Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.043exploits catalogados
36.945CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
Microsoft Windows - NAT Helper Components 'ipnathlp.dll' Remote Denial of Service
CVE-2006-5614doswindows
Microsoft Windows NAT Helper Components (ipnathlp.dll) on Windows XP SP2, when Internet Connection Sharing is enabled, a
60RISCO
abrir
ReferênciaVexDay Proof
ask_rave 0.9 PR - 'end.php?footfile' Remote File Inclusion
CVE-2006-5621webappsphp
PHP remote file inclusion vulnerability in end.php in ask_rave 0.9 PR, and other versions before 0.9b, allows remote att
23RISCO
abrir
ReferênciaVexDay Proof
Coppermine Photo Gallery 1.4.9 - SQL Injection
CVE-2006-5622webappsphp
SQL injection vulnerability in picmgr.php in Coppermine Photo Gallery 1.4.9 allows remote attackers to execute arbitrary
23RISCO
abrir
ReferênciaVexDay Proof
Electronic Engineering Tool (EE TOOL) 0.4.1 - Remote File Inclusion
CVE-2006-5623webappsphp
PHP remote file inclusion vulnerability in ip.inc.php in Electronic Engineering Tool (EE Tool) 0.4-1 and earlier allows
23RISCO
abrir
ReferênciaVexDay Proof
N/X WCMS 4.1 - 'nxheader.inc.php' Remote File Inclusion
CVE-2006-5625webappsphp
PHP remote file inclusion vulnerability in wwwdev/nxheader.inc.php in N/X 2002 Professional Edition Web Content Manageme
23RISCO
abrir
ReferênciaVexDay Proof
phpProfiles 2.1 Beta - Multiple Remote File Inclusions
CVE-2006-5634webappsphp
Multiple PHP remote file inclusion vulnerabilities in phpProfiles 2.1 Beta allow remote attackers to execute arbitrary P
23RISCO
abrir
ReferênciaVexDay Proof
Techno Dreams Announcement - 'key' SQL Injection
CVE-2006-5641webappsasp
SQL injection vulnerability in MainAnnounce2.asp in Techno Dreams Announcement allows remote attackers to execute arbitr
23RISCO
abrir
ReferênciaVexDay Proof
phpBB Spider Friendly Module 1.3.10 - Remote File Inclusion
CVE-2006-5665webappsphp
PHP remote file inclusion vulnerability in admin/modules_data.php in the phpBB module Spider Friendly 1.3.10 and earlier
23RISCO
abrir
ReferênciaVexDay Proof
E Annu 1.0 - Authentication Bypass / SQL Injection
CVE-2006-5666webappsphp
SQL injection vulnerability in includes/menu.inc.php in E-Annu 1.0 allows remote attackers to execute arbitrary SQL comm
23RISCO
abrir
ReferênciaVexDay Proof
GEPI 1.4.0 - '/gestion/savebackup.php' Remote File Inclusion
CVE-2006-5669webappsphp
PHP remote file inclusion vulnerability in gestion/savebackup.php in Gepi 1.4.0 and earlier, and possibly other versions
23RISCO
abrir
ReferênciaVexDay Proof
MySource CMS 2.16.2 - 'init_mysource.php' Remote File Inclusion
CVE-2006-5672webappsphp
PHP remote file inclusion vulnerability in web/init_mysource.php in MySource CMS 2.16.2 and earlier allows remote attack
23RISCO
abrir
ReferênciaVexDay Proof
MiniBB 2.0.2 - 'bb_func_txt.php' Remote File Inclusion
CVE-2006-5673webappsphp
PHP remote file inclusion vulnerability in bb_func_txt.php in miniBB 2.0.2 and earlier, when register_globals is enabled
23RISCO
abrir
ReferênciaVexDay Proof
PHPEasyData Pro 2.2.2 - 'index.php' SQL Injection
CVE-2006-5707webappsphp
SQL injection vulnerability in index.php in PHPEasyData Pro 1.4.1 and 2.2.1 allows remote attackers to execute arbitrary
23RISCO
abrir
ReferênciaVexDay Proof
AEP SmartGate 4.3b - 'GET' Arbitrary File Download
CVE-2006-5725remotewindows
The SSL server in AEP Smartgate 4.3b allows remote attackers to determine existence of directories via a direct request
23RISCO
abrir
ReferênciaVexDay Proof
ASP Smiley 1.0 - 'default.asp' Authentication Bypass / SQL Injection
CVE-2006-5952webappsasp
SQL injection vulnerability in admin/default.asp in ASP Smiley 1.0 allows remote attackers to execute arbitrary SQL comm
23RISCO
abrir
ReferênciaVexDay Proof
Helix Server 11.0.1 (Windows 2000 SP4) - Remote Heap Overflow
CVE-2006-6026remotewindows
Heap-based buffer overflow in Real Networks Helix Server and Helix Mobile Server before 11.1.3, and Helix DNA Server 11.
28RISCO
abrir
ReferênciaVexDay Proof
Etomite CMS 0.6.1.2 - '/manager/index.php' Local File Inclusion
CVE-2006-6047webappsphp
Directory traversal vulnerability in manager/index.php in Etomite 0.6.1.2 allows remote authenticated administrators to
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component MosReporter 0.9.3 - Remote File Inclusion
CVE-2006-6051webappsphp
PHP remote file inclusion vulnerability in reporter.logic.php in the MosReporter (com_reporter) component for Mambo and
23RISCO
abrir
ReferênciaVexDay Proof
e-Ark 1.0 - '/src/ark_inc.php' Remote File Inclusion
CVE-2006-6086webappsphp
PHP remote file inclusion vulnerability in src/ark_inc.php in e-Ark 1.0 allows remote attackers to execute arbitrary PHP
23RISCO
abrir
ReferênciaVexDay Proof
FipsCMS 4.5 - 'index.asp' SQL Injection
CVE-2006-6115webappsasp
SQL injection vulnerability in index.asp in fipsCMS 4.5 and earlier allows remote attackers to execute arbitrary SQL com
23RISCO
abrir
ReferênciaVexDay Proof
fipsForum 2.6 - 'default2.asp' SQL Injection
CVE-2006-6116webappsasp
SQL injection vulnerability in default2.asp in fipsForum 2.6 and earlier allows remote attackers to execute arbitrary SQ
23RISCO
abrir
ReferênciaVexDay Proof
PEGames - 'index.php' Remote File Inclusion
CVE-2006-6213webappsphp
index.php in PEGames uses the extract function to overwrite critical variables, which allows remote attackers to conduct
23RISCO
abrir
ReferênciaVexDay Proof
PgmReloaded 0.8.5 - Multiple Remote File Inclusions
CVE-2006-6710webappsphp
Multiple PHP remote file inclusion vulnerabilities in PgmReloaded 0.8.5 and earlier allow remote attackers to execute ar
23RISCO
abrir
ReferênciaVexDay Proof
phpProfiles 3.1.2b - Multiple Remote File Inclusions
CVE-2006-6740webappsphp
Multiple PHP remote file inclusion vulnerabilities in phpProfiles 3.1.2b and earlier allow remote attackers to execute a
23RISCO
abrir
ReferênciaVexDay Proof
Ixprim CMS 1.2 - Blind SQL Injection
CVE-2006-6756webappsphp
The code function in install.fct.php in Ixprim 1.2 produces a guessable value of the confidential IXP_CODE in mainfile.p
23RISCO
abrir
ReferênciaVexDay Proof
cwmExplorer 1.0 - 'show_file' Source Code Disclosure
CVE-2006-6757webappsasp
Directory traversal vulnerability in index.php in cwmExplorer 1.0 allows remote attackers to read arbitrary files and so
23RISCO
abrir
ReferênciaVexDay Proof
Http explorer Web Server 1.02 - Directory Traversal
CVE-2006-6758remotewindows
Directory traversal vulnerability in Http explorer 1.02 allows remote attackers to read arbitrary files via a .. (dot do
23RISCO
abrir
ReferênciaVexDay Proof
RealPlayer 10.5 - ActiveX Control Denial of Service
CVE-2006-6759doswindows
A certain ActiveX control in rpau3260.dll in RealNetworks RealPlayer 10.5 allows remote attackers to cause a denial of s
23RISCO
abrir
ReferênciaVexDay Proof
PHPMyManga 0.8.1 - 'template.php' Multiple File Inclusions
CVE-2006-6760webappsphp
Multiple PHP remote file inclusion vulnerabilities in template.php in Phpmymanga 0.8.1 and earlier allow remote attacker
23RISCO
abrir
ReferênciaVexDay Proof
Pagetool CMS 1.07 - 'pt_upload.php' Remote File Inclusion
CVE-2006-6765webappsphp
Multiple PHP file inclusion vulnerabilities in src/admin/pt_upload.php in Pagetool 1.07 allow remote attackers to execut
23RISCO
abrir
anteriorpágina 119 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.