Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.280exploits catalogados
37.122CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
Uberghey 0.3.1 - 'FrontPage.php' Remote File Inclusion
CVE-2007-0359webappsphp
PHP remote file inclusion vulnerability in frontpage.php in Uberghey CMS 0.3.1 allows remote attackers to execute arbitr
23RISCO
abrir
ReferênciaVexDay Proof
Envolution 1.1.0 - 'topic' SQL Injection
CVE-2007-4253webappsphp
SQL injection vulnerability in the News module in modules.php in Envolution 1.1.0 and earlier allows remote attackers to
23RISCO
abrir
ReferênciaVexDay Proof
Sami HTTP Server 2.0.1 - HTTP 404 Object not found Denial of Service
CVE-2007-0548doswindows
KarjaSoft Sami HTTP Server 2.0.1 allows remote attackers to cause a denial of service (daemon hang) via a large number o
23RISCO
abrir
ReferênciaVexDay Proof
RPW 1.0.2 - 'config.php?sql_language' Remote File Inclusion
CVE-2007-0559webappsphp
PHP remote file inclusion vulnerability in config.php in RPW 1.0.2 allows remote attackers to execute arbitrary PHP code
23RISCO
abrir
ReferênciaVexDay Proof
Xero Portal - 'phpbb_root_path' Remote File Inclusion
CVE-2007-0561webappsphp
Multiple PHP remote file inclusion vulnerabilities in Xero Portal 1.2 allow remote attackers to execute arbitrary PHP co
28RISCO
abrir
ReferênciaVexDay Proof
ASP NEWS 3.0 - 'news_detail.asp' SQL Injection
CVE-2007-0566webappsasp
SQL injection vulnerability in news_detail.asp in ASP NEWS 3 and earlier allows remote attackers to execute arbitrary SQ
23RISCO
abrir
ReferênciaVexDay Proof
AINS 0.02b - 'ains_main.php?ains_path' Remote File Inclusion
CVE-2007-0570webappsphp
PHP remote file inclusion vulnerability in ains_main.php in Johannes Gijsbers (aka Taradino) Ad Fundum Integratable News
23RISCO
abrir
ReferênciaVexDay Proof
Drunken:Golem Portal 0.5.1 Alpha 2 - Remote File Inclusion
CVE-2007-0572webappsphp
PHP remote file inclusion vulnerability in include/irc/phpIRC.php in Drunken:Golem Gaming Portal 0.5.1 Alpha 2 and earli
23RISCO
abrir
ReferênciaVexDay Proof
nsGalPHP - '/includes/config.inc.php?racineTBS' Remote File Inclusion
CVE-2007-0573webappsphp
PHP remote file inclusion vulnerability in includes/config.inc.php in nsGalPHP 0.41 and earlier allows remote attackers
23RISCO
abrir
ReferênciaVexDay Proof
Surgemail 38k - 'Search' Remote Buffer Overflow
CVE-2007-4377remotewindows
Stack-based buffer overflow in the IMAP service in SurgeMail 38k allows remote authenticated users to execute arbitrary
23RISCO
abrir
ReferênciaVexDay Proof
Epistemon 1.0 - 'common.php?inc_path' Remote File Inclusion
CVE-2007-0701webappsphp
PHP remote file inclusion vulnerability in inc/common.inc.php in Epistemon 1.0 allows remote attackers to execute arbitr
23RISCO
abrir
ReferênciaVexDay Proof
Somery 0.4.6 - 'skin_dir' Remote File Inclusion
CVE-2007-0704webappsphp
PHP remote file inclusion vulnerability in install.php in Somery 0.4.6 allows remote attackers to execute arbitrary PHP
23RISCO
abrir
ReferênciaVexDay Proof
Chicken of the VNC 2.0 - 'NULL-pointer' Remote Denial of Service
CVE-2007-0756dososx
Chicken of the VNC (cotv) 2.0 allows remote attackers to cause a denial of service (application crash) via a large compu
23RISCO
abrir
ReferênciaVexDay Proof
CoD2: DreamStats 4.2 - 'index.php' Remote File Inclusion
CVE-2007-0757webappsphp
PHP remote file inclusion vulnerability in index.php in Miguel Nunes Call of Duty 2 (CoD2) DreamStats System 4.2 and ear
23RISCO
abrir
ReferênciaVexDay Proof
phpBB ezBoard Converter 0.2 - 'ezconvert_dir' Remote File Inclusion
CVE-2007-0761webappsphp
PHP remote file inclusion vulnerability in config.php in phpBB ezBoard converter (ezconvert) 0.2 allows remote attackers
23RISCO
abrir
ReferênciaVexDay Proof
phpBB++ Build 100 - 'phpbb_root_path' Remote File Inclusion
CVE-2007-0762webappsphp
PHP remote file inclusion vulnerability in includes/functions.php in phpBB++ Build 100 allows remote attackers to execut
23RISCO
abrir
ReferênciaVexDay Proof
F3Site 2.1 - Remote Code Execution
CVE-2007-0763webappsphp
Cross-site scripting (XSS) vulnerability in the news comment functionality in F3Site 2.1 and earlier allows remote attac
23RISCO
abrir
ReferênciaVexDay Proof
DL PayCart 1.01 - 'viewitem.php?ItemID' Blind SQL Injection
CVE-2007-4604webappsphp
SQL injection vulnerability in viewitem.php in DL PayCart 1.01 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
ReferênciaVexDay Proof
PHPNuke-Clan 4.2.0 - 'mvcw_conver.php' Remote File Inclusion
CVE-2007-4606webappsphp
PHP remote file inclusion vulnerability in convert/mvcw_conver.php in the Virtual War (VWar) module for PHPNuke-Clan (PN
23RISCO
abrir
ReferênciaVexDay Proof
Snitz Forums 2000 3.1 SR4 - 'pop_profile.asp' SQL Injection
CVE-2007-1023webappsasp
SQL injection vulnerability in pop_profile.asp in Snitz Forums 2000 3.1 SR4 allows remote attackers to execute arbitrary
23RISCO
abrir
ReferênciaVexDay Proof
News Rover 12.1 Rev 1 - Stack Overflow (1)
CVE-2007-1041localwindows
Multiple stack-based buffer overflows in S&H Computer Systems News Rover 12.1 Rev 1 allow remote attackers to execute ar
23RISCO
abrir
ReferênciaVexDay Proof
Nortel SSL VPN Linux Client 6.0.3 - Local Privilege Escalation
CVE-2007-1057locallinux
The Net Direct client for Linux before 6.0.5 in Nortel Application Switch 2424, VPN 3050 and 3070, and SSL VPN Module 10
23RISCO
abrir
ReferênciaVexDay Proof
PHP-Nuke 8.0 Final - HTTP Referers SQL Injection
CVE-2007-1061webappsphp
SQL injection vulnerability in index.php in Francisco Burzi PHP-Nuke 8.0 Final and earlier, when the "HTTP Referers" blo
35RISCO
abrir
ReferênciaVexDay Proof
phpBB Links MOD 1.2.2 - SQL Injection
CVE-2007-4653webappsphp
SQL injection vulnerability in links.php in the Links MOD 1.2.2 and earlier for phpBB 2.0.22 and earlier allows remote a
23RISCO
abrir
ReferênciaVexDay Proof
WebprojectDB 0.1.3 - 'INCDIR' Remote File Inclusion
CVE-2006-2995webappsphp
Multiple PHP remote file inclusion vulnerabilities in WebprojectDB 0.1.3 and earlier allow remote attackers to execute a
23RISCO
abrir
ReferênciaVexDay Proof
aePartner 0.8.3 - 'dir[data]' Remote File Inclusion
CVE-2006-2996webappsphp
PHP remote file inclusion vulnerability in inc/design.inc.php in LoveCompass aePartner 0.8.3 and earlier allows remote a
23RISCO
abrir
ReferênciaVexDay Proof
free QBoard 1.1 - 'qb_path' Remote File Inclusion
CVE-2006-2998webappsphp
PHP remote file inclusion vulnerability in board/post.php in free QBoard 1.1 and earlier allows remote attackers to exec
23RISCO
abrir
ReferênciaVexDay Proof
Sinapis 2.2 Gastebuch - 'sinagb.php?fuss' Remote File Inclusion
CVE-2007-1130webappsphp
PHP remote file inclusion vulnerability in sinagb.php in Sinapis Gastebuch 2.2 allows remote attackers to execute arbitr
23RISCO
abrir
ReferênciaVexDay Proof
PHP 5.2.1 - 'substr_compare()' Information Leak
CVE-2007-1375localmultiple
Integer overflow in the substr_compare function in PHP 5.2.1 and earlier allows context-dependent attackers to read sens
23RISCO
abrir
ReferênciaVexDay Proof
PHP < 4.4.5/5.2.1 - 'shmop' Local Code Execution
CVE-2007-1376locallinux
The shmop functions in PHP before 4.4.5, and before 5.2.1 in the 5.x series, do not verify that their arguments correspo
28RISCO
abrir
anteriorpágina 172 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.