Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.559exploits catalogados
34.978CVEs com exploração pública
24.695testados em laboratório
21.899 exploits
ReferênciaVexDay Proof
n@board 3.1.9e - 'naboard_pnr.php' Remote File Inclusion
CVE-2006-5281webappsphp
PHP remote file inclusion vulnerability in naboard_pnr.php in n@board 3.1.9e and earlier allows remote attackers to exec
23RISCO
abrir
ReferênciaVexDay Proof
SH-News 3.1 - 'scriptpath' Remote File Inclusion
CVE-2006-5282webappsphp
Multiple PHP remote file inclusion vulnerabilities in SH-News 3.1 and earlier allow remote attackers to execute arbitrar
23RISCO
abrir
ReferênciaVexDay Proof
Minichat 6.0 - 'ftag.php' Remote File Inclusion
CVE-2006-5283webappsphp
PHP remote file inclusion vulnerability in ftag.php in Minichat 6.0 allows remote attackers to execute arbitrary PHP cod
23RISCO
abrir
Referência
CVE-2009-4618
Multiple SQL injection vulnerabilities in Tourism Script Bus Script allow remote attackers to execute arbitrary SQL comm
23RISCO
abrir
ReferênciaVexDay Proof
PHP News Reader 2.6.4 - 'phpBB.inc.php' Remote File Inclusion
CVE-2006-5284webappsphp
PHP remote file inclusion vulnerability in auth/phpbb.inc.php in Shen Cheng-Da PHP News Reader (aka pnews) 2.6.4 and ear
23RISCO
abrir
Referência
CVE-2009-4621
SQL injection vulnerability in the JiangHu Inn plugin 1.1 and earlier for Discuz! allows remote attackers to execute arb
23RISCO
abrir
ReferênciaVexDay Proof
vTiger CRM 4.2 - 'calpath' Multiple Remote File Inclusions
CVE-2006-5289webappsphp
Multiple PHP remote file inclusion vulnerabilities in Vtiger CRM 4.2 and earlier allow remote attackers to execute arbit
23RISCO
abrir
ReferênciaVexDay Proof
Download-Engine 1.4.2 - 'spaw' Remote File Inclusion
CVE-2006-5291webappsphp
PHP remote file inclusion vulnerability in admin/includes/spaw/spaw_control.class.php in Download-Engine 1.4.2 allows re
23RISCO
abrir
ReferênciaVexDay Proof
Exhibit Engine 1.5 RC 4 - 'photo_comment.php' File Inclusion
CVE-2006-5292webappsphp
PHP remote file inclusion vulnerability in photo_comment.php in Exhibit Engine 1.5 RC 4 and earlier allows remote attack
23RISCO
abrir
ReferênciaVexDay Proof
Microsoft Office 2003 - '.PPT' Local Buffer Overflow (PoC)
CVE-2006-5296doswindows
PowerPoint in Microsoft Office 2003 does not properly handle a container object whose position value exceeds the record
28RISCO
abrir
ReferênciaVexDay Proof
phpBB SpamBlocker Mod 1.0.2 - Remote File Inclusion
CVE-2006-5301webappsphp
PHP remote file inclusion vulnerability in includes/antispam.php in the SpamBlockerMODv 1.0.2 and earlier module for php
23RISCO
abrir
ReferênciaVexDay Proof
Redaction System 1.0 - 'lang_prefix' Remote File Inclusion
CVE-2006-5302webappsphp
Multiple PHP remote file inclusion vulnerabilities in Redaction System 1.0000 allow remote attackers to execute arbitrar
23RISCO
abrir
ReferênciaVexDay Proof
Cdsagenda 4.2.9 - 'SendAlertEmail.php' File Inclusion
CVE-2006-5384webappsphp
PHP remote file inclusion vulnerability in modification/SendAlertEmail.php in CDS Software Consortium CDS Agenda 4.2.9 a
23RISCO
abrir
ReferênciaVexDay Proof
phpBB SpamOborona Mod 1.0b - Remote File Inclusion
CVE-2006-5385webappsphp
PHP remote file inclusion vulnerability in admin/admin_spam.php in the SpamOborona 1.0b and earlier phpBB module allows
23RISCO
abrir
ReferênciaVexDay Proof
Specimen Image Database - 'client.php' Remote File Inclusion
CVE-2006-5419webappsphp
PHP remote file inclusion vulnerability in client.php in University of Glasgow Specimen Image Database (SID), when regis
23RISCO
abrir
ReferênciaVexDay Proof
WSN Forum 1.3.4 - 'prestart.php' Remote Code Execution
CVE-2006-5421webappsphp
WSN Forum 1.3.4 and earlier allows remote attackers to execute arbitrary PHP code via a modified pathname in the pathtoc
23RISCO
abrir
Referência
CVE-2018-11776
CVE-2018-11776HIGHsob ataque
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISCO
abrir
Referência
CVE-2018-11776
CVE-2018-11776HIGHsob ataque
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RISCO
abrir
ReferênciaVexDay Proof
Techno Dreams Guestbook 1.0 - 'key' SQL Injection
CVE-2006-5640webappsasp
SQL injection vulnerability in guestbookview.asp in Techno Dreams Guest Book 1.0 earlier allows remote attackers to exec
23RISCO
abrir
Referência
CVE-2009-4624
SQL injection vulnerability in download.php in Nicecoder iDesk allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
ReferênciaVexDay Proof
Techno Dreams Announcement - 'key' SQL Injection
CVE-2006-5641webappsasp
SQL injection vulnerability in MainAnnounce2.asp in Techno Dreams Announcement allows remote attackers to execute arbitr
23RISCO
abrir
Referência
CVE-2020-8515
CVE-2020-8515CRITICALsob ataque
DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow
100RISCO
abrir
Referência
CVE-2018-7600
CVE-2018-7600CRITICALsob ataqueransomware
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
Referência
CVE-2018-7600
CVE-2018-7600CRITICALsob ataqueransomware
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
Referência
CVE-2018-7600
CVE-2018-7600CRITICALsob ataqueransomware
Drupal before 7.58, 8.x before 8.3.9, 8.4.x before 8.4.6, and 8.5.x before 8.5.1 allows remote attackers to execute arbi
100RISCO
abrir
ReferênciaVexDay Proof
phpBB Spider Friendly Module 1.3.10 - Remote File Inclusion
CVE-2006-5665webappsphp
PHP remote file inclusion vulnerability in admin/modules_data.php in the phpBB module Spider Friendly 1.3.10 and earlier
23RISCO
abrir
ReferênciaVexDay Proof
MySource CMS 2.16.2 - 'init_mysource.php' Remote File Inclusion
CVE-2006-5672webappsphp
PHP remote file inclusion vulnerability in web/init_mysource.php in MySource CMS 2.16.2 and earlier allows remote attack
23RISCO
abrir
ReferênciaVexDay Proof
MiniBB 2.0.2 - 'bb_func_txt.php' Remote File Inclusion
CVE-2006-5673webappsphp
PHP remote file inclusion vulnerability in bb_func_txt.php in miniBB 2.0.2 and earlier, when register_globals is enabled
23RISCO
abrir
ReferênciaVexDay Proof
Easy File Sharing Web Server 4 - Remote Information Stealer
CVE-2006-5714remotewindows
Easy File Sharing (EFS) Web Server 4.0, when running on an NTFS file system, allows remote attackers to read arbitrary f
23RISCO
abrir
ReferênciaVexDay Proof
EFS Easy Address Book Web Server 1.2 - Remote File Stream
CVE-2006-5715remotewindows
Easy File Sharing (EFS) Easy Address Book 1.2, when run on an NTFS file system, allows remote attackers to read arbitrar
23RISCO
abrir
anteriorpágina 348 / 730próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.