Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.137exploits catalogados
35.961CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.657GitHub PoC 14.424VulnCheck XDB 8.773Nuclei 4.340Metasploit 3.485✓ só verificadosrecentespopularesrisco
24.458 exploits
Exploit-DB✓ VexDay Proof
Cacheflow CacheOS 3.1.x/4.0.x/4.1 - Unresolved Domain Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Blue Coat Systems (formerly CacheFlow) CacheOS on Client Accelerator 4.1.06,
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
GNU Mailman 2.0.x - Admin Login Variant Cross-Site Scripting
Cross-site scripting vulnerability in Mailman before 2.0.12 allows remote attackers to execute script as other users via
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CodeBlue 5.1 - SMTP Response Buffer Overflow
Buffer overflow in CodeBlue 4 and earlier, and possibly other versions, allows remote attackers to execute arbitrary cod
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Pegasus Mail 4.0 1 - Message Header Buffer Overflow
Buffer overflow in Pegasus mail client 4.01 and earlier allows remote attackers to cause a denial of service (crash) and
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Pine 4.x - Empty MIME Boundary Denial of Service
The c-client library in Internet Message Access Protocol (IMAP) dated before 2002 RC2, as used by Pine 4.20 through 4.44
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
VMware GSX Server 2.0 - Authentication Server Buffer Overflow
Buffer overflow in VMware Authorization Service for VMware GSX Server 2.0.0 build-2050 allows remote authenticated users
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cobalt Qube 3.0 - Authentication Bypass
Directory traversal vulnerability in splashAdmin.php for Cobalt Qube 3.0 allows local users and remote attackers, to gai
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
GNU Mailman 2.0.x - Subscribe Cross-Site Scripting
Cross-site scripting vulnerability in Mailman before 2.0.12 allows remote attackers to execute script as other users via
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SecureCRT 2.4/3.x/4.0 - SSH1 Identifier String Buffer Overflow (2)
Buffer overflow in Van Dyke SecureCRT SSH client before 3.4.6, and 4.x before 4.0 beta 3, allows an SSH server to execut
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SecureCRT 2.4/3.x/4.0 - SSH1 Identifier String Buffer Overflow (1)
Buffer overflow in Van Dyke SecureCRT SSH client before 3.4.6, and 4.x before 4.0 beta 3, allows an SSH server to execut
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Opera 6.0.1 / Microsoft Internet Explorer 5/6 - JavaScript Modifier Keypress Event Subversion
Opera 6.0.1 allows remote attackers to upload arbitrary file contents when users press a key corresponding to the JavaSc
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP Interpreter 3.0.x/4.0.x/4.1/4.2 - Direct Invocation Denial of Service
php.exe in PHP 3.0 through 4.2.2, when running on Apache, does not terminate properly, which allows remote attackers to
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Working Resources 1.7.x BadBlue - Administrative Interface Arbitrary File Access
Working Resources Inc. BadBlue Enterprise Edition 1.7 through 1.74 attempts to restrict administrator actions to the IP
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SmartMax MailMax 4.8 - Popmax Buffer Overflow
Buffer overflow in SmartMax MailMax POP3 daemon (popmax) 4.8 allows remote attackers to execute arbitrary code via a lon
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Adobe eBook Reader 2.2 - File Restoration Privilege Escalation
Adobe eBook Reader allows a user to bypass restrictions for copy, print, lend, and give operations by backing up key dat
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle Reports Server 6.0.8/9.0.2 - Information Disclosure
rwcgi60 CGI program in Oracle Reports Server, by design, provides sensitive information such as the full pathname, which
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Trend Micro Interscan VirusWall for Windows NT 3.52 - Space Gap Scan Bypass
InterScan VirusWall 3.52 build 1462 allows remote attackers to bypass virus protection via e-mail messages with headers
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ZYXEL Prestige 642R Router - Malformed Packet Denial of Service
ZyXEL Prestige 642R allows remote attackers to cause a denial of service in the Telnet, FTP, and DHCP services (crash) v
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Macromedia Sitespring 1.2 - Default Error Page Cross-Site Scripting
Cross-site scripting vulnerability in the default HTTP 500 error script (500error.jsp) for Macromedia Sitespring 1.2.0 (
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP-Wiki 1.2/1.3 - Cross-Site Scripting
Cross-site scripting vulnerability in PHPWiki Postnuke wiki module allows remote attackers to execute script as other PH
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
3.3/4.0/4.2 MERCUR MailServer - Control-Service Buffer Overflow
Buffer overflow in the control service for MERCUR Mailserver 4.2 allows remote attackers to execute arbitrary code via a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Oddsock Song Requester 2.1 WinAmp Plugin - Denial of Service
Multiple buffer overflows in the CGI programs for Oddsock Song Requester WinAmp plugin 2.1 allow remote attackers to cau
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
AOL Instant Messenger 4.x - Unauthorized Actions
Cross-site scripting vulnerability AOL Instant Messenger (AIM) 4.5 and 4.7 for MacOS and Windows allows remote attackers
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
IMHO Webmail 0.9x - Account Hijacking
The IMHO Webmail module 0.97.3 and earlier for Roxen leaks the REFERER from the browser's previous login session in an e
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 4.0/5.0 - SMTP Service Encapsulated SMTP Address (MS99-027)
The SMTP service in Microsoft Internet Information Services (IIS) 4.0 and 5.0 allows remote attackers to bypass anti-rel
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Real Networks RealJukebox 1.0.2/RealOne 6.0.10 Player Gold - Skinfile Buffer Overflow
Buffer overflow in RealJukebox 2 1.0.2.340 and 1.0.2.379, and RealOne Player Gold 6.0.10.505, allows remote attackers to
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Ultrafunk Popcorn 1.20 - Multiple Denial of Service Vulnerabilities
Ultrafunk Popcorn 1.20 allows remote attackers to cause a denial of service (crash) via a malformed Subject ("\t\t").
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Summit Computer Networks Lil' HTTP Server 2.1/2.2 - 'pbcgi.cgi' Cross-Site Scripting
Cross-site scripting vulnerability in PowerBASIC pbcgi.cgi, as included in Lil' HTTP web server, allows remote attackers
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Sun i-Runbook 2.5.2 - Directory and File Content Disclosure
none.php for SunPS iRunbook 2.5.2 allows remote attackers to read arbitrary files via an absolute pathname in the argume
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Sun i-Runbook 2.5.2 - Directory and File Content Disclosure
Directory traversal vulnerability in none.php for SunPS iRunbook 2.5.2 allows remote attackers to read arbitrary files v
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.