Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.058exploits catalogados
35.300CVEs com exploração pública
24.695testados em laboratório
24.451 exploits
Exploit-DBVexDay Proof
Kasseler CMS - File Disclosure / Cross-Site Scripting
CVE-2009-2228webappsphp22 jun 2009
Cross-site scripting (XSS) vulnerability in engine.php in Kasseler CMS allows remote attackers to inject arbitrary web s
23RISCO
abrir
Exploit-DBVexDay Proof
AWScripts Gallery Search Engine 1.x - Insecure Cookie
CVE-2009-2233webappsphp22 jun 2009
The admin interface in AWScripts.com Gallery Search Engine 1.5 allows remote attackers to bypass authentication and gain
23RISCO
abrir
Exploit-DBVexDay Proof
MyBB 1.4.6 - Remote Code Execution
CVE-2009-2230webappsphp22 jun 2009
SQL injection vulnerability in inc/datahandlers/user.php in MyBB (aka MyBulletinBoard) before 1.4.7 allows remote authen
23RISCO
abrir
Exploit-DBVexDay Proof
MIDAS 1.43 - (Authentication Bypass) Insecure Cookie Handling
CVE-2009-2231webappscgi22 jun 2009
MIDAS 1.43 allows remote attackers to bypass authentication and obtain administrative access via an admin account record
23RISCO
abrir
Exploit-DBVexDay Proof
Bopup Communications Server 3.2.26.5460 - Remote SYSTEM
CVE-2009-2227remotewindows22 jun 2009
Stack-based buffer overflow in B Labs Bopup Communication Server 3.2.26.5460 allows remote attackers to execute arbitrar
50RISCO
abrir
Exploit-DBVexDay Proof
phpMyAdmin - 'pmaPWN!' Code Injection / Remote Code Execution
CVE-2009-1151CRITICALsob ataquewebappsphp22 jun 2009
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remo
100RISCO
abrir
Exploit-DBVexDay Proof
Kasseler CMS - File Disclosure / Cross-Site Scripting
CVE-2009-2229webappsphp22 jun 2009
Directory traversal vulnerability in engine.php in Kasseler CMS 1.3.5 lite allows remote attackers to read arbitrary fil
23RISCO
abrir
Exploit-DBVexDay Proof
Mozilla Firefox 3.0.11 and Thunderbird 2.0.9 - RDF File Handling Remote Memory Corruption
CVE-2009-2464doslinux21 jun 2009
The nsXULTemplateQueryProcessorRDF::CheckIsSeparator function in Mozilla Firefox before 3.0.12, SeaMonkey 2.0a1pre, and
28RISCO
abrir
Exploit-DBVexDay Proof
Programs Rating - 'postcomments.php?id' Cross-Site Scripting
CVE-2009-4690webappsphp20 jun 2009
Multiple cross-site scripting (XSS) vulnerabilities in YourFreeWorld Programs Rating Script allow remote attackers to in
23RISCO
abrir
Exploit-DBVexDay Proof
Programs Rating - 'rate.php?id' Cross-Site Scripting
CVE-2009-4690webappsphp20 jun 2009
Multiple cross-site scripting (XSS) vulnerabilities in YourFreeWorld Programs Rating Script allow remote attackers to in
23RISCO
abrir
Exploit-DBVexDay Proof
Edraw PDF Viewer Component < 3.2.0.126 - ActiveX Insecure Method
CVE-2009-2169remotewindows18 jun 2009
Insecure method vulnerability in the PDFVIEWER.PDFViewerCtrl.1 ActiveX control (pdfviewer.ocx) in Edraw PDF Viewer Compo
23RISCO
abrir
Exploit-DBVexDay Proof
DESlock+ 4.0.2 - 'dlpcrypt.sys' Local Kernel Ring0 Code Execution
CVE-2009-4832localwindows18 jun 2009
The dlpcrypt.sys kernel driver 0.1.1.27 in DESlock+ 4.0.2 allows local users to gain privileges via a crafted IOCTL 0x80
23RISCO
abrir
Exploit-DBVexDay Proof
Compface 1.5.2 - '.xbm' Local Buffer Overflow (PoC)
CVE-2009-2286doslinux17 jun 2009
Buffer overflow in compface 1.5.2 and earlier allows user-assisted attackers to cause a denial of service (crash) via a
23RISCO
abrir
Exploit-DBVexDay Proof
iDefense COMRaider - ActiveX Control Multiple Insecure Method Vulnerabilities
CVE-2009-3860remotewindows17 jun 2009
Multiple insecure method vulnerabilities in Idefense Labs COMRaider allow remote attackers to create or overwrite arbitr
23RISCO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.6.30 - 'tun_chr_pool()' Null Pointer Dereference
CVE-2009-1897doslinux17 jun 2009
The tun_chr_poll function in drivers/net/tun.c in the tun subsystem in the Linux kernel 2.6.30 and 2.6.30.1, when the -f
23RISCO
abrir
Exploit-DBVexDay Proof
formmail 1.92 - Multiple Vulnerabilities
CVE-2009-1776webappsphp15 jun 2009
Multiple cross-site scripting (XSS) vulnerabilities in FormMail.pl in Matt Wright FormMail 1.92, and possibly earlier, a
23RISCO
abrir
Exploit-DBVexDay Proof
SugarCRM 5.2.0e - Remote Code Execution
CVE-2009-2146webappsphp15 jun 2009
Unrestricted file upload vulnerability in the Compose Email feature in the Emails module in Sugar Community Edition (aka
28RISCO
abrir
Exploit-DBVexDay Proof
Netgear DG632 Router - Authentication Bypass
CVE-2009-2257remotehardware15 jun 2009
The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to bypass authentic
23RISCO
abrir
Exploit-DBVexDay Proof
Netgear DG632 Router - Authentication Bypass
CVE-2009-2258remotehardware15 jun 2009
Directory traversal vulnerability in cgi-bin/webcm in the administrative web interface on the Netgear DG632 with firmwar
23RISCO
abrir
Exploit-DBVexDay Proof
formmail 1.92 - Multiple Vulnerabilities
CVE-2009-1777webappsphp15 jun 2009
CRLF injection vulnerability in FormMail.pl in Matt Wright FormMail 1.92, and possibly earlier, allows remote attackers
23RISCO
abrir
Exploit-DBVexDay Proof
Netgear DG632 Router - Remote Denial of Service
CVE-2009-2256doshardware15 jun 2009
The administrative web interface on the Netgear DG632 with firmware 3.4.0_ap allows remote attackers to cause a denial o
23RISCO
abrir
Exploit-DBVexDay Proof
Oracle 9i/10g Database - Network Foundation Remote Overflow
CVE-2009-1020remotemultiple14 jun 2009
Unspecified vulnerability in the Network Foundation component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4,
28RISCO
abrir
Exploit-DBVexDay Proof
Oracle 9i/10g Database - TNS Command Remote Denial of Service
CVE-2009-1970dosmultiple14 jun 2009
Unspecified vulnerability in the Listener component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.
28RISCO
abrir
Exploit-DBVexDay Proof
Oracle 9i/10g Database - Remote Network Authentication
CVE-2009-1019remotemultiple14 jun 2009
Unspecified vulnerability in the Network Authentication component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.
28RISCO
abrir
Exploit-DBVexDay Proof
Oracle WebLogic Server 10.3 - 'console-help.portal' Cross-Site Scripting
CVE-2009-1975remotemultiple14 jun 2009
Unspecified vulnerability in the WebLogic Server component in BEA Product Suite 10.3 allows remote attackers to affect c
23RISCO
abrir
Exploit-DBVexDay Proof
Oracle 11.1 - Database Network Foundation Heap Memory Corruption
CVE-2009-1963dosmultiple14 jun 2009
Unspecified vulnerability in the Network Foundation component in Oracle Database 11.1.0.6 allows remote authenticated us
23RISCO
abrir
Exploit-DBVexDay Proof
Scriptsez Easy Image Downloader - 'id' Cross-Site Scripting
CVE-2009-2551webappsphp14 jun 2009
Multiple cross-site scripting (XSS) vulnerabilities in ScriptsEz Easy Image Downloader allow remote attackers to inject
23RISCO
abrir
Exploit-DBVexDay Proof
Oracle 10g Secure Enterprise Search - 'search_p_groups' Cross-Site Scripting
CVE-2009-1968remotemultiple14 jun 2009
Unspecified vulnerability in the Secure Enterprise Search component in Oracle Database 10.1.8.3 allows remote attackers
35RISCO
abrir
Exploit-DBVexDay Proof
HP ProCurve Threat Management Services - zl ST.1.0.090213 Module CRL Security Bypass
CVE-2009-1422remotemultiple13 jun 2009
Unspecified vulnerability in HP ProCurve Threat Management Services zl Module (J9155A) ST.1.0.090213 and earlier allows
23RISCO
abrir
Exploit-DBVexDay Proof
4Images 1.7.7 - Filter Bypass HTML Injection / Cross-Site Scripting
CVE-2009-2132webappsphp12 jun 2009
Directory traversal vulnerability in global.php in 4images before 1.7.7, when magic_quotes_gpc is disabled, allows remot
23RISCO
abrir
anteriorpágina 443 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.