Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.476Referência 23.400GitHub PoC 15.250VulnCheck XDB 8.959Nuclei 4.393Metasploit 3.502✓ só verificadosrecentespopularesrisco
3.502 exploits
Metasploit200
Bomberclone 0.11.6 Buffer Overflow
Multiple buffer overflows in BomberClone before 0.11.6.2 allow remote attackers to execute arbitrary code via long error
50RISCO
abrir ↗Metasploit400
HTML Help Workshop 4.74 (hhp Project File) Buffer Overflow
Stack-based buffer overflow in Microsoft HTML Help Workshop 4.74.8702.0, and possibly earlier versions, and as included
60RISCO
abrir ↗Metasploit400
HTML Help Workshop 4.74 (hhp Project File) Buffer Overflow
Stack-based buffer overflow in Microsoft HTML Help Workshop 4.74.8702.0, and possibly earlier versions, and as included
60RISCO
abrir ↗Metasploit300
Firefox location.QueryInterface() Code Execution
Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attac
60RISCO
abrir ↗Metasploit500
Winamp Playlist UNC Path Computer Name Overflow
Buffer overflow in Nullsoft Winamp 5.12 allows remote attackers to execute arbitrary code via a playlist (pls) file with
60RISCO
abrir ↗Metasploit300
KarjaSoft Sami FTP Server v2.0.2 USER Overflow
Buffer overflow in KarjaSoft Sami FTP Server 2.0.2 and earlier allows remote attackers to execute arbitrary code via a l
50RISCO
abrir ↗Metasploit300
KarjaSoft Sami FTP Server v2.0.2 USER Overflow
Stack-based buffer overflow in Sami FTP Server 2.0.1 allows remote attackers to execute arbitrary code via a long USER c
60RISCO
abrir ↗Metasploit500
Windows XP/2003/Vista Metafile Escape() SetAbortProc Code Execution
The Windows Graphical Device Interface library (GDI32.DLL) in Microsoft Windows allows remote attackers to execute arbit
60RISCO
abrir ↗Metasploit500
Qualcomm WorldMail 3.0 IMAPD LIST Buffer Overflow
Stack-based buffer overflow in Qualcomm WorldMail 3.0 allows remote attackers to execute arbitrary code via a long IMAP
50RISCO
abrir ↗Metasploit200
Mercury/32 PH Server Module Buffer Overflow
Buffer overflow in Mercury Mail Transport System 4.01b allows remote attackers to execute arbitrary code via a long requ
50RISCO
abrir ↗Metasploit600
Lyris ListManager MSDE Weak sa Password
The MSDE version of Lyris ListManager 5.0 through 8.9b configures the sa account in the database to use a password with
50RISCO
abrir ↗Metasploit300
MS05-054 Microsoft Internet Explorer JavaScript OnLoad Handler Remote Code Execution
Microsoft Internet Explorer 6 SP2 6.0.2900.2180 and 6.0.2800.1106, and earlier versions, allows remote attackers to caus
60RISCO
abrir ↗Metasploit200
Novell NetMail IMAP STATUS Buffer Overflow
Stack-based buffer overflow in the IMAP daemon in Novell Netmail 3.5.2 allows remote attackers to execute arbitrary code
50RISCO
abrir ↗Metasploit200
freeFTPd 1.0 Username Overflow
Stack-based buffer overflow in freeFTPd before 1.0.9 with Logging enabled, allows remote attackers to cause a denial of
60RISCO
abrir ↗Metasploit300
FileZilla FTP Server Admin Interface Denial of Service
Buffer overflow in FileZilla Server Terminal 0.9.4d may allow remote attackers to cause a denial of service (terminal cr
50RISCO
abrir ↗Metasploit400
Microsoft IIS ISAPI RSA WebAgent Redirect Overflow
Stack-based buffer overflow in IISWebAgentIF.dll in RSA Authentication Agent for Web (aka SecurID Web Agent) 5.2 and 5.3
50RISCO
abrir ↗Metasploit400
Snort Back Orifice Pre-Preprocessor Buffer Overflow
Stack-based buffer overflow in the Back Orifice (BO) preprocessor for Snort before 2.4.3 allows remote attackers to exec
60RISCO
abrir ↗Metasploit200
CA iTechnology iGateway Debug Mode Buffer Overflow
Buffer overflow in Computer Associates (CA) iGateway 3.0 and 4.0 before 4.0.050623, when running in debug mode, allows r
50RISCO
abrir ↗Metasploit500
MailEnable IMAPD W3C Logging Buffer Overflow
Buffer overflow in the W3C logging for MailEnable Enterprise 1.1 and Professional 1.6 allows remote attackers to execute
50RISCO
abrir ↗Metasploit600
TWiki History Function Arbitrary Command Execution
The history (revision control) function in TWiki 02-Sep-2004 and earlier allows remote attackers to execute arbitrary co
60RISCO
abrir ↗Metasploit500
Linksys WRT54 Access Point apply.cgi Buffer Overflow
Buffer overflow in apply.cgi in Linksys WRT54G 3.01.03, 3.03.6, and possibly other versions before 4.20.7, allows remote
60RISCO
abrir ↗Metasploit600
Barracuda IMG.PL Remote Command Execution
img.pl in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to execute arbitrary comman
50RISCO
abrir ↗Metasploit600
HP Openview connectedNodes.ovpl Remote Command Execution
HP OpenView Network Node Manager 6.2 through 7.50 allows remote attackers to execute arbitrary commands via shell metach
100RISCO
abrir ↗Metasploit600
Simple PHP Blog Remote Command Execution
upload_img_cgi.php in Simple PHP Blog (SPHPBlog) does not properly restrict file extensions of uploaded files, which cou
50RISCO
abrir ↗Metasploit500
CA CAM log_security() Stack Buffer Overflow (Win32)
Multiple buffer overflows in Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1
60RISCO
abrir ↗Metasploit600
Google Appliance ProxyStyleSheet Command Execution
The Saxon XSLT parser in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to
50RISCO
abrir ↗Metasploit500
eDirectory 8.7.3 iMonitor Remote Stack Buffer Overflow
Buffer overflow in dhost.exe in iMonitor for Novell eDirectory 8.7.3 on Windows allows attackers to cause a denial of se
50RISCO
abrir ↗Metasploit400
MS05-039 Microsoft Plug and Play Service Overflow
Stack-based buffer overflow in the Plug and Play (PnP) service for Microsoft Windows 2000 and Windows XP Service Pack 1
60RISCO
abrir ↗Metasploit600
WordPress cache_lastpostdate Arbitrary Code Execution
Direct code injection vulnerability in WordPress 1.5.1.3 and earlier allows remote attackers to execute arbitrary PHP co
50RISCO
abrir ↗Metasploit200
CA BrightStor Agent for Microsoft SQL Overflow
Stack-based buffer overflow in the Backup Agent for Microsoft SQL Server in BrightStor ARCserve Backup Agent for SQL Ser
50RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.