Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.295exploits catalogados
36.048CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.721GitHub PoC 14.464VulnCheck XDB 8.813Nuclei 4.350Metasploit 3.489✓ só verificadosrecentespopularesrisco
24.458 exploits
Exploit-DB✓ VexDay Proof
FTPx FTP Explorer 1.0.00.10 - Weak Password Encryption
FTP Explorer uses weak encryption for storing the username, password, and profile of FTP sites.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Pragma Systems InterAccess TelnetD Server 4.0 - Terminal Configuration
InterAccess TelnetD Server 4.0 allows remote attackers to conduct a denial of service via malformed terminal client conf
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Sambar Server 4.2 Beta 7 - Batch CGI
The Sambar server includes batch files ECHO.BAT and HELLO.BAT in the CGI directory, which allow remote attackers to exec
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Corel Linux OS 1.0 - 'setxconf' Local Privilege Escalation
setxconf in Corel Linux allows local users to gain root access via the -T parameter, which executes the user's .xserverr
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Corel Linux OS 1.0 - buildxconfig
buildxconf in Corel Linux allows local users to modify or create arbitrary files via the -x or -f parameters.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
RedHat Linux 6.0 - Single User Mode Authentication
Red Hat 6.0 allows local users to gain root access by booting single user and hitting ^C at the password prompt.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Pragma Systems InterAccess TelnetD Server 4.0 Build 4 - Buffer Overflow
Buffer overflow in the InterAccess telnet server TelnetD allows remote attackers to execute commands via a long login na
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Sun Workshop 5.0 - Licensing Manager Symlink
The lit program in Sun Flex License Manager (FlexLM) follows symlinks, which allows local users to modify arbitrary file
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
FreeBSD 3.0/3.1/3.2/3.3/3.4 - 'Asmon'/'Ascpu' Local Privilege Escalation
asmon and ascpu in FreeBSD allow local users to gain root privileges via a configuration file.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 95/98/NT 4.0 - 'autorun.inf' Code Execution
Windows NT Autorun executes the autorun.inf file on non-removable media, which allows local attackers to specify an alte
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SCO Unixware 7.1/7.1.1 - ARCserver /tmp Symlink
The ARCserve agent in UnixWare allows local attackers to modify arbitrary files via a symlink attack.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SCO Unixware 7.1/7.1.1 - ARCserver /tmp Symlink
ARCserve agent in SCO UnixWare 7.x allows local attackers to gain root privileges via a symlink attack.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
MySQL 3.22.27/3.22.29/3.23.8 - GRANT Global Password Changing
MySQL allows local users to modify passwords for arbitrary MySQL users via the GRANT privilege.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 4.0 - Pickup Directory Denial of Service
IIS Inetinfo.exe allows local users to cause a denial of service by creating a mail file with a long name and a .txt.eml
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Netopia Timbuktu Pro Remote Control 2.0/5.2.1 - Denial of Service
The authentication protocol in Timbuktu Pro 2.0b650 allows remote attackers to cause a denial of service via connections
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
True North Software Internet Anywhere Mail Server 3.1.3 - RETR Denial of Service
Internet Anywhere POP3 Mail Server allows local users to cause a denial of service via a malformed RETR command.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Zeus Web Server 3.x - Null Terminated Strings
Zeus web server allows remote attackers to view the source code for CGI programs via a null character (%00) at the end o
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Novell Groupwise Enhancement Pack 5.5 Enhancement Pack - Denial of Service
The Java Server in the Novell GroupWise Web Access Enhancement Pack allows remote attackers to cause a denial of service
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Novell BorderManager 3.0/3.5 Audit Trail Proxy - Denial of Service
Remote attackers can cause a denial of service in Novell BorderManager 3.5 by pressing the enter key in a telnet connect
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Daniel Beckham The Finger Server 0.82 Beta - Pipe
The Finger Server 0.82 allows remote attackers to execute commands via shell metacharacters.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cat Soft Serv-U FTP Server 2.5/a/b (Windows 95/98/2000/NT 4.0) - Shortcut
Buffer overflow in the SHGetPathFromIDList function of the Serv-U FTP server allows attackers to cause a denial of servi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Jgaa WarFTPd 1.66 x4s/1.67-3 - 'CWD/MKD' Denial of Service
Buffer overflow in War FTPd 1.6x allows users to cause a denial of service via long MKD and CWD commands.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Wired Community Software WWWThreads 5.0 - SQL Command Input
wwwthreads does not properly cleanse numeric data or table names that are passed to SQL queries, which allows remote att
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 3.0/4.0 / Microsoft Index Server 2.0 - Directory Traversal (MS00-006)
Sample Internet Data Query (IDQ) scripts in IIS 3 and 4 allow remote attackers to read files via a .. (dot dot) attack.
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows NT 4.0 - Recycle Bin Pre-created Folder
The Recycle Bin utility in Windows NT and Windows 2000 allows local users to read or modify files by creating a subdirec
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
H. Nomura Tiny FTPDaemon 0.52 - Multiple Buffer Overflow Vulnerabilities
Buffer overflows in Tiny FTPd 0.52 beta3 FTP server allows users to execute commands via the STOR, RNTO, MKD, XMKD, RMD,
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Outlook Express 5 - JavaScript Email Access
Outlook Express 5.01 and Internet Explorer 5.01 allow remote attackers to view a user's email messages via a script that
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Outlook Express 5 - JavaScript Email Access
Microsoft Outlook Express allows remote attackers to monitor a user's email by creating a persistent browser link to the
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
QuickCommerce 2.5/3.0 / Cart32 2.5 a/3.0 / Shop Express 1.0 / StoreCreator 3.0 Web Shopping Cart - Hidden Form Field
The Cart32 shopping cart application allows remote users to modify sensitive purchase information via hidden form fields
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Debian 2.1 - apcd Symlink
Linux apcd program allows local attackers to modify arbitrary files via a symlink attack.
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.