Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.596exploits catalogados
36.656CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
Mailist 3.0 - Insecure Backup / Local File Inclusion
CVE-2009-0570webappsphp
Directory traversal vulnerability in send.php in Ninja Designs Mailist 3.0, when register_globals is enabled and magic_q
23RISCO
abrir
ReferênciaVexDay Proof
RunCMS 1.5.2 - 'debug_show.php' SQL Injection
CVE-2007-2538webappsphp
SQL injection vulnerability in class/debug/debug_show.php in RunCms 1.5.2 and earlier allows remote attackers to execute
23RISCO
abrir
ReferênciaVexDay Proof
Flatnux 2009-01-27 - Remote File Inclusion
CVE-2009-0572webappsphp
PHP remote file inclusion vulnerability in include/flatnux.php in FlatnuX CMS (aka Flatnuke3) 2009-01-27 and 2009-02-04,
23RISCO
abrir
ReferênciaVexDay Proof
Barracuda Web Application Firewall - Authentication Bypass
CVE-2014-2595remotehardware
Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a perm
28RISCO
abrir
ReferênciaVexDay Proof
QuickTicket 1.5 - 'qti_usr.php' SQL Injection
CVE-2007-3539webappsphp
Multiple SQL injection vulnerabilities in QuickTicket 1.2 build:20070621 and QuickTalk Forum 1.3 allow remote attackers
23RISCO
abrir
ReferênciaVexDay Proof
Microsoft Visual 6 - 'VDT70.dll NotSafe' Remote Stack Overflow
CVE-2007-4254remotewindows
Stack-based buffer overflow in a certain ActiveX control in VDT70.DLL in Microsoft Visual Database Tools Database Design
28RISCO
abrir
ReferênciaVexDay Proof
CMS Made Simple 1.2.4 Module FileManager - Arbitrary File Upload
CVE-2008-2267webappsphp
Incomplete blacklist vulnerability in javaUpload.php in Postlet in the FileManager module in CMS Made Simple 1.2.4 and e
23RISCO
abrir
ReferênciaVexDay Proof
mxCamArchive 2.2 - Bypass Configuration Download
CVE-2008-6956webappsphp
Static code injection vulnerability in admin/admin.php in mxCamArchive 2.2 allows remote authenticated administrators to
23RISCO
abrir
ReferênciaVexDay Proof
dBpowerAMP Audio Player 2 - '.m3u' Remote Buffer Overflow
CVE-2008-0661remotewindows
Buffer overflow in dBpowerAMP Audio Player Release 2 allows remote attackers to execute arbitrary code via a .M3U file w
23RISCO
abrir
ReferênciaVexDay Proof
PNPHPBB2 < 1.2i - 'ModName' Multiple Local File Inclusions
CVE-2009-0592webappsphp
Multiple directory traversal vulnerabilities in PNphpBB2 1.2i and earlier allow remote attackers to include and execute
28RISCO
abrir
ReferênciaVexDay Proof
phpskelsite 1.4 - Local File Inclusion / Remote File Inclusion / Cross-Site Scripting
CVE-2009-0596webappsphp
Directory traversal vulnerability in skysilver/login.tpl.php in phpSkelSite 1.4, when register_globals is enabled, allow
23RISCO
abrir
ReferênciaVexDay Proof
w3blabor CMS 3.3.0 - Authentication Bypass
CVE-2009-0597webappsphp
SQL injection vulnerability in admin/index.php in w3b>cms (aka w3blabor CMS) before 3.4.0, when magic_quotes_gpc is disa
23RISCO
abrir
ReferênciaVexDay Proof
Omegaboard 1.0beta4 - 'functions.php' Remote File Inclusion
CVE-2007-0683webappsphp
PHP remote file inclusion vulnerability in includes/functions.php in Omegaboard 1.0beta4 and earlier allows remote attac
23RISCO
abrir
ReferênciaVexDay Proof
Scripteen Free Image Hosting Script 1.2 - 'cookie' Pass Grabber
CVE-2008-3211webappsphp
Scripteen Free Image Hosting Script 1.2 and 1.2.1 allows remote attackers to bypass authentication and gain administrati
23RISCO
abrir
ReferênciaVexDay Proof
Jaws 0.8.8 - Multiple Local File Inclusions
CVE-2009-0645webappsphp
Directory traversal vulnerability in index.php in Jaws 0.8.8 allows remote authenticated users to read arbitrary files v
23RISCO
abrir
ReferênciaVexDay Proof
4Site CMS 2.6 - Multiple SQL Injections
CVE-2009-0646webappsphp
Multiple SQL injection vulnerabilities in 4Site CMS 2.6 and earlier allow remote attackers to execute arbitrary SQL comm
23RISCO
abrir
ReferênciaVexDay Proof
Nokia N95-8 browser - 'setAttributeNode' Method Crash
CVE-2009-0649doshardware
The web browser in Symbian OS on the Nokia N95 cell phone allows remote attackers to cause a denial of service (crash) v
23RISCO
abrir
ReferênciaVexDay Proof
Nessus Vulnerability Scanner 3.0.6 - ActiveX Command Execution
CVE-2007-4061remotewindows
Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote attac
28RISCO
abrir
ReferênciaVexDay Proof
Data Dynamics ActiveBar - ActiveX 'actbar3.ocx 3.1' Insecure Methods
CVE-2007-3883remotewindows
The Data Dynamics ActiveBar ActiveX control (actbar3.ocx) 3.2 and earlier allows remote attackers to create or overwrite
23RISCO
abrir
ReferênciaVexDay Proof
TPTEST 3.1.7 - Stack Buffer Overflow (PoC)
CVE-2009-0650doswindows
Stack-based buffer overflow in the GetStatsFromLine function in TPTEST 3.1.7 and earlier, and possibly 5.02, allows remo
28RISCO
abrir
ReferênciaVexDay Proof
Web Content System 2.7.1 - Remote File Inclusion
CVE-2007-1771webappsphp
PHP remote file inclusion vulnerability in manage/javascript/formjavascript.php in Ay System Solutions Web Content Syste
23RISCO
abrir
ReferênciaVexDay Proof
Bea Weblogic Apache Connector - Code Execution / Denial of Service
CVE-2008-3257remotewindows
Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10
60RISCO
abrir
ReferênciaVexDay Proof
Adobe Acrobat Reader - JBIG2 Local Buffer Overflow (PoC) (2)
CVE-2009-0658doswindows
Buffer overflow in Adobe Reader 9.0 and earlier, and Acrobat 9.0 and earlier, allows remote attackers to execute arbitra
60RISCO
abrir
ReferênciaVexDay Proof
ravennuke 2.3.0 - Multiple Vulnerabilities
CVE-2009-0677webappsphp
avatarlist.php in the Your Account module, reached through modules.php, in Raven Web Services RavenNuke 2.30 allows remo
23RISCO
abrir
ReferênciaVexDay Proof
Netgear SSL312 Router - Denial of Service
CVE-2009-0680doshardware
cgi-bin/welcome/VPN_only in the web interface in Netgear SSL312 allows remote attackers to cause a denial of service (de
23RISCO
abrir
ReferênciaVexDay Proof
Trend Micro Internet Security Pro 2009 - Priviliege Escalation
CVE-2009-0686localwindows
The TrendMicro Activity Monitor Module (tmactmon.sys) 2.52.0.1002 in Trend Micro Internet Pro 2008 and 2009, and Securit
23RISCO
abrir
ReferênciaVexDay Proof
Lms 1.8.9 - Vala Remote File Inclusion
CVE-2007-1643webappsphp
Multiple PHP remote file inclusion vulnerabilities in LAN Management System (LMS) 1.8.9 Vala and earlier allow remote at
28RISCO
abrir
ReferênciaVexDay Proof
EZWebAlbum - Remote File Disclosure
CVE-2008-3293webappsphp
Directory traversal vulnerability in download.php in EZWebAlbum allows remote attackers to read arbitrary files via the
23RISCO
abrir
ReferênciaVexDay Proof
Focus/SIS 1.0/2.2 - Remote File Inclusion
CVE-2007-4806webappsphp
PHP remote file inclusion vulnerability in modules/Discipline/CategoryBreakdownTime.php in Focus/SIS 1.0 allows remote a
23RISCO
abrir
ReferênciaVexDay Proof
Coppermine Photo Gallery 1.4.18 - Local File Inclusion / Remote Code Execution
CVE-2008-3486webappsphp
Directory traversal vulnerability in the user_get_profile function in include/functions.inc.php in Coppermine Photo Gall
23RISCO
abrir
anteriorpágina 44 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.