Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.137exploits catalogados
35.961CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.657GitHub PoC 14.424VulnCheck XDB 8.773Nuclei 4.340Metasploit 3.485✓ só verificadosrecentespopularesrisco
24.458 exploits
Exploit-DB✓ VexDay Proof
Microsoft Site Server 3.0 - Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in the default ASP pages on Microsoft Site Server 3.0 on Windows NT 4.0 allows
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
AHG Search Engine 1.0 - 'search.cgi' Arbitrary Command Execution
search.cgi in AGH HTMLsearch 1.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the t
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Agora.CGI 3/4 - Debug Mode Full Path Disclosure
Agora.cgi 3.2r through 4.0 while in debug mode allows remote attackers to determine the full pathname of the agora.cgi f
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
BRU 17.0 - SetLicense Script Insecure Temporary File Symbolic Link
setlicense for TOLIS Group Backup and Restore Utility (BRU) 17.0 allows local users to overwrite arbitrary files via a s
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
rsync 2.3/2.4/2.5 - Signed Array Index Remote Code Execution
Multiple signedness errors (mixed signed and unsigned numbers) in the I/O functions of rsync 2.4.6, 2.3.2, and other ver
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Citrix Nfuse 1.6 - Published Applications Information Leak
Citrix NFuse 1.6 may allow remote attackers to list applications without authentication by accessing the applist.asp pag
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cyberstop Web Server 0.1 - Long Request Denial of Service
Cyberstop Web Server for Windows 0.1 allows remote attackers to cause a denial of service (crash) and possibly execute a
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OS Internet Explorer 3/4/5 - File Execution
Internet Explorer 5.1 for Macintosh allows remote attackers to bypass security checks and invoke local AppleScripts with
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows XP - '.Manifest' Denial of Service
Microsoft Windows XP allows local users to prevent the system from booting via a corrupt explorer.exe.manifest file.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Caldera UnixWare 7.1.1 - WebTop 'SCOAdminReg.cgi' Arbitrary Command Execution
Vulnerability in webtop in UnixWare 7.1.1 and Open UNIX 8.0.0 allows local and possibly remote attackers to gain root pr
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
DNRD 1.x/2.x - DNS Request/Reply Denial of Service
Domain Name Relay Daemon (dnrd) 2.10 and earlier allows remote malicious DNS sites to cause a denial of service and poss
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Solaris TelnetD - 'TTYPROMPT' Remote Buffer Overflow (1) (Metasploit)
Buffer overflow in login in various System V based operating systems allows remote attackers to execute arbitrary comman
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Netopia Timbuktu Pro for Macintosh 6.0.1 - Denial of Service
Netopia Timbuktu Pro 6.0.1 and earlier allows remote attackers to cause a denial of service (crash) via a series of conn
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP-Nuke 4.x/5.x - SQL_Debug Information Disclosure
sql_layer.php in PHP-Nuke 5.4 and earlier does not restrict access to debugging features, which allows remote attackers
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Brecht Claerhout Sniffit 0.3.6 HIP/0.3.7 Beta - Mail Logging Buffer Overflow (3)
Buffer overflow in Sniffit 0.3.x with the -L logging option enabled allows remote attackers to execute arbitrary command
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Chinput 3.0 - Environment Variable Buffer Overflow
Buffer overflow in Chinput 3.0 allows local users to execute arbitrary code via a long HOME environment variable.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
AT 3.1.8 - Formatted Time Heap Overflow
Heap corruption vulnerability in the "at" program allows local users to execute arbitrary code via a malformed execution
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Lucent 8.x - VitalNet Password Authentication Bypass
Lucent VitalSuite 8.0 through 8.2, including VitalNet, VitalEvent, and VitalHelp/VitalAnalysis, allows remote attackers
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP-Nuke 4.x/5.x - Arbitrary File Inclusion
index.php in Francisco Burzi PHP-Nuke 5.3.1 and earlier, and possibly other versions before 5.5, allows remote attackers
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Sudo 1.6.3 - Unclean Environment Variable Privilege Escalation
sudo 1.6.0 through 1.6.3p7 does not properly clear the environment before calling the mail program, which could allow lo
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
John Roy Pi3Web 2.0 For Windows - Remote Buffer Overflow
CGI handler in John Roy Pi3Web for Windows 2.0 beta 1 and 2 allows remote attackers to cause a denial of service (crash)
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CDRDAO 1.1.x - Home Directory Configuration File Symbolic Link (1)
CDRDAO 1.1.4 and 1.1.5 allows local users to overwrite arbitrary files via a symlink attack on the $HOME/.cdrdao configu
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
IMLib2 - Home Environment Variable Buffer Overflow
Buffer overflow in Eterm of Enlightenment Imlib2 1.0.4 and earlier allows local users to execute arbitrary code via a lo
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CDRDAO 1.1.x - Home Directory Configuration File Symbolic Link (2)
CDRDAO 1.1.4 and 1.1.5 allows local users to overwrite arbitrary files via a symlink attack on the $HOME/.cdrdao configu
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CDRDAO 1.1.x - Home Directory Configuration File Symbolic Link (3)
CDRDAO 1.1.4 and 1.1.5 allows local users to overwrite arbitrary files via a symlink attack on the $HOME/.cdrdao configu
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CDRDAO 1.1.x - Home Directory Configuration File Symbolic Link (4)
CDRDAO 1.1.4 and 1.1.5 allows local users to overwrite arbitrary files via a symlink attack on the $HOME/.cdrdao configu
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
EServ 2.9x - Password-Protected File Access
Etype Eserv 2.97 allows remote attackers to view password protected files via /./ in the URL.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Snort 1.8.3 - ICMP Denial of Service
Snort 1.8.3 does not properly define the minimum ICMP header size, which allows remote attackers to cause a denial of se
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
X-Chat 1.x - CTCP Ping Remote IRC Command Execution
XChat 1.8.7 and earlier, including default configurations of 1.4.2 and 1.4.3, allows remote attackers to execute arbitra
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
YaBB 9.1.2000 - Cross-Agent Scripting
Cross-site scripting vulnerability in Yet Another Bulletin Board (YaBB) 1 Gold SP 1 and earlier allows remote attackers
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.