Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.258exploits catalogados
36.019CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.697GitHub PoC 14.455VulnCheck XDB 8.811Nuclei 4.349Metasploit 3.488✓ só verificadosrecentespopularesrisco
24.458 exploits
Exploit-DB✓ VexDay Proof
Microsoft IIS 3.0/4.0/5.0 - PWS Escaped Characters Decoding Command Execution (7)
Directory traversal vulnerability in IIS 5.0 and earlier allows remote attackers to execute arbitrary commands by encodi
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Maxum Rumpus FTP Server 1.3.2/1.3.4/2.0.3 dev - Remote Denial of Service
Maxum Rumpus FTP Server 1.3.3 and 2.0.3 dev 3 allows a remote attacker to perform a denial of service (hang) by creating
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Pacific Software Carello 1.2.1 Shopping Cart - Command Execution
Carello E-Commerce 1.2.1 and earlier allows a remote attacker to gain additional privileges and execute arbitrary comman
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Immunix OS 6.2/7.0 / RedHat 5.2/6.2/7.0 / SuSE Linux 6.x/7.0/7.1 - 'Man -S' Heap Overflow
Buffer overflow in man program in various distributions of Linux allows local user to execute arbitrary code as group ma
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
OpenServer 5.0.5/5.0.6 / HP-UX 10/11 / Solaris 2.6/7.0/8 - rpc.yppasswdd Buffer Overrun
Buffer overflow in rpc.yppasswdd (yppasswd server) in Solaris 2.6, 7 and 8 allows remote attackers to gain root access v
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Personal Web Sharing 1.1/1.5/1.5.5 - Remote Denial of Service
Personal Web Sharing 1.5.5 allows a remote attacker to cause a denial of service via a long HTTP request.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Server 2000 SP1/SP2 - isapi .printer Extension Overflow (2)
Buffer overflow in Internet Printing ISAPI extension in Windows 2000 allows remote attackers to gain root privileges via
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
DCForum 6.0 - Remote Admin Privilege Arbitrary Commands
DCScripts DCForum versions 2000 and earlier allow a remote attacker to gain additional privileges by inserting pipe symb
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
BeroFTPD 1.3.4(1) (Linux x86) - Remote Code Execution
The lreply function in wu-ftpd 2.6.0 and earlier does not properly cleanse an untrusted format string, which allows remo
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
IRIX 5.3/6.2/6.3/6.4/6.5/6.5.11 - '/usr/lib/print/netprint' Local Privilege Escalation
Unknown vulnerability in netprint in IRIX 6.2, and possibly other versions, allows local users with lp privileges attack
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SCO OpenServer 5.0.x - StartX Weak XHost Permissions
SCO OpenServer 5.0.5 through 5.0.7 only supports Xauthority style access control when users log in using scologin, which
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SpyNet 6.5 Chat Server - Multiple Connection Denial of Service Vulnerabilities
Spytech Spynet Chat Server 6.5 allows a remote attacker to create a denial of service (crash) via a large number of conn
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
IRIX 5.3/6.2/6.3/6.4/6.5/6.5.11 - '/usr/bin/lpstat' Local Overflow / Local Privilege Escalation
Buffer overflow in lpstat in IRIX 6.2 and 6.3 allows local users to gain root privileges via a long -n option.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Jason Rahaim MP3Mystic 1.0.x - Server Directory Traversal
Directory traversal vulnerability in MP3Mystic prior to 1.04b3 allows a remote attacker to download arbitrary files via
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Server 2000 SP1/SP2 - isapi .printer Extension Overflow (1)
Buffer overflow in Internet Printing ISAPI extension in Windows 2000 allows remote attackers to gain root privileges via
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
T. Hauck Jana Server 1.45/1.46/2.0 - MS-DOS Device Name Denial of Service
T. Hauck Jana Webserver 2.01 beta 1 and earlier allows a remote attacker to create a denial of service via a URL request
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
T. Hauck Jana Server 1.45/1.46 - Hex Encoded Directory Traversal
T. Hauck Jana Webserver 1.46 and earlier allows a remote attacker to view arbitrary files via a '..' (dot dot) attack wh
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Vixie Cron crontab 3.0 - Privilege Lowering Failure (1)
crontab in Vixie cron 3.0.1 and earlier does not properly drop privileges after the failed parsing of a modification ope
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Drummond Miles A1Stats 1.0 - 'a1disp2.cgi' Traversal Arbitrary File Read
Directory traversal vulnerability in Drummond Miles A1Stats prior to 1.6 allows a remote attacker to read arbitrary file
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Novell BorderManager Enterprise Edition 3.5 - Denial of Service
Remote attackers can cause a denial of service in Novell BorderManager 3.6 and earlier by sending TCP SYN flood to port
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Drummond Miles A1Stats 1.0 - 'a1disp3.cgi' Traversal Arbitrary File Read
Directory traversal vulnerability in Drummond Miles A1Stats prior to 1.6 allows a remote attacker to read arbitrary file
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Drummond Miles A1Stats 1.0 - 'a1disp4.cgi' Traversal Arbitrary File Read
Directory traversal vulnerability in Drummond Miles A1Stats prior to 1.6 allows a remote attacker to read arbitrary file
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ElectroSoft ElectroComm 1.0/2.0 - Denial of Service
ElectroSystems Engineering Inc. ElectroComm 2.0 and earlier allows a remote attacker to create a denial of service via l
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Hughes Technologies DSL_Vdns 1.0 - Denial of Service
Hughes Technologies Virtual DNS (VDNS) Server 1.0 allows a remote attacker to create a denial of service by connecting t
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
cgiCentral WebStore 400 - Administrator Authentication Bypass
WSSecurity.pl in WebStore allows remote attackers to bypass authentication by providing the program with a filename that
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
cgiCentral WebStore 400 - Arbitrary Command Execution
ws_mail.cgi in WebStore 400/400CS 4.14 allows remote authenticated WebStore administrators to execute arbitrary code via
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WU-FTPD 2.4.2/2.5 .0/2.6.0 - Remote Format String Stack Overwrite (3)
The lreply function in wu-ftpd 2.6.0 and earlier does not properly cleanse an untrusted format string, which allows remo
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco Catalyst 2900 12.0 - '5.2'XU SNMP Empty UDP Packet Denial of Service
Cisco Catalyst 2900XL switch allows a remote attacker to create a denial of service via an empty UDP packet sent to port
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco HSRP - Denial of Service
Cisco Hot Standby Routing Protocol (HSRP) allows local attackers to cause a denial of service by spoofing HSRP packets.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 5.0 - '.printer' ISAPI Extension Buffer Overflow (2)
Buffer overflow in Internet Printing ISAPI extension in Windows 2000 allows remote attackers to gain root privileges via
60RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.