4.1/4.2 - Direct Invocation Denial of Service
CVE-2002-2309dosunix22 jul 2002
php.exe in PHP 3.0 through 4.2.2, when running on Apache, does not terminate properly, which allows remote attackers to
23RISCO
abrir
Exploit-DBVexDay Proof
Working Resources 1.7.x BadBlue - Administrative Interface Arbitrary File Access
CVE-2002-2170remotewindows20 jul 2002
Working Resources Inc. BadBlue Enterprise Edition 1.7 through 1.74 attempts to restrict administrator actions to the IP
23RISCO
abrir
Exploit-DBVexDay Proof
SmartMax MailMax 4.8 - Popmax Buffer Overflow
CVE-2002-1057remotewindows20 jul 2002
Buffer overflow in SmartMax MailMax POP3 daemon (popmax) 4.8 allows remote attackers to execute arbitrary code via a lon
23RISCO
abrir
Exploit-DBVexDay Proof
Adobe eBook Reader 2.2 - File Restoration Privilege Escalation
CVE-2002-1016localwindows19 jul 2002
Adobe eBook Reader allows a user to bypass restrictions for copy, print, lend, and give operations by backing up key dat
23RISCO
abrir
Exploit-DBVexDay Proof
Oracle Reports Server 6.0.8/9.0.2 - Information Disclosure
CVE-2002-1089remotemultiple18 jul 2002
rwcgi60 CGI program in Oracle Reports Server, by design, provides sensitive information such as the full pathname, which
23RISCO
abrir
Exploit-DBVexDay Proof
Trend Micro Interscan VirusWall for Windows NT 3.52 - Space Gap Scan Bypass
CVE-2002-0637remotewindows18 jul 2002
InterScan VirusWall 3.52 build 1462 allows remote attackers to bypass virus protection via e-mail messages with headers
23RISCO
abrir
Exploit-DBVexDay Proof
ZYXEL Prestige 642R Router - Malformed Packet Denial of Service
CVE-2002-1071doshardware17 jul 2002
ZyXEL Prestige 642R allows remote attackers to cause a denial of service in the Telnet, FTP, and DHCP services (crash) v
23RISCO
abrir
Exploit-DBVexDay Proof
Macromedia Sitespring 1.2 - Default Error Page Cross-Site Scripting
CVE-2002-1027webappsjsp17 jul 2002
Cross-site scripting vulnerability in the default HTTP 500 error script (500error.jsp) for Macromedia Sitespring 1.2.0 (
23RISCO
abrir
Exploit-DBVexDay Proof
PHP-Wiki 1.2/1.3 - Cross-Site Scripting
CVE-2002-1070webappsphp17 jul 2002
Cross-site scripting vulnerability in PHPWiki Postnuke wiki module allows remote attackers to execute script as other PH
23RISCO
abrir
Exploit-DBVexDay Proof
3.3/4.0/4.2 MERCUR MailServer - Control-Service Buffer Overflow
CVE-2002-1073remotewindows16 jul 2002
Buffer overflow in the control service for MERCUR Mailserver 4.2 allows remote attackers to execute arbitrary code via a
23RISCO
abrir
Exploit-DBVexDay Proof
Oddsock Song Requester 2.1 WinAmp Plugin - Denial of Service
CVE-2002-1028doscgi16 jul 2002
Multiple buffer overflows in the CGI programs for Oddsock Song Requester WinAmp plugin 2.1 allow remote attackers to cau
23RISCO
abrir
Exploit-DBVexDay Proof
AOL Instant Messenger 4.x - Unauthorized Actions
CVE-2002-2169remotewindows16 jul 2002
Cross-site scripting vulnerability AOL Instant Messenger (AIM) 4.5 and 4.7 for MacOS and Windows allows remote attackers
23RISCO
abrir
Exploit-DBVexDay Proof
IMHO Webmail 0.9x - Account Hijacking
CVE-2002-2165webappscgi15 jul 2002
The IMHO Webmail module 0.97.3 and earlier for Roxen leaks the REFERER from the browser's previous login session in an e
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft IIS 4.0/5.0 - SMTP Service Encapsulated SMTP Address (MS99-027)
CVE-2002-1790remotewindows12 jul 2002
The SMTP service in Microsoft Internet Information Services (IIS) 4.0 and 5.0 allows remote attackers to bypass anti-rel
35RISCO
abrir
Exploit-DBVexDay Proof
Real Networks RealJukebox 1.0.2/RealOne 6.0.10 Player Gold - Skinfile Buffer Overflow
CVE-2002-1014remotewindows12 jul 2002
Buffer overflow in RealJukebox 2 1.0.2.340 and 1.0.2.379, and RealOne Player Gold 6.0.10.505, allows remote attackers to
23RISCO
abrir
Exploit-DBVexDay Proof
Ultrafunk Popcorn 1.20 - Multiple Denial of Service Vulnerabilities
CVE-2002-1043doswindows11 jul 2002
Ultrafunk Popcorn 1.20 allows remote attackers to cause a denial of service (crash) via a malformed Subject ("\t\t").
23RISCO
abrir
Exploit-DBVexDay Proof
Summit Computer Networks Lil' HTTP Server 2.1/2.2 - 'pbcgi.cgi' Cross-Site Scripting
CVE-2002-1009remotewindows11 jul 2002
Cross-site scripting vulnerability in PowerBASIC pbcgi.cgi, as included in Lil' HTTP web server, allows remote attackers
23RISCO
abrir
Exploit-DBVexDay Proof
Sun i-Runbook 2.5.2 - Directory and File Content Disclosure
CVE-2002-1034webappsphp11 jul 2002
none.php for SunPS iRunbook 2.5.2 allows remote attackers to read arbitrary files via an absolute pathname in the argume
23RISCO
abrir
Exploit-DBVexDay Proof
Sun i-Runbook 2.5.2 - Directory and File Content Disclosure
CVE-2002-1033webappsphp11 jul 2002
Directory traversal vulnerability in none.php for SunPS iRunbook 2.5.2 allows remote attackers to read arbitrary files v
23RISCO
abrir
anteriorpágina 750 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.