Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.044exploits catalogados
36.945CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
CodeBB 1.0 Beta 2 - 'phpbb_root_path' Remote File Inclusion
CVE-2007-1839webappsphp
Multiple PHP remote file inclusion vulnerabilities in CodeBB 1.1b3 and earlier allow remote attackers to execute arbitra
23RISCO
abrir
ReferênciaVexDay Proof
XOOPS Module MyAds Bug Fix 2.04jp - 'index.php' SQL Injection
CVE-2007-1846webappsphp
SQL injection vulnerability in index.php in the MyAds 2.04jp and earlier module for Xoops allows remote attackers to exe
23RISCO
abrir
ReferênciaVexDay Proof
Really Simple PHP and Ajax (RSPA) 2007-03-23 - Remote File Inclusion
CVE-2007-1851webappsphp
Multiple directory traversal vulnerabilities in Really Simple PHP and Ajax (RSPA) 2007-03-23 allow remote attackers to i
23RISCO
abrir
ReferênciaVexDay Proof
MySpeach 3.0.7 - Local/Remote File Inclusion
CVE-2007-1896webappsphp
Directory traversal vulnerability in chat.php in Sky GUNNING MySpeach 3.0.7 and earlier allows remote attackers to inclu
23RISCO
abrir
ReferênciaVexDay Proof
MyBloggie 2.1.6 - Multiple SQL Injections
CVE-2007-1899webappsphp
Multiple SQL injection vulnerabilities in myWebland myBloggie 2.1.6 allow remote attackers to execute arbitrary SQL comm
23RISCO
abrir
ReferênciaVexDay Proof
Pathos CMS 0.92-2 - 'warn.php' Remote File Inclusion
CVE-2007-1907webappsphp
PHP remote file inclusion vulnerability in warn.php in Pathos Content Management System (CMS) 0.92-2 allows remote attac
23RISCO
abrir
ReferênciaVexDay Proof
PHP121 Instant Messenger 2.2 - Local File Inclusion
CVE-2007-1908webappsphp
PHP file inclusion vulnerability in php121db.php in PHP121 Instant Messenger 2.2 allows remote attackers to execute arbi
23RISCO
abrir
ReferênciaVexDay Proof
Microsoft Word 2007 - Multiple Vulnerabilities
CVE-2007-1910doswindows
Buffer overflow in wwlib.dll in Microsoft Word 2007 allows remote attackers to cause a denial of service (application cr
28RISCO
abrir
ReferênciaVexDay Proof
Microsoft Windows - '.hlp' Local HEAP Overflow (PoC)
CVE-2007-1912doswindows
Heap-based buffer overflow in Microsoft Windows allows user-assisted remote attackers to have an unknown impact via a cr
28RISCO
abrir
ReferênciaVexDay Proof
Beryo 2.0 - 'downloadpic.php?chemin' Remote File Disclosure
CVE-2007-1929webappsphp
Directory traversal vulnerability in downloadpic.php in Beryo 2.0, and possibly other versions including 2.4, allows rem
23RISCO
abrir
ReferênciaVexDay Proof
cattaDoc 2.21 - 'download2.php?fn1' Remote File Disclosure
CVE-2007-1930webappsphp
Directory traversal vulnerability in download2.php in cattaDoc 2.21, and possibly other versions including 3.0, allows r
23RISCO
abrir
ReferênciaVexDay Proof
SmodCMS 2.10 - Slownik ssid SQL Injection
CVE-2007-1931webappsphp
SQL injection vulnerability in index.php in the slownik module in SmodCMS 2.10 and earlier allows remote attackers to ex
23RISCO
abrir
ReferênciaVexDay Proof
PcP-Guestbook 3.0 - 'lang' Local File Inclusion
CVE-2007-1933webappsphp
Multiple directory traversal vulnerabilities in PcP-Guestbook (PcP-Book) 3.0 allow remote attackers to include and execu
23RISCO
abrir
ReferênciaVexDay Proof
Kodak Image Viewer - TIF/TIFF Code Execution (MS07-055)
CVE-2007-2217localwindows
Kodak Image Viewer in Microsoft Windows 2000 SP4, and in some cases XP SP2 and Server 2003 SP1 and SP2, allows remote at
35RISCO
abrir
ReferênciaVexDay Proof
Microsoft Windows - GDI+ '.ICO' File Remote Denial of Service
CVE-2007-2237doswindows
Microsoft Windows Graphics Device Interface (GDI+, GdiPlus.dll) allows context-dependent attackers to cause a denial of
28RISCO
abrir
ReferênciaVexDay Proof
Adobe Photoshop CS2 / CS3 - '.bmp' Local Buffer Overflow
CVE-2007-2244localwindows
Multiple buffer overflows in Adobe Photoshop CS2 and CS3, Illustrator CS3, and GoLive 9 allow user-assisted remote attac
35RISCO
abrir
ReferênciaVexDay Proof
Quick and Dirty Blog (qdblog) 0.4 - SQL Injection / Local File Inclusion
CVE-2007-2305webappsphp
Multiple SQL injection vulnerabilities in authenticate.php in Quick and Dirty Blog (QDBlog) 0.4, and possibly earlier, a
23RISCO
abrir
ReferênciaVexDay Proof
CodeWand phpBrowse - 'site_path' Remote File Inclusion
CVE-2007-2345webappsphp
PHP remote file inclusion vulnerability in include/include_stream.inc.php in CodeWand phpBrowse allows remote attackers
23RISCO
abrir
ReferênciaVexDay Proof
burnCMS 0.2 - 'root' Remote File Inclusion
CVE-2007-2364webappsphp
Multiple PHP remote file inclusion vulnerabilities in burnCMS 0.2 and earlier allow remote attackers to execute arbitrar
23RISCO
abrir
ReferênciaVexDay Proof
WordPress Plugin mygallery 1.4b4 - Remote File Inclusion
CVE-2007-2426webappsphp
PHP remote file inclusion vulnerability in myfunctions/mygallerybrowser.php in the myGallery 1.4b4 and earlier plugin fo
35RISCO
abrir
ReferênciaVexDay Proof
Sun Board 1.00.00 alpha - Remote File Inclusion
CVE-2007-3370webappsphp
Multiple PHP remote file inclusion vulnerabilities in Sun Board 1.00.00 Alpha allow remote attackers to execute arbitrar
45RISCO
abrir
ReferênciaVexDay Proof
b1gbb 2.24.0 - 'footer.inc.php?tfooter' Remote File Inclusion
CVE-2007-3401webappsphp
PHP remote file inclusion vulnerability in footer.inc.php in B1G b1gBB 2.24 allows remote attackers to execute arbitrary
45RISCO
abrir
ReferênciaVexDay Proof
phpTrafficA 1.4.2 - 'pageid' SQL Injection
CVE-2007-3426webappsphp
Cross-site scripting (XSS) vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to inject
23RISCO
abrir
ReferênciaVexDay Proof
Simple Invoices 2007 05 25 - 'index.php?submit' SQL Injection
CVE-2007-3430webappsphp
SQL injection vulnerability in index.php in Simple Invoices 2007 05 25 allows remote attackers to execute arbitrary SQL
23RISCO
abrir
ReferênciaVexDay Proof
dagger Web engine 23jan2007 - Remote File Inclusion
CVE-2007-3431webappsphp
PHP remote file inclusion vulnerability in cal.func.php in Valerio Capello Dagger - The Cutting Edge r23jan2007 allows r
45RISCO
abrir
ReferênciaVexDay Proof
Pluxml 0.3.1 - Remote Code Execution
CVE-2007-3432webappsphp
Unrestricted file upload vulnerability in admin/images.php in Pluxml 0.3.1 allows remote attackers to upload and execute
23RISCO
abrir
ReferênciaVexDay Proof
Pharmacy System 2.0 - 'index.php?ID' SQL Injection
CVE-2007-3433webappsphp
SQL injection vulnerability in index.php in Pharmacy System 2 and earlier allows remote attackers to execute arbitrary S
23RISCO
abrir
ReferênciaVexDay Proof
RKD Software BarCode ActiveX Control 'BarCodeAx.dll' 4.9 - Remote Overflow
CVE-2007-3435remotewindows
Stack-based buffer overflow in the BeginPrint method in a certain ActiveX control in RKD Software (barcodetools.com) Bar
50RISCO
abrir
ReferênciaVexDay Proof
bugmall shopping cart 2.5 - SQL Injection / Cross-Site Scripting
CVE-2007-3447webappsphp
SQL injection vulnerability in BugMall Shopping Cart 2.5 and earlier allows remote attackers to execute arbitrary SQL co
23RISCO
abrir
ReferênciaVexDay Proof
NCTAudioStudio2 - ActiveX DLL 2.6.1.148 'CreateFile()'/ Insecure Method
CVE-2007-3493remotewindows
A certain ActiveX control in NCTWavChunksEditor2.dll 2.6.1.148 in NCTAudioStudio (NCTAudioStudio2) 2.7, as used by Sienz
35RISCO
abrir
anteriorpágina 120 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.