Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.258exploits catalogados
36.019CVEs com exploração pública
24.695testados em laboratório
24.458 exploits
Exploit-DBVexDay Proof
LBL Traceroute - Local Privilege Escalation
CVE-2000-0949locallinux15 nov 2000
Heap overflow in savestr function in LBNL traceroute 1.4a5 and earlier allows a local user to execute arbitrary commands
23RISCO
abrir
Exploit-DBVexDay Proof
Poll It CGI 2.0 - Multiple Vulnerabilities
CVE-2000-1069webappscgi15 nov 2000
pollit.cgi in Poll It 2.01 and earlier allows remote attackers to access administrative functions without knowing the re
23RISCO
abrir
Exploit-DBVexDay Proof
News Update 1.1 - Change Admin Password
CVE-2000-0944webappscgi15 nov 2000
CGI Script Center News Update 1.1 does not properly validate the original news administration password during a password
28RISCO
abrir
Exploit-DBVexDay Proof
Joe Kloss RobinHood 1.1 - Remote Buffer Overflow
CVE-2000-1154remotebeos14 nov 2000
RHConsole in RobinHood 1.1 web server in BeOS r5 pro and earlier allows remote attackers to cause a denial of service vi
23RISCO
abrir
Exploit-DBVexDay Proof
Small HTTP Server 2.0 1 - Non-Existent File Denial of Service
CVE-2000-0897doswindows14 nov 2000
Small HTTP Server 2.03 and earlier allows remote attackers to cause a denial of service by repeatedly requesting a URL t
23RISCO
abrir
Exploit-DBVexDay Proof
DCForum 1-6 - Arbitrary File Disclosure
CVE-2000-1132remotecgi14 nov 2000
DCForum cgforum.cgi CGI script allows remote attackers to read arbitrary files, and delete the program itself, via a mal
23RISCO
abrir
Exploit-DBVexDay Proof
Linux modutils 2.3.9 - 'modprobe' Arbitrary Command Execution
CVE-2000-1095locallinux12 nov 2000
modprobe in the modutils 2.3.x package on Linux systems allows a local user to execute arbitrary commands via shell meta
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Indexing Service (Windows 2000) - File Verification
CVE-2000-1105remotewindows10 nov 2000
The ixsso.query ActiveX Object is marked as safe for scripting, which allows malicious web site operators to embed a scr
28RISCO
abrir
Exploit-DBVexDay Proof
Computer Associates InoculateIT 4.53 - Microsoft Exchange Agent
CVE-2000-1244localwindows10 nov 2000
Computer Associates InoculateIT Agent for Exchange Server does not recognize an e-mail virus attachment if the SMTP head
23RISCO
abrir
Exploit-DBVexDay Proof
Solaris 2.5/2.5.1/2.6/7.0 - 'sadmind' Remote Buffer Overflow (3)
CVE-1999-0977remotesolaris10 nov 2000
Buffer overflow in Solaris sadmind allows remote attackers to gain root privileges using a NETMGT_PROC_SERVICE request.
28RISCO
abrir
Exploit-DBVexDay Proof
HP-UX 10.20 - registrar Local Arbitrary File Read
CVE-2000-1127localhp-ux08 nov 2000
registrar in the HP resource monitor service allows local users to read and modify arbitrary files by renaming the origi
23RISCO
abrir
Exploit-DBVexDay Proof
YaBB 9.11.2000 - 'search.pl' Arbitrary Command Execution
CVE-2000-1176remotecgi07 nov 2000
Directory traversal vulnerability in YaBB search.pl CGI script allows remote attackers to read arbitrary files via a ..
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft IIS 4.0/5.0 - Executable File Parsing
CVE-2000-0886remotewindows06 nov 2000
IIS 5.0 allows remote attackers to execute arbitrary commands via a malformed request for an executable file whose name
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft IIS 4.0 - ISAPI Buffer Overflow
CVE-2000-1147localwindows06 nov 2000
Buffer overflow in IIS ISAPI .ASP parsing mechanism allows attackers to execute arbitrary commands via a long string to
23RISCO
abrir
Exploit-DBVexDay Proof
RedHat 0.4 b15 restore - Insecure Environment Variables
CVE-2000-1125locallinux04 nov 2000
restore 0.4b15 and earlier in Red Hat Linux 6.2 trusts the pathname specified by the RSH environmental variable, which a
23RISCO
abrir
Exploit-DBVexDay Proof
Solaris 2.6/7.0 /locale - Subsystem Format String
CVE-2000-0844localsolaris02 nov 2000
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which
28RISCO
abrir
Exploit-DBVexDay Proof
HP-UX 9.x/10.x/11.x - cu Buffer Overflow
CVE-2000-1028doshp-ux02 nov 2000
Buffer overflow in cu program in HP-UX 11.0 may allow local users to gain privileges via a long -l command line argument
23RISCO
abrir
Exploit-DBVexDay Proof
Samba 2.0.7 - SWAT Symlink (1)
CVE-2000-0935locallinux01 nov 2000
Samba Web Administration Tool (SWAT) in Samba 2.0.7 allows local users to overwrite arbitrary files via a symlink attack
23RISCO
abrir
Exploit-DBVexDay Proof
ManTrap 1.6.1 - Root Directory Inode Disclosure
CVE-2000-1144localunix01 nov 2000
Recourse ManTrap 1.6 sets up a chroot environment to hide the fact that it is running, but the inode number for the resu
23RISCO
abrir
Exploit-DBVexDay Proof
FreeBSD 3.5/4.x - '/usr/bin/top' Format String
CVE-2000-0998localfreebsd01 nov 2000
Format string vulnerability in top program allows local attackers to gain root privileges via the "kill" or "renice" fun
23RISCO
abrir
Exploit-DBVexDay Proof
Samba 2.0.7 - SWAT Logging Failure
CVE-2000-0937remoteunix01 nov 2000
Samba Web Administration Tool (SWAT) in Samba 2.0.7 does not log login attempts in which the username is correct but the
23RISCO
abrir
Exploit-DBVexDay Proof
Samba 2.0.7 - SWAT Logfile Permissions
CVE-2000-0936locallinux01 nov 2000
Samba Web Administration Tool (SWAT) in Samba 2.0.7 installs the cgi.log logging file with world readable permissions, w
23RISCO
abrir
Exploit-DBVexDay Proof
Samba 2.0.7 - SWAT Symlink (2)
CVE-2000-0935locallinux01 nov 2000
Samba Web Administration Tool (SWAT) in Samba 2.0.7 allows local users to overwrite arbitrary files via a symlink attack
23RISCO
abrir
Exploit-DBVexDay Proof
ManTrap 1.6.1 - Hidden Process Disclosure
CVE-2000-1140localunix01 nov 2000
Recourse ManTrap 1.6 does not properly hide processes from attackers, which could allow attackers to determine that they
23RISCO
abrir
Exploit-DBVexDay Proof
ISC BIND 8.2.2-P5 - Denial of Service
CVE-2000-0887doslinux01 nov 2000
named in BIND 8.2 through 8.2.2-P6 allows remote attackers to cause a denial of service by making a compressed zone tran
28RISCO
abrir
Exploit-DBVexDay Proof
Unify eWave ServletExec 3.0 c - Denial of Service
CVE-2000-1025dosmultiple30 out 2000
eWave ServletExec JSP/Java servlet engine, versions 3.0C and earlier, allows remote attackers to cause a denial of servi
23RISCO
abrir
Exploit-DBVexDay Proof
Kootenay Web Inc whois 1.0 - Remote Command Execution
CVE-2000-0941remotecgi29 out 2000
Kootenay Web KW Whois 1.0 CGI program allows remote attackers to execute arbitrary commands via shell metacharacters in
28RISCO
abrir
Exploit-DBVexDay Proof
Cat Soft Serv-U FTP Server 2.5.x - Brute Force
CVE-2000-1033remotewindows29 out 2000
Serv-U FTP Server allows remote attackers to bypass its anti-hammering feature by first logging on as a valid user (poss
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Indexing Service (Windows 2000/NT 4.0) - '.htw' Cross-Site Scripting
CVE-2000-0942remotewindows28 out 2000
The CiWebHitsFile component in Microsoft Indexing Services for Windows 2000 allows remote attackers to conduct a cross s
28RISCO
abrir
Exploit-DBVexDay Proof
ISC BIND 8.1 - Host Remote Buffer Overflow
CVE-2000-1029remoteunix27 out 2000
Buffer overflow in host command allows a remote attacker to execute arbitrary commands via a long response to an AXFR qu
28RISCO
abrir
anteriorpágina 782 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.