Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.324exploits catalogados
36.054CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.721GitHub PoC 14.477VulnCheck XDB 8.829Nuclei 4.350Metasploit 3.489✓ só verificadosrecentespopularesrisco
24.458 exploits
Exploit-DB✓ VexDay Proof
SGI IRIX 6.2 - 'midikeys'/'soundplayer' Local Privilege Escalation
IRIX soundplayer program allows local users to gain privileges by including shell metacharacters in a .wav file, which i
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
AnalogX SimpleServer:WWW 1.0.1 - GET Buffer Overflow
Buffer overflow in AnalogX SimpleServer:WWW HTTP server allows remote attackers to execute commands via a long GET reque
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Nortel Networks Optivity NETarchitect 2.0 - PATH
The bna_pass program in Optivity NETarchitect uses the PATH environmental variable for finding the "rm" program, which a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
BroadGun Software CamShot WebCam 2.5 - GET Buffer Overflow
Buffer overflow in CamShot WebCam HTTP server allows remote attackers to execute commands via a long GET request.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Majordomo 1.94.4/1.94.5 - Local -C Parameter (1)
Majordomo wrapper allows local users to gain privileges by specifying an alternate configuration file.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
AltaVista Search Intranet 2.0 b/2.3 - Directory Traversal
AltaVista search engine allows remote attackers to read files above the document root via a .. (dot dot) in the query.cg
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Systems Management Server 2.0 - Default Permissions
The SMS Remote Control program is installed with insecure permissions, which allows local users to gain privileges by mo
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Majordomo 1.94.4/1.94.5 - Local -C Parameter (2)
Majordomo wrapper allows local users to gain privileges by specifying an alternate configuration file.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Michael Lamont Savant Web Server 2.0 - NULL Character Denial of Service
Denial of service in Savant web server via a null character in the requested URL.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Great Circle Associates Majordomo 1.94.4 - Local resend
resend command in Majordomo allows local users to gain privileges via shell metacharacters.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
IBM Network Station Manager 2.0 R1 - Race Condition
IBM Network Station Manager NetStation allows local users to gain privileges via a symlink attack.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Tony Greenwood WebWho+ 1.1 - Remote Command Execution
WebWho+ whois.cgi program allows remote attackers to execute commands via shell metacharacters in the TLD parameter.
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ZBServer Pro 1.5 - Remote Buffer Overflow (1)
Buffer overflow in ZBServer Pro 1.50 allows remote attackers to execute commands via a long GET request.
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Real Networks Real Server 5.0 - ramgen Denial of Service
RealMedia server allows remote attackers to cause a denial of service via a long ramgen request.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ZBServer Pro 1.5 - Remote Buffer Overflow (2)
Buffer overflow in ZBServer Pro 1.50 allows remote attackers to execute commands via a long GET request.
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
glFTPd 1.17.2 - Code Execution
glFtpD includes a default glftpd user account with a default password and a UID of 0.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Solaris 7.0 - DMI Denial of Service
Solaris dmi_cmd allows local users to crash the dmispd daemon by adding a malformed file to the /var/dmi/db database.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Eric Allman Sendmail 8.9.1/8.9.3 - ETRN Denial of Service
Sendmail before 8.10.0 allows remote attackers to cause a denial of service by sending a series of ETRN commands then di
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Windowmaker wmmon 1.0 b2 - Command Execution
wmmon in FreeBSD allows local users to gain privileges via the .wmmonrc configuration file.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 4/5/5.5/5.0.1 - external.NavigateAndFind() Cross-Frame
Internet Explorer 5.0 and 5.01 allows remote attackers to bypass the cross frame security policy and read files via the
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SCO Unixware 7.1 - i2odialogd Remote Buffer Overflow
Buffer overflow in UnixWare i2odialogd daemon allows remote attackers to gain root access via a long username/password a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
McAfee 4.0 / Network Associates for Windows NT 4.0.2/4.0.3 a / Norton AntiVirus 2000 - Recycle Bin Exclusion
The default configurations for McAfee Virus Scan and Norton Anti-Virus virus checkers do not check files in the RECYCLED
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linuxconf 1.1.6 r10 - Remote Buffer Overflow
Buffer overflow in Linux linuxconf package allows remote attackers to gain root privileges via a long parameter.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WU-FTPD 2.4.2/2.5 .0/2.6.0/2.6.1/2.6.2 - FTP Conversion
wu-ftp with FTP conversion enabled allows an attacker to execute commands via a malformed file name that is interpreted
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Netscape Enterprise Server / Novell Groupwise 5.2/5.5 - 'GWWEB.EXE' Multiple Vulnerabilities
Groupwise web server GWWEB.EXE allows remote attackers to read arbitrary files with .htm extensions via a .. (dot dot) a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Ipswitch IMail Server 5.0/5.0.5/5.0.6/5.0.7/5.0.8/6.0 - Weak Password Encryption
Ipswitch IMail 5.0 and 6.0 uses weak encryption to store passwords in registry keys, which allows local attackers to rea
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Infoseek Ultraseek 2.1/3.1 for NT - GET Buffer Overflow
Buffer overflow in Infoseek Ultraseek search engine allows remote attackers to execute commands via a long GET request.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
RSA Security RSAREF 2.0 - Local Buffer Overflow
Buffer overflow in RSAREF2 via the encryption and decryption functions in the RSAREF library.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
VDOLive Player 3.0.2 - Local Buffer Overflow
Buffer overflow in VDO Live Player allows remote attackers to execute commands on the VDO client via a malformed .vdo fi
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Solaris 2.5/2.5.1/2.6/7.0 - 'sadmind' Remote Buffer Overflow (4)
Buffer overflow in Solaris sadmind allows remote attackers to gain root privileges using a NETMGT_PROC_SERVICE request.
28RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.