Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.258exploits catalogados
36.019CVEs com exploração pública
24.695testados em laboratório
24.458 exploits
Exploit-DBVexDay Proof
GNOME esound 0.2.19 - Unix Domain Socket Race Condition
CVE-2000-0864localunix31 ago 2000
Race condition in the creation of a Unix domain socket in GNOME esound 0.2.19 and earlier allows a local user to change
23RISCO
abrir
Exploit-DBVexDay Proof
Ipswitch IMail 6.x - File Attachment
CVE-2000-0780remotewindows30 ago 2000
The web server in IPSWITCH IMail 6.04 and earlier allows remote attackers to read and delete arbitrary files via a .. (d
23RISCO
abrir
Exploit-DBVexDay Proof
CGI Script Center Auction Weaver 1.0.2 - Remote Command Execution
CVE-2000-0690remotecgi30 ago 2000
Auction Weaver CGI script 1.02 and earlier allows remote attackers to execute arbitrary commands via shell metacharacter
28RISCO
abrir
Exploit-DBVexDay Proof
GWScripts News Publisher 1.0 - 'author.file' Write
CVE-2000-0720remotecgi29 ago 2000
news.cgi in GWScripts News Publisher does not properly authenticate requests to add an author to the author index, which
23RISCO
abrir
Exploit-DBVexDay Proof
RobTex Viking Server 1.0.6 Build 355 - Remote Buffer Overflow
CVE-2000-0775remotewindows28 ago 2000
Buffer overflow in RobTex Viking server earlier than 1.06-370 allows remote attackers to cause a denial of service or ex
23RISCO
abrir
Exploit-DBVexDay Proof
Gert Doering mgetty 1.1.19/1.1.20/1.1.21/1.22.8 - Symbolic Link Traversal
CVE-2000-0691localunix25 ago 2000
The faxrunq and faxrunqd in the mgetty package allows local users to create or modify arbitrary files via a symlink atta
23RISCO
abrir
Exploit-DBVexDay Proof
User-Mode Linux (Linux Kernel 2.4.17-8) - Memory Access Privilege Escalation
CVE-2002-2016locallinux25 ago 2000
User-mode Linux (UML) 2.4.17-8 does not restrict access to kernel address space, which allows local users to execute arb
23RISCO
abrir
Exploit-DBVexDay Proof
PragmaSys TelnetServer 2000 - rexec Buffer Overflow
CVE-2000-1002doswindows24 ago 2000
POP3 daemon in Stalker CommuniGate Pro 3.3.2 generates different error messages for invalid usernames versus invalid pas
23RISCO
abrir
Exploit-DBVexDay Proof
PragmaSys TelnetServer 2000 - rexec Buffer Overflow
CVE-2000-0708doswindows24 ago 2000
Buffer overflow in Pragma Systems TelnetServer 2000 version 4.0 allows remote attackers to cause a denial of service via
23RISCO
abrir
Exploit-DBVexDay Proof
CGI Script Center Account Manager 1.0 LITE / PRO - Administrative Password Alteration (1)
CVE-2000-0689remotecgi23 ago 2000
Account Manager LITE does not properly authenticate attempts to change the administrator password, which allows remote a
23RISCO
abrir
Exploit-DBVexDay Proof
CGI Script Center Subscribe Me Lite 2.0 - Administrative Password Alteration (1)
CVE-2000-0688remotecgi23 ago 2000
Subscribe Me LITE does not properly authenticate attempts to change the administrator password, which allows remote atta
23RISCO
abrir
Exploit-DBVexDay Proof
CGI Script Center Account Manager 1.0 LITE / PRO - Administrative Password Alteration (2)
CVE-2000-0689remotecgi23 ago 2000
Account Manager LITE does not properly authenticate attempts to change the administrator password, which allows remote a
23RISCO
abrir
Exploit-DBVexDay Proof
CGI Script Center Subscribe Me Lite 2.0 - Administrative Password Alteration (2)
CVE-2000-0688remotecgi23 ago 2000
Subscribe Me LITE does not properly authenticate attempts to change the administrator password, which allows remote atta
23RISCO
abrir
Exploit-DBVexDay Proof
Darxite 0.4 - Login Buffer Overflow
CVE-2000-0846remotelinux22 ago 2000
Buffer overflow in Darxite 0.4 and earlier allows a remote attacker to execute arbitrary commands via a long username or
23RISCO
abrir
Exploit-DBVexDay Proof
HP-UX 11.0 - net.init RC Script
CVE-2000-0702localhp-ux22 ago 2000
The net.init rc script in HP-UX 11.00 (S008net.init) allows local users to overwrite arbitrary files via a symlink attac
23RISCO
abrir
Exploit-DBVexDay Proof
PHP-Nuke 1.0/2.5 - Administrative Privileges
CVE-2000-0745webappsphp21 ago 2000
admin.php3 in PHP-Nuke does not properly verify the PHP-Nuke administrator password, which allows remote attackers to ga
28RISCO
abrir
Exploit-DBVexDay Proof
UMN Gopherd 2.x - Halidate Function Buffer Overflow
CVE-2000-0743remotelinux20 ago 2000
Buffer overflow in University of Minnesota (UMN) gopherd 2.x allows remote attackers to execute arbitrary commands via a
28RISCO
abrir
Exploit-DBVexDay Proof
Minicom 1.82/1.83 - Capture-file Group Ownership
CVE-2000-0698locallinux19 ago 2000
Minicom 1.82.1 and earlier on some Linux systems allows local users to create arbitrary files owned by the uucp user via
23RISCO
abrir
Exploit-DBVexDay Proof
vqSoft vqServer 1.4.49 - Denial of Service
CVE-2000-0766dosmultiple19 ago 2000
Buffer overflow in vqSoft vqServer 1.4.49 allows remote attackers to cause a denial of service or possibly gain privileg
23RISCO
abrir
Exploit-DBVexDay Proof
netwin netauth 4.2 - Directory Traversal
CVE-2000-0782remotecgi17 ago 2000
netauth.cgi program in Netwin Netauth 4.2e and earlier allows remote attackers to read arbitrary files via a .. (dot dot
23RISCO
abrir
Exploit-DBVexDay Proof
X-Chat 1.2/1.3/1.4/1.5 - Command Execution via URLs
CVE-2000-0787remotelinux17 ago 2000
IRC Xchat client versions 1.4.2 and earlier allows remote attackers to execute arbitrary commands by encoding shell meta
23RISCO
abrir
Exploit-DBVexDay Proof
Check Point Software Firewall-1 3.0/1 4.0/1 4.1 - Session Agent Dictionary Attack (1)
CVE-2000-1037remotemultiple15 ago 2000
Check Point Firewall-1 session agent 3.0 through 4.1 generates different error messages for invalid user names versus in
23RISCO
abrir
Exploit-DBVexDay Proof
David Bagley xlock 4.16 - User Supplied Format String (1)
CVE-2000-0763localunix15 ago 2000
xlockmore and xlockf do not properly cleanse user-injected format strings, which allows local users to gain root privile
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Server 2000 - 'telnet.exe' NTLM Authentication
CVE-2000-0834remotewindows14 ago 2000
The Windows 2000 telnet client attempts to perform NTLM authentication by default, which allows remote attackers to capt
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft IIS 5.0 - 'Translate: f' Source Disclosure (1)
CVE-2000-0778remotewindows14 ago 2000
IIS 5.0 allows remote attackers to obtain source code for .ASP files and other scripts via an HTTP GET request with a "T
45RISCO
abrir
Exploit-DBVexDay Proof
Microsoft IIS 5.0 - 'Translate: f' Source Disclosure (2)
CVE-2000-0778remotewindows14 ago 2000
IIS 5.0 allows remote attackers to obtain source code for .ASP files and other scripts via an HTTP GET request with a "T
45RISCO
abrir
Exploit-DBVexDay Proof
Luca Deri ntop 1.2 a7-9/1.3.1 - Remote Buffer Overflow
CVE-2000-0706remoteunix14 ago 2000
Buffer overflows in ntop running in web mode allows remote attackers to execute arbitrary commands.
23RISCO
abrir
Exploit-DBVexDay Proof
Multisoft FlagShip 4.4 - Installation Permission
CVE-2000-0721locallinux10 ago 2000
The FSserial, FlagShip_c, and FlagShip_p programs in the FlagShip package are installed world-writeable, which allows lo
23RISCO
abrir
Exploit-DBVexDay Proof
MediaHouse Software Statistics Server LiveStats 5.2 - Remote Buffer Overflow
CVE-2000-0776remotewindows10 ago 2000
Mediahouse Statistics Server 5.02x allows remote attackers to execute arbitrary commands via a long HTTP GET request.
23RISCO
abrir
Exploit-DBVexDay Proof
Aptis Software TotalBill 3.0 - Remote Command Execution
CVE-2000-0757remotelinux08 ago 2000
The sysgen service in Aptis Totalbill does not perform authentication, which allows remote attackers to gain root privil
23RISCO
abrir
anteriorpágina 786 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.