Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.095exploits catalogados
36.945CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
asg-sentry 7.0.0 - Multiple Vulnerabilities
CVE-2008-1322dosmultiple
The File Check Utility (fcheck.exe) in ASG-Sentry Network Manager 7.0.0 and earlier allows remote attackers to cause a d
23RISCO
abrir
ReferênciaVexDay Proof
WEBBDOMAIN Petition 1.02/2.0/3.0 - Authentication Bypass
CVE-2008-6624webappsphp
SQL injection vulnerability in getin.php in WEBBDOMAIN Petition 1.02, 2.0, and 3.0 allows remote attackers to execute ar
23RISCO
abrir
ReferênciaVexDay Proof
WEBBDOMAIN Polls 1.01 - Authentication Bypass
CVE-2008-6625webappsphp
SQL injection vulnerability in getin.php in WEBBDOMAIN Polls (aka Poll) 1.0 and 1.01 allows remote attackers to execute
23RISCO
abrir
ReferênciaVexDay Proof
ashNews 0.83 - 'pathtoashnews' Remote File Inclusion
CVE-2003-1292webappsphp
PHP remote file include vulnerability in Derek Ashauer ashNews 0.83 allows remote attackers to include and execute arbit
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component LMO 1.0b2 - Remote File Inclusion
CVE-2006-3970webappsphp
PHP remote file inclusion vulnerability in lmo.php in the LMO Component (com_lmo) 1.0b2 and earlier for Joomla! allows r
23RISCO
abrir
ReferênciaVexDay Proof
UNAK-CMS 1.5 - 'dirroot' Remote File Inclusion
CVE-2006-4890webappsphp
Multiple PHP remote file inclusion vulnerabilities in UNAK-CMS 1.5 and earlier allow remote attackers to execute arbitra
23RISCO
abrir
ReferênciaVexDay Proof
CWB PRO 1.5 - 'INCLUDE_PATH' Remote File Inclusion
CVE-2007-1809webappsphp
Multiple PHP remote file inclusion vulnerabilities in GraFX Company WebSite Builder (CWB) PRO 1.5 allow remote attackers
23RISCO
abrir
ReferênciaVexDay Proof
XnView 1.92.1 - 'FontName' Slideshow Buffer Overflow
CVE-2008-0069localwindows
Stack-based buffer overflow in XnView 1.92 and 1.92.1 allows user-assisted remote attackers to execute arbitrary code vi
23RISCO
abrir
ReferênciaVexDay Proof
eXV2 Module MyAnnonces - 'lid' SQL Injection
CVE-2008-1406webappsphp
SQL injection vulnerability in annonces-p-f.php in the MyAnnonces 1.8 module for eXV2 allows remote attackers to execute
23RISCO
abrir
ReferênciaVexDay Proof
Bitweaver 1.3 - 'tmpImagePath' Attachment mod_mime
CVE-2006-3102webappsphp
Race condition in articles/BitArticle.php in Bitweaver 1.3, when run on Apache with the mod_mime extension, allows remot
23RISCO
abrir
ReferênciaVexDay Proof
FluentCMS - 'view.php' SQL Injection
CVE-2008-6642webappsphp
SQL injection vulnerability in view.php in DotContent FluentCMS 4.x allows remote attackers to execute arbitrary SQL com
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component Alberghi 2.1.3 - 'id' SQL Injection
CVE-2008-1459webappsphp
SQL injection vulnerability in the Alberghi (com_alberghi) 2.1.3 and earlier component for Mambo and Joomla! allows remo
23RISCO
abrir
ReferênciaVexDay Proof
CA BrightStor ARCserve Backup r11.5 - ActiveX Remote Buffer Overflow
CVE-2008-1472remotewindows
Stack-based buffer overflow in the ListCtrl ActiveX Control (ListCtrl.ocx), as used in multiple CA products including Br
50RISCO
abrir
ReferênciaVexDay Proof
Simple Machines Forum (SMF) 1.1.6 - Code Execution
CVE-2008-6657webappsphp
Cross-site request forgery (CSRF) vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 be
23RISCO
abrir
ReferênciaVexDay Proof
Jasmine CMS 1.0 - SQL Injection / Remote Code Execution
CVE-2007-3313webappsphp
Multiple SQL injection vulnerabilities in Jasmine CMS 1.0 allow remote attackers to execute arbitrary SQL commands via (
23RISCO
abrir
ReferênciaVexDay Proof
BitDefender Online Scanner 8 - ActiveX Heap Overflow
CVE-2007-6189remotewindows
A certain ActiveX control in (1) OScan8.ocx and (2) Oscan81.ocx in BitDefender Online Anti-Virus Scanner 8.0 allows remo
23RISCO
abrir
ReferênciaVexDay Proof
Yahoo! JukeBox MediaGrid - 'AddBitmap()' ActiveX Buffer Overflow
CVE-2008-0625remotewindows
Buffer overflow in the MediaGrid ActiveX control (mediagrid.dll) in Yahoo! Music Jukebox 2.2.2.56 allows remote attacker
23RISCO
abrir
ReferênciaVexDay Proof
Maian Weblog 4.0 - Insecure Cookie Handling
CVE-2008-3318webappsphp
admin/index.php in Maian Weblog 4.0 and earlier allows remote attackers to bypass authentication and gain administrative
23RISCO
abrir
ReferênciaVexDay Proof
DELTAScripts PHP Links 1.3 - Authentication Bypass
CVE-2008-6720webappsphp
SQL injection vulnerability in admin/adm_login.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component rekry 1.0.0 - 'op_id' SQL Injection
CVE-2008-1535webappsphp
SQL injection vulnerability in the Matti Kiviharju rekry (aka com_rekry or rekry!Joom) 1.0.0 component for Joomla! allow
23RISCO
abrir
ReferênciaVexDay Proof
PHPmotion 2.1 - Cross-Site Request Forgery
CVE-2008-6729webappsphp
Multiple cross-site request forgery (CSRF) vulnerabilities in password.php in PHPmotion 2.1 and earlier allow remote att
23RISCO
abrir
ReferênciaVexDay Proof
RunCMS 1.5.2 - 'debug_show.php' SQL Injection
CVE-2007-2539webappsphp
The show_files function in RunCms 1.5.2 and earlier allows remote attackers to obtain sensitive information (file existe
23RISCO
abrir
ReferênciaVexDay Proof
Mini Web Calendar 1.2 - File Disclosure / Cross-Site Scripting
CVE-2008-5062webappsphp
Directory traversal vulnerability in php/cal_pdf.php in Mini Web Calendar (mwcal) 1.2 allows remote attackers to read ar
23RISCO
abrir
ReferênciaVexDay Proof
BlogPHP 2.0 - Privilege Escalation / SQL Injection
CVE-2008-6745webappsphp
index.php in BlogPHP 2.0 allows remote attackers to gain administrator privileges via a crafted email parameter in a reg
23RISCO
abrir
ReferênciaVexDay Proof
Downline Goldmine Builder - SQL Injection
CVE-2008-4178webappsphp
SQL injection vulnerability in tr.php in DownlineGoldmine Special Category Addon, Downline Builder Pro, New Addon, and D
23RISCO
abrir
ReferênciaVexDay Proof
Megacubo 5.0.7 - 'mega://' Remote 'eval()' Injection
CVE-2008-6748remotewindows
Eval injection vulnerability in Megacubo 5.0.7 allows remote attackers to inject and execute arbitrary PHP code via the
23RISCO
abrir
ReferênciaVexDay Proof
Shadows Rising RPG 0.0.5b - Remote File Inclusion
CVE-2006-4329webappsphp
Multiple PHP remote file inclusion vulnerabilities in Shadows Rising RPG (Pre-Alpha) 0.0.5b and earlier allow remote att
23RISCO
abrir
ReferênciaVexDay Proof
SendStudio 2004.14 - 'ROOTDIR' Remote File Inclusion
CVE-2007-1060webappsphp
Multiple PHP remote file inclusion vulnerabilities in Interspire SendStudio 2004.14 and earlier, when register_globals a
23RISCO
abrir
ReferênciaVexDay Proof
Imageview 5.3 - 'fileview.php?album' Local File Inclusion
CVE-2007-2425webappsphp
Directory traversal vulnerability in fileview.php in Imageview 5.3 allows remote attackers to read arbitrary files via a
23RISCO
abrir
ReferênciaVexDay Proof
Autodesk DWF Viewer Control / LiveUpdate Module - Remote Code Execution
CVE-2008-4472remotewindows
The UpdateEngine class in the LiveUpdate ActiveX control (LiveUpdate16.DLL 17.2.56), as used in Revit Architecture 2009
23RISCO
abrir
anteriorpágina 131 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.