Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.095exploits catalogados
36.945CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
KnowledgeBuilder 2.2 - 'visEdit_root' Remote File Inclusion
CVE-2006-5919webappsphp
PHP remote file inclusion vulnerability in admin/e_data/visEdit_control.class.php in ActiveCampaign KnowledgeBuilder 2.2
23RISCO
abrir
ReferênciaVexDay Proof
addalink 4 Beta - Write Approved Links
CVE-2008-4146webappsphp
Addalink 1.0 beta 4 and earlier allows remote attackers to (1) approve web-site additions via a modified approved field
23RISCO
abrir
ReferênciaVexDay Proof
TurnkeyForms Web Hosting Directory - Multiple Vulnerabilities
CVE-2008-6939webappsphp
TurnkeyForms Web Hosting Directory allows remote attackers to bypass authentication and (1) gain administrative privileg
23RISCO
abrir
ReferênciaVexDay Proof
POP Peeper 3.4.0.0 - Date Remote Buffer Overflow
CVE-2009-1029remotewindows
Stack-based buffer overflow in POP Peeper 3.4.0.0 and earlier allows remote POP3 servers to execute arbitrary code via a
50RISCO
abrir
ReferênciaVexDay Proof
WordPress MU < 2.7 - 'HOST' HTTP Header Cross-Site Scripting
CVE-2009-1030webappsphp
Cross-site scripting (XSS) vulnerability in the choose_primary_blog function in wp-includes/wpmu-functions.php in WordPr
23RISCO
abrir
ReferênciaVexDay Proof
Confixx Pro 3.3.1 - 'saveserver.php' Remote File Inclusion
CVE-2007-4009webappsphp
PHP remote file inclusion vulnerability in admin/business_inc/saveserver.php in SWSoft Confixx Pro 2.0.12 through 3.3.1
23RISCO
abrir
ReferênciaVexDay Proof
WebPortal CMS 0.6-beta - Remote Password Change
CVE-2008-0141webappsphp
actions.php in WebPortal CMS 0.6-beta generates predictable passwords containing only the time of day, which makes it ea
23RISCO
abrir
ReferênciaVexDay Proof
Alt-N SecurityGateway 1.00-1.01 - Remote Stack Overflow
CVE-2008-4193remotewindows
Stack-based buffer overflow in SecurityGateway.dll in Alt-N Technologies SecurityGateway 1.0.1 allows remote attackers t
60RISCO
abrir
ReferênciaVexDay Proof
Scriptsez Easy Image Downloader - Local File Download
CVE-2008-6089webappsphp
Directory traversal vulnerability in main.php in ScriptsEz Easy Image Downloader allows remote attackers to read arbitra
23RISCO
abrir
ReferênciaVexDay Proof
FreeBSD 7.0/7.1 - 'ktimer' Local Privilege Escalation
CVE-2009-1041localfreebsd
The ktimer feature (sys/kern/kern_time.c) in FreeBSD 7.0, 7.1, and 7.2 allows local users to overwrite arbitrary kernel
23RISCO
abrir
ReferênciaVexDay Proof
ExBB Italiano 0.2 - exbb[home_path] Remote File Inclusion
CVE-2006-4488webappsphp
PHP remote file inclusion vulnerability in modules/userstop/userstop.php in ExBB Italia 0.2 and earlier, when register_g
23RISCO
abrir
ReferênciaVexDay Proof
WFTPD Explorer Pro 1.0 - Remote Heap Overflow (PoC)
CVE-2007-6473doswindows
Heap-based buffer overflow in Texas Imperial Software WFTPD Pro Explorer 1.0 allows remote FTP servers to execute arbitr
23RISCO
abrir
ReferênciaVexDay Proof
Stash 1.0.3 - Multiple SQL Injections
CVE-2008-4080webappsphp
SQL injection vulnerability in Stash 1.0.3, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitr
23RISCO
abrir
ReferênciaVexDay Proof
BS.Player 2.34 - '.bsl' Universal Overwrite (SEH)
CVE-2009-1068localwindows
Stack-based buffer overflow in BS.Player (bsplayer) 2.32 Build 975 Free and 2.34 Build 980 PRO and earlier allows remote
28RISCO
abrir
ReferênciaVexDay Proof
BS.Player 2.34 Build 980 - '.bsl' Local Buffer Overflow (SEH)
CVE-2009-1068localwindows
Stack-based buffer overflow in BS.Player (bsplayer) 2.32 Build 975 Free and 2.34 Build 980 PRO and earlier allows remote
28RISCO
abrir
ReferênciaVexDay Proof
ExBB 0.22 - Local/Remote File Inclusion
CVE-2008-1862webappsphp
ExBB Italia 0.22 and earlier only checks GET requests that use the QUERY_STRING for certain path manipulations, which al
23RISCO
abrir
ReferênciaVexDay Proof
Mantis Bug Tracker 1.1.1 - Code Execution / Cross-Site Scripting / Cross-Site Request Forgery
CVE-2008-2276webappsphp
Cross-site request forgery (CSRF) vulnerability in manage_user_create.php in Mantis 1.1.1 allows remote attackers to cre
23RISCO
abrir
ReferênciaVexDay Proof
Observer 0.3.2.1 - Multiple Remote Command Execution Vulnerabilities
CVE-2008-4318webappsphp
Observer 0.3.2.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the query
28RISCO
abrir
ReferênciaVexDay Proof
GeoVision LiveAudio - ActiveX Remote Freed-Memory Access
CVE-2009-1092remotewindows
Use-after-free vulnerability in the LIVEAUDIO.LiveAudioCtrl.1 ActiveX control in LIVEAU~1.OCX 7.0 for GeoVision DVR syst
23RISCO
abrir
ReferênciaVexDay Proof
BBClone 0.31 - 'selectlang.php' Remote File Inclusion
CVE-2007-0508webappsphp
PHP remote file inclusion vulnerability in lib/selectlang.php in BBClone 0.31 allows remote attackers to execute arbitra
23RISCO
abrir
ReferênciaVexDay Proof
AT Contenator 1.0 - 'Root_To_Script' Remote File Inclusion
CVE-2007-0983webappsphp
PHP remote file inclusion vulnerability in _admin/nav.php in AT Contenator 1.0 and earlier allows remote attackers to ex
23RISCO
abrir
ReferênciaVexDay Proof
IntelliTamper 2.07 - HTTP Header Remote Code Execution
CVE-2008-3361remotewindows
Stack-based buffer overflow in IntelliTamper 2.07 allows remote web sites to execute arbitrary code via a long HTTP Serv
23RISCO
abrir
ReferênciaVexDay Proof
cPanel 11.x - 'Fantastico' Local File Inclusion
CVE-2008-4181webappsphp
Directory traversal vulnerability in includes/xml.php in the Netenberg Fantastico De Luxe module before 2.10.4 r19 for c
23RISCO
abrir
ReferênciaVexDay Proof
Mozilla Firefox XSL - Parsing Remote Memory Corruption (PoC) (1)
CVE-2009-1169dosmultiple
The txMozillaXSLTProcessor::TransformToDoc function in Mozilla Firefox before 3.0.8 and SeaMonkey before 1.1.16 allows r
28RISCO
abrir
ReferênciaVexDay Proof
Moodle < 1.6.9/1.7.7/1.8.9/1.9.5 - File Disclosure
CVE-2009-1171webappsphp
The TeX filter in Moodle 1.6 before 1.6.9+, 1.7 before 1.7.7+, 1.8 before 1.8.9, and 1.9 before 1.9.5 allows user-assist
23RISCO
abrir
ReferênciaVexDay Proof
OWLLib 1.0 - 'OWLMemoryProperty.php' Remote File Inclusion
CVE-2006-6150webappsphp
PHP remote file inclusion vulnerability in memory/OWLMemoryProperty.php in OWLLib 1.0 allows remote attackers to execute
23RISCO
abrir
ReferênciaVexDay Proof
BrowseDialog Class - 'ccrpbds6.dll' Multiple Denial of Service Vulnerabilities
CVE-2007-1162doswindows
A certain ActiveX control in the Common Controls Replacement Project (CCRP) CCRP BrowseDialog Server (ccrpbds6.dll) allo
23RISCO
abrir
ReferênciaVexDay Proof
PHP-Nuke - 'iframe.php' Remote File Inclusion
CVE-2007-1626webappsphp
PHP remote file inclusion vulnerability in iframe.php in the iFrame Module for PHP-NUKE allows remote attackers to execu
23RISCO
abrir
ReferênciaVexDay Proof
Hot Links SQL-PHP 3 - 'report.php' Multiple Vulnerabilities
CVE-2008-4379webappsphp
Cross-site scripting (XSS) vulnerability in report.php in Mr. CGI Guy Hot Links SQL-PHP 3.0 and earlier allows remote at
23RISCO
abrir
ReferênciaVexDay Proof
ftp Admin 0.1.0 - Local File Inclusion / Cross-Site Scripting / Authentication Bypass
CVE-2007-6234webappsphp
index.php in FTP Admin 0.1.0 allows remote attackers to bypass authentication and obtain administrative access via a log
23RISCO
abrir
anteriorpágina 139 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.