Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.095exploits catalogados
36.945CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
CoolPlayer 2.17 - '.m3u' Local Stack Overflow
CVE-2006-6288localwindows
Multiple buffer overflows in Niek Albers CoolPlayer 216 and earlier allow remote attackers to execute arbitrary code via
23RISCO
abrir
ReferênciaVexDay Proof
torrentflux 2.2 - Arbitrary File Create/ Execute/Delete
CVE-2006-6330webappsphp
index.php for TorrentFlux 2.2 allows remote registered users to execute arbitrary commands via shell metacharacters in t
23RISCO
abrir
ReferênciaVexDay Proof
F-Prot AntiVirus 4.6.6 - CHM Heap Overflow (PoC)
CVE-2006-6293doslinux
Heap-based buffer overflow in FRISK Software F-Prot Antivirus before 4.6.7 allows user-assisted remote attackers to exec
28RISCO
abrir
ReferênciaVexDay Proof
RiteCMS 2.2.1 - Authenticated Remote Code Execution
CVE-2020-23934webappsphp
An issue was discovered in RiteCMS 2.2.1. An authenticated user can directly execute system commands by uploading a php
28RISCO
abrir
ReferênciaVexDay Proof
vBlog / C12 0.1 - 'cfgProgDir' Remote File Inclusion
CVE-2006-6586webappsphp
Multiple PHP remote file inclusion vulnerabilities in Vortex Blog (vBlog, aka C12) a0.1_nonfunc allow remote attackers t
23RISCO
abrir
ReferênciaVexDay Proof
TorrentFlux 2.2 - 'downloaddetails.php' Local File Disclosure
CVE-2006-6604webappsphp
Directory traversal vulnerability in downloaddetails.php in TorrentFlux 2.2 allows remote authenticated users to read ar
23RISCO
abrir
ReferênciaVexDay Proof
PHPMyCMS 0.3 - 'basic.inc.php' Remote File Inclusion
CVE-2006-6612webappsphp
PHP remote file inclusion vulnerability in basic.inc.php in PhpMyCms 0.3 allows remote attackers to execute arbitrary PH
23RISCO
abrir
ReferênciaVexDay Proof
PHPAlbum 0.4.1 Beta 6 - 'language.php' Local File Inclusion
CVE-2006-6613webappsphp
Directory traversal vulnerability in language.php in phpAlbum 0.4.1 Beta 6 and earlier, when magic_quotes_gpc is disable
23RISCO
abrir
ReferênciaVexDay Proof
AstonSoft DeepBurner 1.8.0 - '.dbr' File Parsing Buffer Overflow
CVE-2006-6665localwindows
Buffer overflow in Astonsoft DeepBurner Pro and Free 1.8.0 and earlier allows user-assisted remote attackers to execute
50RISCO
abrir
ReferênciaVexDay Proof
VerliAdmin 0.3 - 'index.php' Remote File Inclusion
CVE-2006-6666webappsphp
PHP remote file inclusion vulnerability in index.php in VerliAdmin 0.3 and earlier allows remote authenticated users to
23RISCO
abrir
ReferênciaVexDay Proof
TextSend 1.5 - '/config/sender.php' Remote File Inclusion
CVE-2006-6686webappsphp
PHP remote file inclusion vulnerability in sender.php in Carsen Klock TextSend 1.5 allows remote attackers to execute ar
23RISCO
abrir
ReferênciaVexDay Proof
Webmin 1.962 - 'Package Updates' Escape Bypass RCE (Metasploit)
CVE-2020-35606webappslinux
Arbitrary command execution can occur in Webmin through 1.962. Any user authorized for the Package Updates module can ex
28RISCO
abrir
ReferênciaVexDay Proof
Valdersoft Shopping Cart 3.0 - Multiple Remote File Inclusions
CVE-2006-6691webappsphp
Multiple PHP remote file inclusion vulnerabilities in Valdersoft Shopping Cart 3.0 and earlier allow remote attackers to
23RISCO
abrir
ReferênciaVexDay Proof
E-Uploader Pro 1.0 - Image Upload / Code Execution
CVE-2006-6694webappsphp
Directory traversal vulnerability in include/config.php in E-Uploader Pro 1.0 and earlier allows remote attackers to exe
23RISCO
abrir
ReferênciaVexDay Proof
Newxooper-PHP 0.9.1 - 'mapage.php' Remote File Inclusion
CVE-2006-6711webappsphp
PHP remote file inclusion vulnerability in compteur/mapage.php in Newxooper 0.9.1 allows remote attackers to execute arb
23RISCO
abrir
ReferênciaVexDay Proof
PowerClan 1.14a - 'footer.inc.php' Remote File Inclusion
CVE-2006-6715webappsphp
PHP remote file inclusion vulnerability in footer.inc.php in PowerClan 1.14a and earlier, when register_globals is enabl
23RISCO
abrir
ReferênciaVexDay Proof
Microsoft Windows - 'NetrWkstaUserEnum()' Remote Denial of Service
CVE-2006-6723doswindows
The Workstation service in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to cause a denial of service (m
35RISCO
abrir
ReferênciaVexDay Proof
BolinTech DreamFTP Server 1.0.2 - 'PORT' Remote Denial of Service
CVE-2006-6724doswindows
BolinTech Dream FTP Server 1.02 allows remote authenticated users, including anonymous users, to cause a denial of servi
23RISCO
abrir
ReferênciaVexDay Proof
cwmVote 1.0 - 'archive.php' Remote File Inclusion
CVE-2006-6732webappsphp
PHP remote file inclusion vulnerability in archive.php in cwmVote 1.0 allows remote attackers to execute arbitrary PHP c
23RISCO
abrir
ReferênciaVexDay Proof
Paristemi 0.8.3b - 'buycd.php' Remote File Inclusion
CVE-2006-6739webappsphp
PHP remote file inclusion vulnerability in buycd.php in Paristemi 0.8.3 allows remote attackers to execute arbitrary PHP
23RISCO
abrir
ReferênciaVexDay Proof
PHP-Update 2.7 - Multiple Vulnerabilities
CVE-2006-6880webappsphp
Multiple SQL injection vulnerabilities in code/guestadd.php in PHP-Update 2.7 and earlier allow remote attackers to exec
23RISCO
abrir
ReferênciaVexDay Proof
Macromedia Shockwave 10 'SwDir.dll' Internet Explorer 7 - Denial of Service
CVE-2006-6885doswindows
An ActiveX control in SwDir.dll in Macromedia Shockwave 10 allows remote attackers to cause a denial of service (Interne
23RISCO
abrir
ReferênciaVexDay Proof
Voodoo chat 1.0RC1b - 'users.dat' Password Disclosure
CVE-2006-6890webappsphp
Voodoo chat 1.0RC1b stores sensitive information under the web root with insufficient access control, which allows remot
23RISCO
abrir
ReferênciaVexDay Proof
Vz (Adp) Forum 2.0.3 - Remote Password Disclosure
CVE-2006-6891webappsphp
Vz (Adp) Forum 2.0.3 stores sensitive information under the web root with insufficient access control, which allows remo
23RISCO
abrir
ReferênciaVexDay Proof
Formbankserver 1.9 - 'Name' Remote Denial of Service
CVE-2006-6910doswindows
formbankcgi.exe in Fersch Formbankserver 1.9, when the PATH_INFO begins with Abfrage, allows remote attackers to cause a
23RISCO
abrir
ReferênciaVexDay Proof
Quote&Ordering System 1.0 - 'ordernum' Multiple Vulnerabilities
CVE-2006-6911webappsasp
SQL injection vulnerability in search.asp in Digitizing Quote And Ordering System 1.0 allows remote authenticated users
23RISCO
abrir
ReferênciaVexDay Proof
CA BrightStor ARCserve - 'tapeeng.exe' Remote Buffer Overflow
CVE-2006-6917remotewindows
Multiple buffer overflows in Computer Associates (CA) BrightStor ARCserve Backup R11.5 Server before SP2 allows remote a
28RISCO
abrir
ReferênciaVexDay Proof
uniForum 4 - 'wbsearch.aspx' SQL Injection
CVE-2007-0226webappsphp
SQL injection vulnerability in wbsearch.aspx in uniForum 4 and earlier allows remote attackers to execute arbitrary SQL
23RISCO
abrir
ReferênciaVexDay Proof
WordPress Core 2.0.6 - 'wp-trackback.php' SQL Injection
CVE-2007-0233webappsphp
wp-trackback.php in WordPress 2.0.6 and earlier does not properly unset variables when the input data includes a numeric
28RISCO
abrir
ReferênciaVexDay Proof
Apple Mac OSX 10.4.8 - AppleTalk 'ATPsndrsp()' Heap Buffer Overflow (PoC)
CVE-2007-0236dososx
Double free vulnerability in the _ATPsndrsp function in Apple Mac OS X 10.4.8, and possibly other versions, allows remot
28RISCO
abrir
anteriorpágina 129 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.