Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.137exploits catalogados
35.961CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.657GitHub PoC 14.424VulnCheck XDB 8.773Nuclei 4.340Metasploit 3.485✓ só verificadosrecentespopularesrisco
24.458 exploits
Exploit-DB✓ VexDay Proof
ISC INN 2.0/2.1/2.2.x - Multiple Local Format String Vulnerabilities
Format string vulnerabilities in (1) inews or (2) rnews for INN 2.2.3 and earlier allow local users and remote malicious
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 4.0/5.0 - HTTP Error Page Cross-Site Scripting
Cross-site scripting vulnerability in Internet Information Server (IIS) 4.0, 5.0 and 5.1 allows remote attackers to exec
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 4.0/5.0 - Chunked Encoding Transfer Heap Overflow (1)
Buffer overflow in the chunked encoding transfer mechanism in Internet Information Server (IIS) 4.0 and 5.0 Active Serve
45RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 4.0/5.0 - Chunked Encoding Transfer Heap Overflow (3)
Buffer overflow in the chunked encoding transfer mechanism in Internet Information Server (IIS) 4.0 and 5.0 Active Serve
45RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Abyss Web Server 1.0 - File Disclosure
Directory traversal vulnerability in Aprelium Abyss Web Server (abyssws) before 1.0.0.2 allows remote attackers to read
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Abyss Web Server 1.0 - File Disclosure
Aprelium Abyss Web Server (abyssws) before 1.0.3 stores the administrative console password in plaintext in the abyss.co
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
phpGroupWare 0.9.13 - Debian Package Configuration
PHPGroupware 0.9.12 and earlier, when running with the magic_quotes_gpc feature disabled, allows remote attackers to com
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Sun Solaris 2.6/7.0/8 - XSun Color Database File Heap Overflow
Buffer overflow in Xsun on Solaris 2.6 through 8 allows local users to gain root privileges via a long -co (color databa
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5 - Cascading Style Sheet File Disclosure (MS02-023)
Microsoft Internet Explorer 5.01, 5.5 and 6.0 allows remote attackers to view arbitrary files that contain the "{" chara
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle 8i - TNS Listener Local Command Parameter Buffer Overflow
Buffer overflow in tnslsnr of Oracle 8i Database Server 8.1.5 for Linux allows local users to execute arbitrary code as
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PostNuke 0.703 - caselist Arbitrary Module Include
PHP file inclusion vulnerability in user.php in PostNuke 0.703 allows remote attackers to include arbitrary files and po
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SquirrelMail 1.2.x - Theme Remote Command Execution
SquirrelMail 1.2.5 and earlier allows authenticated SquirrelMail users to execute arbitrary commands by modifying the TH
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
LogWatch 2.1.1/2.5 - Insecure Temporary Directory Creation
LogWatch before 2.5 allows local users to execute arbitrary code via a symlink attack on the logwatch temporary director
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Citrix NFuse 1.51/1.6 - Cross-Site Scripting
Cross-site scripting vulnerability in Citrix NFuse 1.6 and earlier does not quote results from the getLastError method,
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.2.x/2.3/2.4.x - 'd_path()' Path Truncation
The d_path function in Linux kernel 2.2.20 and earlier, and 2.4.18 and earlier, truncates long pathnames without generat
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CSSearch 2.3 - Remote Command Execution
csSearch.cgi in csSearch 2.3 and earlier allows remote attackers to execute arbitrary Perl code via the savesetup comman
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
DCShop Beta 1.0 - Form Manipulation
dcshop.cgi in DCShop 1.002 Beta allows remote attackers to delete arbitrary setup files via a null character in the data
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Progress Database 9.1 - sqlcpp Local Buffer Overflow
Buffer overflow in Progress database 8.3D and 9.1C could allow a local user to execute arbitrary code via (1) _proapsv,
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WorkforceROI Xpede 4.1/7.0 - Weak Password Encryption
Intellisol Xpede 4.1 uses weak encryption to store authentication information in cookies, which could allow local users
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache Win32 1.3.x/2.0.x - Batch File Remote Command Execution
Apache for Win32 before 1.3.24, and 2.0.x before 2.0.34-beta, allows remote attackers to execute arbitrary commands via
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP-Nuke 5.x - Error Message Web Root Disclosure
index.php for PHP-Nuke 5.4 and earlier allows remote attackers to determine the physical pathname of the web server when
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Webmin 0.x - Code Input Validation
The web interface for Webmin 0.92 does not properly quote or filter script code in files that are displayed to the inter
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5/6 / Mozilla 0.8/0.9.x / Opera 5/6 - JavaScript Interpreter Denial of Service
Internet Explorer 5.01 through 6 allows remote attackers to cause a denial of service (application crash) via Javascript
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 3.0.x/4.x - Move_Uploaded_File open_basedir Circumvention
move_uploaded_file in PHP does not does not check for the base directory (open_basedir), which could allow remote attack
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Qualcomm QPopper 4.0.x - Remote Denial of Service
Qpopper (aka in.qpopper or popper) 4.0.3 and earlier allows remote attackers to cause a denial of service (CPU consumpti
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHProjekt 3.1 - Remote File Inclusion
filemanager_forms.php in PHProjekt 3.1 and 3.1a allows remote attackers to execute arbitrary PHP code by specifying the
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows NT 4.0/2000 - Process Handle Local Privilege Escalation
smss.exe debugging subsystem in Windows NT and Windows 2000 does not properly authenticate programs that connect to othe
71RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Trend Micro Interscan VirusWall 3.5/3.6 - Content-Length Scan Bypass
Trend Micro InterScan VirusWall HTTP proxy 3.6 with the "Skip scanning if Content-length equals 0" option enabled allows
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Solaris 7.0/8 Sunsolve CD - SSCD_SunCourier.pl CGI Script Arbitrary Command Execution
sscd_suncourier.pl CGI script in the Sun Sunsolve CD pack allows remote attackers to execute arbitrary commands via shel
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
XTux Server 2001.0 6.01 - Garbage Denial of Service
XTux allows remote attackers to cause a denial of service (CPU consumption) via random inputs in the initial connection.
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.