Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.183exploits catalogados
37.028CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
Microsoft Windows - GDI+ '.ICO' Remote Division By Zero
CVE-2008-4327doswindows
gdiplus.dll in GDI+ in Microsoft Windows XP SP3 does not properly handle crafted .ico files, which allows remote attacke
28RISCO
abrir
ReferênciaVexDay Proof
phpBB Import Tools Mod 0.1.4 - Remote File Inclusion
CVE-2006-7147webappsphp
PHP remote file inclusion vulnerability in includes/functions_mod_user.php in phpBB Import Tools Mod 0.1.4 and earlier a
23RISCO
abrir
ReferênciaVexDay Proof
Flat Chat 2.0 - 'include online.txt' Remote Code Execution
CVE-2007-1394webappsphp
Direct static code injection vulnerability in startsession.php in Flat Chat 2.0 allows remote attackers to execute arbit
23RISCO
abrir
ReferênciaVexDay Proof
STPHPLibrary - 'STPHPLIB_DIR' Remote File Inclusion
CVE-2007-4737webappsphp
Multiple PHP remote file inclusion vulnerabilities in SpeedTech PHP Library (STPHPLibrary) 0.8.0 allow remote attackers
23RISCO
abrir
ReferênciaVexDay Proof
CenterIM 4.22.3 - Remote Command Execution
CVE-2008-1467remotelinux
CenterIM 4.22.3 and earlier allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters
23RISCO
abrir
ReferênciaVexDay Proof
KwsPHP - 'Upload' Remote Code Execution
CVE-2008-6201webappsphp
Directory traversal vulnerability in help.php in the eskuel module in KwsPHP 1.3.456, as available before 20080416, allo
23RISCO
abrir
ReferênciaVexDay Proof
mxBB Module calsnails 1.06 - 'mx_common.php' File Inclusion
CVE-2006-6065webappsphp
PHP remote file inclusion vulnerability in includes/mx_common.php in the CalSnails Module for MxBB Portal 1.06 allows re
23RISCO
abrir
ReferênciaVexDay Proof
zeeproperty 1.0 - Arbitrary File Upload / Cross-Site Scripting
CVE-2008-6914webappsphp
Unrestricted file upload vulnerability in viewprofile.php in Zeeways ZEEPROPERTY 1.0 allows remote authenticated users t
23RISCO
abrir
ReferênciaVexDay Proof
Camera Life 2.6.2b4 - Arbitrary File Upload
CVE-2008-4366webappsphp
Unrestricted file upload vulnerability in the image upload component in Camera Life 2.6.2b4 allows remote authenticated
23RISCO
abrir
ReferênciaVexDay Proof
PollMentor 2.0 - 'pollmentorres.asp?id' SQL Injection
CVE-2007-0984webappsasp
SQL injection vulnerability in admin_poll.asp in PollMentor 2.0 allows remote attackers to execute arbitrary SQL command
23RISCO
abrir
ReferênciaVexDay Proof
PHPCC 4.2 Beta - 'nickpage.php?npid' SQL Injection
CVE-2007-0985webappsphp
SQL injection vulnerability in nickpage.php in phpCC 4.2 beta and earlier allows remote attackers to execute arbitrary S
23RISCO
abrir
ReferênciaVexDay Proof
Apple Mac OSX xnu 1228.3.13 - 'zip-notify' Remote Kernel Overflow (PoC)
CVE-2009-1236dososx
Heap-based buffer overflow in the AppleTalk networking stack in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and e
23RISCO
abrir
ReferênciaVexDay Proof
Apple Mac OSX xnu 1228.x - 'vfssysctl' Local Kernel Denial of Service (PoC)
CVE-2009-1238dososx
Race condition in the HFS vfs sysctl interface in XNU 1228.8.20 and earlier on Apple Mac OS X 10.5.6 and earlier allows
23RISCO
abrir
ReferênciaVexDay Proof
acute control panel 1.0.0 - SQL Injection / Remote File Inclusion
CVE-2009-1247webappsphp
SQL injection vulnerability in login.php in Acute Control Panel 1.0.0 allows remote attackers to execute arbitrary SQL c
28RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component com_Projectfork 2.0.10 - Local File Inclusion
CVE-2009-2100webappsphp
Directory traversal vulnerability in the JoomlaPraise Projectfork (com_projectfork) component 2.0.10 for Joomla! allows
38RISCO
abrir
ReferênciaVexDay Proof
Hitweb 4.2.1 - 'REP_INC' Remote File Inclusion
CVE-2006-4113webappsphp
PHP remote file inclusion vulnerability in genpage-cgi.php in Brian Fraval hitweb 4.2 and possibly earlier versions allo
23RISCO
abrir
ReferênciaVexDay Proof
phpBB Journals System Mod 1.0.2 RC2 - Remote File Inclusion
CVE-2006-5306webappsphp
Multiple PHP remote file inclusion vulnerabilities in the Journals System module 1.0.2 (RC2) and earlier for phpBB allow
23RISCO
abrir
ReferênciaVexDay Proof
Chilkat Mail ActiveX 7.8 - 'ChilkatCert.dll' Insecure Method
CVE-2008-4584remotewindows
Insecure method vulnerability in Chilkat Mail 7.8 ActiveX control (ChilkatCert.dll) allows remote attackers to overwrite
23RISCO
abrir
ReferênciaVexDay Proof
PHP 5.2.3 - 'bz2 com_print_typeinfo()' Denial of Service
CVE-2007-3790dosmultiple
The com_print_typeinfo function in the bz2 extension in PHP 5.2.3 allows context-dependent attackers to cause a denial o
23RISCO
abrir
ReferênciaVexDay Proof
Macrovision FlexNet - 'isusweb.dll' DownloadAndExecute Method
CVE-2008-4586remotewindows
Insecure method vulnerability in the MVSNCLientWebAgent61.WebAgent.1 ActiveX control (isusweb.dll 6.1.100.61372) in Macr
23RISCO
abrir
ReferênciaVexDay Proof
UltraISO 9.3.3.2685 - CCD/IMG Universal Buffer Overflow
CVE-2009-1260localwindows
Multiple stack-based buffer overflows in UltraISO 9.3.3.2685 and earlier allow remote attackers to cause a denial of ser
50RISCO
abrir
ReferênciaVexDay Proof
Link Request Contact Form 3.4 - Remote Code Execution
CVE-2007-3199webappsphp
Unrestricted file upload vulnerability in Link Request Contact Form 3.4 allows remote attackers to execute arbitrary PHP
23RISCO
abrir
ReferênciaVexDay Proof
Simple Machines Forum (SMF) 1.1.3 - Blind SQL Injection
CVE-2007-5646webappsphp
SQL injection vulnerability in Sources/Search.php in Simple Machines Forum (SMF) 1.1.3, when MySQL 5 is used, allows rem
23RISCO
abrir
ReferênciaVexDay Proof
PowerPHPBoard 1.00b - Multiple Local File Inclusions
CVE-2008-1534webappsphp
Multiple directory traversal vulnerabilities in PowerPHPBoard 1.00b allow remote attackers to include and execute arbitr
23RISCO
abrir
ReferênciaVexDay Proof
ITechBids 7.0 gold - Cross-Site Scripting / SQL Injection
CVE-2008-3237webappsphp
Cross-site scripting (XSS) vulnerability in forward_to_friend.php in ITechBids 7.0 Gold allows remote attackers to injec
23RISCO
abrir
ReferênciaVexDay Proof
easysite 2.3 - Multiple Vulnerabilities
CVE-2008-4155webappsphp
Multiple directory traversal vulnerabilities in EasySite 2.3 allow remote attackers to read arbitrary files or list dire
23RISCO
abrir
ReferênciaVexDay Proof
PowerPortal 2.0.13 - 'path' Local Directory Traversal
CVE-2008-4361webappsphp
Directory traversal vulnerability in PowerPortal 2.0.13 allows remote attackers to list and possibly read arbitrary file
23RISCO
abrir
ReferênciaVexDay Proof
ASX to MP3 Converter 3.0.0.7 - '.m3u' Universal Stack Overflow
CVE-2009-1324localwindows
Stack-based buffer overflow in Mini-stream ASX to MP3 Converter 3.0.0.7 allows remote attackers to execute arbitrary cod
28RISCO
abrir
ReferênciaVexDay Proof
Mini-stream Ripper - '.m3u' Local Stack Overflow (PoC)
CVE-2009-1325doswindows
Stack-based buffer overflow in Mini-stream Ripper 3.0.1.1 allows remote attackers to execute arbitrary code via a long U
23RISCO
abrir
ReferênciaVexDay Proof
EZ Publish < 3.9.5/3.10.1/4.0.1 - Privilege Escalation
CVE-2008-6844webappsphp
The registration view (/user/register) in eZ Publish 3.5.6 and earlier, and possibly other versions before 3.9.5, 3.10.1
23RISCO
abrir
anteriorpágina 143 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.