Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.151exploits catalogados
35.370CVEs com exploração pública
24.695testados em laboratório
24.451 exploits
Exploit-DBVexDay Proof
X-BLC 0.2.0 - 'get_read.php?section' SQL Injection
CVE-2009-2310webappsphp23 mar 2009
SQL injection vulnerability in include/get_read.php in Extensible-BioLawCom CMS (X-BLC) 0.2.0 and earlier allows remote
23RISCO
abrir
Exploit-DBVexDay Proof
Codice CMS 2 - Command Execution (via SQL Injection)
CVE-2009-2309webappsphp23 mar 2009
SQL injection vulnerability in index.php in Codice CMS 2 allows remote attackers to execute arbitrary SQL commands via t
23RISCO
abrir
Exploit-DBVexDay Proof
ExpressionEngine 1.6 - Avtaar Name HTML Injection
CVE-2009-1070webappsphp22 mar 2009
Cross-site scripting (XSS) vulnerability in system/index.php in ExpressionEngine 1.6.4 through 1.6.6, and possibly earli
23RISCO
abrir
Exploit-DBVexDay Proof
Racer 0.5.3 Beta 5 - Remote Stack Buffer Overflow
CVE-2007-4370remotewindows20 mar 2009
Multiple buffer overflows in the (1) client and (2) server in Racer 0.5.3 beta 5 allow remote attackers to execute arbit
50RISCO
abrir
Exploit-DBVexDay Proof
Xlight FTP Server 3.2 - 'user' SQL Injection
CVE-2009-4795remotemultiple19 mar 2009
Multiple SQL injection vulnerabilities in Xlight FTP Server before 3.2.1, when ODBC authentication is enabled, allow rem
23RISCO
abrir
Exploit-DBVexDay Proof
DeluxeBB 1.3 - 'qorder' SQL Injection
CVE-2010-4151webappsphp18 mar 2009
SQL injection vulnerability in misc.php in DeluxeBB 1.3, and possibly earlier, when magic_quotes_gpc is disabled, allows
23RISCO
abrir
Exploit-DBVexDay Proof
Foxit Reader 3.0 (Build 1301) - PDF Universal Buffer Overflow
CVE-2009-0837localwindows13 mar 2009
Stack-based buffer overflow in Foxit Reader 3.0 before Build 1506, including 1120 and 1301, allows remote attackers to e
60RISCO
abrir
Exploit-DBVexDay Proof
YAP 1.1.1 - 'index.php' Local File Inclusion
CVE-2009-1038webappsphp13 mar 2009
Multiple SQL injection vulnerabilities in YAP Blog 1.1.1 allow remote attackers to execute arbitrary SQL commands via th
23RISCO
abrir
Exploit-DBVexDay Proof
TikiWiki 2.2/3.0 - 'tiki-galleries.php' Cross-Site Scripting
CVE-2009-1204webappsphp12 mar 2009
Cross-site scripting (XSS) vulnerability in TikiWiki (Tiki) CMS/Groupware 2.2 allows remote attackers to inject arbitrar
23RISCO
abrir
Exploit-DBVexDay Proof
TikiWiki 2.2/3.0 - 'tiki-listpages.php' Cross-Site Scripting
CVE-2009-1204webappsphp12 mar 2009
Cross-site scripting (XSS) vulnerability in TikiWiki (Tiki) CMS/Groupware 2.2 allows remote attackers to inject arbitrar
23RISCO
abrir
Exploit-DBVexDay Proof
phpmysport 1.4 - Cross-Site Scripting / SQL Injection
CVE-2010-1109webappsphp12 mar 2009
Multiple SQL injection vulnerabilities in index.php in phpMySport 1.4, when magic_quotes_gpc is disabled, allow remote a
23RISCO
abrir
Exploit-DBVexDay Proof
TikiWiki 2.2/3.0 - 'tiki-list_file_gallery.php' Cross-Site Scripting
CVE-2009-1204webappsphp12 mar 2009
Cross-site scripting (XSS) vulnerability in TikiWiki (Tiki) CMS/Groupware 2.2 allows remote attackers to inject arbitrar
23RISCO
abrir
Exploit-DBVexDay Proof
SlySoft (Multiple Products) - Driver IOCTL Request Multiple Local Buffer Overflow Vulnerabilities
CVE-2009-0824localwindows12 mar 2009
Elaborate Bytes ElbyCDIO.sys 6.0.2.0 and earlier, as distributed in SlySoft AnyDVD before 6.5.2.6, Virtual CloneDrive 5.
23RISCO
abrir
Exploit-DBVexDay Proof
PostgreSQL 8.3.6 - Conversion Encoding Remote Denial of Service
CVE-2009-0922doslinux11 mar 2009
PostgreSQL before 8.3.7, 8.2.13, 8.1.17, 8.0.21, and 7.4.25 allows remote authenticated users to cause a denial of servi
28RISCO
abrir
Exploit-DBVexDay Proof
CMS WEBjump! - Multiple SQL Injections
CVE-2009-4892webappsphp10 mar 2009
SQL injection vulnerability in Content Management System WEBjump! allows remote attackers to execute arbitrary SQL comma
23RISCO
abrir
Exploit-DBVexDay Proof
IBM System Director Agent 5.20 - CIM Server Privilege Escalation
CVE-2009-0880localwindows10 mar 2009
Directory traversal vulnerability in the CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows rem
50RISCO
abrir
Exploit-DBVexDay Proof
Sun xVM VirtualBox 2.0/2.1 - Local Privilege Escalation
CVE-2009-0876locallinux10 mar 2009
Sun xVM VirtualBox 2.0.0, 2.0.2, 2.0.4, 2.0.6r39760, 2.1.0, 2.1.2, and 2.1.4r42893 on Linux allows local users to gain p
23RISCO
abrir
Exploit-DBVexDay Proof
NextApp Echo < 2.1.1 - XML Injection
CVE-2009-5135remotemultiple10 mar 2009
The Java XML parser in Echo before 2.1.1 and 3.x before 3.0.b6 allows remote attackers to read arbitrary files via a req
23RISCO
abrir
Exploit-DBVexDay Proof
phpCommunity 2.1.8 - SQL Injection / Directory Traversal / Cross-Site Scripting
CVE-2009-4886webappsphp09 mar 2009
Multiple directory traversal vulnerabilities in phpCommunity 2 2.1.8 allow remote attackers to read arbitrary files via
23RISCO
abrir
Exploit-DBVexDay Proof
woltlab burning board 3.0.x - Multiple Vulnerabilities
CVE-2008-7192webappsphp09 mar 2009
Cross-site request forgery (CSRF) vulnerability in index.php in WoltLab Burning Board (wBB) 3.0.1, and possibly other 3.
23RISCO
abrir
Exploit-DBVexDay Proof
PHORTAIL 1.2.1 - 'poster.php' Multiple HTML Injection Vulnerabilities
CVE-2009-4888webappsphp09 mar 2009
Cross-site scripting (XSS) vulnerability in poster.php in PHortail 1.2.1 allows remote attackers to inject arbitrary web
23RISCO
abrir
Exploit-DBVexDay Proof
nForum 1.5 - Multiple SQL Injections
CVE-2009-0882webappsphp09 mar 2009
Multiple SQL injection vulnerabilities in nForum 1.5 allow remote attackers to execute arbitrary SQL commands via the (1
23RISCO
abrir
Exploit-DBVexDay Proof
PHP-Fusion Mod Book Panel - 'bookid' SQL Injection
CVE-2009-4889webappsphp09 mar 2009
SQL injection vulnerability in books.php in the Book Panel (book_panel) module for PHP-Fusion allows remote attackers to
23RISCO
abrir
Exploit-DBVexDay Proof
PHPRecipeBook 2.24 - 'base_id' SQL Injection
CVE-2009-4883webappsphp09 mar 2009
SQL injection vulnerability in index.php in PHPRecipeBook 2.24 and 2.39 allows remote attackers to execute arbitrary SQL
23RISCO
abrir
Exploit-DBVexDay Proof
EO Video 1.36 - Playlist Overwrite (SEH)
CVE-2008-3733localwindows09 mar 2009
Stack-based buffer overflow in EO Video (eo-video) 1.36 allows remote attackers to cause a denial of service (applicatio
23RISCO
abrir
Exploit-DBVexDay Proof
TinXCMS 3.5 - 'rss.php' SQL Injection
CVE-2009-0825webappsphp06 mar 2009
SQL injection vulnerability in system/rss.php in TinX/cms 3.x before 3.5.1 allows remote attackers to execute arbitrary
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 7 - Memory Corruption (MS09-002)
CVE-2009-0076remotewindows04 mar 2009
Microsoft Internet Explorer 7, when XHTML strict mode is used, allows remote attackers to execute arbitrary code via the
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 7 - Memory Corruption (MS09-002)
CVE-2009-0075remotewindows04 mar 2009
Microsoft Internet Explorer 7 does not properly handle errors during attempted access to deleted objects, which allows r
60RISCO
abrir
Exploit-DBVexDay Proof
Easy File Sharing Web Server 4.8 - File Disclosure
CVE-2009-4809remotewindows04 mar 2009
Directory traversal vulnerability in thumbnail.ghp in Easy File Sharing (EFS) Web Server 4.8 allows remote attackers to
23RISCO
abrir
Exploit-DBVexDay Proof
Mozilla Firefox 2.0.x - Nested 'window.print()' Denial of Service
CVE-2009-0821dosmultiple03 mar 2009
Mozilla Firefox 2.0.0.20 and earlier allows remote attackers to cause a denial of service (application crash) via nested
23RISCO
abrir
anteriorpágina 454 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.