Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.137exploits catalogados
35.961CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.657GitHub PoC 14.424VulnCheck XDB 8.773Nuclei 4.340Metasploit 3.485✓ só verificadosrecentespopularesrisco
24.458 exploits
Exploit-DB✓ VexDay Proof
Nullsoft SHOUTcast 1.8.9 - Remote Buffer Overflow
Buffer overflow in SHOUTcast 1.8.9 and other versions before 1.8.12 allows a remote authenticated DJ to execute arbitrar
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
QNX RTOS 4.25/6.1 - su Password Hash Disclosure
/bin/su in QNX realtime operating system (RTOS) 4.25 and 6.1.0 allows local users to obtain sensitive information from c
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
QNX RTOS 4.25/6.1 - 'phgrafx' Local Privilege Escalation
The (1) phrafx and (2) phgrafx-startup programs in QNX realtime operating system (RTOS) 4.25 and 6.1.0 do not properly d
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
QNX 6.x - 'ptrace()' Arbitrary Process Modification
ptrace in the QNX realtime operating system (RTOS) 4.25 and 6.1.0 allows programs to attach to privileged processes, whi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
QNX RTOS 6.1 - 'PKG-Installer' Local Buffer Overflow
Multiple buffer overflows in realtime operating system (RTOS) 6.1.0 allows local users to execute arbitrary code via (1)
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
QNX RTOS 6.1 - '/usr/photon/bin/phlocale' Environment Variable Buffer Overflow
Multiple buffer overflows in realtime operating system (RTOS) 6.1.0 allows local users to execute arbitrary code via (1)
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
QNX RTOS 4.25/6.1 - 'phgrafx-startup' Local Privilege Escalation
The (1) phrafx and (2) phgrafx-startup programs in QNX realtime operating system (RTOS) 4.25 and 6.1.0 do not properly d
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Teekai Tracking Online 1.0 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in userlog.php in TeeKai Tracking Online 1.0 allows remote attackers to inject
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Evolvable Shambala Server 4.5 - Web Server Denial of Service
Web server for Shambala 4.5 allows remote attackers to cause a denial of service (crash) via a malformed HTTP request.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
QNX RTOS 4.25 - monitor Arbitrary File Modification
Hard link and possibly symbolic link following vulnerabilities in QNX RTOS 4.25 (aka QNX4) allow local users to overwrit
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
QNX RTOS 4.25 - dumper Arbitrary File Modification
Hard link and possibly symbolic link following vulnerabilities in QNX RTOS 4.25 (aka QNX4) allow local users to overwrit
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
QNX RTOS 4.25 - 'CRTTrap' File Disclosure
Hard link and possibly symbolic link following vulnerabilities in QNX RTOS 4.25 (aka QNX4) allow local users to overwrit
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
IBM Informix SE 7.25 sqlexec - Local Buffer Overflow (1)
Buffer overflow in sqlexec for Informix SE-7.25 allows local users to gain root privileges via a long INFORMIXDIR enviro
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
IBM Informix SE 7.25 sqlexec - Local Buffer Overflow (2)
Buffer overflow in sqlexec for Informix SE-7.25 allows local users to gain root privileges via a long INFORMIXDIR enviro
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CGIScript.net - 'csPassword.cgi' 1.0 Information Disclosure
CGIScript.net csPassword.cgi allows remote authenticated users to modify the .htaccess file and gain privileges via newl
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CGIScript.net - 'csPassword.cgi' 1.0 HTAccess File Modification
CGIScript.net csPassword.cgi allows remote authenticated users to modify the .htaccess file and gain privileges via newl
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CGIScript.net - 'csPassword.cgi' 1.0 Information Disclosure
CGIScript.net csPassword.cgi leaks sensitive information such as the pathname of the server in debug messages that are p
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Netscape Enterprise Web Server for Netware 4/5 5.0 - Information Disclosure
Novell NetWare 5.1 installs sample applications that allow remote attackers to obtain sensitive information via (1) ndso
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Caldera OpenServer 5.0.5/5.0.6 - SCOAdmin Symbolic Link
scoadmin for Caldera/SCO OpenServer 5.0.5 and 5.0.6 allows local users to overwrite arbitrary files via a symlink attack
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Tomcat 3.2.3/3.2.4 - Example Files Web Root Full Path Disclosure
The default installations of Apache Tomcat 3.2.3 and 3.2.4 allows remote attackers to obtain sensitive system informatio
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Tomcat 3.2.3/3.2.4 - 'Source.jsp' Information Disclosure
The default installations of Apache Tomcat 3.2.3 and 3.2.4 allows remote attackers to obtain sensitive system informatio
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Tomcat 3.2.3/3.2.4 - 'RealPath.jsp' Information Disclosuree
The default installations of Apache Tomcat 3.2.3 and 3.2.4 allows remote attackers to obtain sensitive system informatio
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Gafware CFXImage 1.6.4/1.6.6 - ShowTemp File Disclosure
showtemp.cfm for Gafware CFXImage 1.6.6 allows remote attackers to read arbitrary files via (1) a .. or (2) a C: style p
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Image Display System 0.8.1 - Directory Existence Disclosure
The getAlbumToDisplay function in idsShared.pm for Image Display System (IDS) 0.81 allows remote attackers to determine
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 95/98/2000/NT 4.0 - WinHlp Item Buffer Overflow
Buffer overflow in Winhlp32.exe allows remote attackers to execute arbitrary code via an HTML document that calls the HT
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Opera 6.0.1/6.0.2 - Arbitrary File Disclosure
Opera 6.0.1 and 6.0.2 allows a remote web site to upload arbitrary files from the client system, without prompting the c
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Yahoo! Messenger 5.0 - Call Center Buffer Overflow
Buffer overflows in Yahoo! Messenger 5,0,0,1064 and earlier allows remote attackers to execute arbitrary code via a ymsg
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHPBB2 - Image Tag HTML Injection
Cross-site scripting vulnerability in phpBB 2.0.0 (phpBB2) allows remote attackers to execute Javascript as other phpBB
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft MSN Messenger 1 < 4 - Malformed Invite Request Denial of Service
Microsoft MSN Messenger Service 1.0 through 4.6 allows remote attackers to cause a denial of service (crash) via an invi
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
OpenBB 1.0 - Unauthorized Moderator Access
Open Bulletin Board (OpenBB) 1.0.0 RC3 allows remote attackers to bypass authentication and access modifier options via
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.