Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.526exploits catalogados
36.593CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
sma-db 0.3.12 - Remote File Inclusion / Cross-Site Scripting
CVE-2009-1451webappsphp
Cross-site scripting (XSS) vulnerability in startpage.php in SMA-DB 0.3.12 allows remote attackers to inject arbitrary w
23RISCO
abrir
ReferênciaVexDay Proof
LokiCMS 0.3.4 - 'index.php' Arbitrary Check File
CVE-2008-5965webappsphp
Directory traversal vulnerability in index.php in LokiCMS 0.3.4 and earlier, when magic_quotes_gpc is disabled, allows r
23RISCO
abrir
ReferênciaVexDay Proof
OpenSSL 0.9.8c-1 < 0.9.8g-9 (Debian and Derivatives) - Predictable PRNG Brute Force SSH (Ruby)
CVE-2008-0166remotelinux
OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that ge
45RISCO
abrir
ReferênciaVexDay Proof
SunByte e-Flower - 'id' SQL Injection
CVE-2008-5969webappsphp
SQL injection vulnerability in popupproduct.php in Sunbyte e-Flower allows remote attackers to execute arbitrary SQL com
23RISCO
abrir
ReferênciaVexDay Proof
Ocean12 Mailing List Manager Gold - File Disclosure / SQL Injection / Cross-Site Scripting
CVE-2008-5979webappsphp
Cross-site scripting (XSS) vulnerability in default.asp in Ocean12 Mailing List Manager Gold allows remote attackers to
23RISCO
abrir
ReferênciaVexDay Proof
Jetik Emlak ESA 2.0 - Multiple SQL Injections
CVE-2008-5992webappsphp
Multiple SQL injection vulnerabilities in Jetik Emlak Sistem A (ESA) 2.0 allow remote attackers to execute arbitrary SQL
23RISCO
abrir
ReferênciaVexDay Proof
Microsoft Internet Explorer 6 - 'mshtml.dll' Null Pointer Dereference
CVE-2007-0811doswindows
Microsoft Internet Explorer 6.0 SP1 on Windows 2000, and 6.0 SP2 on Windows XP, allows remote attackers to cause a denia
28RISCO
abrir
ReferênciaVexDay Proof
QuickTime Player 7.3.1.70 - 'RTSP' Remote Buffer Overflow
CVE-2008-0234remotewindows
Buffer overflow in Apple Quicktime Player 7.3.1.70 and other versions before 7.4.1, when RTSP tunneling is enabled, allo
28RISCO
abrir
ReferênciaVexDay Proof
WordPress Plugin Download Manager 0.2 - Arbitrary File Upload
CVE-2008-3362webappsphp
Unrestricted file upload vulnerability in upload.php in the Giulio Ganci Wp Downloads Manager module 0.2 for WordPress a
28RISCO
abrir
ReferênciaVexDay Proof
SG Real Estate Portal 2.0 - Blind SQL Injection
CVE-2008-6011webappsphp
SQL injection vulnerability in index.php in SG Real Estate Portal 2.0 allows remote attackers to execute arbitrary SQL c
23RISCO
abrir
ReferênciaVexDay Proof
SG Real Estate Portal 2.0 - Blind SQL Injection / Local File Inclusion
CVE-2008-6011webappsphp
SQL injection vulnerability in index.php in SG Real Estate Portal 2.0 allows remote attackers to execute arbitrary SQL c
23RISCO
abrir
ReferênciaVexDay Proof
phpskelsite 1.4 - Local File Inclusion / Remote File Inclusion / Cross-Site Scripting
CVE-2009-0595webappsphp
PHP remote file inclusion vulnerability in skysilver/login.tpl.php in phpSkelSite 1.4, when register_globals is enabled
28RISCO
abrir
ReferênciaVexDay Proof
XNova 0.8 sp1 - 'xnova_root_path' Remote File Inclusion
CVE-2008-6022webappsphp
PHP remote file inclusion vulnerability in includes/todofleetcontrol.php in an older version of Xnova, possibly 0.8 sp1,
23RISCO
abrir
ReferênciaVexDay Proof
XNova 0.8 sp1 - 'xnova_root_path' Remote File Inclusion
CVE-2008-6023webappsphp
PHP remote file inclusion vulnerability in includes/todofleetcontrol.php in a newer version of Xnova, possibly 0.8 sp1,
23RISCO
abrir
ReferênciaVexDay Proof
WSN Links 2.20 - 'comments.php' SQL Injection
CVE-2008-6033webappsphp
SQL injection vulnerability in comments.php in WSN Links 2.20 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
ReferênciaVexDay Proof
PHP-Post 1.0 - Cookie Modification Privilege Escalation
CVE-2006-3772webappsphp
PHP-Post 0.21 and 1.0, and possibly earlier versions, when auto-login is enabled, allows remote attackers to bypass secu
28RISCO
abrir
ReferênciaVexDay Proof
AvailScript Article Script - 'view.php' SQL Injection
CVE-2008-6037webappsphp
SQL injection vulnerability in view.php in AvailScript Article Script allows remote attackers to execute arbitrary SQL c
23RISCO
abrir
ReferênciaVexDay Proof
DomPHP 0.81 - 'cat' SQL Injection
CVE-2008-6064webappsphp
Multiple SQL injection vulnerabilities in DomPHP 0.81 allow remote attackers to execute arbitrary SQL commands via the c
23RISCO
abrir
ReferênciaVexDay Proof
TaskFreak! 0.6.1 - SQL Injection
CVE-2008-0270webappsphp
SQL injection vulnerability in index.php in TaskFreak! 0.6.1 and earlier allows remote authenticated users to execute ar
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component JoomlaDate 1.2 - 'user' SQL Injection
CVE-2008-6068webappsphp
SQL injection vulnerability in the JoomlaDate (com_joomladate) component 1.2 for Joomla! allows remote attackers to exec
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component Daily Message 1.0.3 - 'id' SQL Injection
CVE-2008-6076webappsphp
SQL injection vulnerability in the Daily Message (com_dailymessage) 1.0.3 component for Joomla! allows remote attackers
23RISCO
abrir
ReferênciaVexDay Proof
Simple Customer 1.2 - 'contact.php' SQL Injection
CVE-2008-6081webappsphp
SQL injection vulnerability in contact.php in Simple Customer 1.2 allows remote attackers to execute arbitrary SQL comma
23RISCO
abrir
ReferênciaVexDay Proof
Iamma Simple Gallery 1.0/2.0 - Arbitrary File Upload
CVE-2008-6084webappsphp
Unrestricted file upload vulnerability in pages/download.php in Iamma Simple Gallery 1.0 and 2.0 allows remote attackers
23RISCO
abrir
ReferênciaVexDay Proof
Camera Life 2.6.2b4 - SQL Injection / Cross-Site Scripting
CVE-2008-6086webappsphp
SQL injection vulnerability in album.php in Camera Life 2.6.2b4 allows remote attackers to execute arbitrary SQL command
23RISCO
abrir
ReferênciaVexDay Proof
DigitalHive 2.0 RC2 - 'user_id' SQL Injection
CVE-2008-0290webappsphp
Multiple SQL injection vulnerabilities in Digital Hive 2.0 RC2 and earlier allow (1) remote attackers to execute arbitra
23RISCO
abrir
ReferênciaVexDay Proof
RichStrong CMS - 'cat' SQL Injection
CVE-2008-0291webappsasp
SQL injection vulnerability in showproduct.asp in RichStrong CMS allows remote attackers to execute arbitrary SQL comman
23RISCO
abrir
ReferênciaVexDay Proof
T-Dreams Job Career Package 3.0 - Insecure Cookie Handling
CVE-2009-1638webappsasp
Techno Dreams Job Career Package 3.0 allows remote attackers to bypass authentication and obtain administrative access b
23RISCO
abrir
ReferênciaVexDay Proof
phpscripts Ranking Script - Insecure Cookie Handling
CVE-2008-6092webappsphp
phpscripts Ranking Script allows remote attackers to bypass authentication and gain administrative access by sending an
23RISCO
abrir
ReferênciaVexDay Proof
Noname CMS 1.0 - Multiple SQL Injections
CVE-2008-6093webappsphp
SQL injection vulnerability in index.php in Noname CMS 1.0, when magic_quotes_gpc is disabled, allows remote attackers t
23RISCO
abrir
ReferênciaVexDay Proof
FaScript FaPersian Petition - SQL Injection
CVE-2008-0325webappsphp
SQL injection vulnerability in show.php in FaScript FaPersian Petition allows remote attackers to execute arbitrary SQL
23RISCO
abrir
anteriorpágina 35 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.