Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.302exploits catalogados
35.469CVEs com exploração pública
24.695testados em laboratório
24.451 exploits
Exploit-DBVexDay Proof
BlueCat Networks Adonis 5.0.2.8 - CLI Privilege Escalation
CVE-2007-4390locallinux16 ago 2007
The Command Line Interface (CLI), aka Adonis Administration Console, on the BlueCat Networks Adonis DNS/DHCP appliance 5
23RISCO
abrir
Exploit-DBVexDay Proof
Sun Java Runtime Environment 1.4.2 - Font Parsing Privilege Escalation
CVE-2007-4381remotejava15 ago 2007
Unspecified vulnerability in the font parsing implementation in Sun JDK and JRE 5.0 Update 9 and earlier, and SDK and JR
23RISCO
abrir
Exploit-DBVexDay Proof
Yahoo! Messenger 8.1 - 'KDU_V32M.DLL' Remote Denial of Service
CVE-2007-4391doswindows15 ago 2007
Heap-based buffer overflow in Kakadu kdu_v32m.dll in Yahoo! Messenger 8.1.0.413 allows remote attackers to cause a denia
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft XML Core Services 6.0 - SubstringData Integer Overflow
CVE-2007-2223remotewindows14 ago 2007
Microsoft XML Core Services (MSXML) 3.0 through 6.0 allows remote attackers to execute arbitrary code via the substringD
35RISCO
abrir
Exploit-DBVexDay Proof
Apache Tomcat 6.0.13 - Host Manager Servlet Cross-Site Scripting
CVE-2007-3386remotemultiple14 ago 2007
Cross-site scripting (XSS) vulnerability in the Host Manager Servlet for Apache Tomcat 6.0.0 to 6.0.13 and 5.5.0 to 5.5.
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 5.0.1 - Vector Markup Language 'VGX.dll' Remote Buffer Overflow
CVE-2007-1749doswindows14 ago 2007
Integer underflow in the CDownloadSink class code in the Vector Markup Language (VML) component (VGX.DLL), as used in In
35RISCO
abrir
Exploit-DBVexDay Proof
Apache Tomcat 6.0.13 - Insecure Cookie Handling Quote Delimiter Session ID Disclosure
CVE-2007-3382remotemultiple14 ago 2007
Apache Tomcat 6.0.0 to 6.0.13, 5.5.0 to 5.5.24, 5.0.0 to 5.0.30, 4.1.0 to 4.1.36, and 3.3 to 3.3.2 treats single quotes
35RISCO
abrir
Exploit-DBVexDay Proof
Zoidcom 0.6.x - Malformed Packet Denial of Service
CVE-2007-4358dosmultiple14 ago 2007
Zoidcom 0.6.7 and earlier allows remote attackers to cause a denial of service (application crash) via a JOIN packet (ak
23RISCO
abrir
Exploit-DBVexDay Proof
WordPress Core 1.0.7 - 'Pool index.php' Cross-Site Scripting
CVE-2007-4482webappsphp13 ago 2007
Cross-site scripting (XSS) vulnerability in index.php in the Pool 1.0.7 theme for WordPress allows remote attackers to i
23RISCO
abrir
Exploit-DBVexDay Proof
OWASP Stinger - Filter Bypass
CVE-2007-4385remotemultiple13 ago 2007
OWASP Stinger before 2.5 allows remote attackers to bypass input validation routines by using multipart encoded requests
23RISCO
abrir
Exploit-DBVexDay Proof
Savant Web Server 3.1 - GET Universal Remote Overflow
CVE-2002-1120remotewindows12 ago 2007
Buffer overflow in Savant Web Server 3.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP G
50RISCO
abrir
Exploit-DBVexDay Proof
Lib2 PHP Library 0.2 - 'My_Statistics.php' Remote File Inclusion
CVE-2007-4341webappsphp11 ago 2007
PHP remote file inclusion vulnerability in adm/my_statistics.php in Omnistar Lib2 PHP 0.2 allows remote attackers to exe
23RISCO
abrir
Exploit-DBVexDay Proof
Haudenschilt Family Connections 0.8 - 'index.php' Authentication Bypass
CVE-2007-4338webappsphp11 ago 2007
index.php in Ryan Haudenschilt Family Connections (FCMS) before 0.9 allows remote attackers to access an arbitrary accou
23RISCO
abrir
Exploit-DBVexDay Proof
PHP-Stats 0.1.9.2 - 'WhoIs.php' Cross-Site Scripting
CVE-2007-4334webappsphp11 ago 2007
Cross-site scripting (XSS) vulnerability in whois.php in Php-stats 0.1.9.2 allows remote attackers to inject arbitrary w
23RISCO
abrir
Exploit-DBVexDay Proof
ZYXEL ZyWALL 2 3.62 - '/Forms/General_1?sysSystemName' Cross-Site Scripting
CVE-2007-4318remotehardware10 ago 2007
Cross-site scripting (XSS) vulnerability in Forms/General_1 in the management interface in ZyNOS firmware 3.62(WK.6) on
23RISCO
abrir
Exploit-DBVexDay Proof
File Uploader 1.1 - 'datei.php?config[root_ordner]' Remote File Inclusion
CVE-2007-4327webappsphp09 ago 2007
Multiple PHP remote file inclusion vulnerabilities in File Uploader 1.1 allow remote attackers to execute arbitrary PHP
23RISCO
abrir
Exploit-DBVexDay Proof
File Uploader 1.1 - 'index.php?config[root_ordner]' Remote File Inclusion
CVE-2007-4327webappsphp09 ago 2007
Multiple PHP remote file inclusion vulnerabilities in File Uploader 1.1 allow remote attackers to execute arbitrary PHP
23RISCO
abrir
Exploit-DBVexDay Proof
Mapos-Scripts.de Gastebuch 1.5 - 'index.php' Remote File Inclusion
CVE-2007-4325webappsphp09 ago 2007
PHP remote file inclusion vulnerability in index.php in Gaestebuch 1.5 allows remote attackers to execute arbitrary PHP
23RISCO
abrir
Exploit-DBVexDay Proof
Web News 1.1 - 'index.php?config[root_ordner]' Remote File Inclusion
CVE-2007-4329webappsphp09 ago 2007
Multiple PHP remote file inclusion vulnerabilities in Web News 1.1 allow remote attackers to execute arbitrary PHP code
23RISCO
abrir
Exploit-DBVexDay Proof
Web News 1.1 - 'feed.php?config[root_ordner]' Remote File Inclusion
CVE-2007-4329webappsphp09 ago 2007
Multiple PHP remote file inclusion vulnerabilities in Web News 1.1 allow remote attackers to execute arbitrary PHP code
23RISCO
abrir
Exploit-DBVexDay Proof
Bilder Galerie 1.0 - 'index.php' Remote File Inclusion
CVE-2007-4328webappsphp09 ago 2007
Multiple PHP remote file inclusion vulnerabilities in Mapos Bilder Galerie 1.0 allow remote attackers to execute arbitra
23RISCO
abrir
Exploit-DBVexDay Proof
Generic Software Wrappers Toolkit 1.6.3 (GSWTK) - Race Condition Privilege Escalation
CVE-2007-4302locallinux09 ago 2007
Multiple race conditions in certain system call wrappers in Generic Software Wrappers Toolkit (GSWTK) allow local users
23RISCO
abrir
Exploit-DBVexDay Proof
Systrace - Multiple System Call Wrappers Concurrency Vulnerabilities
CVE-2007-4305localbsd09 ago 2007
Multiple race conditions in the (1) Sudo monitor mode and (2) Sysjail policies in Systrace on NetBSD and OpenBSD allow l
23RISCO
abrir
Exploit-DBVexDay Proof
Web News 1.1 - 'news.php?config[root_ordner]' Remote File Inclusion
CVE-2007-4329webappsphp09 ago 2007
Multiple PHP remote file inclusion vulnerabilities in Web News 1.1 allow remote attackers to execute arbitrary PHP code
23RISCO
abrir
Exploit-DBVexDay Proof
Shoutbox 1.0 - 'Shoutbox.php' Remote File Inclusion
CVE-2007-4330webappsphp09 ago 2007
PHP remote file inclusion vulnerability in shoutbox.php in Shoutbox 1.0 allows remote attackers to execute arbitrary PHP
23RISCO
abrir
Exploit-DBVexDay Proof
Cisco IOS Next Hop Resolution Protocol (NHRP) - Denial of Service
CVE-2007-4286doswindows09 ago 2007
Buffer overflow in the Next Hop Resolution Protocol (NHRP) functionality in Cisco IOS 12.0 through 12.4 allows remote at
28RISCO
abrir
Exploit-DBVexDay Proof
PHP 5.2.3 - 'snmpget()' object id Local Buffer Overflow (EDI)
CVE-2007-1413localwindows09 ago 2007
Buffer overflow in the snmpget function in the snmp extension in PHP 5.2.3 and earlier, including PHP 4.4.6 and probably
28RISCO
abrir
Exploit-DBVexDay Proof
Coppermine Photo Gallery 1.3/1.4 - 'YABBSE.INC.php' Remote File Inclusion
CVE-2007-4283webappsphp08 ago 2007
PHP remote file inclusion vulnerability in bridge/yabbse.inc.php in Coppermine Photo Gallery (CPG) 1.3.1 allows remote a
23RISCO
abrir
Exploit-DBVexDay Proof
PHP mSQL (msql_connect) - Local Buffer Overflow
CVE-2007-4255localwindows08 ago 2007
Buffer overflow in the mSQL extension in PHP 5.2.3 allows context-dependent attackers to execute arbitrary code via a lo
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Media Player 11 - AU Divide-by-Zero Denial of Service
CVE-2007-4288doswindows08 ago 2007
Microsoft Windows Media Player 11 (wmplayer.exe) allows user-assisted remote attackers to cause a denial of service (app
28RISCO
abrir
anteriorpágina 518 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.