Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.258exploits catalogados
36.019CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.697GitHub PoC 14.455VulnCheck XDB 8.811Nuclei 4.349Metasploit 3.488✓ só verificadosrecentespopularesrisco
24.458 exploits
Exploit-DB✓ VexDay Proof
Nevis Systems All-Mail 1.1 - Remote Buffer Overflow
Buffer overflow in All-Mail 1.1 allows remote attackers to execute arbitrary commands via a long "MAIL FROM" or "RCPT TO
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Evolvable Shambala Server 4.5 - Denial of Service
Shambala Server 4.5 allows remote attackers to cause a denial of service by opening then closing a connection.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
extropia webstore 1.0/2.0 - Directory Traversal
Directory traversal vulnerability in html_web_store.cgi and web_store.cgi CGI programs in eXtropia WebStore allows remot
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Bytes interactive Web shopper 1.0/2.0 - Directory Traversal
Directory traversal vulnerability in Bytes Interactive Web Shopper shopping cart program (shopper.cgi) 2.0 and earlier a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
phpix 1.0 - Directory Traversal
Directory traversal vulnerability in PHPix Photo Album 1.0.2 and earlier allows remote attackers to read arbitrary files
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Hassan Consulting Shopping Cart 1.18 - Directory Traversal
Directory traversal vulnerability in Hassan Consulting shop.cgi shopping cart program allows remote attackers to read ar
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
RedHat 6.2/7.0 Tmpwatch - Arbitrary Command Execution
Linux tmpwatch --fuser option allows local users to execute arbitrary commands by creating files whose names contain she
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
OpenBSD 2.x - Pending ARP Request Remote Denial of Service
OpenBSD 2.6 and earlier allows remote attackers to cause a denial of service by flooding the server with ARP requests.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Virtual Machine 2000/3100/3200/3300 Series - 'com.ms.activeX.ActiveXComponent' Arbitrary Program Execution
Microsoft Virtual Machine (VM) in Internet Explorer 4.x and 5.x allows an unsigned applet to create and use ActiveX cont
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
OpenBSD 2.x - 'fstat' Format String
Format string vulnerability in OpenBSD fstat program (and possibly other BSD-based operating systems) allows local users
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 5.0 - Indexed Directory Disclosure
A misconfiguration in IIS 5.0 with Index Server enabled and the Index property set allows remote attackers to list direc
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
David Harris Pegasus Mail 3.12 - File Forwarding
Pegasus Mail 3.12 allows remote attackers to read arbitrary files via an embedded URL that calls the mailto: protocol wi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco PIX Firewall 5.2 - PASV Mode FTP Internal Address Disclosure
Cisco Secure PIX Firewall 5.2(2) allows remote attackers to determine the real IP address of a target FTP server by floo
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Smartwin Technology CyberOffice Shopping Cart 2.0 - Price Modification
SmartWin CyberOffice Shopping Cart 2 (aka CyberShop) allows remote attackers to modify price information by changing the
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Moreover CGI script - File Disclosure
Directory traversal vulnerability in Moreover.com cached_feed.cgi script version 4.July.00 allows remote attackers to re
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SmartWin CyberOffice Shopping Cart 2.0 - Client Information Disclosure
The default installation of SmartWin CyberOffice Shopping Cart 2 (aka CyberShop) installs the _private directory with wo
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Check Point Software Firewall-1 3.0/1 4.0/1 4.1 - Session Agent Dictionary Attack (2)
Check Point Firewall-1 session agent 3.0 through 4.1 generates different error messages for invalid user names versus in
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
OpenSSH 1.2 - '.scp' File Create/Overwrite
Directory traversal vulnerability in scp in sshd 1.2.xx allows a remote malicious scp server to overwrite arbitrary file
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
LBL Traceroute 1.4 a5 - Heap Corruption (3)
Heap overflow in savestr function in LBNL traceroute 1.4a5 and earlier allows a local user to execute arbitrary commands
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
LBL Traceroute 1.4 a5 - Heap Corruption (1)
Heap overflow in savestr function in LBNL traceroute 1.4a5 and earlier allows a local user to execute arbitrary commands
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
LBL Traceroute 1.4 a5 - Heap Corruption (2)
Heap overflow in savestr function in LBNL traceroute 1.4a5 and earlier allows a local user to execute arbitrary commands
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WU-FTPD 2.4.2/2.5 .0/2.6.0 - Remote Format String Stack Overwrite (2)
The lreply function in wu-ftpd 2.6.0 and earlier does not properly cleanse an untrusted format string, which allows remo
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Palm OS 3.5.2 - Weak Encryption
PalmOS 3.5.2 and earlier uses weak encryption to store the user password, which allows attackers with physical access to
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Media Player 7 - Embedded OCX Control
Microsoft Windows Media Player 7 allows attackers to cause a denial of service in RTF-enabled email clients via an embed
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Unixware 7.0 - SCOhelp HTTP Server Format String
Format string vulnerability in the search97.cgi CGI script in SCO help http server for Unixware 7 allows remote attacker
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Script Host 5.1/5.5 - 'GetObject()' File Disclosure
Windows Scripting Host in Internet Explorer 5.5 and earlier allows remote attackers to read arbitrary files via the GetO
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
HP OpenView Network Node Manager 6.10 - SNMP Denial of Service
Buffer overflow in OverView5 CGI program in HP OpenView Network Node Manager (NNM) 6.1 and earlier allows remote attacke
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Alabanza Control Panel 3.0 - Domain Modification
The Alabanza Control Panel does not require passwords to access administrative commands, which allows remote attackers t
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
UoW Pine 4.0.4/4.10/4.21 - 'From:' Remote Buffer Overflow
Buffer overflow in the automatic mail checking component of Pine 4.21 and earlier allows remote attackers to execute arb
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
NetcPlus BrowseGate 2.80 - Denial of Service
BrowseGate 2.80 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via long Au
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.