Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.095exploits catalogados
36.945CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
Nukedit 4.9.x - Remote Create Admin
CVE-2008-5582webappsphp
SQL injection vulnerability in utilities/login.asp in Nukedit 4.9.x, and possibly earlier, allows remote attackers to ex
23RISCO
abrir
ReferênciaVexDay Proof
lcxbbportal 0.1 alpha 2 - Remote File Inclusion
CVE-2008-5585webappsphp
Multiple PHP remote file inclusion vulnerabilities in lcxBBportal 0.1 Alpha 2 allow remote attackers to execute arbitrar
23RISCO
abrir
ReferênciaVexDay Proof
Product Sale Framework 0.1b - SQL Injection
CVE-2008-5590webappsphp
SQL injection vulnerability in customer.forumtopic.php in Kalptaru Infotech Product Sale Framework 0.1 beta allows remot
23RISCO
abrir
ReferênciaVexDay Proof
nightfall personal diary 1.0 - Cross-Site Scripting / File Disclosure
CVE-2008-5591webappsphp
Cross-site scripting (XSS) vulnerability in login.asp in Nightfall Personal Diary 1.0 allows remote attackers to inject
23RISCO
abrir
ReferênciaVexDay Proof
eXchange POP3 5.0.050203 - RPCT TO Remote Buffer Overflow
CVE-2006-0537remotewindows
Buffer overflow in the POP3 server in Kinesphere Corporation eXchange before 5.0.060125 allows remote attackers to execu
35RISCO
abrir
ReferênciaVexDay Proof
BM Classifieds 20080409 - Multiple SQL Injections
CVE-2008-1272webappsphp
Multiple SQL injection vulnerabilities in BM Classifieds 20080309 and earlier allow remote attackers to execute arbitrar
23RISCO
abrir
ReferênciaVexDay Proof
jspwiki 2.4.104/2.5.139 - Multiple Vulnerabilities
CVE-2008-1229webappsjsp
Cross-site scripting (XSS) vulnerability in Edit.jsp in JSPWiki 2.4.104 and 2.5.139 allows remote attackers to inject ar
23RISCO
abrir
ReferênciaVexDay Proof
Active Time Billing 3.2 - Authentication Bypass
CVE-2008-5632webappsphp
SQL injection vulnerability in Account.asp in Active Time Billing 3.2 allows remote attackers to execute arbitrary SQL c
23RISCO
abrir
ReferênciaVexDay Proof
Lito Lite CMS - 'cid' SQL Injection
CVE-2008-5636webappsphp
SQL injection vulnerability in cate.php in Lito Lite CMS, when magic_quotes_gpc is disabled, allows remote attackers to
23RISCO
abrir
ReferênciaVexDay Proof
CMS Made Simple 1.4.1 - Local File Inclusion
CVE-2008-5642webappsphp
Directory traversal vulnerability in admin/login.php in CMS Made Simple 1.4.1 allows remote attackers to read arbitrary
23RISCO
abrir
ReferênciaVexDay Proof
phpBB Mod FileBase 2.0 - 'id' SQL Injection
CVE-2008-1305webappsphp
SQL injection vulnerability in filebase.php in the Filebase mod for phpBB allows remote attackers to execute arbitrary S
23RISCO
abrir
ReferênciaVexDay Proof
Apple QuickTime 7.2/7.3 (OSX/Windows) - RSTP Response Universal
CVE-2002-0252remotemultiple
Buffer overflow in Apple QuickTime Player 5.01 and 5.02 allows remote web servers to execute arbitrary code via a respon
28RISCO
abrir
ReferênciaVexDay Proof
PHP Ticket 0.71 - 'search.php' SQL Injection
CVE-2006-1481webappsphp
SQL injection vulnerability in search.php in PHP Ticket 0.71 allows remote authenticated users to execute arbitrary SQL
23RISCO
abrir
ReferênciaVexDay Proof
Crafty Syntax Image Gallery 3.1g - Remote Code Execution
CVE-2006-1668webappsphp
newimage.php in Eric Gerdes Crafty Syntax Image Gallery (CSIG) (aka PHP thumbnail Photo Gallery) 3.1g and earlier allows
23RISCO
abrir
ReferênciaVexDay Proof
Digital WebShop 1.128 - Multiple Remote File Inclusions
CVE-2006-4945webappsphp
Multiple PHP remote file inclusion vulnerabilities in Cardway (aka Frederic Boudaud) DigitalWebShop 1.128 and earlier al
23RISCO
abrir
ReferênciaVexDay Proof
BCWB 0.99 - 'ROOT_PATH' Remote File Inclusion
CVE-2006-4946webappsphp
PHP remote file inclusion vulnerability in include/startup.inc.php in CMSDevelopment Business Card Web Builder (BCWB) 0.
23RISCO
abrir
ReferênciaVexDay Proof
WSN Links Basic Edition - 'catid' SQL Injection
CVE-2007-3981webappsphp
SQL injection vulnerability in index.php in WSN Links Basic Edition allows remote attackers to execute arbitrary SQL com
23RISCO
abrir
ReferênciaVexDay Proof
Limbo CMS 1.0.4.2 - 'sql.php' Remote File Inclusion
CVE-2006-2142webappsphp
PHP remote file inclusion vulnerability in classes/adodbt/sql.php in Limbo CMS 1.04 and earlier allows remote attackers
23RISCO
abrir
ReferênciaVexDay Proof
Aardvark Topsites PHP 4.2.2 - 'lostpw.php' Remote File Inclusion
CVE-2006-2149webappsphp
PHP remote file inclusion vulnerability in sources/lostpw.php in Aardvark Topsites PHP 4.2.2 and earlier, when register_
23RISCO
abrir
ReferênciaVexDay Proof
Apple Mac OSX Safari 2.0.3 (417.9.2) - 'ROWSPAN' Denial of Service (PoC)
CVE-2006-2019dososx
Apple Mac OS X Safari 2.0.3, 1.3.1, and possibly other versions allows remote attackers to cause a denial of service (CP
23RISCO
abrir
ReferênciaVexDay Proof
ACal 2.2.6 - 'day.php' Remote File Inclusion
CVE-2006-2261webappsphp
PHP remote file inclusion vulnerability in day.php in ACal 2.2.6 allows remote attackers to execute arbitrary PHP code v
23RISCO
abrir
ReferênciaVexDay Proof
BlueShoes Framework 4.6 - Remote File Inclusion
CVE-2006-2864webappsphp
Multiple PHP remote file inclusion vulnerabilities in BlueShoes Framework 4.6 allow remote attackers to execute arbitrar
28RISCO
abrir
ReferênciaVexDay Proof
GeekLog 1.4.0sr3 - 'f(u)ckeditor' Remote Code Execution
CVE-2006-3362webappsphp
Unrestricted file upload vulnerability in connectors/php/connector.php in FCKeditor mcpuk file manager, as used in (1) G
23RISCO
abrir
ReferênciaVexDay Proof
WonderEdit Pro CMS (template_path) - Remote File Inclusion
CVE-2006-3422webappsphp
PHP remote file inclusion vulnerability in WonderEdit Pro CMS allows remote attackers to execute arbitrary PHP code via
23RISCO
abrir
ReferênciaVexDay Proof
BXCP 0.3.0.4 - 'where' SQL Injection
CVE-2006-3394webappsphp
SQL injection vulnerability in the files mod in index.php in BXCP 0.3.0.4 allows remote attackers to execute arbitrary S
23RISCO
abrir
ReferênciaVexDay Proof
Quake 3 Engine Client - 'CG_ServerCommand()' Remote Overflow
CVE-2006-3400doswindows
Stack-based buffer overflow in the CG_ServerCommand function in Quake 3 Engine as used by Soldier of Fortune 2 (SOF2MP)
23RISCO
abrir
ReferênciaVexDay Proof
PAPOO 3_RC3 - SQL Injection / Admin Credentials Disclosure
CVE-2006-3572webappsphp
SQL injection vulnerability in forumthread.php in Papoo 3 RC3 and earlier allows remote attackers to execute arbitrary S
23RISCO
abrir
ReferênciaVexDay Proof
Microsoft Internet Explorer - WebViewFolderIcon setSlice() Overflow (Metasploit) (1)
CVE-2006-3730HIGHremotewindows
Integer overflow in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service
68RISCO
abrir
ReferênciaVexDay Proof
Mambo Component com_videodb 0.3en - Remote File Inclusion
CVE-2006-3736webappsphp
PHP remote file inclusion vulnerability in core/videodb.class.xml.php in the VideoDB component for Mambo 0.3 and earlier
23RISCO
abrir
ReferênciaVexDay Proof
WinRAR 3.60 Beta 6 (French) - SFX Path Local Stack Overflow
CVE-2006-3912localwindows
Stack-based buffer overflow in the SFX module in WinRAR before 3.60 beta 8 has unspecified vectors and impact.
23RISCO
abrir
anteriorpágina 135 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.