Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.058exploits catalogados
35.300CVEs com exploração pública
24.695testados em laboratório
24.451 exploits
Exploit-DBVexDay Proof
School Data Navigator - 'page' Local/Remote File Inclusion
CVE-2009-2641webappsphp10 jun 2009
PHP remote file inclusion vulnerability in app_and_readme/navigator/index.php in School Data Navigator allows remote att
23RISCO
abrir
Exploit-DBVexDay Proof
Desi Short URL Script - (Authentication Bypass) Insecure Cookie Handling
CVE-2009-2642webappsphp10 jun 2009
index.php in Desi Short URL Script 1.0 allows remote attackers to bypass authentication by setting the logged cookie to
23RISCO
abrir
Exploit-DBVexDay Proof
Joomla! Component com_realestatemanager 1.0 - Remote File Inclusion
CVE-2009-2635webappsphp09 jun 2009
PHP remote file inclusion vulnerability in toolbar_ext.php in the RealEstateManager (com_realestatemanager) component 1.
23RISCO
abrir
Exploit-DBVexDay Proof
Joomla! Component Akobook 2.3 - 'gbid' SQL Injection
CVE-2009-2638webappsphp09 jun 2009
SQL injection vulnerability in the AkoBook (com_akobook) component 2.3 for Joomla! allows remote attackers to execute ar
23RISCO
abrir
Exploit-DBVexDay Proof
Joomla! Component BookLibrary 1.5.2.4 - Remote File Inclusion
CVE-2009-2637webappsphp09 jun 2009
PHP remote file inclusion vulnerability in toolbar_ext.php in the BookLibrary (com_booklibrary) component 1.5.2.4 Basic
23RISCO
abrir
Exploit-DBVexDay Proof
Joomla! Component com_vehiclemanager 1.0 - Remote File Inclusion
CVE-2009-2633webappsphp09 jun 2009
PHP remote file inclusion vulnerability in toolbar_ext.php in the VehicleManager (com_vehiclemanager) component 1.0 Basi
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 5.0.1 - Cached Content Cross Domain Information Disclosure
CVE-2009-1140remotewindows09 jun 2009
Microsoft Internet Explorer 5.01 SP4; 6 SP1; 6 and 7 for Windows XP SP2 and SP3; 6 and 7 for Server 2003 SP2; 7 for Vist
28RISCO
abrir
Exploit-DBVexDay Proof
Joomla! Component com_media_library 1.5.3 - Remote File Inclusion
CVE-2009-2634webappsphp09 jun 2009
PHP remote file inclusion vulnerability in toolbar_ext.php in the MediaLibrary (com_media_library) component 1.5.3 Basic
23RISCO
abrir
Exploit-DBVexDay Proof
mrcgiguy the ticket system 2.0 PHP - Multiple Vulnerabilities
CVE-2009-2639webappsphp09 jun 2009
SQL injection vulnerability in admin.php in MRCGIGUY The Ticket System 2.0 allows remote attackers to execute arbitrary
23RISCO
abrir
Exploit-DBVexDay Proof
Winds3D Viewer 3 - 'GetURL()' Arbitrary File Download
CVE-2009-2386remotemultiple08 jun 2009
Insecure method vulnerability in Awingsoft Awakening Winds3D Viewer plugin 3.5.0.0, 3.0.0.5, and possibly other versions
23RISCO
abrir
Exploit-DBVexDay Proof
Interlogy Profile Manager Basic - Insecure Cookie Handling
CVE-2009-2640webappscgi08 jun 2009
Multiple SQL injection vulnerabilities in cgi/admin.cgi in Interlogy Profile Manager Basic allow remote attackers to exe
23RISCO
abrir
Exploit-DBVexDay Proof
MySQL 5.0.75 - 'sql_parse.cc' Multiple Format String Vulnerabilities
CVE-2009-2446doslinux08 jun 2009
Multiple format string vulnerabilities in the dispatch_command function in libmysqld/sql_parse.cc in mysqld in MySQL 4.0
28RISCO
abrir
Exploit-DBVexDay Proof
Computer Associates SiteMinder - '%00' Cross-Site Scripting Protection Security Bypass
CVE-2009-2704webappsphp08 jun 2009
CA SiteMinder allows remote attackers to bypass cross-site scripting (XSS) protections for J2EE applications via a reque
23RISCO
abrir
Exploit-DBVexDay Proof
Computer Associates SiteMinder - Unicode Cross-Site Scripting Protection Security Bypass
CVE-2009-2705webappsjava08 jun 2009
CA SiteMinder allows remote attackers to bypass cross-site scripting (XSS) protections for J2EE applications via a reque
23RISCO
abrir
Exploit-DBVexDay Proof
Avax Vector 1.3 - 'avPreview.ocx' ActiveX Control Buffer Overflow
CVE-2009-2377remotewindows06 jun 2009
Buffer overflow in the Avax Vector ActiveX control in avPreview.ocx in AVAX-software Avax Vector ActiveX 1.3 allows remo
23RISCO
abrir
Exploit-DBVexDay Proof
ClanSphere 2009 - 'text' Cross-Site Scripting
CVE-2009-2438webappsphp06 jun 2009
Cross-site scripting (XSS) vulnerability in index.php in the search module in ClanSphere 2009.0 and 2009.0.2 allows remo
23RISCO
abrir
Exploit-DBVexDay Proof
Horde 3.1 - 'Passwd' Module Cross-Site Scripting
CVE-2009-2360webappsphp05 jun 2009
Cross-site scripting (XSS) vulnerability in passwd/main.php in the Passwd module before 3.1.1 for Horde allows remote at
23RISCO
abrir
Exploit-DBVexDay Proof
PeaZIP 2.6.1 - Compressed Filename Command Injection
CVE-2009-2261localwindows05 jun 2009
PeaZIP 2.6.1, 2.5.1, and earlier on Windows allows user-assisted remote attackers to execute arbitrary commands via a .z
50RISCO
abrir
Exploit-DBVexDay Proof
Online Armor < 3.5.0.12 - 'OAmon.sys' Local Privilege Escalation
CVE-2009-2450localwindows04 jun 2009
The OAmon.sys kernel driver 3.1.0.0 and earlier in Tall Emu Online Armor Personal Firewall AV+ before 3.5.0.12, and Pers
23RISCO
abrir
Exploit-DBVexDay Proof
Google Chrome 0.3.154 - 'JavaScript:' URI in 'Refresh' Header Cross-Site Scripting
CVE-2009-2352remotemultiple03 jun 2009
Google Chrome 1.0.154.48 and earlier does not block javascript: URIs in Refresh headers in HTTP responses, which allows
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 6 - 'JavaScript:' URI in 'Refresh' Header Cross-Site Scripting
CVE-2009-2350remotewindows03 jun 2009
Microsoft Internet Explorer 6.0.2900.2180 and earlier does not block javascript: URIs in Refresh headers in HTTP respons
28RISCO
abrir
Exploit-DBVexDay Proof
Joomla! Component Omilen Photo Gallery 0.5b - Local File Inclusion
CVE-2009-4202webappsphp03 jun 2009
Directory traversal vulnerability in the Omilen Photo Gallery (com_omphotogallery) component Beta 0.5 for Joomla! allows
38RISCO
abrir
Exploit-DBVexDay Proof
Joomla! Component Seminar 1.28 - 'id' Blind SQL Injection
CVE-2009-4200webappsphp03 jun 2009
SQL injection vulnerability in the Seminar (com_seminar) component 1.28 for Joomla! allows remote attackers to execute a
23RISCO
abrir
Exploit-DBVexDay Proof
Apple QuickTime - Image Description Atom Sign Extension (PoC)
CVE-2009-0955doswindows03 jun 2009
Apple QuickTime before 7.6.2 allows remote attackers to execute arbitrary code or cause a denial of service (application
23RISCO
abrir
Exploit-DBVexDay Proof
Joomla! Component com_mosres - Multiple SQL Injections
CVE-2009-4199webappsphp03 jun 2009
Multiple SQL injection vulnerabilities in the Mambo Resident (aka Mos Res or com_mosres) component 1.0f for Mambo and Jo
23RISCO
abrir
Exploit-DBVexDay Proof
Sitecore CMS 6.0.0 rev. 090120 - 'default.aspx' Cross-Site Scripting
CVE-2009-2163webappsphp03 jun 2009
Cross-site scripting (XSS) vulnerability in login/default.aspx in Sitecore CMS before 6.0.2 Update-1 090507 allows remot
23RISCO
abrir
Exploit-DBVexDay Proof
Joomla! < 1.5.11 - Multiple Cross-Site Scripting / HTML Injection Vulnerabilities
CVE-2009-1938webappsphp03 jun 2009
Cross-site scripting (XSS) vulnerability in Joomla! 1.5.x through 1.5.10 allows remote attackers to inject arbitrary web
23RISCO
abrir
Exploit-DBVexDay Proof
Apache Tomcat 6.0.18 - Form Authentication Existing/Non-Existing 'Username' Enumeration
CVE-2009-0580remotemultiple03 jun 2009
Apache Tomcat 4.1.0 through 4.1.39, 5.5.0 through 5.5.27, and 6.0.0 through 6.0.18, when FORM authentication is used, al
60RISCO
abrir
Exploit-DBVexDay Proof
Movie PHP Script 2.0 - 'init.php?anticode' Code Execution
CVE-2009-4836webappsphp03 jun 2009
Eval injection vulnerability in system/services/init.php in Movie PHP Script 2.0 allows remote attackers to execute arbi
23RISCO
abrir
Exploit-DBVexDay Proof
My Mini Bill - 'orderid' SQL Injection
CVE-2009-4198webappsphp03 jun 2009
SQL injection vulnerability in my_orders.php in MyMiniBill allows remote authenticated users to execute arbitrary SQL co
23RISCO
abrir
anteriorpágina 444 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.