Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
78.329exploits catalogados
36.057CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.721GitHub PoC 14.482VulnCheck XDB 8.829Nuclei 4.350Metasploit 3.489✓ só verificadosrecentespopularesrisco
24.458 exploits
Exploit-DB✓ VexDay Proof
BSD 2 / CND 1 / Sendmail 8.x / FreeBSD 2.1.x / HP-UX 10.x / AIX 4 / RedHat 4 - Sendmail Daemon
Local users can start Sendmail in daemon mode and gain root privileges.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SGI IRIX 6.3 - 'Systour' / 'OutOfBox' Local Privilege Escalation
Indigo Magic System Tour in the SGI system tour package (systour) for IRIX 5.x through 6.3 allows local users to gain ro
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SGI IRIX 6.2 - SpaceWare
spaceball program in SpaceWare 7.3 v1.0 in IRIX 6.2 allows local users to gain root privileges by setting the HOSTNAME e
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
BSD/OS 2.1 / FreeBSD 2.1.5 / NeXTstep 4.x / IRIX 6.4 / SunOS 4.1.3/4.1.4 - 'lpr' Buffer Overrun (1)
Buffer overflow in lpr, as used in BSD-based systems including Linux, allows local users to execute arbitrary code as ro
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
BSD / Linux - 'lpr' Local Privilege Escalation
The line printer daemon (lpd) in the lpr package in multiple Linux operating systems allows local users to gain root pri
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
BSD/OS 2.1 / FreeBSD 2.1.5 / NeXTstep 4.x / IRIX 6.4 / SunOS 4.1.3/4.1.4 - '/usr/bin/lpr' Buffer Overrun Privilege Escalation (2)
Buffer overflow in lpr, as used in BSD-based systems including Linux, allows local users to execute arbitrary code as ro
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
BSD/OS 2.1 / FreeBSD 2.1.5 / NeXTstep 4.x / IRIX 6.4 / SunOS 4.1.3/4.1.4 - '/usr/bin/lpr' Buffer Overrun Privilege Escalation (2)
20RISCO
abrir ↗Exploit-DB✓ VexDay Proof
BSD/OS 2.1 / FreeBSD 2.1.5 / NeXTstep 4.x / IRIX 6.4 / SunOS 4.1.3/4.1.4 - 'lpr' Buffer Overrun (1)
20RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Ping of Death - Remote Denial of Service
The Cayman 3220-H DSL router allows remote attackers to cause a denial of service via oversized ICMP echo (ping) request
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Ping of Death - Remote Denial of Service
Oversized ICMP ping packets can result in a denial of service, aka Ping o' Death.
45RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Xt Library - Local Privilege Escalation
Buffer overflow in Xt library of X Windowing System allows local users to execute commands with root privileges.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
BSD / Linux - 'umount' Local Privilege Escalation
Buffer overflow in Linux mount and umount allows local users to gain root privileges via a long relative pathname.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Solaris 7.0 - 'Coredump' File Write
Solaris 2.4 before kernel jumbo patch -35 allows set-gid programs to dump core even if the real user id is not in the se
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
GlimpseHTTP 1.0/2.0 / WebGlimpse 1.0 - Piped Command
The aglimpse CGI program of the Glimpse package allows remote execution of arbitrary commands.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
BSDI BSD/OS 2.1 / FreeBSD 2.1 / IBM AIX 4.2 / SGI IRIX 6.4 / Sun SunOS 4.1.3 - Buffer Overrun
Local user gains root privileges via buffer overflow in rdist, via lookup() function.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Novell NetWare Web Server 2.x - convert.bas
The convert.bas program in the Novell web server allows a remote attackers to read any file on the system that is intern
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
suid_perl 5.001 - Command Execution
Buffer overflow in suidperl (sperl), Perl 4.x and 5.x.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SGI IRIX 5.3/6.2 / SGI license_oeo 1.0 LicenseManager - 'NETLS_LICENSE_FILE' Local Privilege Escalation
Arbitrary file creation and program execution using FLEXlm LicenseManager, from versions 4.0 to 5.0, in IRIX.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Apache 0.8.x/1.0.x / NCSA HTTPd 1.x - 'test-cgi' Directory Listing
test-cgi program allows an attacker to list files on the server.
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft IIS 1.0 / Netscape Server 1.0/1.12 / OReilly WebSite Professional 1.1b - '.cmd' / '.CMD' Remote Command Execution
IIS 1.0 allows users to execute arbitrary commands using .bat or .cmd files.
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
RedHat Linux 2.1 - 'abuse.console' Local Privilege Escalation
abuse.console in Red Hat 2.1 uses relative pathnames to find and execute the undrv program, which allows local users to
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Microsoft FrontPage Personal Web Server 1.0/4.0 - Directory Traversal
Microsoft Personal Web Server and FrontPage Personal Web Server in some Windows systems allows a remote attacker to read
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Resolv+ 'RESOLV_HOST_CONF' - Linux Library Command Execution
glibc 2.1.9x and earlier does not properly clear the RESOLV_HOST_CONF, HOSTALIASES, or RES_OPTIONS environmental variabl
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
John S.2 Roberts AnyForm 1.0/2.0 - CGI Semicolon
AnyForm CGI remote execution.
53RISCO
abrir ↗Exploit-DB✓ VexDay Proof
IRIX 5.2/6.0 - Permissions File Manipulation
SGI Desktop Permissions Tool in IRIX 6.0.1 and earlier allows local users to modify permissions for arbitrary files and
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
NCSA HTTPd 1.x - Remote Buffer Overflow (2)
Buffer overflow in NCSA HTTP daemon v1.3 allows remote command execution.
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
NCSA HTTPd 1.x - Remote Buffer Overflow (2)
Buffer overflow in NCSA WebServer (1.4.1 and below) gives remote access.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
SGI IRIX 6.0.1 - 'colorview' Read Files
colorview in Silicon Graphics IRIX 5.1, 5.2, and 6.0 allows local attackers to read arbitrary files via the -text argume
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Majordomo 1.89/1.90 - 'lists' Command Execution
Remote attacker can execute commands through Majordomo using the Reply-To field and a "lists" command.
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Sendmail 8.6.9 IDENT - Remote Command Execution
Sendmail 8.6.9 allows remote attackers to execute root commands, using ident.
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.