Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.149exploits catalogados
35.965CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.657GitHub PoC 14.424VulnCheck XDB 8.773Nuclei 4.349Metasploit 3.488✓ só verificadosrecentespopularesrisco
24.458 exploits
Exploit-DB✓ VexDay Proof
NetWin DMail 2.x / SurgeFTP 1.0/2.0 - Weak Password Encryption
NetWin Authentication module (NWAuth) 2.0 and 3.0b, as implemented in SurgeFTP, DMail, and possibly other packages, uses
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Solaris 2.x/7.0/8 / IRIX 6.5.x / OpenBSD 2.x / NetBSD 1.x / Debian 3 / HP-UX 10 - 'TelnetD' Remote Buffer Overflow
Buffer overflow in BSD-based telnetd telnet daemon on various operating systems allows remote attackers to execute arbit
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ID Software Quake 1.9 - Denial of Service
Quake 1 and NetQuake servers allow remote attackers to cause a denial of service (resource exhaustion or forced disconne
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Check Point Firewall-1 4.x - SecuRemote Internal Interface Address Information Leakage
Check Point FireWall-1 4.0 and 4.1 before SP5 allows remote attackers to obtain the IP addresses of internal interfaces
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Check Point Firewall-1 4 Securemote - Network Information Leak
The default configuration of SecuRemote for Check Point Firewall-1 allows remote attackers to obtain sensitive configura
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Interactive story 1.3 - Directory Traversal
Directory traversal vulnerability in story.pl in Interactive Story 1.3 allows a remote attacker to read arbitrary files
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Debian 2.2 /usr/bin/pileup - Local Privilege Escalation
Buffer overflows in Pileup before 1.2 allows local users to gain root privileges via (1) long command line arguments, or
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Outlook 98/2000/2002 - Unauthorized Email Access
Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers to execute arbitrar
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Outlook 98/2000/2002 - Arbitrary Code Execution
Microsoft Outlook View ActiveX Control in Microsoft Outlook 2002 and earlier allows remote attackers to execute arbitrar
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
3Com SuperStack II PS Hub 40 - TelnetD Weak Password Protection
The telnet server for 3Com hardware such as PS40 SuperStack II does not delay or disconnect remote attackers who provide
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ArGoSoft FTP Server 1.2.2.2 - Weak Password Encryption
ArGoSoft FTP Server 1.2.2.2 uses weak encryption for user passwords, which allows an attacker with access to the passwor
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
cfingerd 1.4.1/1.4.2/1.4.3 Utilities - Local Buffer Overflow (2)
Buffer overflow in cfingerd 1.4.3 and earlier with the ALLOW_LINE_PARSING option enabled allows local users to execute a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
cfingerd 1.4.1/1.4.2/1.4.3 Utilities - Local Buffer Overflow (3)
Buffer overflow in cfingerd 1.4.3 and earlier with the ALLOW_LINE_PARSING option enabled allows local users to execute a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache 1.3 - Directory Index Disclosure
Apache 1.3.20 with Multiviews enabled allows remote attackers to view directory contents and bypass the index page via a
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Samsung ml85p Printer Driver 1.0 - Insecure Temporary File Creation (1)
ml85p in Samsung ML-85G GDI printer driver before 0.2.0 allows local users to overwrite arbitrary files via a symlink at
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Samsung ml85p Printer Driver 1.0 - Insecure Temporary File Creation (3)
ml85p in Samsung ML-85G GDI printer driver before 0.2.0 allows local users to overwrite arbitrary files via a symlink at
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
xloadimage 4.1 - Remote Buffer Overflow
Buffer overflow in xloadimage 4.1 (aka xli 1.16 and 1.17) in Linux allows remote attackers to execute arbitrary code via
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Samsung ml85p Printer Driver 1.0 - Insecure Temporary File Creation (2)
ml85p in Samsung ML-85G GDI printer driver before 0.2.0 allows local users to overwrite arbitrary files via a symlink at
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
HP-UX 11 / Linux Kernel 2.4 / Windows 2000/NT 4.0 / IRIX 6.5 - Small TCP MSS Denial of Service
Multiple TCP implementations could allow remote attackers to cause a denial of service (bandwidth and CPU exhaustion) by
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Basilix Webmail 1.0 - File Disclosure
Directory traversal vulnerability in basilix.php3 in Basilix Webmail 1.0.3beta and earlier allows remote attackers to re
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Vixie Cron crontab 3.0 - Privilege Lowering Failure (2)
crontab in Vixie cron 3.0.1 and earlier does not properly drop privileges after the failed parsing of a modification ope
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cobalt Qube Webmail 1.0 - Directory Traversal
Directory traversal vulnerability in readmsg.php in WebMail 2.0.1 in Cobalt Qube 3 allows remote attackers to read arbit
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cobalt Raq3 PopRelayD - Arbitrary SMTP Relay
poprelayd script before 2.0 in Cobalt RaQ3 servers allows remote attackers to bypass authentication for relaying by caus
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 4.0/5.0 - Device File Local Denial of Service
Scripting.FileSystemObject in asp.dll for Microsoft IIS 4.0 and 5.0 allows local or remote attackers to cause a denial o
45RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Lmail 2.7 - Temporary File Race Condition
Lmail 2.7 and earlier allows local users to overwrite arbitrary files via a symlink attack on a temporary file.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 4.0/5.0 - Device File Remote Denial of Service
Scripting.FileSystemObject in asp.dll for Microsoft IIS 4.0 and 5.0 allows local or remote attackers to cause a denial o
45RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Citrix Nfuse 1.51 - Webroot Disclosure
Citrix Nfuse 1.51 allows remote attackers to obtain the absolute path of the web root via a malformed request to launch.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Xvt 2.1 - Local Buffer Overflow
Buffer overflow in Xvt 2.1 in Debian Linux 2.2 allows local users to execute arbitrary code via long (1) -name and (2) -
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 4.x - SafeMode Arbitrary File Execution
PHP 4.0.5 through 4.1.0 in safe mode does not properly cleanse the 5th parameter to the mail() function, which allows lo
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Active Classifieds 1.0 - Arbitrary Code Execution
admin.cgi in Active Classifieds Free Edition 1.0, and possibly commercial versions, allows remote attackers to modify th
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.