Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.095exploits catalogados
36.945CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
W1L3D4 philboard 1.0 - 'philboard_reply.asp' SQL Injection
CVE-2008-1939webappsasp
Multiple SQL injection vulnerabilities in W1L3D4 Philboard 1.0 allow remote attackers to execute arbitrary SQL commands
23RISCO
abrir
ReferênciaVexDay Proof
QNX Neutrino 0.8.4 Atomic Edition - Remote Code Execution
CVE-2008-3150webappsphp
Directory traversal vulnerability in index.php in Neutrino Atomic Edition 0.8.4 allows remote attackers to read and modi
23RISCO
abrir
ReferênciaVexDay Proof
Half-Life CSTRIKE Server 1.6 - 'no-steam' Denial of Service
CVE-2008-7203dosmultiple
Valve Software Half-Life Counter-Strike 1.6 allows remote attackers to cause a denial of service (crash) via multiple cr
23RISCO
abrir
ReferênciaVexDay Proof
Mambo Component zOOm Media Gallery 2.5 Beta 2 - Remote File Inclusion
CVE-2007-1992webappsphp
Multiple PHP remote file inclusion vulnerabilities in the com_zoom 2.5 beta 2 and earlier module for Mambo allow remote
23RISCO
abrir
ReferênciaVexDay Proof
Mcms Easy Web Make - 'index.php?template' Local File Inclusion
CVE-2007-6344webappsphp
Directory traversal vulnerability in modules/cms/index.php in Mcms Easy Web Make 1.3, allows remote attackers to include
23RISCO
abrir
ReferênciaVexDay Proof
PHPUserBase 1.3b - 'unverified.inc.php' Local File Inclusion
CVE-2008-7240webappsphp
Directory traversal vulnerability in include/unverified.inc.php in Linux Web Shop (LWS) php User Base 1.3beta allows rem
23RISCO
abrir
ReferênciaVexDay Proof
Joovili 3.1 - 'browse.videos.php' SQL Injection
CVE-2008-2063webappsphp
SQL injection vulnerability in browse.videos.php in Joovili 3.1 allows remote attackers to execute arbitrary SQL command
23RISCO
abrir
ReferênciaVexDay Proof
Dokeos E-Learning System 1.8.5 - Local File Inclusion
CVE-2008-3363webappsphp
Directory traversal vulnerability in user_portal.php in the Dokeos E-Learning System 1.8.5 on Windows allows remote atta
23RISCO
abrir
ReferênciaVexDay Proof
QuickTime 7.4.1 - 'QTPlugin.ocx' Multiple Stack Overflow Vulnerabilities
CVE-2008-0778doswindows
Multiple stack-based buffer overflows in an ActiveX control in QTPlugin.ocx for Apple QuickTime 7.4.1 and earlier allow
23RISCO
abrir
ReferênciaVexDay Proof
ActualAnalyzer Lite (free) 2.78 - Local File Inclusion
CVE-2008-2076webappsphp
Directory traversal vulnerability in admin.php in ActualScripts ActualAnalyzer Lite 2.78 allows remote attackers to incl
23RISCO
abrir
ReferênciaVexDay Proof
Microsoft Internet Explorer 7 (Windows 2003 SP2) - Memory Corruption (MS09-002)
CVE-2009-0075remotewindows
Microsoft Internet Explorer 7 does not properly handle errors during attempted access to deleted objects, which allows r
60RISCO
abrir
ReferênciaVexDay Proof
Advanced Webhost Billing System (AWBS) 2.4.0 - 'cart2.php' Remote File Inclusion
CVE-2007-2272webappsphp
PHP remote file inclusion vulnerability in docs/front-end-demo/cart2.php in Advanced Webhost Billing System (AWBS) 2.4.0
23RISCO
abrir
ReferênciaVexDay Proof
Microsoft FoxServer - 'vfp6r.dll 6.0.8862.0' ActiveX Command Execution
CVE-2008-0236remotewindows
An ActiveX control for Microsoft Visual FoxPro (vfp6r.dll 6.0.8862.0) allows remote attackers to execute arbitrary comma
28RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component Community Builder 1.0.1 - Blind SQL Injection
CVE-2008-2093webappsphp
SQL injection vulnerability in the Profiler (com_comprofiler) component in Community Builder for Mambo and Joomla! allow
23RISCO
abrir
ReferênciaVexDay Proof
mailwatch 1.0.4 - 'doc' Local File Inclusion
CVE-2008-5991webappsphp
Directory traversal vulnerability in docs.php in MailWatch for MailScanner 1.0.4 and earlier allows remote attackers to
23RISCO
abrir
ReferênciaVexDay Proof
PHP Live Helper 2.0.1 - Multiple Vulnerabilities
CVE-2008-3764webappsphp
Eval injection vulnerability in globalsoff.php in Turnkey PHP Live Helper 2.0.1 and earlier allows remote attackers to e
23RISCO
abrir
ReferênciaVexDay Proof
PHPCollab 2.x / NetOffice 2.x - 'sendpassword.php' SQL Injection
CVE-2006-1495webappsphp
SQL injection vulnerability in general/sendpassword.php in (1) PHPCollab 2.4 and 2.5.rc3, and (2) NetOffice 2.5.3-pl1 an
23RISCO
abrir
ReferênciaVexDay Proof
PHP 4.4.6/5.2.1 - ext/gd Already Freed Resources Usage
CVE-2007-1582locallinux
The resource system in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allows context-dependent attackers to execute arb
23RISCO
abrir
ReferênciaVexDay Proof
ezpack 4.2b2 - Cross-Site Scripting / SQL Injection
CVE-2009-0104webappsphp
SQL injection vulnerability in index.php in EZpack 4.2b2 allows remote attackers to execute arbitrary SQL commands via t
23RISCO
abrir
ReferênciaVexDay Proof
MyBlog: PHP and MySQL Blog/CMS software - Remote File Inclusion
CVE-2007-1968webappsphp
PHP remote file inclusion vulnerability in games.php in Sam Crew MyBlog, possibly 1.0 through 1.6, allows remote attacke
23RISCO
abrir
ReferênciaVexDay Proof
PHPEasyData 1.5.4 - 'cat_id' SQL Injection
CVE-2008-2113webappsphp
SQL injection vulnerability in annuaire.php in PHPEasyData 1.5.4 allows remote attackers to execute arbitrary SQL comman
23RISCO
abrir
ReferênciaVexDay Proof
ezpack 4.2b2 - Cross-Site Scripting / SQL Injection
CVE-2009-0105webappsphp
Cross-site scripting (XSS) vulnerability in index.php in EZpack 4.2b2 allows remote attackers to inject arbitrary web sc
23RISCO
abrir
ReferênciaVexDay Proof
Asterisk 1.2.x - SIP channel driver / in pedantic mode Remote Crash
CVE-2008-2119dosmultiple
Asterisk Open Source 1.0.x and 1.2.x before 1.2.29 and Business Edition A.x.x and B.x.x before B.2.5.3, when pedantic pa
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component xstandard editor 1.5.8 - Local Directory Traversal
CVE-2009-0113webappsphp
Directory traversal vulnerability in attachmentlibrary.php in the XStandard component for Joomla! 1.5.8 and earlier allo
23RISCO
abrir
ReferênciaVexDay Proof
PHPLibrary 1.5.3 - 'grid3.lib.php' Remote File Inclusion
CVE-2006-5471webappsphp
PHP remote file inclusion vulnerability in example/lib/grid3.lib.php in Softerra PHP Developer Library 1.5.3 and earlier
23RISCO
abrir
ReferênciaVexDay Proof
FipsCMS 2.1 - 'print.asp' SQL Injection
CVE-2008-2124webappsasp
SQL injection vulnerability in modules/print.asp in fipsASP fipsCMS allows remote attackers to execute arbitrary SQL com
23RISCO
abrir
ReferênciaVexDay Proof
Devalcms 1.4a - Cross-Site Scripting / Remote Code Execution
CVE-2008-6982webappsphp
Cross-site scripting (XSS) vulnerability in index.php in devalcms 1.4a allows remote attackers to inject arbitrary web s
38RISCO
abrir
ReferênciaVexDay Proof
AAA EasyGrid ActiveX 3.51 - Remote File Overwrite
CVE-2009-0134remotewindows
Insecure method vulnerability in the EasyGrid.SGCtrl.32 ActiveX control in EasyGrid.ocx 1.0.0.1 in AAA EasyGrid ActiveX
23RISCO
abrir
ReferênciaVexDay Proof
WinAsm Studio 5.1.5.0 - Local Heap Overflow (PoC)
CVE-2009-1040doswindows
Buffer overflow in WinAsm Studio 5.1.5.0 allows user-assisted remote attackers to execute arbitrary code via a crafted p
23RISCO
abrir
ReferênciaVexDay Proof
SubEdit Player build 4066 - subtitle Buffer Overflow (PoC)
CVE-2008-1973doswindows
Heap-based buffer overflow in SubEdit Player build 4056 and 4066 allows remote attackers to cause a denial of service (c
23RISCO
abrir
anteriorpágina 125 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.