Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

81.524exploits catalogados
37.962CVEs com exploração pública
24.695testados em laboratório
24.482 exploits
Exploit-DB✓ VexDay Proof
Mozilla Firefox 3.0.5 - location.hash Remote Crash
CVE-2009-2953—doswindows23 dez 2008
Mozilla Firefox 3.0.6 through 3.0.13, and 3.5.x, allows remote attackers to cause a denial of service (CPU consumption)
23RISCO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component com_lowcosthotels - Blind SQL Injection
CVE-2008-5864—webappsphp23 dez 2008
SQL injection vulnerability in the Top Hotel (com_tophotelmodule) component 1.0 in the Hotel Booking Reservation System
23RISCO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component com_lowcosthotels - Blind SQL Injection
CVE-2008-5865—webappsphp23 dez 2008
SQL injection vulnerability in the com_hbssearch component 1.0 in the Hotel Booking Reservation System (aka HBS) 1.0.0 f
23RISCO
abrir ↗
Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.x - 'qdisc_run()' Local Denial of Service
CVE-2008-5713—doslinux23 dez 2008
The __qdisc_run function in net/sched/sch_generic.c in the Linux kernel before 2.6.25 on SMP machines allows local users
23RISCO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component com_allhotels - Blind SQL Injection
CVE-2008-5875—webappsphp23 dez 2008
SQL injection vulnerability in the com_lowcosthotels component in the Hotel Booking Reservation System (aka HBS) for Joo
23RISCO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component com_lowcosthotels - Blind SQL Injection
CVE-2008-5874—webappsphp23 dez 2008
Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System (aka HBS) for Joomla! allow remote attack
23RISCO
abrir ↗
Exploit-DB✓ VexDay Proof
QEMU 0.9 / KVM 36/79 - VNC Server Remote Denial of Service
CVE-2008-2382—doslinux22 dez 2008
The protocol_client_msg function in vnc.c in the VNC server in (1) Qemu 0.9.1 and earlier and (2) KVM kvm-79 and earlier
23RISCO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component com_hbssearch 1.0 - Blind SQL Injection
CVE-2008-5864—webappsphp21 dez 2008
SQL injection vulnerability in the Top Hotel (com_tophotelmodule) component 1.0 in the Hotel Booking Reservation System
23RISCO
abrir ↗
Exploit-DB✓ VexDay Proof
Joomla! Component com_tophotelmodule 1.0 - Blind SQL Injection
CVE-2008-5865—webappsphp21 dez 2008
SQL injection vulnerability in the com_hbssearch component 1.0 in the Hotel Booking Reservation System (aka HBS) 1.0.0 f
23RISCO
abrir ↗
Exploit-DB✓ VexDay Proof
DO-CMS 3.0 - 'p' Multiple SQL Injections
CVE-2008-6019—webappsphp18 dez 2008
SQL injection vulnerability in index.php in EACOMM DO-CMS 3.0 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir ↗
Exploit-DB✓ VexDay Proof
ESET Smart Security 3.0.672 - 'epfw.sys' Local Privilege Escalation
CVE-2008-5724—localwindows18 dez 2008
The Personal Firewall driver (aka epfw.sys) 3.0.672.0 and earlier in ESET Smart Security 3.0.672 and earlier allows loca
23RISCO
abrir ↗
Exploit-DB✓ VexDay Proof
Easysitenetwork Jokes Complete Website - 'joke.php' SQL Injection
CVE-2008-6880—webappsphp18 dez 2008
SQL injection vulnerability in joke.php in EasySiteNetwork Free Jokes Website allows remote attackers to execute arbitra
23RISCO
abrir ↗
Exploit-DB✓ VexDay Proof
TinyMCE 2.0.1 - 'menuID' SQL Injection
CVE-2008-6049—webappsphp17 dez 2008
20RISCO
abrir ↗
Exploit-DB✓ VexDay Proof
PHPcksec 0.2 - 'PHPcksec.php' Cross-Site Scripting
CVE-2008-6609—webappsphp17 dez 2008
Cross-site scripting (XSS) vulnerability in phpcksec.php in Stefan Ott phpcksec 0.2 allows remote attackers to inject ar
23RISCO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft SQL Server - 'sp_replwritetovarbin()' Heap Overflow
CVE-2008-4270—localwindows17 dez 2008
20RISCO
abrir ↗
Exploit-DB✓ VexDay Proof
Injader 2.1.1 - SQL Injection / HTML Injection
CVE-2008-5891—webappsphp15 dez 2008
Cross-site scripting (XSS) vulnerability in the profile editing functionality in Injader before 2.1.2 allows remote atta
23RISCO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer - XML Parsing Buffer Overflow (1)
CVE-2010-1175—remotewindows15 dez 2008
Microsoft Internet Explorer 7.0 on Windows XP and Windows Server 2003 allows remote attackers to have an unspecified imp
28RISCO
abrir ↗
Exploit-DB✓ VexDay Proof
FLDS 1.2a - 'redir.php' SQL Injection
CVE-2008-5779—webappsphp14 dez 2008
SQL injection vulnerability in lpro.php in Free Links Directory Script (FLDS) 1.2a allows remote attackers to execute ar
23RISCO
abrir ↗
Exploit-DB✓ VexDay Proof
Flatnux - html/JavaScript Injection Cookie Grabber
CVE-2008-5759—webappsphp14 dez 2008
Cross-site scripting (XSS) vulnerability in FlatnuX CMS (aka Flatnuke3) 2008-12-11 allows remote attackers to inject arb
23RISCO
abrir ↗
Exploit-DB✓ VexDay Proof
FLDS 1.2a - 'redir.php' SQL Injection
CVE-2008-5778—webappsphp14 dez 2008
SQL injection vulnerability in report.php in Free Links Directory Script (FLDS) 1.2a allows remote attackers to execute
23RISCO
abrir ↗
Exploit-DB✓ VexDay Proof
ProSysInfo TFTP server TFTPDWIN 0.4.2 - Universal Remote Buffer Overflow
CVE-2006-4948—remotewindows14 dez 2008
Stack-based buffer overflow in tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 and earlier allows remote attackers to
50RISCO
abrir ↗
Exploit-DB✓ VexDay Proof
ASP-DEV XM Events Diary - 'cat' SQL Injection
CVE-2008-5923—webappsasp13 dez 2008
SQL injection vulnerability in default.asp in ASP-DEv XM Events Diary allows remote attackers to execute arbitrary SQL c
23RISCO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Visual Basic - ActiveX Controls mscomct2.ocx Buffer Overflow (PoC)
CVE-2008-4255—doswindows12 dez 2008
Heap-based buffer overflow in mscomct2.ocx (aka Windows Common ActiveX control or Microsoft Animation ActiveX control) i
35RISCO
abrir ↗
Exploit-DB✓ VexDay Proof
Multiple Ad Server Solutions Products - 'logon_processing.jsp' SQL Injection
CVE-2008-6365—webappsjsp11 dez 2008
SQL injection vulnerability in logon.jsp in Ad Server Solutions Ad Management Software Java allows remote attackers to e
23RISCO
abrir ↗
Exploit-DB✓ VexDay Proof
Multiple Ad Server Solutions Products - 'logon_processing.jsp' SQL Injection
CVE-2008-6366—webappsjsp11 dez 2008
SQL injection vulnerability in logon.jsp in Ad Server Solutions Affiliate Software Java 4.0 allows remote attackers to e
23RISCO
abrir ↗
Exploit-DB✓ VexDay Proof
Microsoft Internet Explorer 8 - CSS 'expression' Property Cross-Site Scripting Filter Bypass
CVE-2008-5551—remotewindows11 dez 2008
The XSS Filter in Microsoft Internet Explorer 8.0 Beta 2 allows remote attackers to bypass the XSS protection mechanism
28RISCO
abrir ↗
Exploit-DB✓ VexDay Proof
Linux Kernel 2.6.27.8 - ATMSVC Local Denial of Service
CVE-2008-5079—doslinux10 dez 2008
net/atm/svc.c in the ATM subsystem in the Linux kernel 2.6.27.8 and earlier allows local users to cause a denial of serv
23RISCO
abrir ↗
Exploit-DB✓ VexDay Proof
Professional Download Assistant 0.1 - SQL Injection
CVE-2008-5571—webappsasp09 dez 2008
SQL injection vulnerability in admin/login.asp in Professional Download Assistant 0.1 allows remote attackers to execute
23RISCO
abrir ↗
Exploit-DB✓ VexDay Proof
PHPmyGallery 1.0beta2 - Local/Remote File Inclusion
CVE-2008-6317—webappsphp09 dez 2008
Directory traversal vulnerability in _conf/_php-core/common-tpl-vars.php in PHPmyGallery 1.5 beta allows remote attacker
23RISCO
abrir ↗
Exploit-DB✓ VexDay Proof
PHPmyGallery 1.5beta - '/common-tpl-vars.php' Local/Remote File Inclusion
CVE-2008-6316—webappsphp09 dez 2008
Directory traversal vulnerability in _conf/core/common-tpl-vars.php in PHPmyGallery 1.0 beta2 allows remote attackers to
23RISCO
abrir ↗
← anteriorpágina 461 / 817próximo →

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.