Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.258exploits catalogados
36.019CVEs com exploração pública
24.695testados em laboratório
24.458 exploits
Exploit-DBVexDay Proof
Cisco Virtual Central Office 4000 (VCO/4K) 5.1.3 - Remote Username / Password Retrieval
CVE-2000-0955remotehardware26 out 2000
Cisco Virtual Central Office 4000 (VCO/4K) uses weak encryption to store usernames and passwords in the SNMP MIB, which
23RISCO
abrir
Exploit-DBVexDay Proof
Cisco Catalyst 3500 XL - Arbitrary Command Execution
CVE-2000-0945remotehardware26 out 2000
The web configuration interface for Catalyst 3500 XL switches allows remote attackers to execute arbitrary commands with
60RISCO
abrir
Exploit-DBVexDay Proof
Sun HotJava Browser 3 - Arbitrary DOM Access
CVE-2000-0958remotemultiple25 out 2000
HotJava Browser 3.0 allows remote attackers to access the DOM of a web page by opening a javascript: URL in a named wind
23RISCO
abrir
Exploit-DBVexDay Proof
Cisco IOS 12 - Software '?/' HTTP Request Denial of Service
CVE-2000-0984doshardware25 out 2000
The HTTP server in Cisco IOS 12.0 through 12.1 allows local users to cause a denial of service (crash and reload) via a
23RISCO
abrir
Exploit-DBVexDay Proof
Netscape Directory Server 4.12 - Directory Server Directory Traversal
CVE-2000-1075remotewindows25 out 2000
Directory traversal vulnerability in iPlanet Certificate Management System 4.2 and Directory Server 4.12 allows remote a
23RISCO
abrir
Exploit-DBVexDay Proof
iPlanet Certificate Management System 4.2 - Directory Traversal
CVE-2000-1075remotewindows25 out 2000
Directory traversal vulnerability in iPlanet Certificate Management System 4.2 and Directory Server 4.12 allows remote a
23RISCO
abrir
Exploit-DBVexDay Proof
Allaire JRun 3 - Directory Disclosure
CVE-2000-1050remotemultiple23 out 2000
Allaire JRun 3.0 http servlet server allows remote attackers to directly access the WEB-INF directory via a URL request
23RISCO
abrir
Exploit-DBVexDay Proof
Avirt Mail 4.0/4.2 - 'Mail From:' / 'Rcpt to:' Denial of Service
CVE-2000-0971doswindows23 out 2000
Avirt Mail 4.0 and 4.2 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via
23RISCO
abrir
Exploit-DBVexDay Proof
Allaire JRun 2.3 - Arbitrary Code Execution
CVE-2000-1053remotemultiple23 out 2000
Allaire JRun 2.3.3 server allows remote attackers to compile and execute JSP code by inserting it via a cross-site scrip
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft IIS 4.0/5.0 and PWS - Extended Unicode Directory Traversal (2)
CVE-2000-0884remotewindows21 out 2000
IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary comman
45RISCO
abrir
Exploit-DBVexDay Proof
David Bagley xlock 4.16 - User Supplied Format String (2)
CVE-2000-0763localunix21 out 2000
xlockmore and xlockf do not properly cleanse user-injected format strings, which allows local users to gain root privile
23RISCO
abrir
Exploit-DBVexDay Proof
HP-UX 10.20/11.0 - crontab '/tmp' File
CVE-2000-0972localhp-ux20 out 2000
HP-UX 11.00 crontab allows local users to read arbitrary files via the -e option by creating a symlink to the target fil
23RISCO
abrir
Exploit-DBVexDay Proof
Intel InBusiness eMail Station 1.4.87 - Denial of Service
CVE-2000-0989doshardware20 out 2000
Buffer overflow in Intel InBusiness eMail Station 1.04.87 POP service allows remote attackers to cause a denial of servi
23RISCO
abrir
Exploit-DBVexDay Proof
Oracle Internet Directory 2.0.6 - oidldap
CVE-2000-0987locallinux18 out 2000
Buffer overflow in oidldapd in Oracle 8.1.6 allow local users to gain privileges via a long "connect" command line param
23RISCO
abrir
Exploit-DBVexDay Proof
Hilgraeve HyperTerminal 6.0 - Telnet Buffer Overflow
CVE-2000-0991doswindows18 out 2000
Buffer overflow in Hilgraeve, Inc. HyperTerminal client on Windows 98, ME, and 2000 allows remote attackers to execute a
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft IIS 4.0/5.0 and PWS - Extended Unicode Directory Traversal (5)
CVE-2000-0884remotewindows17 out 2000
IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary comman
45RISCO
abrir
Exploit-DBVexDay Proof
Microsoft IIS 4.0/5.0 and PWS - Extended Unicode Directory Traversal (1)
CVE-2000-0884remotewindows17 out 2000
IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary comman
45RISCO
abrir
Exploit-DBVexDay Proof
Microsoft IIS 4.0/5.0 and PWS - Extended Unicode Directory Traversal (4)
CVE-2000-0884remotewindows17 out 2000
IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary comman
45RISCO
abrir
Exploit-DBVexDay Proof
Microsoft IIS 4.0/5.0 and PWS - Extended Unicode Directory Traversal (3)
CVE-2000-0884remotewindows17 out 2000
IIS 4.0 and 5.0 allows remote attackers to read documents outside of the web root, and possibly execute arbitrary comman
45RISCO
abrir
Exploit-DBVexDay Proof
anaconda Foundation 1.4 < 1.9 - Directory Traversal
CVE-2000-0975remotecgi13 out 2000
Directory traversal vulnerability in apexec.pl in Anaconda Foundation Directory allows remote attackers to read arbitrar
23RISCO
abrir
Exploit-DBVexDay Proof
cURL 6.1 < 7.4 - Remote Buffer Overflow (2)
CVE-2000-0973remotelinux13 out 2000
Buffer overflow in curl earlier than 6.0-1.1, and curl-ssl earlier than 6.0-1.2, allows remote attackers to execute arbi
28RISCO
abrir
Exploit-DBVexDay Proof
cURL 6.1 < 7.4 - Remote Buffer Overflow (1)
CVE-2000-0973remotefreebsd13 out 2000
Buffer overflow in curl earlier than 6.0-1.1, and curl-ssl earlier than 6.0-1.2, allows remote attackers to execute arbi
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft NetMeeting 3.0.1 4.4.3385 - Remote Desktop Sharing Denial of Service
CVE-2000-0983doswindows13 out 2000
Microsoft NetMeeting with Remote Desktop Sharing enabled allows remote attackers to cause a denial of service (CPU utili
28RISCO
abrir
Exploit-DBVexDay Proof
XFree86 3.3.5/3.3.6 - Xlib Display Buffer Overflow
CVE-2000-0976localunix12 out 2000
Buffer overflow in xlib in XFree 3.3.x possibly allows local users to execute arbitrary commands via a long DISPLAY envi
23RISCO
abrir
Exploit-DBVexDay Proof
PHP 3.0/4.0 - Error Logging Format String
CVE-2000-0967remotephp12 out 2000
PHP 3 and 4 do not properly cleanse user-injected format strings, which allows remote attackers to execute arbitrary com
28RISCO
abrir
Exploit-DBVexDay Proof
Oatmeal Studios Mail File 1.10 - Arbitrary File Disclosure
CVE-2000-0977remotecgi11 out 2000
mailfile.cgi CGI program in MailFile 1.10 allows remote attackers to read arbitrary files by specifying the target file
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 9x/ME - Share Level Password Bypass (2)
CVE-2000-0979remotewindows10 out 2000
File and Print Sharing service in Windows 95, Windows 98, and Windows Me does not properly check the password for a file
35RISCO
abrir
Exploit-DBVexDay Proof
Netscape iCal 2.1 Patch2 - iPlanet iCal 'iplncal.sh' Permissions
CVE-2000-1072localsolaris10 out 2000
iCal 2.1 Patch 2 installs many files with world-writeable permissions, which allows local users to modify the iCal confi
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows 9x/ME - Share Level Password Bypass (1)
CVE-2000-0979remotewindows10 out 2000
File and Print Sharing service in Windows 95, Windows 98, and Windows Me does not properly check the password for a file
35RISCO
abrir
Exploit-DBVexDay Proof
Netscape iCal 2.1 Patch2 - iPlanet iCal 'csstart' Local Privilege Escalation
CVE-2000-1074localsolaris10 out 2000
csstart program in iCal 2.1 Patch 2 uses relative pathnames to install the libsocket and libnsl libraries, which could a
23RISCO
abrir
anteriorpágina 783 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.