Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.056exploits catalogados
37.663CVEs com exploração pública
24.695testados em laboratório
24.482 exploits
Exploit-DBVexDay Proof
SIMM Management System (SMS) - Local File Inclusion
CVE-2010-2313webappsphp02 jun 2010
Directory traversal vulnerability in index.php in Anodyne Productions SIMM Management System (SMS) 2.6.10, when magic_qu
23RISCO
abrir
Exploit-DBVexDay Proof
TCExam 10.1.7 - '/admin/code/tce_functions_tcecode_editor.php' Arbitrary File Upload
CVE-2010-2153webappsphp02 jun 2010
Unrestricted file upload vulnerability in admin/code/tce_functions_tcecode_editor.php in TCExam 10.1.006 and 10.1.007 al
23RISCO
abrir
Exploit-DBVexDay Proof
DM Database Server - 'SP_DEL_BAK_EXPIRED' Memory Corruption
CVE-2010-2159dosmultiple31 mai 2010
Dameng DM Database Server allows remote authenticated users to cause a denial of service (crash) and possibly execute ar
23RISCO
abrir
Exploit-DB
Joomla! Component JS Jobs 1.0.5.8 - SQL Injection
CVE-2009-4599webappsphp31 mai 2010
Multiple SQL injection vulnerabilities in the JS Jobs (com_jsjobs) component 1.0.5.6 for Joomla! allow remote attackers
23RISCO
abrir
Exploit-DBVexDay Proof
Visitor Logger - 'banned.php' Remote File Inclusion
CVE-2010-2146webappsphp31 mai 2010
PHP remote file inclusion vulnerability in banned.php in Visitor Logger allows remote attackers to execute arbitrary PHP
23RISCO
abrir
Exploit-DBVexDay Proof
CMScout - Cross-Site Scripting / HTML Injection
CVE-2010-2154webappsphp30 mai 2010
Cross-site scripting (XSS) vulnerability in the Search Site in CMScout 2.09, and possibly other versions, allows remote
23RISCO
abrir
Exploit-DBVexDay Proof
Symphony CMS - Local File Inclusion
CVE-2010-2143webappsphp30 mai 2010
Directory traversal vulnerability in index.php in Symphony CMS 2.0.7 allows remote attackers to read arbitrary files and
23RISCO
abrir
Exploit-DBVexDay Proof
Zeeways Script - Multiple Vulnerabilities
CVE-2010-2144webappsphp30 mai 2010
Cross-site scripting (XSS) vulnerability in signinform.php in Zeeways eBay Clone Auction Script allows remote attackers
23RISCO
abrir
Exploit-DB
Nucleus Plugin Twitter - Remote File Inclusion
CVE-2010-2314webappsphp29 mai 2010
PHP remote file inclusion vulnerability in nucleus/plugins/NP_Twitter.php in the NP_Twitter Plugin 0.8 and 0.9 for Nucle
23RISCO
abrir
Exploit-DBVexDay Proof
Nucleus Plugin Gallery - Remote File Inclusion / SQL Injection
CVE-2010-5041webappsphp29 mai 2010
SQL injection vulnerability in index.php in the NP_Gallery plugin 0.94 for Nucleus allows remote attackers to execute ar
23RISCO
abrir
Exploit-DBVexDay Proof
fusebox - 'ProductList.cfm?CatDisplay' SQL Injection
CVE-2010-5033webappswindows29 mai 2010
SQL injection vulnerability in ProductList.cfm in Fusebox 5.5.1 allows remote attackers to execute arbitrary SQL command
23RISCO
abrir
Exploit-DBVexDay Proof
Nucleus Plugin Gallery - Remote File Inclusion / SQL Injection
CVE-2010-5040webappsphp29 mai 2010
PHP remote file inclusion vulnerability in nucleus/plugins/NP_gallery.php in the NP_Gallery plugin 0.94 for Nucleus allo
23RISCO
abrir
Exploit-DBVexDay Proof
Joomla! Component BF Quiz 1.0 - SQL Injection (2)
CVE-2010-5032webappsphp29 mai 2010
SQL injection vulnerability in the BF Quiz (com_bfquiztrial) component before 1.3.1 for Joomla! allows remote attackers
23RISCO
abrir
Exploit-DBVexDay Proof
Joomla! Component JE Job 1.0 - 'catid' SQL Injection
CVE-2010-5028webappsphp28 mai 2010
SQL injection vulnerability in the JExtensions JE Job (com_jejob) component 1.0 for Joomla! allows remote attackers to e
38RISCO
abrir
Exploit-DBVexDay Proof
Joomla! Component My Car 1.0 - Multiple Vulnerabilities
CVE-2010-2147webappsphp28 mai 2010
Cross-site scripting (XSS) vulnerability in the My Car (com_mycar) component 1.0 for Joomla! allows remote attackers to
23RISCO
abrir
Exploit-DBVexDay Proof
Joomla! Component My Car 1.0 - Multiple Vulnerabilities
CVE-2010-2148webappsphp28 mai 2010
SQL injection vulnerability in the My Car (com_mycar) component 1.0 for Joomla! allows remote attackers to execute arbit
23RISCO
abrir
Exploit-DBVexDay Proof
Joomla! Component BF Quiz 1.3.0 - SQL Injection (1)
CVE-2010-5032webappsphp28 mai 2010
SQL injection vulnerability in the BF Quiz (com_bfquiztrial) component before 1.3.1 for Joomla! allows remote attackers
23RISCO
abrir
Exploit-DBVexDay Proof
FreeBSD 8.0 - 'ftpd' (FreeBSD-SA-10:05) Off-By-One (PoC)
CVE-2010-1938dosfreebsd27 mai 2010
Off-by-one error in the __opiereadrec function in readrec.c in libopie in OPIE 2.4.1-test1 and earlier, as used on FreeB
28RISCO
abrir
Exploit-DBVexDay Proof
Adobe Photoshop CS4 Extended 11.0 - '.GRD' File Handling Remote Buffer Overflow (PoC)
CVE-2010-1296doswindows26 mai 2010
Multiple buffer overflows in Adobe Photoshop CS4 before 11.0.2 allow user-assisted remote attackers to execute arbitrary
28RISCO
abrir
Exploit-DBVexDay Proof
Adobe Photoshop CS4 Extended 11.0 - '.ABR' File Handling Remote Buffer Overflow (PoC)
CVE-2010-1296doswindows26 mai 2010
Multiple buffer overflows in Adobe Photoshop CS4 before 11.0.2 allow user-assisted remote attackers to execute arbitrary
28RISCO
abrir
Exploit-DBVexDay Proof
Adobe Photoshop CS4 Extended 11.0 - '.ASL' File Handling Remote Buffer Overflow (PoC)
CVE-2010-1296doswindows26 mai 2010
Multiple buffer overflows in Adobe Photoshop CS4 before 11.0.2 allow user-assisted remote attackers to execute arbitrary
28RISCO
abrir
Exploit-DBVexDay Proof
Worldweaver DX Studio Player 3.0.29 - 'shell.execute()' Command Execution (Metasploit)
CVE-2009-2011remotewindows26 mai 2010
Worldweaver DX Studio Player 3.0.29.0, 3.0.22.0, 3.0.12.0, and probably other versions before 3.0.29.1, when used as a p
50RISCO
abrir
Exploit-DBVexDay Proof
Nitro Web Gallery - SQL Injection
CVE-2010-2141webappsphp25 mai 2010
SQL injection vulnerability in index.php in NITRO Web Gallery allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
Exploit-DBVexDay Proof
Webby WebServer - Overflow (SEH) (PoC)
CVE-2010-2102doswindows25 mai 2010
Buffer overflow in Webby Webserver 1.01 allows remote attackers to execute arbitrary code via a long HTTP GET request.
23RISCO
abrir
Exploit-DBVexDay Proof
Cisco DPC2100 2.0.2 r1256-060303 - Multiple Security Bypass / Cross-Site Request Forgery Vulnerabilities
CVE-2010-2025remotehardware24 mai 2010
Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface on the Cisco Scientific Atlanta WebSTAR
23RISCO
abrir
Exploit-DBVexDay Proof
e107 - Code Exection
CVE-2010-2099webappsmultiple24 mai 2010
bbcode/php.bb in e107 0.7.20 and earlier does not perform access control checks for all inputs that could contain the ph
23RISCO
abrir
Exploit-DBVexDay Proof
RazorCMS 1.0 - '/admin/index.php' HTML Injection
CVE-2010-5051webappsphp24 mai 2010
Cross-site scripting (XSS) vulnerability in admin/core/admin_func.php in razorCMS 1.0 stable allows remote attackers to
23RISCO
abrir
Exploit-DBVexDay Proof
Joomla! Component Q-Personel 1.0 - SQL Injection
CVE-2010-1720webappsphp24 mai 2010
SQL injection vulnerability in the Q-Personel (com_qpersonel) component 1.0.2 and earlier for Joomla! allows remote atta
23RISCO
abrir
Exploit-DB
Microsoft Outlook Web Access (OWA) 8.2.254.0 - Information Disclosure
CVE-2010-2091webappswindows24 mai 2010
Microsoft Outlook Web Access (OWA) 8.2.254.0, when Internet Explorer 7 on Windows Server 2003 is used, does not properly
28RISCO
abrir
Exploit-DB
LiSK CMS 4.4 - SQL Injection
CVE-2010-2015webappsphp24 mai 2010
Multiple SQL injection vulnerabilities in LiSK CMS 4.4 allow remote attackers to execute arbitrary SQL commands via (1)
23RISCO
abrir
anteriorpágina 375 / 817próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.