Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.258exploits catalogados
36.019CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.697GitHub PoC 14.455VulnCheck XDB 8.811Nuclei 4.349Metasploit 3.488✓ só verificadosrecentespopularesrisco
24.458 exploits
Exploit-DB✓ VexDay Proof
KTH Kerberos 4 - Arbitrary Proxy Usage
KTH Kerberos IV allows local users to specify an alternate proxy using the krb4_proxy variable, which allows the user to
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MetaProducts Offline Explorer 1.x - FileSystem Disclosure
Offline Explorer 1.4 before Service Release 2 allows remote attackers to read arbitrary files by specifying the drive le
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Oops Proxy Server 1.4.22 - Remote Buffer Overflow (2)
Buffer overflow in the HTML parsing code in oops WWW proxy server 1.5.2 and earlier allows remote attackers to execute a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
keware technologies homeseer 1.4 - Directory Traversal
Directory traversal vulnerability in HomeSeer before 1.4.29 allows remote attackers to read arbitrary files via a URL co
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Endymion MailMan 3.0.x - Arbitrary Command Execution
MailMan Webmail 3.0.25 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache 1.3 + PHP 3 - File Disclosure
PHP 3.x (PHP3) on Apache 1.3.6 allows remote attackers to read arbitrary files via a modified .. (dot dot) attack contai
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 3.0.16/4.0.2 - Remote Format Overflow
PHP 3 and 4 do not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary com
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco Catalyst 4000 4.x/5.x / Catalyst 5000 4.5/5.x / Catalyst 6000 5.x - Memory Leak Denial of Service
Memory leak in Cisco Catalyst 4000, 5000, and 6000 series switches allows remote attackers to cause a denial of service
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
IBM DB2 - Universal Database for Linux 6.1/Windows NT 6.1 Known Default Password
IBM DB2 Universal Database version 6.1 creates an account with a default user name and password, which allows remote att
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cat Soft Serv-U FTP Server 2.4/2.5 - FTP Directory Traversal
Directory traversal vulnerability in FTP Serv-U before 2.5i allows remote attackers to escape the FTP root and read arbi
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
IBM DB2 - Universal Database for Windows NT 6.1/7.1 SQL Denial of Service
IBM DB2 Universal Database version 6.1 allows users to cause a denial of service via a malformed query.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows NT 4.0 - Phonebook Server Buffer Overflow
Buffer overflow in Microsoft Phone Book Service allows local users to execute arbitrary commands, aka the "Phone Book Se
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
UUCP - File Creation/Overwriting Symlinks
Multiple shell programs on various Unix systems, including (1) tcsh, (2) csh, (3) sh, and (4) bash, follow symlinks when
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
BitchX IRC Client 1.0 c17 - DNS Buffer Overflow
Buffer overflow in BitchX IRC client allows remote attackers to cause a denial of service and possibly execute arbitrary
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
GLIBC locale - bug mount
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows - 'Jolt2.c' Denial of Service (MS00-029)
Windows 95, Windows 98, Windows 2000, Windows NT 4.0, and Terminal Server systems allow a remote attacker to cause a den
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
dislocate 1.3 - Local i386
Secure Locate (slocate) allows local users to corrupt memory via a malformed database file that specifies an offset valu
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft SQL Server 7.0/2000 / Data Engine 1.0/2000 - xp_peekqueue Buffer Overflow
The xp_peekqueue function in Microsoft SQL Server 2000 and SQL Server Desktop Engine (MSDE) does not properly restrict t
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5 - 'INPUT TYPE=FILE' Remote File Upload
Internet Explorer 5.0 through 5.5 allows remote attackers to read arbitrary files from the client via the INPUT TYPE ele
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft SQL Server 7.0/2000 / Data Engine 1.0/2000 - xp_showcolv Buffer Overflow
The xp_showcolv function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict the len
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHF (Linux/x86) - Remote Buffer Overflow
Buffer overflow in phf CGI program allows remote attackers to execute arbitrary commands by specifying a large number of
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
HP-UX FTPD - Remote Buffer Overflow
Format string vulnerability in ftpd in HP-UX 10.20 allows remote attackers to cause a denial of service or execute arbit
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
IBM AIX 4.3.x - '/usr/lib/lpd/piobe' Local Buffer Overflow
Buffer overflow in piobe command in IBM AIX 4.3.x allows local users to gain privileges via long environmental variables
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
IBM AIX 4.3 - '/usr/lib/lpd/digest' Local Buffer Overflow
Buffer overflow in digest command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft SQL Server 7.0/2000 / Data Engine 1.0/2000 - xp_displayparamstmt Buffer Overflow
The xp_displayparamstmt function in SQL Server and Microsoft SQL Server Desktop Engine (MSDE) does not properly restrict
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
IBM AIX 4.x - '/usr/bin/setsenv' Local Buffer Overflow
Buffer overflow in setsenv command in IBM AIX 4.3.x and earlier allows local users to execute arbitrary commands via a l
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Solaris sadmind - Remote Buffer Overflow
Buffer overflow in Solaris sadmind allows remote attackers to gain root privileges using a NETMGT_PROC_SERVICE request.
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Solaris 2.6/7.0 - 'locale' Format Strings noexec stack Overflow
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Trlinux Postaci Webmail 1.1.3 - Password Disclosure
The default configuration for PostACI webmail system installs the /includes/global.inc configuration file within the web
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
GLIBC - '/bin/su' Local Privilege Escalation
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which
28RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.