Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
IncCMS Core 1.0.0 - 'settings.php' Remote File Inclusion
CVE-2006-5304webappsphp
PHP remote file inclusion vulnerability in inc/settings.php in IncCMS Core 1.0.0 and earlier allows remote attackers to
23RISCO
abrir
ReferênciaVexDay Proof
SuperNET Shop 1.0 - SQL Injection
CVE-2008-6204webappsasp
Multiple SQL injection vulnerabilities in SuperNET Shop 1.0 and earlier allow remote attackers to execute arbitrary SQL
23RISCO
abrir
ReferênciaVexDay Proof
SQLiteWebAdmin 0.1 - 'tpl.inc.php' Remote File Inclusion
CVE-2006-4102webappsphp
PHP remote file inclusion vulnerability in tpl.inc.php in Falko Timme and Till Brehm SQLiteWebAdmin 0.1 and earlier allo
23RISCO
abrir
ReferênciaVexDay Proof
JaxUltraBB 2.0 - 'delete.php' Remote Auto Deface
CVE-2006-5511webappsphp
Direct static code injection vulnerability in delete.php in JaxUltraBB (JUBB) 2.0, when register_globals is enabled, all
23RISCO
abrir
ReferênciaVexDay Proof
WordPress Plugin wp-Table 1.43 - 'inc_dir' Remote File Inclusion
CVE-2007-2484webappsphp
PHP remote file inclusion vulnerability in js/wptable-button.php in the wp-Table 1.43 and earlier plugin for WordPress,
35RISCO
abrir
ReferênciaVexDay Proof
PStruh-CZ 1.3/1.5 - 'download.asp' File Disclosure
CVE-2007-2486webappsasp
Directory traversal vulnerability in download.asp in Motobit 1.3 and 1.5 (aka PStruh-CZ) allows remote attackers to read
23RISCO
abrir
ReferênciaVexDay Proof
PowerPoint Viewer OCX 3.2 - ActiveX Control Denial of Service
CVE-2007-2494doswindows
Multiple stack-based buffer overflows in the PowerPointOCX ActiveX control in PowerPointViewer.ocx 3.1.0.3 allow remote
23RISCO
abrir
ReferênciaVexDay Proof
NoAh 0.9 pre 1.2 - 'mfa_theme.php' Remote File Inclusion
CVE-2007-2572webappsphp
PHP remote file inclusion vulnerability in modules/noevents/templates/mfa_theme.php in NoAh (aka PHP Content Architect,
23RISCO
abrir
ReferênciaVexDay Proof
Sciurus Hosting Panel - Remote Code Injection
CVE-2007-6082webappsphp
Direct static code injection vulnerability in acp/savenews.php in Sciurus Hosting Panel, possibly 2.0.3, allows remote a
23RISCO
abrir
ReferênciaVexDay Proof
KB-Bestellsystem - 'kb_whois.cgi' Command Execution
CVE-2007-6176webappscgi
kb_whois.cgi in K+B-Bestellsystem (aka KB-Bestellsystem) allows remote attackers to execute arbitrary commands via shell
23RISCO
abrir
ReferênciaVexDay Proof
TuMusika Evolution 1.7R5 - Remote File Disclosure
CVE-2007-6188webappsphp
Multiple directory traversal vulnerabilities in TuMusika Evolution 1.7R5 allow remote attackers to include and execute a
23RISCO
abrir
ReferênciaVexDay Proof
phpPrintAnalyzer 1.2 - Remote File Inclusion
CVE-2006-4164webappsphp
PHP remote file inclusion vulnerability in inc/header.inc.php in phpPrintAnalyzer 1.2 and earlier allows remote attacker
23RISCO
abrir
ReferênciaVexDay Proof
Seditio CMS 121 - SQL Injection
CVE-2007-6202webappsphp
SQL injection vulnerability in plugins/search/search.php in Neocrome Seditio CMS 121 and earlier allows remote attackers
23RISCO
abrir
ReferênciaVexDay Proof
KML share 1.1 - 'region.php?layer' Remote File Disclosure
CVE-2007-6212webappsphp
Directory traversal vulnerability in region.php in KML share 1.1 allows remote attackers to read arbitrary files via a .
23RISCO
abrir
ReferênciaVexDay Proof
ProjectButler 0.8.4 - 'rootdir' Remote File Inclusion
CVE-2006-4205webappsphp
Multiple PHP remote file inclusion vulnerabilities in WebDynamite ProjectButler 0.8.4 allow remote attackers to execute
23RISCO
abrir
ReferênciaVexDay Proof
Google Chrome 0.2.149.27 - Denial of Service
CVE-2008-6995doswindows
Integer underflow in net/base/escape.cc in chrome.dll in Google Chrome 0.2.149.27 allows remote attackers to cause a den
23RISCO
abrir
ReferênciaVexDay Proof
Mambo Component mambelfish 1.1 - Remote File Inclusion
CVE-2006-4270webappsphp
PHP remote file inclusion vulnerability in mambelfish.class.php in the mambelfish component (com_mambelfish) 1.1 and ear
23RISCO
abrir
ReferênciaVexDay Proof
Tutti Nova 1.6 - 'TNLIB_DIR' Remote File Inclusion
CVE-2006-4276webappsphp
PHP remote file inclusion vulnerability in Tutti Nova 1.6 and earlier allows remote attackers to execute arbitrary PHP c
23RISCO
abrir
ReferênciaVexDay Proof
Mambo Component bigAPE-Backup 1.1 - Remote File Inclusion
CVE-2006-4296webappsphp
PHP remote file inclusion vulnerability in classes/Tar.php in bigAPE-Backup component (com_babackup) for Mambo 1.1 allow
23RISCO
abrir
ReferênciaVexDay Proof
Empire CMS 3.7 - 'checklevel.php' Remote File Inclusion
CVE-2006-4354webappsphp
PHP remote file inclusion vulnerability in e/class/CheckLevel.php in Phome Empire CMS 3.7 and earlier allows remote atta
23RISCO
abrir
ReferênciaVexDay Proof
MDaemon POP3 Server < 9.06 - 'USER' Remote Buffer Overflow (PoC)
CVE-2006-4364doswindows
Multiple heap-based buffer overflows in the POP3 server in Alt-N Technologies MDaemon before 9.0.6 allow remote attacker
35RISCO
abrir
ReferênciaVexDay Proof
SerWeb 2.0.0 dev1 2007-02-20 - Multiple Local/Remote File Inclusion Vulnerabilities
CVE-2007-6289webappsphp
Multiple PHP remote file inclusion vulnerabilities in SerWeb 2.0.0 dev1 and earlier allow remote attackers to execute ar
23RISCO
abrir
ReferênciaVexDay Proof
Web3news 0.95 - 'PHPSECURITYADMIN_PATH' Remote File Inclusion
CVE-2006-4452webappsphp
PHP remote file inclusion vulnerability in security/include/_class.security.php in Web3news 0.95 and earlier, when regis
23RISCO
abrir
ReferênciaVexDay Proof
XChat 2.6.7 (Windows) - Remote Denial of Service
CVE-2006-4455doswindows
Unspecified vulnerability in Xchat 2.6.7 and earlier allows remote attackers to cause a denial of service (crash) via un
23RISCO
abrir
ReferênciaVexDay Proof
HP Compaq Notebooks - ActiveX Remote Code Execution
CVE-2007-6333remotewindows
The HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 i
23RISCO
abrir
ReferênciaVexDay Proof
ClamAV 0.91.2 - libclamav MEW PE Buffer Overflow
CVE-2007-6335remotelinux
Integer overflow in libclamav in ClamAV before 0.92 allows remote attackers to execute arbitrary code via a crafted MEW
28RISCO
abrir
ReferênciaVexDay Proof
Joomla! / Mambo Component rsgallery 2.0b5 - 'catid' SQL Injection
CVE-2007-6362webappsphp
SQL injection vulnerability in index.php in the RSGallery (com_rsgallery) 2.0 beta 5 and earlier component for Mambo and
23RISCO
abrir
ReferênciaVexDay Proof
SineCMS 2.3.4 - Calendar SQL Injection
CVE-2007-6366webappsphp
Multiple SQL injection vulnerabilities in SineCMS 2.3.4 and earlier allow remote attackers to execute arbitrary SQL comm
23RISCO
abrir
ReferênciaVexDay Proof
Linksys SPA941 - Remote Reboot (Denial of Service)
CVE-2007-2270doshardware
The Linksys SPA941 VoIP Phone allows remote attackers to cause a denial of service (device reboot) via a 0377 (0xff) cha
23RISCO
abrir
ReferênciaVexDay Proof
USP FOSS Distribution 1.01 - 'dnld' Remote File Disclosure
CVE-2007-2271webappsphp
Directory traversal vulnerability in Rajneel Lal TotaRam USP FOSS Distribution 1.01 allows remote attackers to read arbi
23RISCO
abrir
anteriorpágina 107 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.