Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.258exploits catalogados
36.019CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.697GitHub PoC 14.455VulnCheck XDB 8.811Nuclei 4.349Metasploit 3.488✓ só verificadosrecentespopularesrisco
24.458 exploits
Exploit-DB✓ VexDay Proof
extent technologies rbs isp 2.5 - Directory Traversal
Directory traversal vulnerability in Extent RBS ISP web server allows remote attackers to read sensitive information via
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco Secure ACS for Windows NT 2.42 - Remote Buffer Overflow
Buffer overflow in CSAdmin module in CiscoSecure ACS Server 2.4(2) and earlier allows remote attackers to cause a denial
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
NetcPlus BrowseGate 2.80 - Denial of Service
BrowseGate 2.80 allows remote attackers to cause a denial of service and possibly execute arbitrary commands via long Au
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco PIX Firewall 4.x/5.x - SMTP Content Filtering Evasion
The mailguard feature in Cisco Secure PIX Firewall 5.2(2) and earlier does not properly restrict access to SMTP commands
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows NT 4.0/2000 - DLL Search Path
When a Microsoft Office 2000 document is launched, the directory of that document is first used to locate DLL's such as
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CamShot WebCam 2.6 Trial - Remote Buffer Overflow
Buffer overflow in CamShot WebCam Trial2.6 allows remote attackers to execute arbitrary commands via a long Authorizatio
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Sambar Server 4.3/4.4 Beta 3 - Search CGI
search.dll Sambar ISAPI Search utility in Sambar Server 4.4 Beta 3 allows remote attackers to read arbitrary directories
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
IBM Websphere Application Server 3.0.2 Server Plugin - Denial of Service
Buffer overflow in IBM WebSphere web application server (WAS) allows remote attackers to execute arbitrary commands via
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MultiHTML 1.5 - File Disclosure
MultiHTML CGI script allows remote attackers to read arbitrary files and possibly execute arbitrary commands by specifyi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WebTV for Windows 98/ME - Denial of Service
annclist.exe in webTV for Windows allows remote attackers to cause a denial of service by via a large, malformed UDP pac
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Jack De Winter WinSMTP 1.6 f/2.0 - Buffer Overflow
Buffer overflow in WinSMTP 1.06f and 2.X allows remote attackers to cause a denial of service via a long (1) USER or (2)
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Mandrake 6.1/7.0/7.1 - '/perl' HTTP Directory Disclosure
The default configuration of mod_perl for Apache as installed on Mandrake Linux 6.1 through 7.1 sets the /perl/ director
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
YaBB 9.1.2000 - Arbitrary File Read
YaBB Bulletin Board 9.1.2000 allows remote attackers to read arbitrary files via a .. (dot dot) attack.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
RedHat Linux 6.1 i386 - Tmpwatch Recursive Write Denial of Service
The tmpwatch utility in Red Hat Linux forks a new process for each directory level, which allows local users to cause a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Solaris 2.6/7.0 'eject' locale - Subsystem Format String
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Mobius DocumentDirect for the Internet 1.2 - Remote Buffer Overflow
Buffer overflow in ddicgi.exe in Mobius DocumentDirect for the Internet 1.2 allows remote attackers to execute arbitrary
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
nathan purciful phpphotoalbum 0.9.9 - Directory Traversal
explorer.php in PhotoAlbum 0.9.9 allows remote attackers to read arbitrary files via a .. (dot dot) attack.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache 1.3.12 - WebDAV Directory Listings
The default configuration of Apache 1.3.12 in SuSE Linux 6.4 enables WebDAV, which allows remote attackers to list arbit
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
LPPlus 3.2.2/3.3 - Permissions Denial of Service
LPPlus creates the lpdprocess file with world-writeable permissions, which allows local users to kill arbitrary processe
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
LPPlus 3.2.2/3.3 - dccscan Unprivileged read
The dccscan setuid program in LPPlus does not properly check if the user has the permissions to print the file that is s
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
RedHat 6 GLIBC/locale - Subsystem Format String
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Server 2000 - Still Image Service Privilege Escalation
Buffer overflow in the Still Image Service in Windows 2000 allows local users to gain additional privileges via a long W
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Juergen Weigert screen 3.9 - User Supplied Format String
Format string vulnerability in screen 3.9.5 and earlier allows local users to gain root privileges via format characters
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Libc locale - Local Privilege Escalation (2)
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Libc locale - Local Privilege Escalation (1)
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Immunix OS 6.2 - LC glibc format string
Some functions that implement the locale subsystem on Unix do not properly cleanse user-injected format strings, which
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
AIX 4.2/4.3 - netstat -Z Statistic Clearing
netstat in AIX 4.x.x does not properly restrict access to the -Zi option, which allows local users to clear network inte
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
QSSL Voyager 2.0 1B - Arbitrary File Access
Directory traversal vulnerability in Voyager web server 2.01B in the demo disks for QNX 405 allows remote attackers to r
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
QSSL Voyager 2.0 1B - '.photon' Directory Information Disclosure
Voyager web server 2.01B in the demo disks for QNX 405 stores sensitive web client information in the .photon directory
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
GNOME esound 0.2.19 - Unix Domain Socket Race Condition
Race condition in the creation of a Unix domain socket in GNOME esound 0.2.19 and earlier allows a local user to change
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.