Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.324exploits catalogados
37.130CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
QuickUpCMS - Multiple SQL Injections Vulnerabilities
CVE-2008-2530webappsphp
Multiple SQL injection vulnerabilities in Concepts & Solutions QuickUpCMS allow remote attackers to execute arbitrary SQ
23RISCO
abrir
ReferênciaVexDay Proof
Power Phlogger 2.2.5 - 'css_str' SQL Injection
CVE-2008-2562webappsphp
SQL injection vulnerability in edCss.php in PowerPhlogger 2.2.5 and earlier allows remote authenticated users to execute
23RISCO
abrir
ReferênciaVexDay Proof
PHP-Address Book 3.1.5 - SQL Injection / Cross-Site Scripting
CVE-2008-2566webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in PHP Address Book 3.1.5 and earlier allow remote attackers to inje
23RISCO
abrir
ReferênciaVexDay Proof
freeSSHd 1.2.1 - (Authenticated) Remote Stack Overflow (PoC)
CVE-2008-2573doswindows
Stack-based buffer overflow in SFTP in freeSSHd 1.2.1 allows remote authenticated users to execute arbitrary code via a
23RISCO
abrir
ReferênciaVexDay Proof
freeSSHd 1.2.1 - (Authenticated) Remote Overflow (SEH)
CVE-2008-2573remotewindows
Stack-based buffer overflow in SFTP in freeSSHd 1.2.1 allows remote authenticated users to execute arbitrary code via a
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component SimpleShop 3.4 - SQL Injection
CVE-2008-2568webappsphp
SQL injection vulnerability in the Simple Shop Galore (com_simpleshop) component 3.4 and earlier for Joomla! allows remo
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component JooBlog 0.1.1 - Blind SQL Injection
CVE-2008-2630webappsphp
SQL injection vulnerability in the JooBlog (com_jb2) component 0.1.1 for Joomla! allows remote attackers to execute arbi
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component Bible Study 1.5.0 - 'id' SQL Injection
CVE-2008-2643webappsphp
SQL injection vulnerability in the Bible Study (com_biblestudy) component before 6.0.7c for Joomla! allows remote attack
23RISCO
abrir
ReferênciaVexDay Proof
mebiblio 0.4.7 - SQL Injection / Arbitrary File Upload / Cross-Site Scripting
CVE-2008-2647webappsphp
SQL injection vulnerability in admin/journal_change_mask.inc.php in meBiblio 0.4.7 allows remote attackers to execute ar
23RISCO
abrir
ReferênciaVexDay Proof
CMSimple 3.1 - Local File Inclusion / Arbitrary File Upload
CVE-2008-2650webappsphp
Directory traversal vulnerability in cmsimple/cms.php in CMSimple 3.1, when register_globals is enabled, allows remote a
43RISCO
abrir
ReferênciaVexDay Proof
Roundcube Webmail 0.2b - Remote Code Execution
CVE-2008-5619webappsphp
html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail)
35RISCO
abrir
ReferênciaVexDay Proof
phpMyAdmin 3.1.0 - Cross-Site Request Forgery / SQL Injection
CVE-2008-5621webappsphp
Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.11.x before 2.11.9.4 and 3.x before 3.1.1.0 allows remot
23RISCO
abrir
ReferênciaVexDay Proof
CzarNews 1.14 - 'tpath' Remote File Inclusion
CVE-2005-0859webappsphp
PHP remote file inclusion vulnerability in CzarNews 1.13b allows remote attackers to execute arbitrary PHP code via the
28RISCO
abrir
ReferênciaVexDay Proof
Achievo 1.3.2 - 'FCKeditor' Arbitrary File Upload
CVE-2008-2742webappsphp
Unrestricted file upload in the mcpuk file editor (atk/attributes/fck/editor/filemanager/browser/mcpuk/connectors/php/co
23RISCO
abrir
ReferênciaVexDay Proof
PHP-Fusion Mod TI - 'id' SQL Injection
CVE-2008-5733webappsphp
SQL injection vulnerability in blog.php in the Team Impact TI Blog System mod for PHP-Fusion allows remote attackers to
23RISCO
abrir
ReferênciaVexDay Proof
JiRo's FAQ Manager eXperience 1.0 - 'fID' SQL Injection
CVE-2008-2691webappsasp
SQL injection vulnerability in read.asp in JiRo's FAQ Manager eXperience 1.0 allows remote attackers to execute arbitrar
23RISCO
abrir
ReferênciaVexDay Proof
Black Ice Software Annotation Plugin - 'BiAnno.ocx' Remote Buffer Overflow (2)
CVE-2008-2745remotewindows
Stack-based buffer overflow in BiAnno ActiveX Control (BiAnno.ocx) in Black Ice Software Annotation Plugin 10.95 allows
28RISCO
abrir
ReferênciaVexDay Proof
Black Ice Software Inc Barcode SDK - 'BITiff.ocx' Remote Buffer Overflow (1)
CVE-2008-2693remotewindows
Stack-based buffer overflow in the BITIFF.BITiffCtrl.1 ActiveX control in BITiff.ocx 10.9.3.0 in Black Ice Barcode SDK 5
28RISCO
abrir
ReferênciaVexDay Proof
Black Ice Software Inc Barcode SDK - 'BITiff.ocx' Remote Buffer Overflow (2)
CVE-2008-2693remotewindows
Stack-based buffer overflow in the BITIFF.BITiffCtrl.1 ActiveX control in BITiff.ocx 10.9.3.0 in Black Ice Barcode SDK 5
28RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component Rapid Recipe 1.6.6/1.6.7 - SQL Injection
CVE-2008-2697webappsphp
SQL injection vulnerability in the Rapid Recipe (com_rapidrecipe) component 1.6.6 and 1.6.7 for Joomla! allows remote at
23RISCO
abrir
ReferênciaVexDay Proof
CoolPlayer 2.19 - '.Skin' Local Buffer Overflow
CVE-2008-5735localwindows
Stack-based buffer overflow in skin.c in CoolPlayer 2.17 through 2.19 allows remote attackers to execute arbitrary code
23RISCO
abrir
ReferênciaVexDay Proof
CoolPlayer 2.19 - '.Skin' Local Buffer Overflow
CVE-2008-5735localwindows
Stack-based buffer overflow in skin.c in CoolPlayer 2.17 through 2.19 allows remote attackers to execute arbitrary code
23RISCO
abrir
ReferênciaVexDay Proof
Nitro Web Gallery 1.4.3 - 'section' SQL Injection
CVE-2008-2817webappsphp
SQL injection vulnerability in albums.php in NiTrO Web Gallery 1.4.3 and earlier allows remote attackers to execute arbi
23RISCO
abrir
ReferênciaVexDay Proof
Mybizz-Classifieds - 'cat' SQL Injection
CVE-2008-2845webappsphp
SQL injection vulnerability in index.php in MyBizz-Classifieds allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
ReferênciaVexDay Proof
CaupoShop Classic 1.3 - 'saArticle[ID]' SQL Injection
CVE-2008-2866webappsphp
SQL injection vulnerability in csc_article_details.php in Caupo.net CaupoShop Classic 1.3 allows remote attackers to exe
23RISCO
abrir
ReferênciaVexDay Proof
E-topbiz ViralDX 2.07 - 'bannerid' SQL Injection
CVE-2008-2867webappsphp
SQL injection vulnerability in adclick.php in E-topbiz Viral DX 1 2.07 allows remote attackers to execute arbitrary SQL
23RISCO
abrir
ReferênciaVexDay Proof
DUcalendar 1.0 - 'iEve' SQL Injection
CVE-2008-2868webappsasp
SQL injection vulnerability in detail.asp in DUware DUcalendar 1.0 and possibly earlier allows remote attackers to execu
23RISCO
abrir
ReferênciaVexDay Proof
Link ADS 1 - 'linkid' SQL Injection
CVE-2008-2869webappsphp
SQL injection vulnerability in out.php in E-topbiz Link ADS 1 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
ReferênciaVexDay Proof
Efestech Shop 2.0 - 'cat_id' SQL Injection
CVE-2008-3030webappsphp
SQL injection vulnerability in default.asp in EfesTECH Shop 2.0 allows remote attackers to execute arbitrary SQL command
23RISCO
abrir
ReferênciaVexDay Proof
XchangeBoard 1.70 - 'boardID' SQL Injection
CVE-2008-3035webappsphp
SQL injection vulnerability in newThread.php in XchangeBoard 1.70 Final and earlier allows remote authenticated users to
23RISCO
abrir
anteriorpágina 179 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.