Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.258exploits catalogados
36.019CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.697GitHub PoC 14.455VulnCheck XDB 8.811Nuclei 4.349Metasploit 3.488✓ só verificadosrecentespopularesrisco
24.458 exploits
Exploit-DB✓ VexDay Proof
Tomcat 3.0/3.1 Snoop Servlet - Information Disclosure
The Snoop servlet in Jakarta Tomcat 3.1 and 3.0 under Apache reveals sensitive system information when a remote attacker
50RISCO
abrir ↗Exploit-DB✓ VexDay Proof
HP JetDirect J3111A - Invalid FTP Command Denial of Service
HP JetDirect printers versions G.08.20 and H.08.20 and earlier allow remote attackers to cause a denial of service via a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
NetZero ZeroPort 3.0 - Weak Encryption Method
BEA WebLogic 5.1.x does not properly restrict access to the JSPServlet, which could allow remote attackers to compile an
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Computer Software Manufaktur Alibaba 2.0 - Piped Command
Buffer overflow in Alibaba web server allows remote attackers to cause a denial of service via a long GET request.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Computer Software Manufaktur Alibaba 2.0 - Denial of Service
Buffer overflow in Alibaba web server allows remote attackers to cause a denial of service via a long GET request.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Outlook 97/98/2000 / Outlook Express 4.0/5.0 - GMT Field Buffer Overflow (2)
Buffer overflow in Microsoft Outlook and Outlook Express allows remote attackers to execute arbitrary commands via a lon
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Outlook 97/98/2000 / Outlook Express 4.0/5.0 - GMT Field Buffer Overflow (1)
Buffer overflow in Microsoft Outlook and Outlook Express allows remote attackers to execute arbitrary commands via a lon
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Armada Design Master Index 1.0 - Directory Traversal
Directory traversal vulnerability in search.cgi CGI script in Armada Master Index allows remote attackers to read arbitr
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
NetZero ZeroPort 3.0 - Weak Encryption Method
NetZero 3.0 and earlier uses weak encryption for storing a user's login information, which allows a local user to decryp
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 4.0/5.0 - Source Fragment Disclosure
IIS 4.0 and 5.0 allows remote attackers to obtain fragments of source code by appending a +.htr to the URL, a variant of
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Conectiva 4.x/5.x / Debian 2.x / RedHat 6.x / S.u.S.E 6.x/7.0 / Trustix 1.x - rpc.statd Remote Format String (1)
rpc.statd in the nfs-utils package in various Linux distributions does not properly cleanse untrusted format strings, wh
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
AnalogX SimpleServer:WWW 1.0.5 - Denial of Service
Buffer overflow in AnalogX SimpleServer 1.05 allows a remote attacker to cause a denial of service via a long GET reques
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 2.0/3.0/4.0/5.0/5.1 - Internal IP Address Disclosure
IIS 4.0 allows remote attackers to obtain the internal IP address of the server via an HTTP 1.0 request for a web page w
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Infopulse GateKeeper 3.5 - Remote Buffer Overflow
Buffer overflow in Infopulse Gatekeeper 3.5 and earlier allows remote attackers to execute arbitrary commands via a long
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CVSWeb Developer CVSWeb 1.80 - Insecure Perl 'open' Code Execution
The cvsweb CGI script in CVSWeb 1.80 allows remote attackers with write access to a CVS repository to execute arbitrary
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
alt-n WorldClient standard 2.1 - Directory Traversal
The WDaemon web server for WorldClient 2.1 allows remote attackers to read arbitrary files via a .. (dot dot) attack.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Texas Imperial Software WFTPD 2.4.1 - RNTO Denial of Service
WFTPD and WFTPD Pro 2.41 allows local users to cause a denial of service by executing the RENAME TO (RNTO) command befor
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Sean MacGuire Big Brother 1.x - Directory Traversal
bb-hostsvc.sh in Big Brother 1.4h1 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Novell Netware 5.0 SP5/6.0 SP1 - SMDR.NLM Denial of Service
Novell NetWare 5.0 allows remote attackers to cause a denial of service by flooding port 40193 with random data.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PIX Firewall 2.7/3.x/4.x/5 - Forged TCP RST
Cisco Secure PIX Firewall does not properly identify forged TCP Reset (RST) packets, which allows remote attackers to fo
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
DrPhibez and Nitro187 Guild FTPD 0.9.7 - File Existence Disclosure
Guild FTPd allows remote attackers to determine the existence of files outside the FTP root via a .. (dot dot) attack, w
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
BitchX IRC Client 75p1/75p3/1.0 c16 - '/INVITE' Format String
BitchX IRC client does not properly cleanse an untrusted format string, which allows remote attackers to cause a denial
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CGI-World Poll It 2.0 - Internal Variable Override
Poll It 2.0 CGI script allows remote attackers to read arbitrary files by specifying the file name in the data_dir param
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
West Street Software LocalWEB HTTP Server 1.2 - Buffer Overflow
LocalWEB HTTP server 1.2.0 allows remote attackers to cause a denial of service via a long GET request.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Michael Lamont Savant Web Server 2.1/3.0 - Remote Buffer Overflow
Savant web server allows remote attackers to execute arbitrary commands via a long GET request.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Canna Canna 3.5 b2 - Remote Buffer Overflow
Buffer overflow in Canna input system allows remote attackers to execute arbitrary commands via an SR_INIT command with
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
IRIX 5.2/5.3/6.x - TelnetD Environment Variable Format String
Telnetd telnet server in IRIX 5.2 through 6.1 does not properly cleans user-injected format strings, which allows remote
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Server 2000 - Remote CPU-overload
Windows 2000 Server allows remote attackers to cause a denial of service by sending a continuous stream of binary zeros
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Sybergen SyGate 2.0/3.11 - Denial of Service
Sybergen Sygate allows remote attackers to cause a denial of service by sending a malformed DNS UDP packet to its intern
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Server 2000 - Telnet Server Denial of Service
Windows 2000 Telnet Server allows remote attackers to cause a denial of service by sending a continuous stream of binary
28RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.