Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.324exploits catalogados
36.054CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.721GitHub PoC 14.477VulnCheck XDB 8.829Nuclei 4.350Metasploit 3.489✓ só verificadosrecentespopularesrisco
24.458 exploits
Exploit-DB✓ VexDay Proof
Caldera OpenLinux 2.2 / Debian 2.1/2.2 / RedHat 6.0 - Vixie Cron MAILTO Sendmail
Vixie Cron on Linux systems allows local users to set parameters of sendmail commands via the MAILTO environmental varia
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
RedHat Linux 4.2/5.2/6.0 / S.u.S.E Linux 6.0/6.1 - Cron Buffer Overflow (2)
Buffer overflow in Vixie Cron on Red Hat systems via the MAILTO environmental variable.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
GNU glibc 2.1/2.1.1 -6 - 'pt_chown' Local Privilege Escalation
The pt_chown command in Linux allows local users to modify TTY terminal devices that belong to other users.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
IBM GINA for NT 1.0 - Local Privilege Escalation
IBM GINA, when used for OS/2 domain authentication of Windows NT users, allows local users to gain administrator privile
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
GNU Ffingerd 1.19 - 'Username' Validity Disclosure
The ffingerd 1.19 allows remote attackers to identify users on the target system based on its responses.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 4/5 - ActiveX 'Eyedog' Remote Overflow
The Eyedog ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote attacker to ex
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5 - ActiveX Object For Constructing Type Libraries For Scriptlets File Write
The scriptlet.typelib ActiveX control is marked as "safe for scripting" for Internet Explorer, which allows a remote att
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
RedHat Linux 6.0 / Slackware Linux 4.0 - Termcap 'tgetent()' Local Buffer Overflow (1)
Buffer overflow in telnet daemon tgetent routing allows remote attackers to gain root access via the TERMCAP environment
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
RedHat Linux 6.0 / Slackware Linux 4.0 - Termcap 'tgetent()' Local Buffer Overflow (2)
Buffer overflow in telnet daemon tgetent routing allows remote attackers to gain root access via the TERMCAP environment
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Hughes Technologies Mini SQL (mSQL) 2.0/2.0.10 - Information Disclosure
The w3-msql CGI script provided with Mini SQL allows remote attackers to view restricted directories.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
AIX 4.1/4.2 - 'pdnsd' Remote Buffer Overflow
Buffer overflow in Source Code Browser Program Database Name Server Daemon (pdnsd) for the IBM AIX C Set ++ compiler.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ProFTPd 1.2 pre1/pre2/pre3/pre4/pre5 - Remote Buffer Overflow (1)
Buffer overflow in ProFTPD, wu-ftpd, and beroftpd allows remote attackers to gain root access via a series of MKD and CW
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle 8 8.1.5 - Intelligent Agent (1)
dbsnmp in Oracle Intelligent Agent allows local users to gain privileges by setting the ORACLE_HOME environmental variab
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Oracle 8 8.1.5 - Intelligent Agent (2)
dbsnmp in Oracle Intelligent Agent allows local users to gain privileges by setting the ORACLE_HOME environmental variab
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 95/98 Internet Explorer 5/Telnet - Local Heap Overflow
Buffer overflow in Microsoft Telnet client in Windows 95 and Windows 98 via a malformed Telnet argument.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SuSE Linux 6.2 / Slackware Linux 3.2/3.6 - 'identd' Denial of Service
A default configuration of in.identd in SuSE Linux waits 120 seconds between requests, allowing a remote attacker to con
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Hybrid Ircd 5.0.3 p7 - Remote Buffer Overflow
Buffer overflow in hybrid-6 IRC server commonly used on EFnet allows remote attackers to execute commands via m_invite i
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Commercial Internet System 2.0/2.5 / IIS 4.0 / Site Server Commerce Edition 3.0 alpha/3.0 - Denial of Service
Denial of service in IIS 4.0 via a flood of HTTP requests with malformed headers.
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 98a/98b/98SE / Solaris 2.6 - IRDP
DHCP clients with ICMP Router Discovery Protocol (IRDP) enabled allow remote attackers to modify their default routes.
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
NetBSD 1.4 / OpenBSD 2.5 / Solaris 7.0 - 'profil(2)' Modify The Internal Data Space
The BSD profil system call allows a local user to modify the internal data space of a program via profiling and execve.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CREAR ALMail32 1.10 - Remote Buffer Overflow
Buffer overflow in ALMail32 POP3 client via From: or To: headers.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft FrontPage Personal Web Server 1.0 - PWS Denial of Service
Buffer overflow in Microsoft FrontPage Server Extensions (PWS) 3.0.2.926 on Windows 95, and possibly other versions, all
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Network Security Wizards Dragon-Fire IDS 1.0 - Command Execution
dfire.cgi script in Dragon-Fire IDS allows remote users to execute commands via shell metacharacters.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ToxSoft NextFTP 1.82 - Remote Buffer Overflow
Buffer overflow in ToxSoft NextFTP client through CWD command.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Fujitsu Chocoa 1.0 beta7R - 'Topic' Remote Buffer Overflow
Buffer overflow in Fujitsu Chocoa IRC client via IRC channel topics.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.0.30/2.0.35/2.0.36/2.0.37 - Blind TCP Spoofing
The default permissions of /dev/kmem in Linux versions before 2.0.36 allows IP spoofing.
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.0.30/2.0.35/2.0.36/2.0.37 - Blind TCP Spoofing
In Linux before version 2.0.36, remote attackers can spoof a TCP connection and pass data to the application layer befor
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Netscape Enterprise Server 3.51/3.6 - JHTML View Source
Default configuration of the search engine in Netscape Enterprise Server 3.5.1, and possibly other versions, allows remo
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows NT 4.0/SP 1/SP 2/Sp 3/SP 4/SP 5 - Malformed Dialer Entry
Buffer overflow in Microsoft Phone Dialer (dialer.exe), via a malformed dialer entry in the dialer.ini file.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Network Associates Gauntlet Firewall 5.0 - Denial of Service
Denial of service in Gauntlet Firewall via a malformed ICMP packet.
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.