Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.107exploits catalogados
34.679CVEs com exploração pública
24.695testados em laboratório
21.692 exploits
ReferênciaVexDay Proof
fipsForum 2.6 - 'default2.asp' SQL Injection
CVE-2006-6116webappsasp
SQL injection vulnerability in default2.asp in fipsForum 2.6 and earlier allows remote attackers to execute arbitrary SQ
23RISCO
abrir
Referência
CVE-2009-4689
SQL injection vulnerability in index.php in PHP Shopping Cart Selling Website Script allows remote attackers to execute
23RISCO
abrir
ReferênciaVexDay Proof
fipsGallery 1.5 - 'index1.asp' SQL Injection
CVE-2006-6117webappsasp
SQL injection vulnerability in index1.asp in fipsGallery 1.5 and earlier allows remote attackers to execute arbitrary SQ
23RISCO
abrir
ReferênciaVexDay Proof
Sisfo Kampus 0.8 - Remote File Inclusion / Download
CVE-2006-6137webappsphp
Multiple PHP remote file inclusion vulnerabilities in Sisfo Kampus 0.8 allow remote attackers to execute arbitrary PHP c
23RISCO
abrir
ReferênciaVexDay Proof
Sisfo Kampus 0.8 - Remote File Inclusion / Download
CVE-2006-6138webappsphp
Directory traversal vulnerability in download.php in Sisfo Kampus 0.8 allows remote attackers to list arbitrary director
23RISCO
abrir
ReferênciaVexDay Proof
Liberum Help Desk 0.97.3 - SQL Injection
CVE-2006-6160webappsasp
SQL injection vulnerability in details.asp in Doug Luxem Liberum Help Desk 0.97.3 and earlier allows remote attackers to
23RISCO
abrir
Referência
CVE-2024-27199
CVE-2024-27199HIGHsob ataqueransomware
In JetBrains TeamCity before 2023.11.4 path traversal allowing to perform limited admin actions was possible
100RISCO
abrir
Referência
CVE-2022-44877
CVE-2022-44877CRITICALsob ataque
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execut
100RISCO
abrir
Referência
CVE-2022-44877
CVE-2022-44877CRITICALsob ataque
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execut
100RISCO
abrir
Referência
CVE-2022-44877
CVE-2022-44877CRITICALsob ataque
login/index.php in CWP (aka Control Web Panel or CentOS Web Panel) 7 before 0.9.8.1147 allows remote attackers to execut
100RISCO
abrir
Referência
CVE-2006-6184
Multiple stack-based buffer overflows in Allied Telesyn TFTP Server (AT-TFTP) 1.9, and possibly earlier, allow remote at
50RISCO
abrir
Referência
CVE-2006-6184
Multiple stack-based buffer overflows in Allied Telesyn TFTP Server (AT-TFTP) 1.9, and possibly earlier, allow remote at
50RISCO
abrir
ReferênciaVexDay Proof
SimpleBlog 2.3 - '/admin/edit.asp' SQL Injection
CVE-2006-6191webappsasp
SQL injection vulnerability in admin/edit.asp in 8pixel.net simpleblog 2.3 and earlier allows remote attackers to execut
23RISCO
abrir
ReferênciaVexDay Proof
Hacks List phpBB Mod 1.21 - SQL Injection
CVE-2006-6216webappsphp
SQL injection vulnerability in admin_hacks_list.php in the Nivisec Hacks List 1.21 and earlier phpBB module allows remot
23RISCO
abrir
ReferênciaVexDay Proof
Recipes Complete Website 1.1.14 - SQL Injection
CVE-2006-6220webappsphp
Multiple SQL injection vulnerabilities in Recipes Website (Recipes Complete Website) 1.1.14 allow remote attackers to ex
23RISCO
abrir
ReferênciaVexDay Proof
GeekLog 1.4.0sr3 - '_CONF[path]' Remote File Inclusion
CVE-2006-6225webappsphp
Multiple PHP remote file inclusion vulnerabilities in GeekLog 1.4 allow remote attackers to execute arbitrary code via a
23RISCO
abrir
ReferênciaVexDay Proof
S9Y Serendipity 1.0.3 - 'comment.php' Local File Inclusion
CVE-2006-6242webappsphp
Multiple directory traversal vulnerabilities in Serendipity 1.0.3 and earlier allow remote attackers to read or include
23RISCO
abrir
ReferênciaVexDay Proof
Songbird Media Player 0.2 - Format String Denial of Service (PoC)
CVE-2006-6250doswindows
Format string vulnerability in Songbird Media Player 0.2 and earlier allows remote attackers to cause a denial of servic
23RISCO
abrir
ReferênciaVexDay Proof
VUPlayer 2.44 - '.m3u' UNC Name Buffer Overflow (Metasploit)
CVE-2006-6251remotewindows
Stack-based buffer overflow in VUPlayer 2.44 and earlier allows remote attackers to execute arbitrary code via a long st
50RISCO
abrir
ReferênciaVexDay Proof
Quintessential Player 4.50.1.82 - Playlist Denial of Service (PoC)
CVE-2006-6261doswindows
Buffer overflow in Quintessential Player 4.50.1.82 and earlier allows remote attackers to cause a denial of service (cra
23RISCO
abrir
ReferênciaVexDay Proof
CoolPlayer 2.17 - '.m3u' Local Stack Overflow
CVE-2006-6288localwindows
Multiple buffer overflows in Niek Albers CoolPlayer 216 and earlier allow remote attackers to execute arbitrary code via
23RISCO
abrir
ReferênciaVexDay Proof
F-Prot AntiVirus 4.6.6 - CHM Heap Overflow (PoC)
CVE-2006-6293doslinux
Heap-based buffer overflow in FRISK Software F-Prot Antivirus before 4.6.7 allows user-assisted remote attackers to exec
28RISCO
abrir
ReferênciaVexDay Proof
mxBB Module mx_tinies 1.3.0 - Remote File Inclusion
CVE-2006-6295webappsphp
PHP remote file inclusion vulnerability in includes/mx_common.php in the mx_tinies 1.3.0 Module for MxBB Portal 1.06 all
23RISCO
abrir
ReferênciaVexDay Proof
Microsoft Windows - spoolss GetPrinterData() Remote Denial of Service
CVE-2006-6296doswindows
The RpcGetPrinterData function in the Print Spooler (spoolsv.exe) service in Microsoft Windows 2000 SP4 and earlier, and
28RISCO
abrir
ReferênciaVexDay Proof
F-Prot AntiVirus 4.6.6 - 'ACE' Denial of Service
CVE-2006-6352doslinux
FRISK Software F-Prot Antivirus before 4.6.7 allows user-assisted remote attackers to cause a denial of service (infinit
23RISCO
abrir
ReferênciaVexDay Proof
Ultimate HelpDesk - Cross-Site Scripting / Local File Disclosure
CVE-2006-6380webappsasp
Cross-site scripting (XSS) vulnerability in index.asp in Ultimate HelpDesk allows remote attackers to inject arbitrary w
23RISCO
abrir
Referência
CVE-2023-46805
CVE-2023-46805HIGHsob ataqueransomware
An authentication bypass vulnerability in the web component of Ivanti ICS 9.x, 22.x and Ivanti Policy Secure allows a re
100RISCO
abrir
Referência
CVE-2023-22527
CVE-2023-22527CRITICALsob ataqueransomware
A template injection vulnerability on older versions of Confluence Data Center and Server allows an unauthenticated atta
100RISCO
abrir
ReferênciaVexDay Proof
mxBB Module kb_mods 2.0.2 - Remote File Inclusion
CVE-2006-6568webappsphp
Directory traversal vulnerability in includes/kb_constants.php in the Knowledge Base (mx_kb) 2.0.2 module for mxBB allow
23RISCO
abrir
Referência
CVE-2009-4721
Multiple SQL injection vulnerabilities in Admin/index.asp in Andrews-Web (A-W) BannerAd 1.0 allow remote attackers to ex
23RISCO
abrir
anteriorpágina 286 / 724próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.