Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.324exploits catalogados
36.054CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.721GitHub PoC 14.477VulnCheck XDB 8.829Nuclei 4.350Metasploit 3.489✓ só verificadosrecentespopularesrisco
24.458 exploits
Exploit-DB✓ VexDay Proof
Microsoft JET 3.5/3.51/4.0 - VBA Shell
The Microsoft Jet database engine allows an attacker to execute commands via a database query, aka the "VBA Shell" vulne
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Check Point Software Firewall-1 3.0/1 4.0 - Table Saturation Denial of Service
Firewall-1 sets a long timeout for connections that begin with ACK or other packets except SYN, allowing an attacker to
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Squid Web Proxy 2.2 - 'cachemgr.cgi' Unauthorized Connection
The Squid package in Red Hat Linux 5.2 and 6.0, and other distributions, installs cachemgr.cgi in a public web directory
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Samba < 2.0.5 - Local Overflow
Buffer overflow in Samba smbd program via a malformed message command.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Data Access Components (MDAC) 2.1 / Microsoft IIS 3.0/4.0 / Microsoft Index Server 2.0 / Microsoft Site Server Commerce Edition 3.0 i386 MDAC - RDS (1)
The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x expose
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Data Access Components (MDAC) 2.1 / Microsoft IIS 3.0/4.0 / Microsoft Index Server 2.0 / Microsoft Site Server Commerce Edition 3.0 i386 MDAC - RDS (2)
The Remote Data Service (RDS) DataFactory component of Microsoft Data Access Components (MDAC) in IIS 3.x and 4.x expose
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
BSD/Linux Kernel 2.3 (BSD/OS 4.0 / FreeBSD 3.2 / NetBSD 1.4) - Shared Memory Denial of Service
Operating systems with shared memory implementations based on BSD 4.4 code allow a user to conduct a denial of service a
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
BMC Software Patrol 3.2.5 - Patrol SNMP Agent File Creation/Permission
BMC PATROL SNMP Agent before 3.2.07 allows local users to create arbitrary world-writeable files as root by specifying t
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Caldera OpenUnix 8.0/UnixWare 7.1.1 / HP HP-UX 11.0 / Solaris 7.0 / SunOS 4.1.4 - rpc.cmsd Buffer Overflow (2)
Buffer overflow in CDE Calendar Manager Service Daemon (rpc.cmsd).
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.0.37 - Segment Limit Privilege Escalation
Linux 2.0.37 does not properly encode the Custom segment limit, which allows local users to gain root privileges by acce
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Caldera OpenUnix 8.0/UnixWare 7.1.1 / HP HP-UX 11.0 / Solaris 7.0 / SunOS 4.1.4 - rpc.cmsd Buffer Overflow (1)
Buffer overflow in CDE Calendar Manager Service Daemon (rpc.cmsd).
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apple Mac OS 8 8.6 - Weak Password Encryption
MacOS uses weak encryption for passwords that are stored in the Users & Groups Data File.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Netscape Enterprise Server 3.6 - SSL Buffer Overflow (Denial of Service) (PoC)
Denial of service in Netscape Enterprise Server via a buffer overflow in the SSL handshake.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 95/98 / NT Enterprise Server 4.0 SP5 / NT Terminal Server 4.0 SP4 / NT Workstation 4.0 SP5 - Denial of Service (1)
Denial of service in various Windows systems via malformed, fragmented IGMP packets.
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows 95/98 / NT Enterprise Server 4.0 SP5 / NT Terminal Server 4.0 SP4 / NT Workstation 4.0 SP5 - Denial of Service (2)
Denial of service in various Windows systems via malformed, fragmented IGMP packets.
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
mailx 8.1.1-10 (BSD/Slackware) - Local Buffer Overflow (2)
Buffer overflow in mailx mail command (aka Mail) on Linux systems allows local users to gain privileges via a long -c (c
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
BSDI BSD/OS 4.0 /FreeBSD 3.2 /NetBSD 1.4 x86 / OpenBSD 2.5 - UFS Secure Level 1
BSD 4.4 based operating systems, when running at security level 1, allow the root user to clear the immutable and append
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows NT 4.0/SP 1/SP 2/SP 3/SP 4/SP 5 - Null Session Admin Name
The registry in Windows NT can be accessed remotely by users who are not administrators.
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
VMware 1.0.1 - Local Buffer Overflow
Buffer overflow in VMWare 1.0.1 for Linux via a long HOME environmental variable.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Xi Graphics Accelerated X 4.0.x/5.0 - Local Buffer Overflow
Buffer overflow in Xi Graphics Accelerated-X server allows local users to gain root access via a long display or query p
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 3.0/4.0 - Double Byte Code Page
When IIS is run with a default language of Chinese, Korean, or Japanese, it allows a remote attacker to view the source
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Solaris 2.5/2.5.1/2.6/7.0 - 'sadmind' Remote Buffer Overflow (1)
Buffer overflow in Solaris sadmind allows remote attackers to gain root privileges using a NETMGT_PROC_SERVICE request.
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Solaris 2.5/2.5.1/2.6/7.0 - 'sadmind' Remote Buffer Overflow (2)
Buffer overflow in Solaris sadmind allows remote attackers to gain root privileges using a NETMGT_PROC_SERVICE request.
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Debian 2.1 - HTTPd
A default configuration of Apache on Debian GNU/Linux sets the ServerRoot to /usr/doc, which allows remote users to read
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
tcpdump 3.4 - Protocol Four / Zero Header Length
ip_print procedure in Tcpdump 3.4a allows remote attackers to cause a denial of service via a packet with a zero length
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 4.0 - Remote Buffer Overflow (4)
Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 4.0 - Remote Buffer Overflow (3)
Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 4.0 - Remote Buffer Overflow (2)
Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 4.0 - Remote Buffer Overflow (1)
Buffer overflow in IIS 4.0 allows remote attackers to cause a denial of service via a malformed request for files with .
60RISCO
abrir ↗Exploit-DB✓ VexDay Proof
RedHat Linux 5.2 i386/6.0 - No Logging
The Red Hat Linux su program does not log failed password guesses if the su process is killed before it times out, which
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.