Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.258exploits catalogados
36.019CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.697GitHub PoC 14.455VulnCheck XDB 8.811Nuclei 4.349Metasploit 3.488✓ só verificadosrecentespopularesrisco
24.458 exploits
Exploit-DB✓ VexDay Proof
SunOS 5.7 Catman - Local Insecure tmp Symlink Clobber
catman in Solaris 2.7 and 2.8 allows local users to overwrite arbitrary files via a symlink attack on the sman_PID tempo
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Brian Stanback bsguest.cgi 1.0 - Remote Command Execution
bsguest.cgi guestbook script allows remote attackers to execute arbitrary commands via shell metacharacters in the email
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Brian Stanback bslist.cgi 1.0 - Remote Command Execution
bslist.cgi mailing list script allows remote attackers to execute arbitrary commands via shell metacharacters in the ema
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ProFTPd 1.2 - 'SIZE' Remote Denial of Service
Memory leak in ProFTPd 1.2.0rc2 allows remote attackers to cause a denial of service via a series of USER commands, and
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
OpenBSD ftpd 2.6/2.7 - Remote Overflow
One-byte buffer overflow in replydirname function in BSD-based ftpd allows remote attackers to gain root privileges.
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
BEA Systems WebLogic Server 4.0 x/4.5 x/5.1 x - Double Dot Buffer Overflow
Buffer overflow in Bea WebLogic Server before 5.1.0 allows remote attackers to execute arbitrary commands via a long URL
45RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Solaris 2.7/2.8 Catman - Local Insecure tmp Symlink
catman in Solaris 2.7 and 2.8 allows local users to overwrite arbitrary files via a symlink attack on the sman_PID tempo
23RISCO
abrir ↗Exploit-DB
BOA Web Server 0.94.8.2 - Arbitrary File Access
Directory traversal vulnerability in BOA web server 0.94.8.2 and earlier allows remote attackers to read arbitrary files
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Itetris 1.6.1/1.6.2 - Privileged Arbitrary Command Execution
itetris/xitetris 1.6.2 and earlier trusts the PATH environmental variable to find and execute the gunzip program, which
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
BSD ftpd 0.3.2 - Single Byte Buffer Overflow
One-byte buffer overflow in replydirname function in BSD-based ftpd allows remote attackers to gain root privileges.
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Solaris 2.5.1/2.6/7.0/8 - patchadd Race Condition
patchadd in Solaris allows local users to overwrite arbitrary files via a symlink attack.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
xsoldier 0.96 (RedHat 6.2) - Local Buffer Overflow
xsoldier program allows local users to gain root access via a long argument.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Oops! 1.4.6 - one russi4n proxy-server Heap Buffer Overflow
Buffer overflow in oops WWW proxy server 1.4.6 (and possibly other versions) allows remote attackers to execute arbitrar
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
LPRng 3.6.24-1 - Remote Command Execution
Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary comman
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Leif M. Wright simplestguest.cgi 2.0 - Remote Command Execution
simplestguest.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharact
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Check Point Software Firewall-1 4.1 SP2 - Fast Mode TCP Fragment
Check Point VPN-1/FireWall-1 4.1 SP2 with Fastmode enabled allows remote attackers to bypass access restrictions via mal
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco Catalyst 4000/5000/6000 6.1 - SSH Protocol Mismatch Denial of Service
Cisco Catalyst 6000, 5000, or 4000 switches allow remote attackers to cause a denial of service by connecting to the SSH
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
alex heiphetz Group eZshopper 2.0/3.0 - Directory Traversal
loadpage.cgi CGI program in EZshopper 3.0 and 2.0 allows remote attackers to list and read files in the EZshopper data d
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
AOL Instant Messenger 4.0/4.1.2010/4.2.1193 - BuddyIcon Buffer Overflow
Buffer overflow in AOL Instant Messenger (AIM) before 4.3.2229 allows remote attackers to execute arbitrary commands via
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
AOL Instant Messenger 3.5.1856/4.0/4.1.2010/4.2.1193 - 'aim://' Remote Buffer Overflow
Buffer overflow in AOL Instant Messenger before 4.3.2229 allows remote attackers to execute arbitrary commands via a lon
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Leif M. Wright everythingform.cgi 2.0 - Arbitrary Command Execution
everythingform.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharac
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Oops Proxy Server 1.4.22 - Remote Buffer Overflow (1)
Buffer overflow in the HTML parsing code in oops WWW proxy server 1.5.2 and earlier allows remote attackers to execute a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Leif M. Wright - 'ad.cgi' 1.0 Unchecked Input
ad.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacters in the
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Leif M. Wright simplestmail.cgi 1.0 - Remote Command Execution
simplestmail.cgi CGI program by Leif Wright allows remote attackers to execute arbitrary commands via shell metacharacte
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
RedHat Linux 7.0 - Roaring Penguin PPPoE Denial of Service
rp-pppoe PPPoE client allows remote attackers to cause a denial of service via the Clamp MSS option and a TCP packet wit
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
LPRng 3.6.22/23/24 - Remote Command Execution
Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary comman
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ssldump 0.9 b1 - Format String
Format string vulnerability in ssldump possibly allows remote attackers to cause a denial of service and possibly gain r
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
University of Washington Pico 3.x/4.x - File Overwrite
Vulnerability in (1) pine before 4.33 and (2) the pico editor, included with pine, allows local users local users to ove
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
LPRng (RedHat 7.0) - 'lpd' Format String
Format string vulnerability in use_syslog() function in LPRng 3.6.24 allows remote attackers to execute arbitrary comman
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
KTH Kerberos 4 - Arbitrary Proxy Usage
KTH Kerberos IV allows local users to specify an alternate proxy using the krb4_proxy variable, which allows the user to
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.