Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.206exploits catalogados
35.418CVEs com exploração pública
24.695testados em laboratório
24.451 exploits
Exploit-DBVexDay Proof
Meeting Room Booking System (MRBS) 1.2.6 - 'search.php' Cross-Site Scripting
CVE-2008-3565webappsphp04 ago 2008
Multiple cross-site scripting (XSS) vulnerabilities in Meeting Room Booking System (MRBS) 1.2.6 allow remote attackers t
23RISCO
abrir
Exploit-DBVexDay Proof
Meeting Room Booking System (MRBS) 1.2.6 - 'day.php' Cross-Site Scripting
CVE-2008-3565webappsphp04 ago 2008
Multiple cross-site scripting (XSS) vulnerabilities in Meeting Room Booking System (MRBS) 1.2.6 allow remote attackers t
23RISCO
abrir
Exploit-DBVexDay Proof
XAMPP Linux 1.6 - 'ming.php?text' Cross-Site Scripting
CVE-2008-3569remotelinux04 ago 2008
Multiple cross-site scripting (XSS) vulnerabilities in XAMPP 1.6.7, when register_globals is enabled, allow remote attac
23RISCO
abrir
Exploit-DBVexDay Proof
Pcshey Portal - 'kategori.asp' SQL Injection
CVE-2008-3495webappsasp04 ago 2008
SQL injection vulnerability in kategori.asp in Pcshey Portal allows remote attackers to execute arbitrary SQL commands v
23RISCO
abrir
Exploit-DBVexDay Proof
UNAK-CMS 1.5 - 'connector.php' Local File Inclusion
CVE-2008-3568webappsphp04 ago 2008
Absolute path traversal vulnerability in fckeditor/editor/filemanager/browser/default/connectors/php/connector.php in UN
23RISCO
abrir
Exploit-DBVexDay Proof
XAMPP Linux 1.6 - 'iart.php?text' Cross-Site Scripting
CVE-2008-3569remotelinux04 ago 2008
Multiple cross-site scripting (XSS) vulnerabilities in XAMPP 1.6.7, when register_globals is enabled, allow remote attac
23RISCO
abrir
Exploit-DBVexDay Proof
Homes 4 Sale - 'results.php' Cross-Site Scripting
CVE-2008-3587webappsphp04 ago 2008
Cross-site scripting (XSS) vulnerability in result.php in Chris Bunting Homes 4 Sale allows remote attackers to inject a
23RISCO
abrir
Exploit-DBVexDay Proof
e-vision CMS 2.02 - SQL Injection / Arbitrary File Upload / Information Gathering
CVE-2008-0856webappsphp02 ago 2008
Multiple SQL injection vulnerabilities in e-Vision CMS 2.02 allow remote attackers to execute arbitrary SQL commands via
23RISCO
abrir
Exploit-DBVexDay Proof
e-vision CMS 2.02 - SQL Injection / Arbitrary File Upload / Information Gathering
CVE-2006-5016webappsphp02 ago 2008
Unrestricted file upload vulnerability in admin/x_image.php in Szava Gyula and Csaba Tamas e-Vision CMS, probably 1.0, a
23RISCO
abrir
Exploit-DBVexDay Proof
Pligg CMS 9.9.5 - 'CAPTCHA' Registration Automation Security Bypass
CVE-2008-3573webappsphp02 ago 2008
The CAPTCHA implementation in (1) Pligg 9.9.5 and possibly (2) Francisco Burzi PHP-Nuke 8.1 provides a critical random n
23RISCO
abrir
Exploit-DBVexDay Proof
IrfanView 3.99 - '.IFF' File Local Stack Buffer Overflow
CVE-2007-2363localwindows01 ago 2008
Buffer overflow in IrfanView 4.00 and earlier allows user-assisted remote attackers to execute arbitrary code via a craf
23RISCO
abrir
Exploit-DBVexDay Proof
PHP-Nuke Book Catalog Module 1.0 - 'catid' SQL Injection
CVE-2008-3513webappsphp01 ago 2008
SQL injection vulnerability in the Book Catalog module 1.0 for PHP-Nuke allows remote attackers to execute arbitrary SQL
23RISCO
abrir
Exploit-DBVexDay Proof
Apache Tomcat 6.0.16 - 'RequestDispatcher' Information Disclosure
CVE-2008-2370remotemultiple01 ago 2008
Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16, when a RequestDispatcher is used, pe
35RISCO
abrir
Exploit-DBVexDay Proof
Apache Tomcat 6.0.16 - 'HttpServletResponse.sendError()' Cross-Site Scripting
CVE-2008-1232remotemultiple01 ago 2008
Cross-site scripting (XSS) vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through
45RISCO
abrir
Exploit-DBVexDay Proof
freeForum 1.7 - 'acuparam' Cross-Site Scripting
CVE-2008-3566webappsphp01 ago 2008
Cross-site scripting (XSS) vulnerability in ZoneO-soft freeForum 1.7 allows remote attackers to inject arbitrary web scr
23RISCO
abrir
Exploit-DBVexDay Proof
Apple Mac OSX 10.x - CoreGraphics Multiple Memory Corruption Vulnerabilities
CVE-2008-2321dososx31 jul 2008
Unspecified vulnerability in CoreGraphics in Apple Mac OS X 10.4.11 and 10.5.4 allows remote attackers to execute arbitr
28RISCO
abrir
Exploit-DBVexDay Proof
libxslt 1.1.x - RC4 Encryption and Decryption functions Buffer Overflow
CVE-2008-2935remotelinux31 jul 2008
Multiple heap-based buffer overflows in the rc4 (1) encryption (aka exsltCryptoRc4EncryptFunction) and (2) decryption (a
28RISCO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.6.x - 'net/ipv6/ip6_output.c' Null Pointer Dereference Denial of Service
CVE-2010-0437doslinux31 jul 2008
The ip6_dst_lookup_tail function in net/ipv6/ip6_output.c in the Linux kernel before 2.6.27 does not properly handle cer
28RISCO
abrir
Exploit-DBVexDay Proof
common Solutions csphonebook 1.02 - 'index.php' Cross-Site Scripting
CVE-2008-3448webappsphp31 jul 2008
Cross-site scripting (XSS) vulnerability in index.php in common solutions csphonebook 1.02 allows remote attackers to in
23RISCO
abrir
Exploit-DBVexDay Proof
Pligg CMS 9.9.0 - Cross-Site Scripting / Local File Inclusion / SQL Injection
CVE-2008-6968webappsphp30 jul 2008
Multiple SQL injection vulnerabilities in submit.php in Pligg CMS 9.9.5 allow remote attackers to execute arbitrary SQL
23RISCO
abrir
Exploit-DBVexDay Proof
MJGUEST 6.8 - 'Guestbook.js.php' Cross-Site Scripting
CVE-2008-3404webappsphp30 jul 2008
Cross-site scripting (XSS) vulnerability in guestbook.js.php in MJGuest 6.8 GT allows remote attackers to inject arbitra
23RISCO
abrir
Exploit-DBVexDay Proof
Unreal Tournament 3 - Memory Corruption (Denial of Service)
CVE-2008-3409dosmultiple30 jul 2008
Buffer overflow in Unreal Tournament 3 1.3beta4 and earlier allows remote attackers to cause a denial of service (memory
28RISCO
abrir
Exploit-DBVexDay Proof
Unreal Tournament 2004 - Null Pointer Remote Denial of Service
CVE-2008-3396dosmultiple30 jul 2008
Unreal Tournament 2004 (UT2004) 3369 and earlier allows remote attackers to cause a denial of service (NULL pointer dere
23RISCO
abrir
Exploit-DBVexDay Proof
Pligg CMS 9.9.0 - Remote Code Execution
CVE-2008-7091webappsphp30 jul 2008
Multiple SQL injection vulnerabilities in Pligg 9.9 and earlier allow remote attackers to execute arbitrary SQL commands
23RISCO
abrir
Exploit-DBVexDay Proof
PozScripts Classified Ads Script - 'cid' SQL Injection
CVE-2008-3672webappsphp30 jul 2008
SQL injection vulnerability in showcategory.php in PozScripts Classified Ads allows remote attackers to execute arbitrar
23RISCO
abrir
Exploit-DBVexDay Proof
Eyeball MessengerSDK 'CoVideoWindow.ocx' 5.0.907 - ActiveX Control Remote Buffer Overflow
CVE-2008-3430remotewindows29 jul 2008
Buffer overflow in the CoVideoWindow.ocx ActiveX control 5.0.907.1 in Eyeball MessengerSDK, as used in products such as
23RISCO
abrir
Exploit-DBVexDay Proof
e107 Plugin BLOG Engine 2.2 - Blind SQL Injection
CVE-2008-6438webappsphp29 jul 2008
SQL injection vulnerability in macgurublog_menu/macgurublog.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows re
23RISCO
abrir
Exploit-DBVexDay Proof
Cisco IOS 12.3(18) (FTP Server) - Remote (Attached to GDB)
CVE-2007-2586remotehardware29 jul 2008
The FTP Server in Cisco IOS 11.3 through 12.4 does not properly check user authorization, which allows remote attackers
28RISCO
abrir
Exploit-DBVexDay Proof
Jamroom 3.3.8 - Cookie Authentication Bypass
CVE-2008-3375webappsphp28 jul 2008
The jrCookie function in includes/jamroom-misc.inc.php in JamRoom before 3.4.0 allows remote attackers to bypass authent
23RISCO
abrir
Exploit-DBVexDay Proof
Owl Intranet Engine 0.95 - 'register.php' Cross-Site Scripting
CVE-2008-3100webappsphp28 jul 2008
Cross-site scripting (XSS) vulnerability in lib/owl.lib.php in Steve Bourgeois and Chris Vincent Owl Intranet Knowledgeb
23RISCO
abrir
anteriorpágina 476 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.