Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.137exploits catalogados
35.961CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.657GitHub PoC 14.424VulnCheck XDB 8.773Nuclei 4.340Metasploit 3.485✓ só verificadosrecentespopularesrisco
24.458 exploits
Exploit-DB✓ VexDay Proof
OpenSSH 3.x - Challenge-Response Buffer Overflow (2)
Buffer overflow in sshd in OpenSSH 2.3.1 through 3.3 may allow remote attackers to execute arbitrary code via a large nu
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
OpenSSH 3.x - Challenge-Response Buffer Overflow (1)
Buffer overflow in sshd in OpenSSH 2.3.1 through 3.3 may allow remote attackers to execute arbitrary code via a large nu
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Working Resources BadBlue 1.7 - 'ext.dll' Cross-Site Scripting
Cross-site scripting vulnerability (XSS) in BadBlue Enterprise Edition and Personal Edition 1.7 and 1.7.2 allows remote
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache mod_ssl 2.8.x - Off-by-One HTAccess Buffer Overflow
Off-by-one buffer overflow in the ssl_compat_directive function, as called by the rewrite_command hook for mod_ssl Apach
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
YaBB 1 - Invalid Topic Error Page Cross-Site Scripting
Cross-site scripting vulnerability in YaBB.cgi for Yet Another Bulletin Board (YaBB) 1 Gold SP1 and earlier allows remot
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Pirch IRC 98 Client - Malformed Link Buffer Overrun
Buffer overflow in the Pirch 98 IRC client allows remote attackers to cause a denial of service and possibly execute arb
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SGI IRIX 6.x - 'rpc.xfsmd' Remote Command Execution
xfsmd for IRIX 6.5 through 6.5.16 allows remote attackers to execute arbitrary code via shell metacharacters that are no
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Half-Life Server 1.1/3.1 - New Player Flood Denial of Service
Half-Life Server 1.1.1.0 and earlier allows remote attackers to cause a denial of service (resource exhaustion) via mult
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft SQL Server 2000 / Microsoft Jet 4.0 Engine - Unicode Buffer Overflow (PoC)
Buffer overflow in the OpenDataSource function of the Jet engine on Microsoft SQL Server 2000 allows remote attackers to
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
BasiliX Webmail 1.1 - Message Content Script Injection
Cross-site scripting vulnerability (XSS) in BasiliX Webmail 1.10 allows remote attackers to execute arbitrary script as
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco VPN Client for Unix 3.5.1 - Local Buffer Overflow
Buffer overflow in the vpnclient program for UNIX VPN Client before 3.5.2 allows local users to gain administrative priv
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Interbase 6.0 - GDS_Drop Interbase Environment Variable Buffer Overflow (2)
Buffer overflow in Borland InterBase 6.0 allows local users to execute arbitrary code via a long INTERBASE environment v
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Interbase 6.0 - GDS_Drop Interbase Environment Variable Buffer Overflow (2)
Buffer overflow in Firebird 1.0.2 and other versions before 1.5, and possibly other products that use the InterBase code
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache 1.x/2.0.x - Chunked-Encoding Memory Corruption (1)
Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possi
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Wolfram Research webMathematica 4.0 - File Disclosure
Directory traversal vulnerability in Wolfram Research webMathematica 1.0.0 and 1.0.0.1 allows remote attackers to read a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache 1.x/2.0.x - Chunked-Encoding Memory Corruption (2)
Apache 1.3 through 1.3.24, and Apache 2.0 through 2.0.36, allows remote attackers to cause a denial of service and possi
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP-Address 0.2 e - Remote File Inclusion
globals.php in PHP Address before 0.2f, with the PHP allow_url_fopen and register_globals variables enabled, allows remo
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
osCommerce 2.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in include_once.php in osCommerce (a.k.a. Exchange Project) 2.1 allows remote at
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
osCommerce 2.1 - Remote File Inclusion
PHP file inclusion vulnerability in osCommerce 2.1 execute arbitrary commands via the include_file parameter to include_
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Interbase 6.0 - GDS_Drop Interbase Environment Variable Buffer Overflow (1)
Buffer overflow in Firebird 1.0.2 and other versions before 1.5, and possibly other products that use the InterBase code
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Interbase 6.0 - GDS_Drop Interbase Environment Variable Buffer Overflow (1)
Buffer overflow in Borland InterBase 6.0 allows local users to execute arbitrary code via a long INTERBASE environment v
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5/6 - CSSText Bold Font Denial of Service
Microsoft Internet Explorer 5.5 through 6.0 allows remote attackers to cause a denial of service (crash) via a Cascading
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ZeroBoard 4.1 - PHP Include File Arbitrary Command Execution
Zeroboard 4.1, when the "allow_url_fopen" and "register_globals" variables are enabled, allows remote attackers to execu
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
My Postcards 6.0 - 'MagicCard.cgi' Arbitrary File Disclosure
Directory traversal vulnerability in magiccard.cgi in My Postcards Platinum 5.0 and 6.0 allows remote attackers to read
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco Secure ACS for Windows NT 3.0 - Cross-Site Scripting
Cross-site scripting vulnerability in CiscoSecure ACS 3.0 allows remote attackers to execute arbitrary script or HTML as
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Lumigent Log Explorer XP - _LogAttach_StartProf Buffer Overflow
Buffer overflows in Lugiment Log Explorer before 3.02 allow attackers with database permissions to execute arbitrary cod
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Mewsoft NetAuction 3.0 - Cross-Site Scripting
Cross-site scripting vulnerability (XSS) in auction.cgi for Mewsoft NetAuction 3.0 allows remote attackers to execute ar
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft SQL Server 2000 - Password Encrypt procedure Buffer Overflow
Buffer overflow in the password encryption function of Microsoft SQL Server 2000, including Microsoft SQL Server Desktop
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP Classifieds 6.0.5 - Cross-Site Scripting
Cross-site scripting vulnerability (XSS) in DeltaScripts PHP Classifieds 6.0.5 allows remote attackers to execute arbitr
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Imatix Xitami 2.5 - GSL Template Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in Errors.gsl in Imatix Xitami 2.5b4 and 2.5b5 allows remote attackers to injec
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.