Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
SoftBB 0.1 - 'cmd' Remote Command Execution
CVE-2006-4633webappsphp
index.php in SoftBB 0.1, and possibly earlier, allows remote attackers to obtain the installation path via a null or inv
23RISCO
abrir
ReferênciaVexDay Proof
GeekLog 1.4.0sr3 - '_CONF[path]' Remote File Inclusion
CVE-2006-6225webappsphp
Multiple PHP remote file inclusion vulnerabilities in GeekLog 1.4 allow remote attackers to execute arbitrary code via a
23RISCO
abrir
ReferênciaVexDay Proof
C-News 1.0.1 - 'path' Remote File Inclusion
CVE-2006-4629webappsphp
PHP remote file inclusion vulnerability in affichage/commentaires.php in C-News.fr C-News 1.0.1 and earlier allows remot
23RISCO
abrir
ReferênciaVexDay Proof
MySpeach 3.0.2 - 'my_ms[root]' Remote File Inclusion
CVE-2006-4630webappsphp
PHP remote file inclusion vulnerability in jscript.php in Sky GUNNING MySpeach 3.0.2 and earlier, when register_globals
23RISCO
abrir
ReferênciaVexDay Proof
Woltlab Burning Board Lite 1.0.2 - 'decode_cookie()' SQL Injection
CVE-2006-6237webappsphp
SQL injection vulnerability in the decode_cookie function in thread.php in Woltlab Burning Board Lite 1.0.2 allows remot
23RISCO
abrir
ReferênciaVexDay Proof
TIBCO Rendezvous 7.4.11 - Password Extractor
CVE-2006-4676localwindows
TIBCO RendezVous 7.4.11 and earlier logs base64-encoded usernames and passwords in rvrd.db, which allows local users to
23RISCO
abrir
ReferênciaVexDay Proof
IBM Director < 5.10 - 'Redirect.bat' Directory Traversal
CVE-2006-4681remotewindows
Directory traversal vulnerability in Redirect.bat in IBM Director before 5.10 allows remote attackers to read arbitrary
23RISCO
abrir
ReferênciaVexDay Proof
LimeSurvey 4.1.11 - 'File Manager' Path Traversal
CVE-2020-11455webappsphp
LimeSurvey before 4.1.12+200324 contains a path traversal vulnerability in application/controllers/admin/LimeSurveyFileM
60RISCO
abrir
ReferênciaVexDay Proof
Magic News Pro 1.0.3 - 'script_path' Remote File Inclusion
CVE-2006-4823webappsphp
PHP remote file inclusion vulnerability in scripts/news_page.php in Reamday Enterprises Magic News Pro 1.0.3 and earlier
23RISCO
abrir
ReferênciaVexDay Proof
The Classified Ad System 1.0 - 'main' SQL Injection
CVE-2006-6349webappsasp
Multiple SQL injection vulnerabilities in PWP Technologies The Classified Ad System allow remote attackers to execute ar
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component ChronoForms 2.3.5 - Remote File Inclusion
CVE-2008-0567webappsphp
Multiple PHP remote file inclusion vulnerabilities in ChronoEngine ChronoForms (com_chronocontact) 2.3.5 component for J
35RISCO
abrir
ReferênciaVexDay Proof
Downstat 1.8 - 'art' Remote File Inclusion
CVE-2006-4827webappsphp
Multiple PHP remote file inclusion vulnerabilities in Vmist Downstat 1.8 and earlier allow remote attackers to execute a
23RISCO
abrir
ReferênciaVexDay Proof
Mindmeld 1.2.0.10 - Multiple Remote File Inclusions
CVE-2008-0572webappsphp
Multiple PHP remote file inclusion vulnerabilities in Mindmeld 1.2.0.10 allow remote attackers to execute arbitrary PHP
28RISCO
abrir
ReferênciaVexDay Proof
SafeNet 10.4.0.12 - 'IPSecDrv.sys' Local kernel Ring0 SYSTEM
CVE-2008-0573localwindows
IPSecDrv.sys 10.4.0.12 in SafeNET HighAssurance Remote and SoftRemote allows local users to gain privileges via a crafte
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component Expose RC35 - Arbitrary File Upload
CVE-2007-3932webappsphp
uploadimg.php in the Expose RC35 and earlier (com_expose) component for Joomla! sends an error message but does not exit
23RISCO
abrir
ReferênciaVexDay Proof
Gallery 2.0.3 - 'stepOrder[]' Remote Command Execution
CVE-2006-1219webappsphp
Directory traversal vulnerability in Gallery 2.0.3 and earlier, and 2.1 before RC-2a, allows remote attackers to include
23RISCO
abrir
ReferênciaVexDay Proof
bwired - 'index.php?newsID' SQL Injection
CVE-2007-3976webappsphp
SQL injection vulnerability in index.php in bwired allows remote attackers to execute arbitrary SQL commands via the new
23RISCO
abrir
ReferênciaVexDay Proof
Blog System 1.x - 'index.php?news_id' SQL Injection
CVE-2007-3979webappsphp
SQL injection vulnerability in index.php in BlogSite Professional (aka Blog System) 1.x allows remote attackers to execu
23RISCO
abrir
ReferênciaVexDay Proof
Linux Kernel 2.6.x - 'sys_timer_create()' Local Denial of Service
CVE-2006-7051doslinux
The sys_timer_create function in posix-timers.c for Linux kernel 2.6.x allows local users to cause a denial of service (
23RISCO
abrir
ReferênciaVexDay Proof
phpunity.postcard - 'gallery_path' Remote File Inclusion
CVE-2006-4869webappsphp
PHP remote file inclusion vulnerability in phpunity-postcard.php in phpunity.postcard allows remote attackers to execute
23RISCO
abrir
ReferênciaVexDay Proof
File Store PRO 3.2 - Multiple Blind SQL Injections
CVE-2006-1278webappsphp
SQL injection vulnerability in @1 File Store 2006.03.07 allows remote attackers to execute arbitrary SQL commands via th
23RISCO
abrir
ReferênciaVexDay Proof
PHP iCalendar 2.21 - 'publish.ical.php' Remote Code Execution
CVE-2006-1291webappsphp
publish.ical.php in Jim Hu and Chad Little PHP iCalendar 2.21 and earlier does not require authentication for write acce
23RISCO
abrir
ReferênciaVexDay Proof
Web-News 1.6.3 - 'template.php' Remote File Inclusion
CVE-2006-5053webappsphp
PHP remote file inclusion vulnerability in webnews/template.php in Web-News 1.6.3 and earlier allows remote attackers to
23RISCO
abrir
ReferênciaVexDay Proof
NaviCOPA Web Server 2.01 - 'GET' Remote Buffer Overflow
CVE-2006-5112remotewindows
Buffer overflow in InterVations NaviCOPA Web Server 2.01 allows remote attackers to execute arbitrary code via a long HT
50RISCO
abrir
ReferênciaVexDay Proof
gCards 1.45 - Multiple Vulnerabilities
CVE-2006-1348webappsphp
Cross-site scripting (XSS) vulnerability in index.php in Greg Neustaetter gCards 1.45 and earlier allows remote attacker
23RISCO
abrir
ReferênciaVexDay Proof
Claroline 1.8.0 rc1 - 'import.lib.php' Remote File Inclusion
CVE-2006-5256webappsphp
PHP remote file inclusion vulnerability in claroline/inc/lib/import.lib.php in Claroline 1.8.0 and earlier allows remote
23RISCO
abrir
ReferênciaVexDay Proof
Yahoo! Music Jukebox 2.2 - 'AddImage()' ActiveX Remote Buffer Overflow (1)
CVE-2008-0623remotewindows
Stack-based buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! Music Jukebox 2.2.2.056 allows
23RISCO
abrir
ReferênciaVexDay Proof
FreeWPS 2.11 - 'images.php' Remote Code Execution
CVE-2006-1363webappsphp
images.php in Justin White (aka YTZ) Free Web Publishing System (FreeWPS) 2.11 allows remote attackers to execute arbitr
23RISCO
abrir
ReferênciaVexDay Proof
Yahoo! Music Jukebox 2.2 - 'AddImage()' ActiveX Remote Buffer Overflow (2)
CVE-2008-0623remotewindows
Stack-based buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! Music Jukebox 2.2.2.056 allows
23RISCO
abrir
ReferênciaVexDay Proof
XHP CMS 0.5 - 'upload' Remote Command Execution
CVE-2006-1371webappsphp
Laurentiu Matei eXpandable Home Page (XHP) CMS 0.5 and earlier allows remote authenticated users to use the HTMLArea Fil
23RISCO
abrir
anteriorpágina 113 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.