Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.258exploits catalogados
36.019CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.697GitHub PoC 14.455VulnCheck XDB 8.811Nuclei 4.349Metasploit 3.488✓ só verificadosrecentespopularesrisco
24.458 exploits
Exploit-DB✓ VexDay Proof
Linux Kernel 2.2.x 2.4.0-test1 (SGI ProPack 1.2/1.3) - Sendmail 8.10.1 Capabilities Privilege Escalation (2)
The "capabilities" feature in Linux before 2.2.16 allows local users to cause a denial of service or gain privileges by
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Mirabilis ICQ 2000.0 A - Mailclient Temporary Link
ICQwebmail client for ICQ 2000A creates a world readable temporary file during login and does not delete it, which allow
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Intel Corporation Shiva Access Manager 5.0 - Solaris World Readable LDAP Password
When configured to store configuration information in an LDAP directory, Shiva Access Manager 5.0.0 stores the root DN (
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Michael Lamont Savant Web Server 2.1 - CGI Source Code Disclosure
Savant web server allows remote attackers to read source code of CGI scripts via a GET request that does not include the
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
BRU 15.1/16.0 - BRUEXECLOG Environment Variable
BRU backup software allows local users to append data to arbitrary files by specifying an alternate configuration file w
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PassWD 1.2 - Weak Encryption
PassWD 1.2 uses weak encryption (trivial encoding) to store passwords, which allows an attacker who can read the passwor
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
HP-UX 10.20/11.0 - man '/tmp' Symlink
man in HP-UX 10.20 and 11 allows local attackers to overwrite files via a symlink attack.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
BSD 'mailx' 8.1.1-10 - Local Buffer Overflow (1)
Buffer overflow in mailx mail command (aka Mail) on Linux systems allows local users to gain privileges via a long -c (c
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Real Networks Real Server 7.0/7.0.1/8.0 Beta - view-source Denial of Service
Real Networks RealServer 7.x allows remote attackers to cause a denial of service via a malformed request for a page in
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
OReilly Software WebSite Professional 2.3.18/2.4/2.4.9 - 'webfind.exe' Remote Buffer Overflow
Buffer overflow in Webfind CGI program in O'Reilly WebSite Professional web server 2.x allows remote attackers to execut
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Atrus Trivalie Productions Simple Network Time Sync 1.0 - daemon Buffer Overflow
Buffer overflow in Simple Network Time Sync (SMTS) daemon allows remote attackers to cause a denial of service and possi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Sam Lantinga splitvt 1.6.3 - Local Buffer Overflow
Buffer overflow in Linux splitvt 1.6.3 and earlier allows local users to gain root privileges via a long password in the
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
NetWin DMail 2.7/2.8 - ETRN Buffer Overflow
Buffer overflow in the NetWin DSMTP 2.7q in the NetWin dmail package allows remote attackers to execute arbitrary comman
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Allegro RomPager 2.10 - URL Request Denial of Service
Allegro RomPager HTTP server allows remote attackers to cause a denial of service via a malformed authentication request
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Concatus IMate Web Mail Server 2.5 - Remote Buffer Overflow
Imate Webmail Server 2.5 allows remote attackers to cause a denial of service via a long HELO command.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows Media Services 4.0/4.1 - Denial of Service (MS00-038)
Microsoft Windows Media Encoder allows remote attackers to cause a denial of service via a malformed request, aka the "M
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Eterm 0.8.10 / rxvt 2.6.1 / PuTTY 0.48 / X11R6 3.3.3/4.0 - Denial of Service
xterm, Eterm, and rxvt allow an attacker to cause a denial of service by embedding certain escape characters which force
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
KDE 1.1.2 KApplication configfile - Local Privilege Escalation (1)
The KApplication class in the KDE 1.1.2 configuration file management capability allows local users to overwrite arbitra
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
KDE 1.1.2 KApplication configfile - Local Privilege Escalation (3)
The KApplication class in the KDE 1.1.2 configuration file management capability allows local users to overwrite arbitra
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
KDE 1.1.2 KApplication configfile - Local Privilege Escalation (2)
The KApplication class in the KDE 1.1.2 configuration file management capability allows local users to overwrite arbitra
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache 1.3.6/1.3.9/1.3.11/1.3.12/1.3.20 - Root Directory Access
The Apache 1.3.x HTTP server for Windows platforms allows remote attackers to list directory contents by requesting a UR
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Mandriva Linux Mandrake 7.0 - Local Buffer Overflow
Buffer overflow in Linux cdrecord allows local users to gain privileges via the dev parameter.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
KDE 1.1/1.1.1/1.1.2/1.2 - kdesud DISPLAY Environment Variable Overflow
Buffer overflow in KDE kdesud on Linux allows local uses to gain privileges via a long DISPLAY environmental variable.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cygnus Network Security 4.0/KerbNet 5.0 / MIT Kerberos 4/5 / RedHat 6.2 - Compatibility 'krb_rd_req()' Local Buffer Overflow (2)
Buffer overflow in krb_rd_req function in Kerberos 4 and 5 allows remote attackers to gain root privileges.
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Omnis Studio 2.4 - Weak Database Field Encryption
Omnis Studio 2.4 uses weak encryption (trivial encoding) for encrypting database fields.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
HP JetAdmin 5.5.177/jetadmin 5.6 - Directory Traversal
The web interface server in HP Web JetAdmin 5.6 allows remote attackers to read arbitrary files via a .. (dot dot) attac
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cobalt RaQ 2.0/3.0 / qpopper 2.52/2.53 - 'EUIDL' Format String Input
Qpopper 2.53 and earlier allows local users to gain privileges via a formatting string in the From: header, which is pro
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
HP JetAdmin 6.0 - Printing Denial of Service
HP Web JetAdmin 6.0 allows remote attackers to cause a denial of service via a malformed URL to port 8000.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Pacific Software Carello 1.2.1 - File Duplication / Source Disclosure
The add.exe program in the Carello shopping cart software allows remote attackers to duplicate files on the server, whic
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Marty Bochane MDBms 0.9 - xbx Buffer Overflow
Buffer overflow in MDBMS database server allows remote attackers to execute arbitrary commands via a long string.
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.