Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.137exploits catalogados
35.961CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.657GitHub PoC 14.424VulnCheck XDB 8.773Nuclei 4.340Metasploit 3.485✓ só verificadosrecentespopularesrisco
24.458 exploits
Exploit-DB✓ VexDay Proof
Phusion WebServer 1.0 - Directory Traversal (1)
Directory traversal vulnerability in Phusion web server 1.0 allows remote attackers to read arbitrary files via a ... (t
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Ettercap 0.6.3.1 - Large Packet Buffer Overflow
Buffer overflow in various decoders in Ettercap 0.6.3.1 and earlier, when running on networks with an MTU greater than 2
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco IOS 11/12 - SNMP Message Denial of Service
Vulnerabilities in the SNMPv1 request handling of a large number of SNMP implementations allow remote attackers to cause
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
EZNE.NET Ezboard 2000 - Remote Buffer Overflow
Buffer overflow in EasyBoard 2000 1.27 (aka EZboard) allows remote attackers to execute arbitrary code via a long bounda
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Sawmill 6.2.x - Admin Password Insecure Default Permissions
Sawmill for Solaris 6.2.14 and earlier creates the AdminPassword file with world-writable permissions, which allows loca
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Tarantella Enterprise 3 - gunzip Race Condition
Race condition in the installation script for Tarantella Enterprise 3 3.01 through 3.20 creates a world-writeable tempor
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
HP AdvanceStack Switch - Authentication Bypass
Web configuration utility in HP AdvanceStack hubs J3200A through J3210A with firmware version A.03.07 and earlier, allow
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apple QuickTime 5.0 - Content-Type Remote Buffer Overflow
Buffer overflow in Apple QuickTime Player 5.01 and 5.02 allows remote web servers to execute arbitrary code via a respon
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Hanterm 3.3 - Local Buffer Overflow (1)
Buffer overflow in hanterm 3.3.1 and earlier allows local users to execute arbitrary code via a long string in the (1) -
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Hanterm 3.3 - Local Buffer Overflow (2)
Buffer overflow in hanterm 3.3.1 and earlier allows local users to execute arbitrary code via a long string in the (1) -
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Caldera UnixWare 7.1.1 - Message Catalog Environment Variable Format String
Format string vulnerability in the message catalog library functions in UnixWare 7.1.1 allows local users to gain privil
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
OS/400 - User Account Name Disclosure
The System Request menu in IBM AS/400 allows local users to list valid user accounts by viewing the object names that ar
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
AtheOS 0.3.7 - Change Root Directory Escaping
Directory traversal vulnerability in chroot function in AtheOS 0.3.7 allows attackers to escape the jail via a .. (dot d
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Thunderstone TEXIS 3.0 - Full Path Disclosure
Thunderstone Texis CGI script allows remote attackers to obtain the full path of the web root via a request for a nonexi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Sambar Server 5.1 - Sample Script Denial of Service
cgitest.exe in Sambar Server 5.1 before Beta 4 allows remote attackers to cause a denial of service, and possibly execut
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ICQ For Mac OSX 2.6 Client - Denial of Service
Buffer overflow in ICQ 2.6x for MacOS X 10.0 through 10.1.2 allows remote attackers to cause a denial of service and pos
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Faq-O-Matic 2.6/2.7 - Cross-Site Scripting
Cross-site scripting vulnerability in fom.cgi of Faq-O-Matic 2.712 allows remote attackers to execute arbitrary Javascri
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Portix-PHP 0.4 - 'view.php' Directory Traversal
Directory traversal vulnerability in index.php of Portix 0.4.02 allows remote attackers to read arbitrary files via a ..
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Portix-PHP 0.4 - 'index.php' Directory Traversal
Directory traversal vulnerability in index.php of Portix 0.4.02 allows remote attackers to read arbitrary files via a ..
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MIRC 2.x/3.x/4.x/5.x - Nick Buffer Overflow
Buffer overflow in mIRC 5.91 and earlier allows a remote server to execute arbitrary code on the client via a long nickn
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 4.x/5.x MySQL Library - 'Safe_mode' Filesystem Circumvention (1)
Directory traversal vulnerability in functions.php in PhpNewsManager 1.46 allows remote attackers to retrieve arbitrary
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 4.x/5.x MySQL Library - 'Safe_mode' Filesystem Circumvention (2)
Directory traversal vulnerability in functions.php in PhpNewsManager 1.46 allows remote attackers to retrieve arbitrary
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 4.x/5.x MySQL Library - 'Safe_mode' Filesystem Circumvention (1)
Safe Mode feature (safe_mode) in PHP 3.0 through 4.1.0 allows attackers with access to the MySQL database to bypass Safe
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 4.x/5.x MySQL Library - 'Safe_mode' Filesystem Circumvention (2)
Safe Mode feature (safe_mode) in PHP 3.0 through 4.1.0 allows attackers with access to the MySQL database to bypass Safe
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 4.x/5.x MySQL Library - 'Safe_mode' Filesystem Circumvention (3)
Safe Mode feature (safe_mode) in PHP 3.0 through 4.1.0 allows attackers with access to the MySQL database to bypass Safe
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 4.x/5.x MySQL Library - 'Safe_mode' Filesystem Circumvention (3)
Directory traversal vulnerability in functions.php in PhpNewsManager 1.46 allows remote attackers to retrieve arbitrary
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
kicq 2.0.0b1 - Invalid ICQ Packet Denial of Service
KICQ 2.0.0b1 allows remote attackers to cause a denial of service (crash) via a malformed message.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
DistCC Daemon - Command Execution (Metasploit)
distcc 2.x, as used in XCode 1.5 and others, when not configured to restrict access to the server port, allows remote at
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Tru64 - Malformed TCP Packet Denial of Service
Compaq Tru64 4.0 d allows remote attackers to cause a denial of service in (1) telnet, (2) FTP, (3) ypbind, (4) rpc.lock
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Sun Java Virtual Machine 1.2.2/1.3.1 - Segmentation Violation
java.security.AccessController in Sun Java Virtual Machine (JVM) in JRE 1.2.2 and 1.3.1 allows remote attackers to cause
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.