Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.254exploits catalogados
36.016CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.697GitHub PoC 14.451VulnCheck XDB 8.811Nuclei 4.349Metasploit 3.488✓ só verificadosrecentespopularesrisco
24.458 exploits
Exploit-DB✓ VexDay Proof
Microsoft Index Server 2.0 / Indexing Service (Windows 2000) - ISAPI Extension Buffer Overflow (4)
Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier a
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Index Server 2.0 / Indexing Service (Windows 2000) - ISAPI Extension Buffer Overflow (PoC)
Buffer overflow in ISAPI extension (idq.dll) in Index Server 2.0 and Indexing Service 2000 in IIS 6.0 beta and earlier a
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SGI Performance Co-Pilot 2.1.x/2.2 - pmpost Symbolic Link
The pmpost program in Performance Co-Pilot (PCP) before 2.2.1-3 allows a local user to gain privileges via a symlink att
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Internet Software Solutions Air Messenger LAN Server 3.4.2 - Full Path Disclosure
Internet Software Solutions Air Messenger LAN Server (AMLServer) 3.4.2 allows remote attackers to obtain an absolute pat
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Tarantella Enterprise 3 3.x - 'TTAWebTop.cgi' Arbitrary File Viewing
Directory traversal vulnerability in ttawebtop.cgi in Tarantella Enterprise 3.00 and 3.01 allows remote attackers to rea
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ghttpd 1.4 - Daemon Buffer Overflow
Buffer overflows in GazTek ghttpd 1.4 allows a remote attacker to execute arbitrary code via long arguments that are pas
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ghttpd 1.4 - Daemon Buffer Overflow
Buffer overflow in the Log function in util.c in GazTek ghttpd 1.4 through 1.4.3 allows remote attackers to execute arbi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Rxvt 2.6.1/2.6.2 - Local Buffer Overflow
Buffer overflow in tt_printf function of rxvt 2.6.2 allows local users to gain privileges via a long (1) -T or (2) -name
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
NetSQL 1.0 - Remote Buffer Overflow
Buffer overflow in Munica Corporation NetSQL 1.0 allows remote attackers to execute arbitrary code via a long CONNECT ar
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
BestCrypt 0.6/0.7/0.8 - BCTool UMount Buffer Overflow
Buffer overflow in bctool in Jetico BestCrypt 0.8.1 and earlier allows local users to execute arbitrary code via a file
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SiteWare 2.5/3.0/3.1 Editor Desktop - Directory Traversal
ScreamingMedia SITEWare versions 2.5 through 3.1 allows a remote attacker to read world-readable files via a .. (dot do
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache 1.3 - Artificially Long Slash Path Directory Listing (1)
The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview in
45RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Juergen Schoenwaelder scotty 2.1.x - ntping Buffer Overflow
Buffer overflow in ntping in scotty 2.1.0 allows local users to execute arbitrary code via a long hostname as a command
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache 1.3 - Artificially Long Slash Path Directory Listing (3)
The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview in
45RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache 1.3 - Artificially Long Slash Path Directory Listing (4)
The default installation of Apache before 1.3.19 allows remote attackers to list directories instead of the multiview in
45RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MDBms 0.96/0.99 - Query Display Buffer Overflow
A buffer overflow the '\s' console command in MDBMS 0.99b9 and earlier allows remote attackers to execute arbitrary comm
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Rumpus FTP Server 1.3.x/2.0.3 - Stack Overflow Denial of Service
Maximum Rumpus FTP Server 2.0.3 dev and before allows an attacker to cause a denial of service (crash) via a mkdir comma
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Sean MacGuire Big Brother 1.0/1.3/1.4 - CGI File Creation
The default configuration of Big Brother 1.4h2 and earlier does not include proper access restrictions, which allows rem
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
XFree86 X11R6 3.3.2 XMan - ManPath Environment Variable Buffer Overflow
Buffer overflow in xman allows local users to gain privileges via a long MANPATH environment variable.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache 1.3.14 - Mac File Protection Bypass
Apache on MacOS X Client 10.0.3 with the HFS+ file system allows remote attackers to bypass access restrictions via a UR
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
TransSoft Broker FTP Server 3.0/4.0/4.7/5.x - CWD Buffer Overflow
Broker FTP Server 5.9.5.0 allows a remote attacker to cause a denial of service by repeatedly issuing an invalid CD or C
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
BSD - 'TelnetD' Remote Command Execution (1)
Vulnerability in telnetd in FreeBSD 1.5 allows local users to gain root privileges by modifying critical environmental v
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
IBM Tivoli NetView 5/6 - OVActionD SNMPNotify Command Execution
ovactiond in HP OpenView Network Node Manager (NNM) 6.1 and Tivoli Netview 5.x and 6.x allows remote attackers to execut
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Thibault Godouet FCron 1 - Symbolic Link
Thibault Godouet FCron prior to 1.1.1 allows a local user to corrupt another user's crontab file via a symlink attack on
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
LPRng 3.6.x - Failure To Drop Supplementary Groups
LPRng in Red Hat Linux 7.0 and 7.1 does not properly drop memberships in supplemental groups when lowering privileges, w
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Server 2000 - Telnet 'Username' Denial of Service
Microsoft Windows 2000 telnet service allows attackers to cause a denial of service (crash) via a long logon command tha
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
kosch suid wrapper 1.1.1 - Local Buffer Overflow
Buffer overflow in su-wrapper 1.1.1 allows local users to execute arbitrary code via a long first argument.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Exim 3.x - Format String
Format string vulnerability in exim (3.22-10 in Red Hat, 3.12 in Debian and 3.16 in Conectiva) in batched SMTP mode allo
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Pragma Systems InterAccess TelnetD Server 4.0 - Denial of Service
telnet95.exe in Pragma InterAccess 4.0 build 5 allows remote attackers to cause a denial of service (crash) via a large
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Outlook 97/98/2000/4/5 - Address Book Spoofing
Microsoft Outlook 8.5 and earlier, and Outlook Express 5 and earlier, with the "Automatically put people I reply to in m
28RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.