Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.095exploits catalogados
36.945CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
360 Web Manager 3.0 - 'IDFM' SQL Injection
CVE-2008-0430webappsphp
SQL injection vulnerability in form.php in 360 Web Manager 3.0 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
ReferênciaVexDay Proof
phpMyClub 0.0.1 - 'page_courante' Local File Inclusion
CVE-2008-0501webappsphp
Directory traversal vulnerability in phpMyClub 0.0.1 allows remote attackers to include and execute arbitrary local file
23RISCO
abrir
ReferênciaVexDay Proof
Mambo Component 'com_glossary' 2.0 - 'catid' SQL Injection
CVE-2008-0514webappsphp
SQL injection vulnerability in index.php in the Glossary (com_glossary) 2.0 component for Mambo and Joomla! allows remot
23RISCO
abrir
ReferênciaVexDay Proof
Mambo Component Recipes 1.00 - 'id' SQL Injection
CVE-2008-0518webappsphp
SQL injection vulnerability in index.php in the Recipes (com_recipes) 1.00 component for Mambo and Joomla! allows remote
23RISCO
abrir
ReferênciaVexDay Proof
Mambo Component jokes 1.0 - 'cat' SQL Injection
CVE-2008-0519webappsphp
SQL injection vulnerability in index.php in the Atapin Jokes (com_jokes) 1.0 component for Mambo and Joomla! allows remo
23RISCO
abrir
ReferênciaVexDay Proof
Simple Forum 3.2 - File Disclosure / Cross-Site Scripting
CVE-2008-0541webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in forum.php in Gerd Tentler Simple Forum 3.2 allow remote attackers
23RISCO
abrir
ReferênciaVexDay Proof
Debian OpenSSH - (Authenticated) Remote SELinux Privilege Escalation
CVE-2008-3234remotelinux
sshd in OpenSSH 4 on Debian GNU/Linux, and the 20070303 OpenSSH snapshot, allows remote authenticated users to obtain ac
23RISCO
abrir
ReferênciaVexDay Proof
Eurologon CMS - Multiple SQL Injections
CVE-2007-6164webappsphp
Multiple SQL injection vulnerabilities in Eurologon CMS allow remote attackers to execute arbitrary SQL commands via the
23RISCO
abrir
ReferênciaVexDay Proof
SafeNet 10.4.0.12 - 'IPSecDrv.sys' Local kernel Ring0 SYSTEM
CVE-2008-0573localwindows
IPSecDrv.sys 10.4.0.12 in SafeNET HighAssurance Remote and SoftRemote allows local users to gain privileges via a crafte
23RISCO
abrir
ReferênciaVexDay Proof
All Club CMS 0.0.2 - 'index.php' SQL Injection
CVE-2008-0601webappsphp
SQL injection vulnerability in index.php in All Club CMS (ACCMS) 0.0.1f and earlier allows remote attackers to execute a
23RISCO
abrir
ReferênciaVexDay Proof
All Club CMS 0.0.1f - 'index.php' Local File Inclusion
CVE-2008-0602webappsphp
Directory traversal vulnerability in index.php in All Club CMS (ACCMS) 0.0.1f and earlier allows remote attackers to inc
23RISCO
abrir
ReferênciaVexDay Proof
Mambo Component 'com_awesom' 0.3.2 - 'listid' SQL Injection
CVE-2008-0603webappsphp
SQL injection vulnerability in index.php in the amazOOP Awesom! (com_awesom) 0.3.2component for Mambo and Joomla! allows
23RISCO
abrir
ReferênciaVexDay Proof
bilboblog 2.1 - Multiple Vulnerabilities
CVE-2008-3303webappsphp
admin/login.php in BilboBlog 0.2.1, when register_globals is enabled, allows remote attackers to bypass authentication a
23RISCO
abrir
ReferênciaVexDay Proof
Yahoo! Music JukeBox 2.2 - 'AddButton()' ActiveX Remote Buffer Overflow
CVE-2008-0624remotewindows
Buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! JukeBox 2.2.2.56 allows remote attackers to
23RISCO
abrir
ReferênciaVexDay Proof
Astanda Directory Project 1.2 - 'link_id' SQL Injection
CVE-2008-0649webappsphp
SQL injection vulnerability in detail.php in Astanda Directory Project (ADP) 1.2 and 1.3 allows remote attackers to exec
23RISCO
abrir
ReferênciaVexDay Proof
PhotoKorn Gallery 1.543 - 'pic' SQL Injection
CVE-2008-0614webappsphp
SQL injection vulnerability in index.php in Photokorn Gallery 1.543 allows remote attackers to execute arbitrary SQL com
23RISCO
abrir
ReferênciaVexDay Proof
NERO Media Player 1.4.0.35b - '.m3u' File Buffer Overflow (PoC)
CVE-2008-0619doswindows
Buffer overflow in NeroMediaPlayer.exe in Nero Media Player 1.4.0.35 and earlier allows remote attackers to execute arbi
28RISCO
abrir
ReferênciaVexDay Proof
SapLPD 6.28 (Windows x86) - Remote Buffer Overflow
CVE-2008-0621remotewindows_x86
Buffer overflow in SAPLPD 6.28 and earlier included in SAP GUI 7.10 and SAPSprint before 1018 allows remote attackers to
60RISCO
abrir
ReferênciaVexDay Proof
MySpace Uploader - 'MySpaceUploader.ocx 1.0.0.4' Remote Buffer Overflow
CVE-2008-0659remotewindows
Stack-based buffer overflow in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.5.70 and earlier, as used i
35RISCO
abrir
ReferênciaVexDay Proof
MyBulletinBoard (MyBB) 1.2.11 - 'private.php' SQL Injection (1)
CVE-2008-0787webappsphp
SQL injection vulnerability in inc/datahandlers/pm.php in MyBB before 1.2.12 allows remote authenticated users to execut
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component xfaq 1.2 - 'aid' SQL Injection
CVE-2008-0795webappsphp
SQL injection vulnerability in index.php in the MGFi XfaQ (com_xfaq) 1.2 component for Mambo and Joomla! allows remote a
23RISCO
abrir
ReferênciaVexDay Proof
nuBoard 0.5 - 'ssid' SQL Injection
CVE-2008-0796webappsphp
SQL injection vulnerability in threads.php in Nuboard 0.5 allows remote attackers to execute arbitrary SQL commands via
23RISCO
abrir
ReferênciaVexDay Proof
LookStrike Lan Manager 0.9 - Local/Remote File Inclusion
CVE-2008-0803webappsphp
Multiple PHP remote file inclusion vulnerabilities in LookStrike Lan Manager 0.9 allow remote attackers to execute arbit
35RISCO
abrir
ReferênciaVexDay Proof
AuraCMS 1.62 - Multiple SQL Injections
CVE-2008-0811webappsphp
Multiple SQL injection vulnerabilities in AuraCMS 1.62 allow remote attackers to execute arbitrary SQL commands via (1)
23RISCO
abrir
ReferênciaVexDay Proof
XPWeb 3.3.2 - 'url' Remote File Disclosure
CVE-2008-0813webappsphp
Directory traversal vulnerability in Download.php in XPWeb 3.0.1, 3.3.2, and possibly other versions, allows remote atta
23RISCO
abrir
ReferênciaVexDay Proof
TRUC 0.11.0 - 'download.php' Remote File Disclosure
CVE-2008-0814webappsphp
Directory traversal vulnerability in download.php in Tracking Requirements & Use Cases (TRUC) 0.11.0 allows remote attac
23RISCO
abrir
ReferênciaVexDay Proof
Plogger 3.0 - SQL Injection
CVE-2008-3563webappsphp
Multiple SQL injection vulnerabilities in Plogger 3.0 and earlier allow remote attackers to execute arbitrary SQL comman
23RISCO
abrir
ReferênciaVexDay Proof
PHP-Nuke Modules Okul 1.0 - 'okulid' SQL Injection
CVE-2008-0881webappsphp
SQL injection vulnerability in modules.php in the Okul 1.0 module for PHP-Nuke allows remote attackers to execute arbitr
23RISCO
abrir
ReferênciaVexDay Proof
Globsy 1.0 - 'file' Remote File Disclosure
CVE-2008-0905webappsphp
Directory traversal vulnerability in globsy_edit.php in Globsy 1.0 allows remote attackers to read arbitrary files via a
23RISCO
abrir
ReferênciaVexDay Proof
PHP-Nuke Module Docum - 'artid' SQL Injection
CVE-2008-0906webappsphp
SQL injection vulnerability in the Docum module in PHP-Nuke allows remote attackers to execute arbitrary SQL commands vi
23RISCO
abrir
anteriorpágina 126 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.