Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.231exploits catalogados
35.420CVEs com exploração pública
24.695testados em laboratório
24.451 exploits
Exploit-DBVexDay Proof
EncapsGallery 1.11.2 - 'catalog_watermark.php?file' Cross-Site Scripting
CVE-2008-1296webappsphp10 mar 2008
Multiple cross-site scripting (XSS) vulnerabilities in EncapsGallery 1.11.2 allow remote attackers to inject arbitrary w
23RISCO
abrir
Exploit-DBVexDay Proof
PHP-Nuke Hadith Module - 'cat' SQL Injection
CVE-2008-1298webappsphp10 mar 2008
SQL injection vulnerability in Hadith module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands via
23RISCO
abrir
Exploit-DBVexDay Proof
Gallarific - 'search.php?query' Cross-Site Scripting
CVE-2008-1326webappsphp10 mar 2008
Cross-site scripting (XSS) vulnerability in search.php in Gallarific allows remote attackers to inject arbitrary web scr
23RISCO
abrir
Exploit-DBVexDay Proof
Gallarific - Multiple Script Direct Request Authentication Bypass
CVE-2008-1327webappsphp10 mar 2008
Gallarific does not require authentication for (1) users.php and (2) index.php, which allows remote attackers to add and
23RISCO
abrir
Exploit-DBVexDay Proof
Drake CMS 0.4.11 RC8 - 'd_root' Local File Inclusion
CVE-2008-1371webappsphp10 mar 2008
Absolute path traversal vulnerability in install/index.php in Drake CMS 0.4.11 RC8 allows remote attackers to read and e
23RISCO
abrir
Exploit-DBVexDay Proof
RemotelyAnywhere 8.0.668 - 'Accept-Charset' Null Pointer Denial of Service
CVE-2008-1278dosmultiple10 mar 2008
The RemotelyAnywhere.exe service in the Remotely Anywhere Server and Workstation 8.0.668 and earlier allows remote attac
23RISCO
abrir
Exploit-DBVexDay Proof
Panda Internet Security/AntiVirus+Firewall 2008 - 'CPoint.sys' Memory Corruption
CVE-2008-1471doswindows08 mar 2008
The cpoint.sys driver in Panda Internet Security 2008 and Antivirus+ Firewall 2008 allows local users to cause a denial
23RISCO
abrir
Exploit-DBVexDay Proof
Alkacon OpenCMS 7.0.3 - 'logfileViewSettings.jsp?filePath.0' Arbitrary File Access
CVE-2008-1301webappsphp08 mar 2008
Absolute path traversal vulnerability in system/workplace/admin/workplace/logfileview/logfileViewSettings.jsp in Alkacon
23RISCO
abrir
Exploit-DBVexDay Proof
Alkacon OpenCMS 7.0.3 - 'logfileViewSettings.jsp?filePath' Cross-Site Scripting
CVE-2008-1300webappsphp08 mar 2008
Cross-site scripting (XSS) vulnerability in the Logfile Viewer Settings function in system/workplace/admin/workplace/log
23RISCO
abrir
Exploit-DBVexDay Proof
ImageVue 1.7 - 'dirxml.php?path' Cross-Site Scripting
CVE-2008-1273webappsphp07 mar 2008
Multiple cross-site scripting (XSS) vulnerabilities in imageVue 1.7 allow remote attackers to inject arbitrary web scrip
23RISCO
abrir
Exploit-DBVexDay Proof
ImageVue 1.7 - 'popup.php?path' Cross-Site Scripting
CVE-2008-1273webappsphp07 mar 2008
Multiple cross-site scripting (XSS) vulnerabilities in imageVue 1.7 allow remote attackers to inject arbitrary web scrip
23RISCO
abrir
Exploit-DBVexDay Proof
Neptune Web Server 3.0 - 404 Error Page Cross-Site Scripting
CVE-2008-1283remotemultiple07 mar 2008
Cross-site scripting (XSS) vulnerability in Neptune Web Server 3.0 allows remote attackers to inject arbitrary web scrip
23RISCO
abrir
Exploit-DBVexDay Proof
Specimen Image Database - 'taxonservice.php?dir' Remote File Inclusion
CVE-2008-7152webappsphp07 mar 2008
Multiple PHP remote file inclusion vulnerabilities in Specimen Image Database (SID), when register_globals is enabled, a
23RISCO
abrir
Exploit-DBVexDay Proof
ImageVue 1.7 - 'upload.php?path' Cross-Site Scripting
CVE-2008-1273webappsphp07 mar 2008
Multiple cross-site scripting (XSS) vulnerabilities in imageVue 1.7 allow remote attackers to inject arbitrary web scrip
23RISCO
abrir
Exploit-DBVexDay Proof
WordPress Core 2.3.2 - '/wp-admin/invites.php?to' Cross-Site Scripting
CVE-2008-1304webappsphp07 mar 2008
Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.3.2 allow remote attackers to inject arbitrary web sc
23RISCO
abrir
Exploit-DBVexDay Proof
MailEnable 3.13 - IMAP Service Multiple Remote Vulnerabilities
CVE-2008-1277doswindows07 mar 2008
The IMAP service (MEIMAPS.exe) in MailEnable Professional Edition and Enterprise Edition 3.13 and earlier allows remote
23RISCO
abrir
Exploit-DBVexDay Proof
WordPress Core 2.3.2 - '/wp-admin/users.php?inviteemail' Cross-Site Scripting
CVE-2008-1304webappsphp07 mar 2008
Multiple cross-site scripting (XSS) vulnerabilities in WordPress 2.3.2 allow remote attackers to inject arbitrary web sc
23RISCO
abrir
Exploit-DBVexDay Proof
ImageVue 1.7 - 'dir2.php?path' Cross-Site Scripting
CVE-2008-1273webappsphp07 mar 2008
Multiple cross-site scripting (XSS) vulnerabilities in imageVue 1.7 allow remote attackers to inject arbitrary web scrip
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Office 2000/2003/2004/XP - File Memory Corruption
CVE-2008-0118doswindows07 mar 2008
Unspecified vulnerability in Microsoft Office 2000 SP3, XP SP3, 2003 SP2, Excel Viewer 2003 up to SP3, and Office 2004 f
35RISCO
abrir
Exploit-DBVexDay Proof
Yap Blog 1.1 - 'index.php' Remote File Inclusion
CVE-2008-1370webappsphp06 mar 2008
PHP remote file inclusion vulnerability in index.php in wildmary Yap Blog 1.1 allows remote attackers to execute arbitra
23RISCO
abrir
Exploit-DBVexDay Proof
PHP-Nuke KutubiSitte Module - 'kid' SQL Injection
CVE-2008-1219webappsphp06 mar 2008
SQL injection vulnerability in the Kutub-i Sitte (KutubiSitte) 1.1 module for PHP-Nuke allows remote attackers to execut
23RISCO
abrir
Exploit-DBVexDay Proof
Check Point VPN-1 UTM Edge NGX 7.0.48x - Login Page Cross-Site Scripting
CVE-2008-1208remotehardware06 mar 2008
Cross-site scripting (XSS) vulnerability in the login page in Check Point VPN-1 UTM Edge W Embedded NGX 7.0.48x allows r
23RISCO
abrir
Exploit-DBVexDay Proof
Airspan ProST WiMAX Device - Web Interface Authentication Bypass
CVE-2008-1262remotehardware06 mar 2008
The administration panel on the Airspan WiMax ProST 4.1 antenna with 6.5.38.0 software does not verify authentication cr
23RISCO
abrir
Exploit-DBVexDay Proof
Sun Java Runtime Environment 1.x - Image Parsing Heap Buffer Overflow
CVE-2008-1193dosmultiple06 mar 2008
Unspecified vulnerability in Java Runtime Environment Image Parsing Library in Sun JDK and JRE 6 Update 4 and earlier, a
28RISCO
abrir
Exploit-DBVexDay Proof
Microworld eScan Server 9.0.742 - Directory Traversal
CVE-2008-1221remotewindows06 mar 2008
Absolute path traversal vulnerability in the FTP server in MicroWorld eScan Corporate Edition 9.0.742.98 and eScan Manag
23RISCO
abrir
Exploit-DBVexDay Proof
ICQ Toolbar 2.3 - ActiveX Remote Denial of Service
CVE-2008-7135doswindows06 mar 2008
toolbaru.dll in ICQ Toolbar (ICQToolbar) 2.3 allows remote attackers to cause a denial of service (toolbar crash) via a
23RISCO
abrir
Exploit-DBVexDay Proof
PHP-Nuke 4nChat Module 0.91 - 'roomid' SQL Injection
CVE-2008-1220webappsphp06 mar 2008
SQL injection vulnerability in the 4nChat 0.91 module for PHP-Nuke allows remote attackers to execute arbitrary SQL comm
23RISCO
abrir
Exploit-DBVexDay Proof
Perforce Server 2007.3 - Multiple Remote Denial of Service Vulnerabilities
CVE-2008-1303doswindows05 mar 2008
The Perforce service (p4s.exe) in Perforce Server 2007.3/143793 and earlier allows remote attackers to cause a denial of
23RISCO
abrir
Exploit-DBVexDay Proof
Google Android Web Browser - '.BMP' File Integer Overflow
CVE-2008-0986dosandroid04 mar 2008
Integer overflow in the BMP::readFromStream method in the libsgl.so library in Google Android SDK m3-rc37a and earlier,
23RISCO
abrir
Exploit-DBVexDay Proof
Google Android Web Browser - '.GIF' File Heap Buffer Overflow
CVE-2008-0985dosandroid04 mar 2008
Heap-based buffer overflow in the GIF library in the WebKit framework for Google Android SDK m3-rc37a and earlier allows
23RISCO
abrir
anteriorpágina 495 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.