Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.287exploits catalogados
36.046CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.721GitHub PoC 14.458VulnCheck XDB 8.811Nuclei 4.350Metasploit 3.489✓ só verificadosrecentespopularesrisco
24.458 exploits
Exploit-DB✓ VexDay Proof
CRYPTOCard CRYPTOAdmin 4.1 - Weak Encryption (1)
CRYPTOCard CryptoAdmin for PalmOS uses weak encryption to store a user's PIN number, which allows an attacker with acces
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CRYPTOCard CRYPTOAdmin 4.1 - Weak Encryption (2)
CRYPTOCard CryptoAdmin for PalmOS uses weak encryption to store a user's PIN number, which allows an attacker with acces
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Bray Systems Linux Trustees 1.5 - Long Pathname
The Linux trustees kernel patch allows attackers to cause a denial of service by accessing a file or directory with a lo
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cygnus Network Security 4.0/KerbNet 5.0 / MIT Kerberos 4/5 / RedHat 6.2 - Compatibility 'krb_rd_req()' Remote Buffer Overflow (3)
Buffer overflow in krb_rd_req function in Kerberos 4 and 5 allows remote attackers to gain root privileges.
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Be BeOS 4.0/4.5/5.0 - IP Packet Length Field
BeOS allows remote attackers to cause a denial of service via malformed packets whose length field is less than the leng
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Netscape PublishingXPert 2.0/2.2/2.5 - Local File Reading
PSCOErrPage.htm in Netscape PublishingXpert 2.5 before SP2 allows remote attackers to read arbitrary files by specifying
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Symantec pcAnywhere 9.0 - Weak Encryption
The default encryption method of PcAnywhere 9.x uses weak encryption, which allows remote attackers to sniff and decrypt
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apple WebObjects Developer NT4 IIS4.0 CGI-adapter 4.5 - Developer Remote Overflow
Buffer overflow in WebObjects.exe in the WebObjects Developer 4.5 package allows remote attackers to cause a denial of s
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Real Networks RealPlayer 6/7 - Location Buffer Overflow
Buffer overflow in the RealNetworks RealPlayer client versions 6 and 7 allows remote attackers to cause a denial of serv
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Stalker CommuniGate Pro 3.2.4 - Arbitrary File Read
The web administration interface for CommuniGate Pro 3.2.5 and earlier allows remote attackers to read arbitrary files v
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cobalt RaQ 2.0/3.0 - Apache .htaccess Disclosure
The default configuration of Cobalt RaQ2 and RaQ3 as specified in access.conf allows remote attackers to view sensitive
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SalesLogix Corporation eViewer 1.0 - Denial of Service
The SalesLogix Eviewer allows remote attackers to cause a denial of service by accessing the URL for the slxweb.dll admi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Index Server 2.0 - '%20' ASP Source Disclosure
Microsoft Index Server allows remote attackers to view the source code of ASP files by appending a %20 to the filename i
45RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 4.0 - UNC Mapped Virtual Host
IIS 4.0 and 5.0 does not properly perform ISAPI extension processing if a virtual directory is mapped to a UNC share, wh
45RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows NT 4.0/2000 - TCP/IP Printing Service Denial of Service
Microsoft TCP/IP Printing Services, aka Print Services for Unix, allows an attacker to cause a denial of service via a m
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SGI IRIX 5.x/6.x - Objectserver
Vulnerability in SGI IRIX objectserver daemon allows remote attackers to create user accounts.
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Citrix Metaframe 1.0/1.8 - Weak Encryption
The Citrix ICA (Independent Computing Architecture) protocol uses weak encryption (XOR) for user authentication.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
GeoCel WindMail 3.0 - Remote File Read
WindMail allows remote attackers to read arbitrary files or execute commands via shell metacharacters.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
qDecoder 4.x/5.x - Remote Buffer Overflow
Buffer overflow in qDecoder library 5.08 and earlier, as used in CrazyWWWBoard, CrazySearch, and other CGI programs, all
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
AnalogX SimpleServer:WWW 1.0.3 - Denial of Service
AnalogX SimpleServer:WWW HTTP server 1.03 allows remote attackers to cause a denial of service via a short GET request t
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Standard & Poors ComStock 4.2.4 - Command Execution
The mcsp Client Site Processor system (MultiCSP) in Standard and Poor's ComStock is installed with several accounts that
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.2.12/2.2.14/2.3.99 (RedHat 6.x) - Socket Denial of Service
The Linux 2.2.x kernel does not restrict the number of Unix domain sockets as defined by the wmem_max parameter, which a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
gpm 1.18.1/1.19 / Debian 2.x / RedHat 6.x / S.u.S.E 5.3/6.x - gpm Setgid
gpm-root in the gpm package does not properly drop privileges, which allows local users to gain privileges by starting a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
vqsoft vqserver for windows 1.9.9 - Directory Traversal
vqSoft vqServer program allows remote attackers to read arbitrary files via a /........../ in the URL, a variation of a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Netscape Enterprise Server 3.0/3.6/3.51 - Directory Indexing
Netscape Enterprise Server with Directory Indexing enabled allows remote attackers to list server directories via web pu
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Atrium Software Mercur WebView WebMail-Client 1.0 - Buffer Overflow
Buffer overflow in the MERCUR WebView WebMail server allows remote attackers to cause a denial of service via a long mai
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Halloween Linux 4.0 / SuSE Linux 6.0/6.1/6.2/6.3 - 'kreatecd' Local Privilege Escalation
Linux kreatecd trusts a user-supplied path that is used to find the cdrecord program, allowing local users to gain root
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle Web Listener 4.0.x - for NT Batch File
Batch files in the Oracle web listener ows-bin directory allow remote attackers to execute commands via a malformed URL
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Mandrake 6.x / RedHat 6.x / Turbolinux 3.5 b2/4.x/6.0.2 userhelper/PAM - Path (2)
Red Hat userhelper program in the usermode package allows local users to gain root access via PAM and a .. (dot dot) att
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Generation Terrorists Designs & Concepts Sojourn 2.0 - File Access
Sojourn search engine allows remote attackers to read arbitrary files via a .. (dot dot) attack.
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.