Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.095exploits catalogados
36.945CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
PHP Site Lock 2.0 - Insecure Cookie Handling
CVE-2009-1587webappsphp
index.php in PHP Site Lock 2.0 allows remote attackers to bypass authentication and obtain administrative access by sett
23RISCO
abrir
ReferênciaVexDay Proof
DM FileManager 3.9.2 - Insecure Cookie Handling
CVE-2009-2025webappsphp
admin/login.php in DM FileManager 3.9.2 allows remote attackers to bypass authentication and gain administrative access
23RISCO
abrir
ReferênciaVexDay Proof
SimpleBlog 2.0 - 'comments.asp' SQL Injection (1)
CVE-2006-4300webappsasp
SQL injection vulnerability in comments.asp in SimpleBlog 2.0 and earlier allows remote attackers to execute arbitrary S
23RISCO
abrir
ReferênciaVexDay Proof
Barman 0.0.1r3 - 'Interface.php' Remote File Inclusion
CVE-2006-6611webappsphp
PHP remote file inclusion vulnerability in interface.php in Barman 0.0.1r3 allows remote attackers to execute arbitrary
23RISCO
abrir
ReferênciaVexDay Proof
Blog PixelMotion - 'sauvBase.php' Arbitrary Database Backup
CVE-2008-1868webappsphp
admin/sauvBase.php in Blog Pixel Motion (aka Blog PixelMotion) does not require authentication, which allows remote atta
23RISCO
abrir
ReferênciaVexDay Proof
realm CMS 2.3 - Multiple Vulnerabilities
CVE-2008-2681webappsphp
Realm CMS 2.3 and earlier allows remote attackers to obtain sensitive information via a direct request to _db/compact.as
23RISCO
abrir
ReferênciaVexDay Proof
Thickbox Gallery 2.0 - 'Admins.php' Admin Data Disclosure
CVE-2008-3859webappsphp
Davlin Thickbox Gallery 2 allows remote attackers to obtain the administrative username and MD5 password hash via a dire
23RISCO
abrir
ReferênciaVexDay Proof
nightfall personal diary 1.0 - Cross-Site Scripting / File Disclosure
CVE-2008-5592webappsphp
Nightfall Personal Diary 1.0 stores sensitive information under the web root with insufficient access control, which all
23RISCO
abrir
ReferênciaVexDay Proof
Techno Dreams Articles & Papers 2.0 - SQL Injection
CVE-2006-4891webappsasp
SQL injection vulnerability in ArticlesTableview.asp in Techno Dreams Articles & Papers Package 2.0 and earlier allows r
23RISCO
abrir
ReferênciaVexDay Proof
Flatnuke 3 - Remote Command Execution / Privilege Escalation
CVE-2007-5774webappsphp
index.php in the File Manager module in Flatnuke 3 allows remote attackers to obtain sensitive information via an invali
23RISCO
abrir
ReferênciaVexDay Proof
OwnRS blog beta3 - SQL Injection / Cross-Site Scripting
CVE-2008-2856webappsphp
SQL injection vulnerability in clanek.php in OwnRS Beta 3 allows remote attackers to execute arbitrary SQL commands via
23RISCO
abrir
ReferênciaVexDay Proof
mini-pub 0.3 - Local Directory Traversal / File Disclosure
CVE-2008-5883webappsphp
Absolute path traversal vulnerability in front-end/dir.php in mini-pub 0.3 and earlier allows remote attackers to list a
23RISCO
abrir
ReferênciaVexDay Proof
nuseo PHP enterprise 1.6 - Remote File Inclusion
CVE-2007-5409webappsphp
PHP remote file inclusion vulnerability in admin/nuseo_admin_d.php in NuSEO PHP Enterprise 1.6 (NuSEO.PHP), when registe
23RISCO
abrir
ReferênciaVexDay Proof
PHP Live Helper 2.0.1 - Multiple Vulnerabilities
CVE-2008-3763webappsphp
Variable overwrite vulnerability in libsecure.php in Turnkey PHP Live Helper 2.0.1 and earlier, when register_globals is
23RISCO
abrir
ReferênciaVexDay Proof
TlGuestBook 1.2 - Insecure Cookie Handling
CVE-2008-5065webappsphp
TlGuestBook 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the tlGuestBo
23RISCO
abrir
ReferênciaVexDay Proof
Enthusiast 3.1.4 - 'show_joined.php' Remote File Inclusion
CVE-2008-5792webappsphp
PHP remote file inclusion vulnerability in show_joined.php in Indiscripts Enthusiast 3.1.4, and possibly earlier, allows
23RISCO
abrir
ReferênciaVexDay Proof
TurnkeyForms Local Classifieds - Authentication Bypass
CVE-2008-6302webappsphp
TurnkeyForms Local Classifieds allows remote attackers to bypass authentication and gain administrative access via a dir
23RISCO
abrir
ReferênciaVexDay Proof
AJ Auction - Authentication Bypass
CVE-2008-6965webappsphp
AJ Square AJ Auction OOPD, Pro Platinum Skin #1, Pro Platinum Skin #2, and Web 2.0 send a redirect but do not exit when
23RISCO
abrir
ReferênciaVexDay Proof
IceBB 1.0-rc5 - Remote Code Execution
CVE-2007-1726webappsphp
Unrestricted file upload vulnerability in index.php in IceBB 1.0-rc5 allows remote authenticated users to upload arbitra
23RISCO
abrir
ReferênciaVexDay Proof
Crux Gallery 1.32 - Insecure Cookie Handling
CVE-2008-4484webappsphp
main.php in Crux Gallery 1.32 and earlier allows remote attackers to gain administrative access by setting the name para
23RISCO
abrir
ReferênciaVexDay Proof
SG Real Estate Portal 2.0 - Insecure Cookie Handling
CVE-2008-6009webappsphp
SG Real Estate Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the
23RISCO
abrir
ReferênciaVexDay Proof
A+ PHP Scripts - Nms Insecure Cookie Handling
CVE-2008-6667webappsphp
A+ PHP Scripts News Management System (NMS) allows remote attackers to bypass authentication and gain administrator priv
23RISCO
abrir
ReferênciaVexDay Proof
FretsWeb 1.2 - 'name' Blind SQL Injection
CVE-2009-2113webappsphp
Multiple SQL injection vulnerabilities in FretsWeb 1.2 allow remote attackers to execute arbitrary SQL commands via the
23RISCO
abrir
ReferênciaVexDay Proof
Vivvo Article Manager 3.2 - 'id' SQL Injection
CVE-2006-4715webappsphp
SQL injection vulnerability in pdf_version.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.2 and earl
23RISCO
abrir
ReferênciaVexDay Proof
Softbiz Recipes Portal Script - SQL Injection
CVE-2007-5449webappsphp
SQL injection vulnerability in searchresult.php in Softbiz Recipes Portal Script allows remote attackers to execute arbi
23RISCO
abrir
ReferênciaVexDay Proof
MyPicGallery 1.0 - Arbitrary Add Admin
CVE-2008-2347webappsphp
MyPicGallery 1.0 allows remote attackers to bypass application authentication and gain administrative access by setting
23RISCO
abrir
ReferênciaVexDay Proof
odars CMS 1.0.2 - Remote File Inclusion
CVE-2008-2885webappsphp
PHP remote file inclusion vulnerability in src/browser/resource/categories/resource_categories_view.php in Open Digital
23RISCO
abrir
ReferênciaVexDay Proof
Stash 1.0.3 - Insecure Cookie Handling
CVE-2008-4081webappsphp
admin/login.php in Stash 1.0.3 allows remote attackers to bypass authentication and gain administrative access by settin
23RISCO
abrir
ReferênciaVexDay Proof
Atomic Photo Album 1.1.0pre4 - Insecure Cookie Handling
CVE-2008-4714webappsphp
Atomic Photo Album 1.1.0 pre4 does not properly handle the apa_cookie_login and apa_cookie_password cookies, which proba
23RISCO
abrir
ReferênciaVexDay Proof
Docebo 3.5.0.3 - 'lib.regset.php' Command Execution
CVE-2008-7154webappsphp
Docebo 3.5.0.3 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) class/cla
23RISCO
abrir
anteriorpágina 140 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.