Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.449exploits catalogados
35.552CVEs com exploração pública
24.695testados em laboratório
24.451 exploits
Exploit-DBVexDay Proof
Word Viewer OCX 3.2 - Remote Denial of Service
CVE-2007-2496doswindows03 mai 2007
The WordOCX ActiveX control in WordViewer.ocx 3.2.0.5 allows remote attackers to cause a denial of service (Internet Exp
23RISCO
abrir
Exploit-DBVexDay Proof
Pre News Manager 1.0 - SQL Injection
CVE-2006-2763webappsphp03 mai 2007
SQL injection vulnerability in Pre News Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the (1
23RISCO
abrir
Exploit-DBVexDay Proof
PHPSecurityAdmin 4.0.2 - 'Logout.php' Remote File Inclusion
CVE-2007-2628webappsphp03 mai 2007
PHP remote file inclusion vulnerability in include/logout.php in Justin Koivisto SecurityAdmin for PHP (aka PHPSecurityA
23RISCO
abrir
Exploit-DBVexDay Proof
Atomix MP3 - '.MP3' File Buffer Overflow
CVE-2007-2487doswindows02 mai 2007
Stack-based buffer overflow in AtomixMP3 allows remote attackers to execute arbitrary code via a long filename in an MP3
23RISCO
abrir
Exploit-DBVexDay Proof
Progress WebSpeed 3.0/3.1 - Denial of Service
CVE-2007-2506doswindows02 mai 2007
WebSpeed 3.x in OpenEdge 10.x in Progress Software Progress 9.1e, and certain other 9.x versions, allows remote attacker
23RISCO
abrir
Exploit-DBVexDay Proof
ObieWebsite Mini Web Shop 2 - 'order_form.php?PATH_INFO' Cross-Site Scripting
CVE-2007-2532webappsphp02 mai 2007
Multiple cross-site scripting (XSS) vulnerabilities in Minh Nguyen Duong Obie Website Mini Web Shop 2 allow remote attac
23RISCO
abrir
Exploit-DBVexDay Proof
ObieWebsite Mini Web Shop 2 - 'Sendmail.php?PATH_INFO' Cross-Site Scripting
CVE-2007-2532webappsphp02 mai 2007
Multiple cross-site scripting (XSS) vulnerabilities in Minh Nguyen Duong Obie Website Mini Web Shop 2 allow remote attac
23RISCO
abrir
Exploit-DBVexDay Proof
3proxy 0.5.3g - exec-shield 'proxy.c logurl()' Remote Overflow
CVE-2007-2031remotelinux02 mai 2007
Buffer overflow in the HTTP proxy service for 3proxy 0.5 to 0.5.3g, and 0.6b-devel before 20070413, might allow remote a
28RISCO
abrir
Exploit-DBVexDay Proof
CMS Made Simple 1.0.5 - 'Stylesheet.php' SQL Injection
CVE-2007-2473webappsphp02 mai 2007
SQL injection vulnerability in stylesheet.php in CMS Made Simple 1.0.5 and earlier allows remote attackers to execute ar
23RISCO
abrir
Exploit-DBVexDay Proof
WordPress Plugin wordTube 1.43 - 'wpPATH' Remote File Inclusion
CVE-2007-2482webappsphp01 mai 2007
Directory traversal vulnerability in wordtube-button.php in the wordTube 1.43 and earlier plugin for WordPress, when reg
23RISCO
abrir
Exploit-DBVexDay Proof
X.Org X Window System Xserver 1.3 - XRender Extension Divide by Zero Denial of Service
CVE-2007-2437doslinux01 mai 2007
The X render (Xrender) extension in X.org X Window System 7.0, 7.1, and 7.2, with Xserver 1.3.0 and earlier, allows remo
23RISCO
abrir
Exploit-DBVexDay Proof
Mozilla Firefox 2.0.0.3 - Href Denial of Service
CVE-2007-2671doswindows01 mai 2007
Mozilla Firefox 2.0.0.3 allows remote attackers to cause a denial of service (application crash) via a long hostname in
23RISCO
abrir
Exploit-DBVexDay Proof
3proxy 0.5.3g (Linux) - 'proxy.c logurl()' Remote Buffer Overflow
CVE-2007-2031remotelinux30 abr 2007
Buffer overflow in the HTTP proxy service for 3proxy 0.5 to 0.5.3g, and 0.6b-devel before 20070413, might allow remote a
28RISCO
abrir
Exploit-DBVexDay Proof
Aventail Connect 4.1.2.13 - Hostname Remote Buffer Overflow
CVE-2007-2434doswindows30 abr 2007
Buffer overflow in asnsp.dll in Aventail Connect 4.1.2.13 allows remote attackers to cause a denial of service (applicat
28RISCO
abrir
Exploit-DBVexDay Proof
3proxy 0.5.3g (Windows x86) - 'proxy.c logurl()' Remote Buffer Overflow
CVE-2007-2031remotewindows_x8630 abr 2007
Buffer overflow in the HTTP proxy service for 3proxy 0.5 to 0.5.3g, and 0.6b-devel before 20070413, might allow remote a
28RISCO
abrir
Exploit-DBVexDay Proof
Gazi Download Portal - 'Down_Indir.asp' SQL Injection
CVE-2007-2810webappsasp30 abr 2007
SQL injection vulnerability in down_indir.asp in Gazi Download Portal allows remote attackers to execute arbitrary SQL c
23RISCO
abrir
Exploit-DBVexDay Proof
E-Annu - 'home.php' SQL Injection
CVE-2007-2416webappsphp30 abr 2007
SQL injection vulnerability in home.php in E-Annu allows remote attackers to execute arbitrary SQL commands via the a pa
23RISCO
abrir
Exploit-DBVexDay Proof
Fenice Oms server 1.10 - exec-shield Remote Buffer Overflow
CVE-2006-2022remotelinux29 abr 2007
Buffer overflow in the parse_url function in the RTSP module (rtsp/parse_url.c) in Fenice 1.10 and earlier allows remote
28RISCO
abrir
Exploit-DBVexDay Proof
MyDNS 1.1.0 - Remote Heap Overflow (PoC)
CVE-2007-2362doslinux27 abr 2007
Multiple buffer overflows in MyDNS 1.1.0 allow remote attackers to (1) cause a denial of service (daemon crash) and poss
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer - NCTAudioFile2.AudioFile ActiveX Remote Stack Overflow (2)
CVE-2007-0018remotewindows27 abr 2007
Stack-based buffer overflow in the NCTAudioFile2.AudioFile ActiveX control (NCTAudioFile2.dll), as used by multiple prod
50RISCO
abrir
Exploit-DBVexDay Proof
ManageEngine Password Manager Pro Build 5401 - Database Remote Unauthorized Access
CVE-2007-2429remotemultiple27 abr 2007
ManageEngine PasswordManager Pro (PMP) allows remote attackers to obtain administrative access to a database by injectin
23RISCO
abrir
Exploit-DBVexDay Proof
Apache AXIS 1.0 - Non-Existent WSDL Path Information Disclosure
CVE-2007-2353remotemultiple27 abr 2007
Apache Axis 1.0 allows remote attackers to obtain sensitive information by requesting a non-existent WSDL file, which re
28RISCO
abrir
Exploit-DBVexDay Proof
IPIX Image Well - ActiveX 'iPIX-ImageWell-ipix.dll' Remote Buffer Overflow
CVE-2007-1687remotewindows27 abr 2007
Multiple buffer overflows in the Internet Pictures Corporation iPIX Image Well ActiveX control (iPIX-ImageWell-ipix.dll)
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - '.ani' GDI Remote Privilege Escalation (MS07-017)
CVE-2007-1215remotewindows26 abr 2007
Buffer overflow in the Graphics Device Interface (GDI) in Microsoft Windows 2000 SP4; XP SP2; Server 2003 Gold, SP1, and
23RISCO
abrir
Exploit-DBVexDay Proof
GIMP 2.2.14 - '.ras' SUNRAS Plugin Buffer Overflow
CVE-2007-2356localwindows26 abr 2007
Stack-based buffer overflow in the set_color_table function in sunras.c in the SUNRAS plugin in Gimp 2.2.14 allows user-
28RISCO
abrir
Exploit-DBVexDay Proof
Burak Yilmaz Blog 1.0 - 'BRY.asp' SQL Injection
CVE-2007-2420webappsasp26 abr 2007
SQL injection vulnerability in bry.asp in Burak Yilmaz Blog 1.0 allows remote attackers to execute arbitrary SQL command
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - '.ani' GDI Remote Privilege Escalation (MS07-017)
CVE-2007-1211remotewindows26 abr 2007
Unspecified kernel GDI functions in Microsoft Windows 2000 SP4; XP SP2; and Server 2003 Gold, SP1, and SP2 allows user-a
28RISCO
abrir
Exploit-DBVexDay Proof
Doruk100Net - 'Info.php' Remote File Inclusion
CVE-2007-2288webappsphp26 abr 2007
PHP remote file inclusion vulnerability in info.php in Doruk100.net doruk100net allows remote attackers to execute arbit
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - '.ani' GDI Remote Privilege Escalation (MS07-017)
CVE-2007-1212remotewindows26 abr 2007
Buffer overflow in the Graphics Device Interface (GDI) in Microsoft Windows 2000 SP4; XP SP2; Server 2003 Gold, SP1, and
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - '.ani' GDI Remote Privilege Escalation (MS07-017)
CVE-2007-0038remotewindows26 abr 2007
Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attack
60RISCO
abrir
anteriorpágina 533 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.