Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

80.324exploits catalogados
37.130CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
Songbird Media Player 0.2 - Format String Denial of Service (PoC)
CVE-2006-6250doswindows
Format string vulnerability in Songbird Media Player 0.2 and earlier allows remote attackers to cause a denial of servic
23RISCO
abrir
ReferênciaVexDay Proof
VUPlayer 2.44 - '.m3u' UNC Name Buffer Overflow (Metasploit)
CVE-2006-6251remotewindows
Stack-based buffer overflow in VUPlayer 2.44 and earlier allows remote attackers to execute arbitrary code via a long st
50RISCO
abrir
ReferênciaVexDay Proof
CM68 News 12.02.06 - 'addpth' Remote File Inclusion
CVE-2006-6462webappsphp
PHP remote file inclusion vulnerability in engine/oldnews.inc.php in CM68 News 12.02.06 allows remote attackers to execu
23RISCO
abrir
ReferênciaVexDay Proof
HR Assist 1.05 - 'vdateUsr.asp' Remote Authentication Bypass
CVE-2006-6524webappsasp
SQL injection vulnerability in vdateUsr.asp in EzHRS HR Assist 1.05 and earlier allows remote attackers to execute arbit
23RISCO
abrir
ReferênciaVexDay Proof
Gizzar 03162002 - 'index.php' Remote File Inclusion
CVE-2006-6526webappsphp
PHP remote file inclusion vulnerability in index.php in Gizzar 03162002 and earlier allows remote attackers to execute a
23RISCO
abrir
ReferênciaVexDay Proof
yaplap 0.6.1b - 'ldap.php' Remote File Inclusion
CVE-2006-6575webappsphp
PHP remote file inclusion vulnerability in ldap.php in Brian Drawert Yet Another PHP LDAP Admin Project (yaplap) 0.6 and
23RISCO
abrir
ReferênciaVexDay Proof
mxBB Module Meeting 1.1.2 - Remote File Inclusion
CVE-2006-6644webappsphp
PHP remote file inclusion vulnerability in pages/meeting_constants.php in the Meeting (mx_meeting) 1.1.2 and earlier mod
23RISCO
abrir
ReferênciaVexDay Proof
mxBB Module WebLinks 2.05 - Remote File Inclusion
CVE-2006-6645webappsphp
PHP remote file inclusion vulnerability in language/lang_english/lang_admin.php in the Web Links (mx_links) 2.05 and ear
23RISCO
abrir
ReferênciaVexDay Proof
Sambar FTP Server 6.4 - 'SIZE' Remote Denial of Service
CVE-2006-6624doswindows
The FTP Server in Sambar Server 6.4 allows remote authenticated users to cause a denial of service (application crash) v
23RISCO
abrir
ReferênciaVexDay Proof
Genepi 1.6 - 'genepi.php' Remote File Inclusion
CVE-2006-6632webappsphp
PHP remote file inclusion vulnerability in genepi.php in Genepi 1.6 and earlier allows remote attackers to execute arbit
23RISCO
abrir
ReferênciaVexDay Proof
JumbaCMS 0.0.1 - '/includes/functions.php' Remote File Inclusion
CVE-2006-6635webappsphp
PHP remote file inclusion vulnerability in includes/functions.php in JumbaCMS 0.0.1 allows remote attackers to execute a
23RISCO
abrir
ReferênciaVexDay Proof
WonderCMS 3.1.3 - 'content' Persistent Cross-Site Scripting
CVE-2020-29233webappsphp
WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Page description component. This vulnerability can allo
23RISCO
abrir
ReferênciaVexDay Proof
mxbb module charts 1.0.0 - Remote File Inclusion
CVE-2006-6650webappsphp
PHP remote file inclusion vulnerability in charts_constants.php in the Charts (mx_charts) 1.0.0 and earlier module for m
23RISCO
abrir
ReferênciaVexDay Proof
Hospital Management System 4.0 - Persistent Cross-Site Scripting
CVE-2020-5191webappsphp
PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple Persistent XSS vulnerabilities.
38RISCO
abrir
ReferênciaVexDay Proof
Hospital Management System 4.0 - 'searchdata' SQL Injection
CVE-2020-5192webappsphp
PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple SQL injection vulnerabilities: multiple pages an
43RISCO
abrir
ReferênciaVexDay Proof
PHP-Update 2.7 - Multiple Vulnerabilities
CVE-2006-6880webappsphp
Multiple SQL injection vulnerabilities in code/guestadd.php in PHP-Update 2.7 and earlier allow remote attackers to exec
23RISCO
abrir
ReferênciaVexDay Proof
Macromedia Shockwave 10 'SwDir.dll' Internet Explorer 7 - Denial of Service
CVE-2006-6885doswindows
An ActiveX control in SwDir.dll in Macromedia Shockwave 10 allows remote attackers to cause a denial of service (Interne
23RISCO
abrir
ReferênciaVexDay Proof
Voodoo chat 1.0RC1b - 'users.dat' Password Disclosure
CVE-2006-6890webappsphp
Voodoo chat 1.0RC1b stores sensitive information under the web root with insufficient access control, which allows remot
23RISCO
abrir
ReferênciaVexDay Proof
Vz (Adp) Forum 2.0.3 - Remote Password Disclosure
CVE-2006-6891webappsphp
Vz (Adp) Forum 2.0.3 stores sensitive information under the web root with insufficient access control, which allows remo
23RISCO
abrir
ReferênciaVexDay Proof
Formbankserver 1.9 - 'Name' Remote Denial of Service
CVE-2006-6910doswindows
formbankcgi.exe in Fersch Formbankserver 1.9, when the PATH_INFO begins with Abfrage, allows remote attackers to cause a
23RISCO
abrir
ReferênciaVexDay Proof
Quote&Ordering System 1.0 - 'ordernum' Multiple Vulnerabilities
CVE-2006-6911webappsasp
SQL injection vulnerability in search.asp in Digitizing Quote And Ordering System 1.0 allows remote authenticated users
23RISCO
abrir
ReferênciaVexDay Proof
CA BrightStor ARCserve - 'tapeeng.exe' Remote Buffer Overflow
CVE-2006-6917remotewindows
Multiple buffer overflows in Computer Associates (CA) BrightStor ARCserve Backup R11.5 Server before SP2 allows remote a
28RISCO
abrir
ReferênciaVexDay Proof
TaskTracker 1.5 - 'Customize.asp' Remote Add Administrator
CVE-2007-0049webappsasp
Geckovich TaskTracker Pro 1.5 and earlier allows remote attackers to add administrative or other accounts via an Add act
23RISCO
abrir
ReferênciaVexDay Proof
AutoDealer 2.0 - 'detail.asp?iPro' SQL Injection
CVE-2007-0053webappsasp
SQL injection vulnerability in detail.asp in ASP SiteWare autoDealer 2.0 and earlier allows remote attackers to execute
23RISCO
abrir
ReferênciaVexDay Proof
Mint Haber Sistemi 2.7 - 'duyuru.asp?id' SQL Injection
CVE-2007-0304webappsphp
SQL injection vulnerability in duyuru.asp in MiNT Haber Sistemi 2.7 allows remote attackers to execute arbitrary SQL com
23RISCO
abrir
ReferênciaVexDay Proof
Article System 0.1 - 'INCLUDE_DIR' Remote File Inclusion
CVE-2007-0314webappsphp
Multiple PHP remote file inclusion vulnerabilities in Article System 1.0 allow remote attackers to execute arbitrary PHP
23RISCO
abrir
ReferênciaVexDay Proof
JV2 Folder Gallery 3.0 - 'download.php' Remote File Disclosure
CVE-2007-0329webappsphp
download.php in Joonas Viljanen JV2 Folder Gallery allows remote attackers to read sensitive files via a relative pathna
23RISCO
abrir
ReferênciaVexDay Proof
PHP < 4.4.5/5.2.1 - 'shmop' SSL RSA Private-Key Disclosure
CVE-2007-1376locallinux
The shmop functions in PHP before 4.4.5, and before 5.2.1 in the 5.x series, do not verify that their arguments correspo
28RISCO
abrir
ReferênciaVexDay Proof
PHP < 4.4.5/5.2.1 - PHP_binary Session Deserialization Information Leak
CVE-2007-1380localmultiple
The php_binary serialization handler in the session extension in PHP before 4.4.5, and 5.x before 5.2.1, allows context-
23RISCO
abrir
ReferênciaVexDay Proof
WEBO (Web ORGanizer) 1.0 - 'baseDir' Remote File Inclusion
CVE-2007-1391webappsphp
PHP remote file inclusion vulnerability in modules/abook/foldertree.php in Leo West WEBO (aka weborganizer) 1.0 allows r
23RISCO
abrir
anteriorpágina 185 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.