Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.526exploits catalogados
36.593CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
Liberum Help Desk 0.97.3 - SQL Injection / File Disclosure
CVE-2008-6057webappsphp
Doug Luxem Liberum Help Desk 0.97.3 stores db/helpdesk2000.mdb under the web root with insufficient access control, whic
23RISCO
abrir
ReferênciaVexDay Proof
P-News 1.16/1.17 - 'user.dat' Remote Password Disclosure
CVE-2006-6888webappsphp
P-News 1.16 and 1.17 store sensitive information under the web root with insufficient access control, which allows remot
23RISCO
abrir
ReferênciaVexDay Proof
ColdFusion Scripts Red_Reservations - Database Disclosure
CVE-2008-6580webappsasp
The Red_Reservations script for ColdFusion stores sensitive information under the web root with insufficient access cont
23RISCO
abrir
ReferênciaVexDay Proof
Ocean12 FAQ Manager Pro - Database Disclosure
CVE-2008-7063webappsphp
Ocean12 FAQ Manager Pro stores sensitive data under the web root with insufficient access control, which allows remote a
23RISCO
abrir
ReferênciaVexDay Proof
PHPmotion 2.0 - 'update_profile.php' Arbitrary File Upload
CVE-2008-3118webappsphp
SQL injection vulnerability in play.php in PHPmotion 2.0 and earlier allows remote attackers to execute arbitrary SQL co
23RISCO
abrir
ReferênciaVexDay Proof
cf shopkart 5.2.2 - SQL Injection / File Disclosure
CVE-2008-6321webappsasp
CF Shopkart 5.2.2 stores cfshopkart52.mdb under the web root with insufficient access control, which allows remote attac
23RISCO
abrir
ReferênciaVexDay Proof
PhShoutBox 1.5 - Insecure Cookie Handling
CVE-2008-1971webappsphp
phShoutBox Final 1.5 and earlier only checks passwords when specified in $_POST, which allows remote attackers to gain p
23RISCO
abrir
ReferênciaVexDay Proof
DreamPics Builder - 'page' SQL Injection
CVE-2008-3119webappsphp
SQL injection vulnerability in index.php in DreamPics Builder allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
ReferênciaVexDay Proof
TopList 1.3.8 - 'phpBB Hack' Remote File Inclusion (1)
CVE-2006-2151webappsphp
PHP remote file inclusion vulnerability in toplist.php in phpBB TopList 1.3.8 and earlier, when register_globals is enab
28RISCO
abrir
ReferênciaVexDay Proof
Oracle 10g - 'LT.FINDRICSET' SQL Injection (IDS Evasion)
CVE-2007-5511localmultiple
SQL injection vulnerability in Workspace Manager for Oracle Database before OWM 10.2.0.4.1, OWM 10.1.0.8.0, and OWM 9.2.
50RISCO
abrir
ReferênciaVexDay Proof
Oracle 10g/11g - 'SYS.LT.FINDRICSET' SQL Injection (1)
CVE-2007-5511localmultiple
SQL injection vulnerability in Workspace Manager for Oracle Database before OWM 10.2.0.4.1, OWM 10.1.0.8.0, and OWM 9.2.
50RISCO
abrir
ReferênciaVexDay Proof
Oracle 10g/11g - 'SYS.LT.FINDRICSET' SQL Injection (2)
CVE-2007-5511localmultiple
SQL injection vulnerability in Workspace Manager for Oracle Database before OWM 10.2.0.4.1, OWM 10.1.0.8.0, and OWM 9.2.
50RISCO
abrir
ReferênciaVexDay Proof
U&M Software JustBookIt 1.0 - Authentication Bypass
CVE-2008-6718webappsphp
U&M Software JustBookIt 1.0 does not require administrative authentication for all scripts in the admin/ directory, whic
23RISCO
abrir
ReferênciaVexDay Proof
Advanced Guestbook 2.4.0 - 'phpBB' File Inclusion
CVE-2006-2152webappsphp
PHP remote file inclusion vulnerability in admin/addentry.php in phpBB Advanced Guestbook 2.4.0 and earlier, when regist
23RISCO
abrir
ReferênciaVexDay Proof
XOOPS Module Lykos Reviews 1.00 - 'index.php' SQL Injection
CVE-2007-1817webappsphp
SQL injection vulnerability in index.php in the Lykos Reviews (lykos_reviews) 1.00 module for Xoops allows remote attack
23RISCO
abrir
ReferênciaVexDay Proof
Zomplog 3.8 - 'mp3playlist.php' SQL Injection
CVE-2007-2773webappsphp
SQL injection vulnerability in plugins/mp3playlist/mp3playlist.php in Zomplog 3.8 and earlier allows remote attackers to
23RISCO
abrir
ReferênciaVexDay Proof
LimeSurvey 1.52 - 'language.php' Remote File Inclusion
CVE-2007-5573webappsphp
PHP remote file inclusion vulnerability in classes/core/language.php in LimeSurvey 1.5.2 and earlier allows remote attac
23RISCO
abrir
ReferênciaVexDay Proof
awzMB 4.2 Beta 1 - Multiple Remote File Inclusions
CVE-2007-5592webappsphp
Multiple PHP remote file inclusion vulnerabilities in awzMB 4.2 beta 1 and earlier allow remote attackers to execute arb
28RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component BibTeX 1.3 - Blind SQL Injection
CVE-2007-4502webappsphp
SQL injection vulnerability in index.php in the BibTeX component (com_jombib) 1.3 and earlier for Joomla! allows remote
23RISCO
abrir
ReferênciaVexDay Proof
HIOX Banner Rotator 1.3 - 'hm' Remote File Inclusion
CVE-2008-3127webappsphp
PHP remote file inclusion vulnerability in hioxBannerRotate.php in HIOX Banner Rotator (HBR) 1.3, when register_globals
23RISCO
abrir
ReferênciaVexDay Proof
TOWeLS 0.1 - 'scripture.php' Remote File Inclusion
CVE-2007-5628webappsphp
PHP remote file inclusion vulnerability in src/scripture.php in The Online Web Library Site (TOWels) 0.1 allows remote a
28RISCO
abrir
ReferênciaVexDay Proof
CcMail 1.0.1 - Insecure Cookie Handling
CVE-2008-1904webappsphp
Cicoandcico CcMail 1.0.1 and earlier does not verify that the this_cookie cookie corresponds to an authenticated session
23RISCO
abrir
ReferênciaVexDay Proof
Download Accelerator Plus DAP 8.x - '.m3u' File Buffer Overflow
CVE-2008-3182localwindows
Stack-based buffer overflow in DAP.exe in Download Accelerator Plus (DAP) 7.0.1.3, 8.6.6.3, and other 8.x versions allow
23RISCO
abrir
ReferênciaVexDay Proof
CCLeague Pro 1.2 - Insecure Cookie Authentication
CVE-2008-5125webappsphp
admin.php in CCleague Pro 1.2 allows remote attackers to bypass authentication by setting the type cookie value to admin
23RISCO
abrir
ReferênciaVexDay Proof
4Images 1.7.7 - Filter Bypass HTML Injection / Cross-Site Scripting
CVE-2009-2131webappsphp
Cross-site scripting (XSS) vulnerability in 4images 1.7.7 and earlier allows remote authenticated users to inject arbitr
23RISCO
abrir
ReferênciaVexDay Proof
xNews 1.3 - 'xNews.php' SQL Injection
CVE-2007-0569webappsphp
SQL injection vulnerability in xNews.php in xNews 1.3 allows remote attackers to execute arbitrary SQL commands via the
23RISCO
abrir
ReferênciaVexDay Proof
X-ice News System 1.0 - 'devami.asp?id' SQL Injection
CVE-2007-1438webappsasp
SQL injection vulnerability in devami.asp in X-Ice News System 1.0 allows remote attackers to execute arbitrary SQL comm
23RISCO
abrir
ReferênciaVexDay Proof
ImperialBB 2.3.5 - Arbitrary File Upload
CVE-2008-3093webappsphp
Unrestricted file upload vulnerability in ImperialBB 2.3.5 and earlier allows remote authenticated users to upload and e
23RISCO
abrir
ReferênciaVexDay Proof
XOOPS Module Friendfinder 3.3 - 'view.php?id' SQL Injection
CVE-2007-1838webappsphp
SQL injection vulnerability in view.php in the Friendfinder 3.3 and earlier module for Xoops allows remote attackers to
23RISCO
abrir
ReferênciaVexDay Proof
BBPortalS 2.0 - Blind SQL Injection
CVE-2007-5630webappsphp
SQL injection vulnerability in tnews.php in BBsProcesS BBPortalS 1.5.10 through 2.0 allows remote attackers to execute a
23RISCO
abrir
anteriorpágina 36 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.