Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.151exploits catalogados
35.370CVEs com exploração pública
24.695testados em laboratório
24.451 exploits
Exploit-DBVexDay Proof
Net-SNMP 5.1.4/5.2.4/5.4.1 Perl Module - Buffer Overflow (PoC)
CVE-2008-2292doslinux12 nov 2008
Buffer overflow in the __snprint_value function in snmp_get in Net-SNMP 5.1.4, 5.2.4, and 5.4.1, as used in SNMP.xs for
23RISCO
abrir
Exploit-DBVexDay Proof
Joomla! Component com_marketplace 1.2.1 - 'catid' SQL Injection
CVE-2008-0689webappsphp11 nov 2008
SQL injection vulnerability in index.php in the Marketplace (com_marketplace) 1.1.1 and 1.1.1-pl1 component for Joomla!
23RISCO
abrir
Exploit-DBVexDay Proof
Yosemite Backup 8.70 - 'DtbClsLogin()' Remote Buffer Overflow
CVE-2008-5177remotewindows11 nov 2008
Stack-based buffer overflow in the DtbClsLogin function in Yosemite Backup 8.7 allows remote attackers to (1) execute ar
28RISCO
abrir
Exploit-DBVexDay Proof
Joomla! Component Simple RSS Reader 1.0 - Remote File Inclusion
CVE-2008-5053webappsphp11 nov 2008
PHP remote file inclusion vulnerability in admin.rssreader.php in the Simple RSS Reader (com_rssreader) 1.0 component fo
35RISCO
abrir
Exploit-DBVexDay Proof
Sun Java System Identity Manager 6.0/7.x - Multiple Vulnerabilities
CVE-2008-5115webappsjsp11 nov 2008
Cross-site request forgery (CSRF) vulnerability in Sun Java System Identity Manager 6.0 through 6.0 SP4, 7.0, and 7.1 al
23RISCO
abrir
Exploit-DBVexDay Proof
Dizi Portali - 'film.asp' SQL Injection
CVE-2008-5057webappsasp10 nov 2008
SQL injection vulnerability in film.asp in Yigit Aybuga Dizi Portali allows remote attackers to execute arbitrary SQL co
23RISCO
abrir
Exploit-DBVexDay Proof
OTManager CMS 2.4 - 'Tipo' Remote File Inclusion
CVE-2008-5063webappsphp10 nov 2008
PHP remote file inclusion vulnerability in Admin/ADM_Pagina.php in OTManager 2.4 allows remote attackers to execute arbi
23RISCO
abrir
Exploit-DBVexDay Proof
Joomla! Component JooBlog 0.1.1 - 'PostID' SQL Injection
CVE-2008-2630webappsphp10 nov 2008
SQL injection vulnerability in the JooBlog (com_jb2) component 0.1.1 for Joomla! allows remote attackers to execute arbi
23RISCO
abrir
Exploit-DBVexDay Proof
AJSquare Free Polling Script - 'DB' Multiple Vulnerabilities
CVE-2008-7046webappsphp10 nov 2008
AJ Square Free Polling Script (AJPoll) allows remote attackers to bypass authentication and create new polls via a direc
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Vista/2003 - 'UnhookWindowsHookEx' Local Denial of Service
CVE-2008-5044doswindows09 nov 2008
Race condition in Microsoft Windows Server 2003 and Vista allows local users to cause a denial of service (crash or hang
23RISCO
abrir
Exploit-DBVexDay Proof
V3 Chat Profiles/Dating Script 3.0.2 - Insecure Cookie Handling
CVE-2008-5783webappsphp08 nov 2008
admin/index.php in V3 Chat Live Support 3.0.4 allows remote attackers to bypass authentication and gain administrative a
23RISCO
abrir
Exploit-DBVexDay Proof
Zeeways Shaadi Clone 2.0 - Authentication Bypass (2)
CVE-2008-6912webappsphp08 nov 2008
Zeeways SHAADICLONE 2.0 allows remote attackers to bypass authentication and gain administrative privileges via a direct
23RISCO
abrir
Exploit-DBVexDay Proof
V3 Chat Live Support 3.0.4 - Insecure Cookie Handling
CVE-2008-5784webappsphp08 nov 2008
V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to bypass authentication and gain administrative access b
23RISCO
abrir
Exploit-DBVexDay Proof
Myiosoft EasyBookMarker 4 - 'Parent' SQL Injection
CVE-2008-5655webappsphp07 nov 2008
Multiple SQL injection vulnerabilities in MyioSoft EasyBookMarker 4.0 allow remote attackers to execute arbitrary SQL co
23RISCO
abrir
Exploit-DBVexDay Proof
MyioSoft EasyBookMarker 4.0 - Authentication Bypass
CVE-2008-5655webappsphp07 nov 2008
Multiple SQL injection vulnerabilities in MyioSoft EasyBookMarker 4.0 allow remote attackers to execute arbitrary SQL co
23RISCO
abrir
Exploit-DBVexDay Proof
Anti-Trojan Elite 4.2.1 - 'Atepmon.sys' IOCTL Request Local Overflow / Local Privilege Escalation
CVE-2008-5048localwindows07 nov 2008
Buffer overflow in Atepmon.sys in ISecSoft Anti-Trojan Elite 4.2.1 and earlier, and possibly 4.2.2, allows local users t
23RISCO
abrir
Exploit-DBVexDay Proof
SoftComplex PHP Image Gallery 1.0 - Authentication Bypass
CVE-2008-6485webappsphp06 nov 2008
SQL injection vulnerability in index.php in SoftComplex PHP Image Gallery allows remote attackers to execute arbitrary S
23RISCO
abrir
Exploit-DBVexDay Proof
SoftComplex PHP Image Gallery - 'ctg' SQL Injection
CVE-2008-6488webappsphp06 nov 2008
SQL injection vulnerability in index.php in SoftComplex PHP Image Gallery 1.0 allows remote attackers to execute arbitra
23RISCO
abrir
Exploit-DBVexDay Proof
MySQL Quick Admin 1.5.5 - Local File Inclusion
CVE-2008-4454webappsphp06 nov 2008
Directory traversal vulnerability in EKINdesigns MySQL Quick Admin 1.5.5 allows remote attackers to read and execute arb
23RISCO
abrir
Exploit-DBVexDay Proof
Pre Classified Listings - Insecure Cookie Handling
CVE-2008-6232webappsphp05 nov 2008
Pre Shopping Mall allows remote attackers to bypass authentication and gain administrative access by setting the (1) adm
23RISCO
abrir
Exploit-DBVexDay Proof
Pre Shopping Mall - Insecure Cookie Handling
CVE-2008-6231webappsphp05 nov 2008
Pre Classified Listing PHP allows remote attackers to bypass authentication and gain administrative access by setting th
23RISCO
abrir
Exploit-DBVexDay Proof
Struts 2.0.11 - Multiple Directory Traversal Vulnerabilities
CVE-2008-6505remotemultiple04 nov 2008
Multiple directory traversal vulnerabilities in Apache Struts 2.0.x before 2.0.12 and 2.1.x before 2.1.3 allow remote at
45RISCO
abrir
Exploit-DBVexDay Proof
DHCart 3.84 - Multiple Cross-Site Scripting / HTML Injection Vulnerabilities
CVE-2008-6297webappsphp04 nov 2008
Cross-site scripting (XSS) vulnerability in order.php in DHCart allows remote attackers to inject arbitrary web script o
23RISCO
abrir
Exploit-DBVexDay Proof
Simple Document Management System 1.1.4 - Authentication Bypass
CVE-2008-6236webappsphp04 nov 2008
SQL injection vulnerability in login.php in Simple Document Management System (SDMS) 1.1.5 and 1.1.4, and possibly earli
23RISCO
abrir
Exploit-DBVexDay Proof
firmCHANNEL Indoor & Outdoor Digital Signage 3.24 - Cross-Site Scripting
CVE-2008-4931webappsphp04 nov 2008
Cross-site scripting (XSS) vulnerability in the account module in firmCHANNEL Digital Signage 3.24, and possibly earlier
23RISCO
abrir
Exploit-DBVexDay Proof
WEBBDOMAIN WebShop 1.02 - SQL Injection / Cross-Site Scripting
CVE-2008-6628webappsphp04 nov 2008
20RISCO
abrir
Exploit-DBVexDay Proof
nicLOR Puglia Landscape - Local File Inclusion
CVE-2007-6586webappsphp04 nov 2008
SQL injection vulnerability in sezione_news.php in nicLOR-CMS allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
Exploit-DBVexDay Proof
XWork < 2.0.11.2 - 'ParameterInterceptor' Class OGNL Security Bypass
CVE-2008-6504remotemultiple04 nov 2008
ParametersInterceptor in OpenSymphony XWork 2.0.x before 2.0.6 and 2.1.x before 2.1.2, as used in Apache Struts and othe
35RISCO
abrir
Exploit-DBVexDay Proof
Vibro-CMS - Multiple SQL Injections
CVE-2008-6795webappsphp04 nov 2008
SQL injection vulnerability in view_news.php in nicLOR Vibro-School-CMS allows remote attackers to execute arbitrary SQL
23RISCO
abrir
Exploit-DBVexDay Proof
Chilkat Crypt - ActiveX Arbitrary File Creation/Execution
CVE-2011-5289remotewindows03 nov 2008
The SaveDecrypted method in the ChilkatCrypt2.ChilkatOmaDrm.1 ActiveX control in ChilkatCrypt2.dll in aTube Catcher 2.3.
23RISCO
abrir
anteriorpágina 464 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.