Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.324exploits catalogados
36.054CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.721GitHub PoC 14.477VulnCheck XDB 8.829Nuclei 4.350Metasploit 3.489✓ só verificadosrecentespopularesrisco
24.458 exploits
Exploit-DB✓ VexDay Proof
Solaris 2.6/7.0/8 - 'netpr' Local Buffer Overflow (2)
Buffer overflow in Solaris netpr program allows local users to execute arbitrary commands via a long -p option.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Xcmail 0.99.6 - Local Buffer Overflow
Buffer overflow in XCmail 0.99.6 with autoquote enabled allows remote attackers to execute arbitrary commands via a long
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Ipswitch IMail 5.0 - IMonitor Buffer Overflow (Denial of Service) (PoC)
Buffer overflow in IMonitor in IMail 5.0 allows remote attackers to cause a denial of service, and possibly execute arbi
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Ipswitch IMail 5.0 - Imapd Buffer Overflow (Denial of Service) (PoC)
Buffer overflow in the login functions in IMAP server (imapd) in Ipswitch IMail 5.0 and earlier allows remote attackers
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Ipswitch IMail 5.0/6.0 - Web Service Buffer Overflow (Denial of Service) (PoC)
Buffer overflow in Ipswitch IMail Service 5.0 allows an attacker to cause a denial of service (crash) and possibly execu
45RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Debian 2.0 - Super Syslog Buffer Overflow
super 3.11.6 and other versions have a buffer overflow in the syslog utility which allows a local user to gain root acce
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Qbik WinGate 3.0/Pro 4.0.1/Standard 4.0.1 - Buffer Overflow (Denial of Service) (PoC)
Remote attackers can perform a denial of service in WinGate machines using a buffer overflow in the Winsock Redirector S
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.0/2.1/2.2 - 'autofs' Denial of Service
Buffer overflow in Linux autofs module through long directory names allows local users to perform a denial of service.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Windows NT 4.0 SP4 - Known DLL Cache
Local users in Windows NT can obtain administrator privileges by changing the KnownDLLs list to reference malicious prog
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
IBM AIX 4.2.1 - 'snap' Insecure Temporary File Creation
snap command in AIX before 4.3.2 creates the /tmp/ibmsupt directory with world-readable permissions and does not remove
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Debian 2.0/2.0 r5 / FreeBSD 3.2 / OpenBSD 2.4 / RedHat 5.2 i386 / S.u.S.E 6.1 - 'Lsof' Local Buffer Overflow (1)
A buffer overflow in lsof allows local users to obtain root privilege.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Debian 2.0/2.0 r5 / FreeBSD 3.2 / OpenBSD 2.4 / RedHat 5.2 i386 / S.u.S.E 6.1 - 'Lsof' Local Buffer Overflow (2)
A buffer overflow in lsof allows local users to obtain root privilege.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SmartMax MailMax 1.0 - SMTP Buffer Overflow
Buffer overflow in the Mail-Max SMTP server for Windows systems allows remote command execution.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 3.0/4.0 - Using ASP and FSO To Read Server Files
FileSystemObject (FSO) in the showfile.asp Active Server Page (ASP) allows remote attackers to read arbitrary files by s
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Allaire Forums 2.0.4 - Getfile
The GetFile.cfm file in Allaire Forums allows remote attackers to read files through a parameter to GetFile.cfm.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Hancom Office 2007 - 'Reboot.ini' Clear-Text Passwords
The installer for BackOffice Server includes account names and passwords in a setup file (reboot.ini) which is not delet
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WU-FTPD 2.4.2 / SCO Open Server 5.0.5 / ProFTPd 1.2 pre1 - 'realpath' Remote Buffer Overflow (2)
Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
WU-FTPD 2.4.2 / SCO Open Server 5.0.5 / ProFTPd 1.2 pre1 - 'realpath' Remote Buffer Overflow (1)
Buffer overflows in wuarchive ftpd (wu-ftpd) and ProFTPD lead to remote root access, a.k.a. palmetto.
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Ipswitch IMail 5.0 / Ipswitch WS_FTP Server 1.0.1/1.0.2 - Local Privilege Escalation
IPswitch WS_FTP allows local users to gain additional privileges and modify or add mail accounts by setting the "flags"
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Ipswitch IMail 5.0 / Ipswitch WS_FTP Server 1.0.1/1.0.2 - Local Privilege Escalation
IPswitch IMail allows local users to gain additional privileges and modify or add mail accounts by setting the "flags" r
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
S.u.S.E Linux 5.2 - 'lpc' Local Privilege Escalation
SuSE 5.2 PLP lpc program has a buffer overflow that leads to root compromise.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Site Server 2.0 with IIS 4.0 - Arbitrary File Upload
MS Site Server 2.0 with IIS 4 can allow users to upload content, including ASP, to the target web site, thus allowing th
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 5.0.1 - Invalid Byte Cross-Frame Access
Internet Explorer 4.01 allows remote attackers to read local files and spoof web pages via a "%01" character in an "abou
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.2 - 'ldd core' Force Reboot (Denial of Service)
Denial of service in Linux 2.2.0 running the ldd command on a core file.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 5.0 - IISAPI Extension Enumerate Root Web Server Directory
In IIS, an attacker could determine a real path using a request for a non-existent URL that would be interpreted by Perl
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 4 (Windows NT) - Log Avoidance
IIS 4.0 and Apache log HTTP request methods, regardless of how long they are, allowing a remote attacker to hide the URL
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 4 - Clipboard Paste
Internet Explorer 4 allows remote attackers (malicious web site operators) to read the contents of the clipboard via the
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.0 - TCP Port Denial of Service
Denial of service in Linux 2.0.36 allows local users to prevent any server from listening on any non-privileged port.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 4 (Windows NT) - Remote Web-Based Administration
When IIS 2 or 3 is upgraded to IIS 4, ism.dll is inadvertently left in /scripts/iisadmin, which does not restrict access
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Cisco IOS 12.0.2 - Syslog Crash
Cisco IOS 12.0 and other versions can be crashed by malicious UDP packets to the syslog port.
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.