Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.133exploits catalogados
35.369CVEs com exploração pública
24.695testados em laboratório
24.451 exploits
Exploit-DBVexDay Proof
glFusion 1.1.2 - 'COM_applyFilter()/cookies' Blind SQL Injection
CVE-2009-1281webappsphp03 abr 2009
Cross-site scripting (XSS) vulnerability in glFusion before 1.1.3 allows remote attackers to inject arbitrary web script
23RISCO
abrir
Exploit-DBVexDay Proof
IBM DB2 < 9.5 pack 3a - Connect Denial of Service
CVE-2009-0172dosmultiple03 abr 2009
Unspecified vulnerability in IBM DB2 8 before FP17a, 9.1 before FP6a, and 9.5 before FP3a allows remote attackers to cau
23RISCO
abrir
Exploit-DBVexDay Proof
BlogEngine.NET 1.4 - 'search.aspx' Cross-Site Scripting
CVE-2008-6476webappsasp01 abr 2009
Cross-site scripting (XSS) vulnerability in blog/search.aspx in BlogEngine.NET allows remote attackers to inject arbitra
23RISCO
abrir
Exploit-DBVexDay Proof
Oracle WebLogic IIS connector JSESSIONID - Remote Overflow
CVE-2008-5457remotewindows01 abr 2009
Unspecified vulnerability in the Oracle BEA WebLogic Server Plugins for Apache, Sun and IIS web servers component in BEA
50RISCO
abrir
Exploit-DBVexDay Proof
Sun Java System Calendar Server 6 - 'command.shtml' Cross-Site Scripting
CVE-2009-1218webappsjava31 mar 2009
Multiple cross-site scripting (XSS) vulnerabilities in Sun Calendar Express Web Server in Sun ONE Calendar Server 6.0 an
23RISCO
abrir
Exploit-DBVexDay Proof
PHPRecipeBook 2.39 - 'course_id' SQL Injection
CVE-2009-4883webappsphp31 mar 2009
SQL injection vulnerability in index.php in PHPRecipeBook 2.24 and 2.39 allows remote attackers to execute arbitrary SQL
23RISCO
abrir
Exploit-DBVexDay Proof
Community CMS 0.5 - Multiple SQL Injections
CVE-2009-4794webappsphp31 mar 2009
Multiple SQL injection vulnerabilities in Community CMS 0.5 allow remote attackers to execute arbitrary SQL commands via
23RISCO
abrir
Exploit-DBVexDay Proof
Sun Java System Calendar Server 6.3 - Duplicate URI Request Denial of Service
CVE-2009-1219dosjava31 mar 2009
Sun Calendar Express Web Server in Sun ONE Calendar Server 6.0 and Sun Java System Calendar Server 6 2004Q2 through 6.3-
23RISCO
abrir
Exploit-DBVexDay Proof
Cisco ASA Appliance 7.x/8.0 WebVPN - Cross-Site Scripting
CVE-2009-1220remotehardware31 mar 2009
Cross-site scripting (XSS) vulnerability in +webvpn+/index.html in WebVPN on the Cisco Adaptive Security Appliances (ASA
23RISCO
abrir
Exploit-DBVexDay Proof
Turnkey eBook Store 1.1 - 'keywords' Cross-Site Scripting
CVE-2009-1225webappsphp31 mar 2009
Cross-site scripting (XSS) vulnerability in index.php in Turnkey Ebook Store 1.1 allows remote attackers to inject arbit
23RISCO
abrir
Exploit-DBVexDay Proof
SAP MaxDB 7.4/7.6 - 'webdbm' Multiple Cross-Site Scripting Vulnerabilities
CVE-2007-4475remotewindows31 mar 2009
Stack-based buffer overflow in EAI WebViewer3D ActiveX control (webviewer3d.dll) in SAP AG SAPgui before 7.10 Patch Leve
50RISCO
abrir
Exploit-DBVexDay Proof
BandSite CMS 1.1.4 - 'members.php' SQL Injection
CVE-2009-4793webappsphp30 mar 2009
Unrestricted file upload vulnerability in adminpanel/scripts/addphotos.php in BandSite CMS 1.1.4 allows remote authentic
23RISCO
abrir
Exploit-DBVexDay Proof
JobHut 1.2 - 'pk' SQL Injection
CVE-2009-4797webappsphp30 mar 2009
SQL injection vulnerability in browse.php in JobHut 1.2 and earlier allows remote attackers to execute arbitrary SQL com
23RISCO
abrir
Exploit-DBVexDay Proof
Diskos CMS Manager - SQL Injection / File Disclosure / Authentication Bypass
CVE-2009-4798webappsasp30 mar 2009
Multiple SQL injection vulnerabilities in Diskos CMS 6.x allow remote attackers to execute arbitrary SQL commands via th
23RISCO
abrir
Exploit-DBVexDay Proof
AtomixMP3 < 2.3 - 'Playlist' Universal Overwrite (SEH)
CVE-2007-4803localwindows30 mar 2009
Buffer overflow in AtomixMP3 2.3 allows user-assisted remote attackers to execute arbitrary code via long strings in fil
23RISCO
abrir
Exploit-DBVexDay Proof
Diskos CMS Manager - SQL Injection / File Disclosure / Authentication Bypass
CVE-2009-4799webappsasp30 mar 2009
Diskos CMS 6.x stores sensitive information under the web root with insufficient access control, which allows remote att
23RISCO
abrir
Exploit-DBVexDay Proof
family connection 1.8.1 - Multiple Vulnerabilities
CVE-2009-4791webappsphp30 mar 2009
Multiple SQL injection vulnerabilities in Family Connections (aka FCMS) before 1.8.2 allow remote attackers to execute a
23RISCO
abrir
Exploit-DBVexDay Proof
BandSite CMS 1.1.4 - 'members.php' SQL Injection
CVE-2009-4792webappsphp30 mar 2009
SQL injection vulnerability in includes/content/member_content.php in BandSite CMS 1.1.4 allows remote attackers to exec
23RISCO
abrir
Exploit-DBVexDay Proof
iWare CMS 5.0.4 - Multiple SQL Injections
CVE-2006-6446webappsphp29 mar 2009
SQL injection vulnerability in index.php in iWare Professional 5.0.4, when magic_quotes_gpc is disabled, allows remote a
23RISCO
abrir
Exploit-DBVexDay Proof
glFusion 1.1.2 - 'COM_applyFilter()/order' SQL Injection
CVE-2009-4796webappsphp29 mar 2009
Multiple SQL injection vulnerabilities in the ExecuteQueries function in private/system/classes/listfactory.class.php in
23RISCO
abrir
Exploit-DBVexDay Proof
pam-krb5 < 3.13 - Local Privilege Escalation
CVE-2009-0360locallinux29 mar 2009
Russ Allbery pam-krb5 before 3.13, when linked against MIT Kerberos, does not properly initialize the Kerberos libraries
23RISCO
abrir
Exploit-DBVexDay Proof
XM Easy Personal FTP Server 5.7.0 - 'NLST' Denial of Service
CVE-2008-5626doswindows27 mar 2009
XM Easy Personal FTP Server 5.6.0 allows remote authenticated users to cause a denial of service via a crafted argument
50RISCO
abrir
Exploit-DBVexDay Proof
freeSSHd 1.2.1 - 'rename' Remote Buffer Overflow (SEH)
CVE-2008-6899remotewindows27 mar 2009
Multiple buffer overflows in freeSSHd 1.2.1 allow remote authenticated users to cause a denial of service (crash) and ex
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft GdiPlus - EMF GpFont.SetData Integer Overflow (PoC)
CVE-2009-1217doswindows24 mar 2009
Off-by-one error in the GpFont::SetData function in gdiplus.dll in Microsoft GDI+ on Windows XP allows remote attackers
28RISCO
abrir
Exploit-DBVexDay Proof
Femitter FTP Server 1.x - (Authenticated) Multiple Vulnerabilities
CVE-2008-2032remotewindows24 mar 2009
The FTP service in Acritum Femitter Server 1.03 allows remote attackers to cause a denial of service (crash) by sending
23RISCO
abrir
Exploit-DBVexDay Proof
Jinzora Media Jukebox 2.8 - 'name' Local File Inclusion
CVE-2009-2313webappsphp24 mar 2009
Directory traversal vulnerability in index.php in Jinzora Media Jukebox 2.8 and earlier allows remote attackers to inclu
23RISCO
abrir
Exploit-DBVexDay Proof
Sysax Multi Server 4.3 - Arbitrary Delete Files Expoit
CVE-2009-4790remotewindows23 mar 2009
Multiple directory traversal vulnerabilities in Sysax Multi Server 4.5 allow remote authenticated users to read or modif
23RISCO
abrir
Exploit-DBVexDay Proof
Zinf Audio Player 2.2.1 - '.pls' Universal Overwrite (SEH)
CVE-2004-0964localwindows23 mar 2009
Buffer overflow in Zinf 2.2.1 on Windows, and other older versions for Linux, allows remote attackers or local users to
50RISCO
abrir
Exploit-DBVexDay Proof
WBB3 rGallery 1.2.3 - 'UserGallery' Blind SQL Injection
CVE-2009-2311webappsphp23 mar 2009
SQL injection vulnerability in the rGallery plugin 1.2.3 for WoltLab Burning Board (WBB3) allows remote attackers to exe
23RISCO
abrir
Exploit-DBVexDay Proof
Codice CMS 2 - Command Execution (via SQL Injection)
CVE-2009-2309webappsphp23 mar 2009
SQL injection vulnerability in index.php in Codice CMS 2 allows remote attackers to execute arbitrary SQL commands via t
23RISCO
abrir
anteriorpágina 453 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.