Exploração pública
Catálogo de exploits
Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.
77.900exploits catalogados
35.840CVEs com exploração pública
24.695testados em laboratório
TodosExploit-DB 24.458Referência 22.600GitHub PoC 14.323VulnCheck XDB 8.722Nuclei 4.320Metasploit 3.477✓ só verificadosrecentespopularesrisco
24.458 exploits
Exploit-DB✓ VexDay Proof
PHP 3/4/5 - Multiple Local/Remote Vulnerabilities (1)
Multiple integer handling errors in PHP before 4.3.10 allow attackers to bypass safe mode restrictions, cause a denial o
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PHP 3/4/5 - Multiple Local/Remote Vulnerabilities (2)
Multiple integer handling errors in PHP before 4.3.10 allow attackers to bypass safe mode restrictions, cause a denial o
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
OpenText FirstClass 8.0 - HTTP Daemon /Search Remote Denial of Service
The HTTP daemon in OpenText FirstClass 7.1 and 8.0 allows remote attackers to cause a denial of service (service availab
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
CUPS 1.1.x - '.HPGL' File Processor Buffer Overflow
Buffer overflow in the ParseCommand function in hpgl-input.c in the hpgltops program for CUPS 1.1.22 allows remote attac
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ABCPP 1.3 - Directive Handler Buffer Overflow
Multiple buffer overflows in the handle_directive function in abcpp.c for abcpp 1.3.0 allow remote attackers to execute
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
NASM 0.98.x - Error Preprocessor Directive Buffer Overflow
Buffer overflow in the error function in preproc.c for NASM 0.98.38 1.2 allows attackers to execute arbitrary code via a
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ASP2PHP 0.76.23 - Preparse Token Variable Buffer Overflow
Multiple buffer overflows in the preparse function in asp2php 0.76.23 allow remote attackers to execute arbitrary code v
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
abctab2ps 1.6.3 - 'Write_Heading' '.ABC' Remote Buffer Overflow
Multiple buffer overflows in the (1) write_heading function in subs.cpp or (2) trim_title function in parse.cpp for abct
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
LinPopUp 1.2 - Remote Buffer Overflow
Buffer overflow in the strexpand function in string.c for LinPopUp 1.2.0 allows remote attackers to execute arbitrary co
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ChBg 1.5 - Scenario File Overflow
Buffer overflow in the simplify_path function in config.c for ChBg 1.5 allows remote attackers to execute arbitrary code
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Yanf 0.4 - HTTP Response Buffer Overflow
Buffer overflow in the get function in get.c for Yanf 0.4 allows remote malicious web servers to execute arbitrary code
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
PCAL 4.x - Calendar File 'get_holiday' Remote Buffer Overflow
Multiple buffer overflows in (1) the getline function in pcalutil.c and (2) the get_holiday function in readfile.c for p
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Active Server Corner ASP Calendar 1.0 - Administrative Access
The control panel in ASP Calendar does not require authentication to access, which allows remote attackers to gain unaut
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.4.22-28/2.6.9 - 'igmp.c' Local Denial of Service
Multiple vulnerabilities in the IGMP functionality for Linux kernel 2.4.22 to 2.4.28, and 2.6.x to 2.6.9, allow local an
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
ASP-Rider - SQL Injection
SQL injection vulnerability in verify.asp in Asp-rider allows remote attackers to execute arbitrary SQL statements and b
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Linux Kernel 2.4.28/2.6.9 - 'scm_send Local' Denial of Service
The scm_send function in the scm layer for Linux kernel 2.4.x up to 2.4.28, and 2.6.x up to 2.6.9, allows local users to
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
UBBCentral UBB.Threads 6.2.3/6.5 - 'login.php?Cat' Cross-Site Scripting
Cross-site scripting (XSS) vulnerabilities in (1) calendar.php, (2) login.php, and (3) online.php in Infopop UBB.Threads
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
phpMyAdmin 2.x - External Transformations Remote Command Execution
phpMyAdmin 2.6.0-pl2, and other versions before 2.6.1, with external transformations enabled, allows remote attackers to
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
UBBCentral UBB.Threads 6.2.3/6.5 - 'showflat.php?Cat' Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in showflat.php in Infopop UBB.Threads before 6.5 allows remote attackers to in
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
UBBCentral UBB.Threads 6.2.3/6.5 - 'calendar.php?Cat' Cross-Site Scripting
Cross-site scripting (XSS) vulnerabilities in (1) calendar.php, (2) login.php, and (3) online.php in Infopop UBB.Threads
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Opera Web Browser 7.54 - 'KDE KFMCLIENT' Remote Command Execution
Opera 7.54 and earlier uses kfmclient exec to handle unknown MIME types, which allows remote attackers to execute arbitr
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
UBBCentral UBB.Threads 6.2.3/6.5 - 'online.php?Cat' Cross-Site Scripting
Cross-site scripting (XSS) vulnerabilities in (1) calendar.php, (2) login.php, and (3) online.php in Infopop UBB.Threads
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Multiple Vendor - TCP Session Acknowledgement Number Denial of Service
The TCP/IP stack in multiple operating systems allows remote attackers to cause a denial of service (CPU consumption) vi
35RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Lithtech Engine (new protocol) - Socket Unreacheable Denial of Service
The Lithtech engine, as used in (1) Contract Jack 1.1 and earlier, (2) No one lives forever 2 1.3 and earlier, (3) Tron
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Citadel/UX 6.27 - Format String
Format string vulnerability in the lprintf function in Citadel/UX 6.27 and earlier allows remote attackers to execute ar
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Debian top - Format String
Format string vulnerability in top program allows local attackers to gain root privileges via the "kill" or "renice" fun
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
Easy Software Products LPPassWd 1.1.22 - Resource Limit Denial of Service
lppasswd in CUPS 1.1.22 does not remove the passwd.new file if it encounters a file-size resource limit while writing to
23RISCO
abrir ↗Exploit-DB✓ VexDay Proof
NapShare 1.2 - Remote Buffer Overflow (2)
Buffer overflow in the auto_filter_extern function in auto.c for NapShare 1.2, with the extern filter enabled, allows re
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
GNU Wget 1.x - Multiple Vulnerabilities
wget 1.8.x and 1.9.x does not filter or quote control characters when displaying HTTP responses to the terminal, which m
28RISCO
abrir ↗Exploit-DB✓ VexDay Proof
F-Secure Policy Manager 5.11 - 'FSMSH.dll' CGI Application Installation Full Path Disclosure
The Management Agent in F-Secure Policy Manager 5.11.2810 allows remote attackers to gain sensitive information, such as
23RISCO
abrir ↗Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.