Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.496exploits catalogados
34.964CVEs com exploração pública
24.695testados em laboratório
21.899 exploits
ReferênciaVexDay Proof
phpAuction 2.1 - 'phpAds_path' Remote File Inclusion
CVE-2006-3984webappsphp
PHP remote file inclusion vulnerability in phpAdsNew/view.inc.php in Albasoftware Phpauction 2.1 and possibly later vers
23RISCO
abrir
ReferênciaVexDay Proof
newsReporter 1.1 - 'index.php' Remote File Inclusion
CVE-2006-3988webappsphp
PHP remote file inclusion vulnerability in index.php in Knusperleicht newsReporter 1.1 and earlier allows remote attacke
23RISCO
abrir
ReferênciaVexDay Proof
k_shoutbox 4.4 - Remote File Inclusion
CVE-2006-3989webappsphp
PHP remote file inclusion vulnerability in index.php in Knusperleicht Shoutbox 4.4 and earlier allows remote attackers t
23RISCO
abrir
ReferênciaVexDay Proof
Voodoo chat 1.0RC1b - 'file_path' Remote File Inclusion
CVE-2006-3991webappsphp
PHP remote file inclusion vulnerability in index.php in Vlad Vostrykh Voodoo chat 1.0RC1b and earlier allows remote atta
23RISCO
abrir
ReferênciaVexDay Proof
TSEP 0.942 - 'copyright.php' Remote File Inclusion
CVE-2006-3993webappsphp
PHP remote file inclusion vulnerability in copyright.php in Olaf Noehring The Search Engine Project (TSEP) 0.942 allows
23RISCO
abrir
ReferênciaVexDay Proof
XMB 1.9.6 - 'mq=off' 'u2uid' SQL Injection
CVE-2006-3994webappsphp
SQL injection vulnerability in the u2u_send_recp function in u2u.inc.php in XMB (aka extreme message board) 1.9.6 Alpha
23RISCO
abrir
Referência
CVE-2006-3995
Multiple PHP remote file inclusion vulnerabilities in (1) uhp_config.php, and possibly (2) footer.php, (3) functions.php
28RISCO
abrir
ReferênciaVexDay Proof
Mambo Component User Home Pages 0.5 - Remote File Inclusion
CVE-2006-3995webappsphp
Multiple PHP remote file inclusion vulnerabilities in (1) uhp_config.php, and possibly (2) footer.php, (3) functions.php
28RISCO
abrir
ReferênciaVexDay Proof
dotProject 2.0.4 - 'baseDir' Remote File Inclusion
CVE-2006-4234webappsphp
PHP remote file inclusion vulnerability in classes/query.class.php in dotProject 2.0.4 and earlier allows remote attacke
23RISCO
abrir
ReferênciaVexDay Proof
POWERGAP 2003 - 's0x.php' Remote File Inclusion
CVE-2006-4236webappsphp
Multiple PHP remote file inclusion vulnerabilities in POWERGAP allow remote attackers to execute arbitrary PHP code via
28RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component com_jim 1.0.1 - Remote File Inclusion
CVE-2006-4242webappsphp
PHP remote file inclusion vulnerability in install.jim.php in the JIM 1.0.1 component for Joomla or Mambo allows remote
23RISCO
abrir
ReferênciaVexDay Proof
Mambo Component mambelfish 1.1 - Remote File Inclusion
CVE-2006-4270webappsphp
PHP remote file inclusion vulnerability in mambelfish.class.php in the mambelfish component (com_mambelfish) 1.1 and ear
23RISCO
abrir
ReferênciaVexDay Proof
SportsPHool 1.0 - 'mainnav' Remote File Inclusion
CVE-2006-4278webappsphp
PHP remote file inclusion vulnerability in includes/layout/plain.footer.php in SportsPHool 1.0 allows remote attackers t
23RISCO
abrir
ReferênciaVexDay Proof
LBlog 1.05 - 'comments.asp' SQL Injection
CVE-2006-4284webappsasp
SQL injection vulnerability in comments.asp in LBlog 1.05 and earlier allows remote attackers to execute arbitrary SQL c
23RISCO
abrir
ReferênciaVexDay Proof
Fantastic News 2.1.3 - 'script_path' Remote File Inclusion
CVE-2006-4285webappsphp
PHP remote file inclusion vulnerability in news.php in Fantastic News 2.1.3 and earlier allows remote attackers to execu
23RISCO
abrir
Referência
CVE-2009-4560
SQL injection vulnerability in profile.php in WebLeague 2.2.0 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
ReferênciaVexDay Proof
NES Game and NES System c108122 - Remote File Inclusion
CVE-2006-4287webappsphp
Multiple PHP remote file inclusion vulnerabilities in NES Game and NES System c108122 and earlier allow remote attackers
28RISCO
abrir
ReferênciaVexDay Proof
SimpleBlog 2.0 - 'comments.asp' SQL Injection (2)
CVE-2006-4300webappsphp
SQL injection vulnerability in comments.asp in SimpleBlog 2.0 and earlier allows remote attackers to execute arbitrary S
23RISCO
abrir
ReferênciaVexDay Proof
Microsoft Internet Explorer 6 - DirectX Media Remote Overflow Denial of Service
CVE-2006-4301doswindows
Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (crash) via a long Color attrib
35RISCO
abrir
ReferênciaVexDay Proof
OpenSSL < 0.9.7l/0.9.8d - SSLv2 Client Crash
CVE-2006-4343dosmultiple
The get_server_hello function in the SSLv2 client code in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier
28RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component Kochsuite 0.9.4 - Remote File Inclusion
CVE-2006-4348webappsphp
PHP remote file inclusion vulnerability in config.kochsuite.php in the Kochsuite (com_kochsuite) 0.9.4 component for Mam
23RISCO
abrir
Referência
CVE-2009-4561
Multiple SQL injection vulnerabilities in Admin/index.php in WebLeague 2.2.0, when magic_quotes_gpc is disabled, allow r
23RISCO
abrir
ReferênciaVexDay Proof
Empire CMS 3.7 - 'checklevel.php' Remote File Inclusion
CVE-2006-4354webappsphp
PHP remote file inclusion vulnerability in e/class/CheckLevel.php in Phome Empire CMS 3.7 and earlier allows remote atta
23RISCO
abrir
ReferênciaVexDay Proof
Integramod Portal 2.x - 'functions_portal.php' Remote File Inclusion
CVE-2006-4368webappsphp
PHP remote file inclusion vulnerability in includes/functions_portal.php in IntegraMOD Portal 2.x and earlier allows rem
23RISCO
abrir
ReferênciaVexDay Proof
Integramod Portal 2.x - 'functions_portal.php' Remote File Inclusion
CVE-2006-4369webappsphp
Absolute path traversal vulnerability in includes/functions_portal.php in IntegraMOD Portal 2.x and earlier, when magic_
23RISCO
abrir
ReferênciaVexDay Proof
pSlash 0.7 - 'lvc_include_dir' Remote File Inclusion
CVE-2006-4373webappsphp
PHP remote file inclusion vulnerability in modules/visitors2/include/config.inc.php in pSlash 0.70 allows remote attacke
23RISCO
abrir
ReferênciaVexDay Proof
PHPCOIN 1.2.3 - 'session_set.php' Remote File Inclusion
CVE-2006-4424webappsphp
PHP remote file inclusion vulnerability in coin_includes/constants.php in phpCOIN 1.2.3 allows remote attackers to execu
23RISCO
abrir
ReferênciaVexDay Proof
eFiction < 2.0.7 - Remote Admin Authentication Bypass
CVE-2006-4427webappsphp
index.php in eFiction before 2.0.7 allows remote attackers to bypass authentication and gain privileges by setting the (
23RISCO
abrir
ReferênciaVexDay Proof
Ay System CMS 2.6 - 'main.php' Remote File Inclusion
CVE-2006-4440webappsphp
PHP remote file inclusion vulnerability in main.php in Ay System Solutions CMS 2.6 and earlier allows remote attackers t
23RISCO
abrir
ReferênciaVexDay Proof
Interact 2.2 - 'CONFIG[base_path]' Remote File Inclusion
CVE-2006-4448webappsphp
Multiple PHP remote file inclusion vulnerabilities in interact 2.2, when register_globals is enabled, allow remote attac
23RISCO
abrir
anteriorpágina 336 / 730próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.