Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.137exploits catalogados
35.961CVEs com exploração pública
24.695testados em laboratório
24.458 exploits
Exploit-DBVexDay Proof
GoAhead Web Server 2.1.x - Error Page Cross-Site Scripting
CVE-2002-0681remotewindows10 jul 2002
Cross-site scripting vulnerability in GoAhead Web Server 2.1 allows remote attackers to execute script as other web user
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 5/6 - OBJECT Tag Same Origin Policy Violation
CVE-2002-0723remotewindows10 jul 2002
Microsoft Internet Explorer 5.5 and 6.0 does not properly verify the domain of a frame within a browser window, which al
28RISCO
abrir
Exploit-DBVexDay Proof
Fluid Dynamics Search Engine 2.0 - Cross-Site Scripting
CVE-2002-1036webappscgi10 jul 2002
Cross-site scripting vulnerability in search.pl for Fluid Dynamics Search Engine (FDSE) before 2.0.0.0055 allows remote
23RISCO
abrir
Exploit-DBVexDay Proof
HP Tru64 4.0/5.0/5.1 - _XKB_CHARSET Local Buffer Overflow
CVE-2002-1605localunix10 jul 2002
Buffer overflow in HP Tru64 UNIX 5.1a, 5.1, 5.0a, 4.0g, and 4.0f allows attackers to execute arbitrary code via a long _
28RISCO
abrir
Exploit-DBVexDay Proof
GoAhead Web Server 2.1.x - URL Encoded Slash Directory Traversal
CVE-2002-0680remotewindows10 jul 2002
Directory traversal vulnerability in GoAhead Web Server 2.1 allows remote attackers to read arbitrary files via a URL wi
23RISCO
abrir
Exploit-DBVexDay Proof
Apache Tomcat 4.0.3 - Servlet Mapping Cross-Site Scripting
CVE-2002-0682remotelinux10 jul 2002
Cross-site scripting vulnerability in Apache Tomcat 4.0.3 allows remote attackers to execute script as other web users v
28RISCO
abrir
Exploit-DBVexDay Proof
iPlanet Web Server 4.1 - Search Component File Disclosure
CVE-2002-1042remotemultiple09 jul 2002
Directory traversal vulnerability in search engine for iPlanet web server 6.0 SP2 and 4.1 SP9, and Netscape Enterprise S
23RISCO
abrir
Exploit-DBVexDay Proof
icecast server 1.3.12 - Directory Traversal Information Disclosure
CVE-2002-1982remotelinux09 jul 2002
Directory traversal vulnerability in the list_directory function in Icecast 1.3.12 allows remote attackers to determine
23RISCO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX 10.1.x - SoftwareUpdate Arbitrary Package Installation
CVE-2002-0676remoteosx08 jul 2002
SoftwareUpdate for MacOS 10.1.x does not use authentication when downloading a software update, which could allow remote
23RISCO
abrir
Exploit-DBVexDay Proof
Working Resources BadBlue 1.7.3 - 'cleanSearchString()' Cross-Site Scripting
CVE-2002-1683remotewindows08 jul 2002
Cross-site scripting (XSS) vulnerability in BadBlue Personal Edition 1.7.3 allows remote attackers to execute arbitrary
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Foundation Class Library 7.0 - ISAPI Buffer Overflow
CVE-2002-1973remotewindows08 jul 2002
Buffer overflow in CHttpServer::OnParseError in the ISAPI extension (Isapi.cpp) when built using Microsoft Foundation Cl
35RISCO
abrir
Exploit-DBVexDay Proof
Key Focus KF Web Server 1.0.2 - Directory Contents Disclosure
CVE-2002-1031remotewindows08 jul 2002
KeyFocus (KF) web server 1.0.2 allows remote attackers to list directories and read restricted files via an HTTP request
23RISCO
abrir
Exploit-DBVexDay Proof
Working Resources BadBlue 1.7.3 - GET Denial of Service
CVE-2002-1023doswindows08 jul 2002
BadBlue server allows remote attackers to cause a denial of service (crash) via an HTTP GET request without a URI.
23RISCO
abrir
Exploit-DBVexDay Proof
ArGoSoft 1.8 Mail Server - Directory Traversal
CVE-2002-1004remotewindows06 jul 2002
Directory traversal vulnerability in webmail feature of ArGoSoft Mail Server Plus or Pro 1.8.1.5 and earlier allows remo
23RISCO
abrir
Exploit-DBVexDay Proof
WorldSpan Res Manager 4.1 - Malformed TCP Packet Denial of Service
CVE-2002-1029doswindows04 jul 2002
Res Manager in Worldspan for Windows Gateway 4.1 allows remote attackers to cause a denial of service (crash) via a malf
23RISCO
abrir
Exploit-DBVexDay Proof
Nullsoft Winamp 2.80 - Automatic Update Check Buffer Overflow
CVE-2002-2195remotewindows03 jul 2002
Buffer overflow in the version update check for Winamp 2.80 and earlier allows remote attackers who can spoof www.winamp
23RISCO
abrir
Exploit-DBVexDay Proof
Sun SunPCi II VNC Software 2.3 - Password Disclosure
CVE-2002-0994localunix03 jul 2002
SunPCi II VNC uses a weak authentication scheme, which allows remote attackers to obtain the VNC password by sniffing th
23RISCO
abrir
Exploit-DBVexDay Proof
HP Tru64/OSF1 DXTerm - Local Buffer Overflow
CVE-2002-1129localunix03 jul 2002
Buffer overflow in dxterm allows local users to execute arbitrary code via a long -xrm argument.
23RISCO
abrir
Exploit-DBVexDay Proof
phpAuction 1/2 - Unauthorized Administrative Access
CVE-2002-0995webappsphp02 jul 2002
login.php for PHPAuction allows remote attackers to gain privileges via a direct call to login.php with the action param
23RISCO
abrir
Exploit-DBVexDay Proof
BBC Education Betsie 1.5 - Parserl.pl Cross-Site Scripting
CVE-2002-1006webappscgi01 jul 2002
Cross-site scripting (XSS) vulnerability in BBC Education Text to Speech Internet Enhancer (Betsie) 1.5.11 and earlier a
23RISCO
abrir
Exploit-DBVexDay Proof
AnalogX Proxy 4.0 - Socks4A Buffer Overflow
CVE-2002-1001remotewindows01 jul 2002
Buffer overflows in AnalogX Proxy before 4.12 allows remote attackers to cause a denial of service and possibly execute
23RISCO
abrir
Exploit-DBVexDay Proof
BlackBoard 5.0 - Cross-Site Scripting
CVE-2002-1007webappscgi01 jul 2002
Cross-site scripting vulnerabilities in Blackboard 5 allow remote attackers to execute arbitrary web script via (1) the
23RISCO
abrir
Exploit-DBVexDay Proof
E-Guest 1.1 - Server Side Include Arbitrary Command Execution
CVE-2002-2376remotelinux30 jun 2002
Cross-site scripting (XSS) vulnerability in E-Guest_sign.pl in E-Guest 1.1 allows remote attackers to inject arbitrary S
23RISCO
abrir
Exploit-DBVexDay Proof
Mandrake 7/8/9 / RedHat 6.x/7 Bonobo EFSTool - Commandline Argument Buffer Overflow (1)
CVE-2002-1814locallinux29 jun 2002
Buffer overflow in efstools in Bonobo, when installed setuid, allows local users to execute arbitrary code via long comm
23RISCO
abrir
Exploit-DBVexDay Proof
Mandrake 7/8/9 / RedHat 6.x/7 Bonobo EFSTool - Commandline Argument Buffer Overflow (2)
CVE-2002-1814locallinux29 jun 2002
Buffer overflow in efstools in Bonobo, when installed setuid, allows local users to execute arbitrary code via long comm
23RISCO
abrir
Exploit-DBVexDay Proof
Mandrake 7/8/9 / RedHat 6.x/7 Bonobo EFSTool - Commandline Argument Buffer Overflow (3)
CVE-2002-1814locallinux29 jun 2002
Buffer overflow in efstools in Bonobo, when installed setuid, allows local users to execute arbitrary code via long comm
23RISCO
abrir
Exploit-DBVexDay Proof
Macromedia JRun 3/4 - Administrative Authentication Bypass
CVE-2002-0665remotewindows28 jun 2002
Macromedia JRun Administration Server allows remote attackers to bypass authentication on the login form via an extra sl
28RISCO
abrir
Exploit-DBVexDay Proof
Summit Computer Networks Lil' HTTP Server 2 - 'URLCount.cgi' HTML Injection
CVE-2002-1008remotewindows27 jun 2002
Cross-site scripting vulnerability in PowerBASIC urlcount.cgi, as included in Lil' HTTP web server, allows remote attack
23RISCO
abrir
Exploit-DBVexDay Proof
Inktomi Traffic Server 4/5 - Traffic_Manager Path Argument Buffer Overflow
CVE-2002-1013doslinux25 jun 2002
Buffer overflow in traffic_manager for Inktomi Traffic Server 4.0.18 through 5.2.2, Traffic Edge 1.1.2 and 1.5.0, and Me
23RISCO
abrir
Exploit-DBVexDay Proof
WU-IMAP 2000.287(1-2) - Remote Overflow
CVE-2000-0284remotelinux25 jun 2002
Buffer overflow in University of Washington imapd version 4.7 allows users with a valid account to execute commands via
50RISCO
abrir
anteriorpágina 751 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.