Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.449exploits catalogados
35.552CVEs com exploração pública
24.695testados em laboratório
24.451 exploits
Exploit-DBVexDay Proof
Gazi Okul Sitesi 2007 - 'Fotokategori.asp' SQL Injection
CVE-2007-1971webappsasp04 abr 2007
SQL injection vulnerability in fotokategori.asp in Gazi Okul Sitesi 2007 allows remote attackers to execute arbitrary SQ
23RISCO
abrir
Exploit-DBVexDay Proof
FastStone Image Viewer 2.9/3.6 - '.bmp' Image Handling Memory Corruption
CVE-2007-1942doswindows04 abr 2007
Integer overflow in FastStone Image Viewer 2.9 allows context-dependent attackers to cause a denial of service and possi
23RISCO
abrir
Exploit-DBVexDay Proof
HP Mercury Quality Center - Spider90.ocx ProgColor Overflow
CVE-2007-1819remotewindows04 abr 2007
Stack-based buffer overflow in the SPIDERLib.Loader ActiveX control (Spider90.ocx) 9.1.0.4353 in TestDirector (TD) for M
50RISCO
abrir
Exploit-DBVexDay Proof
phpMyNewsletter 0.6.10 - 'customize.php' Remote File Inclusion
CVE-2002-1887webappsphp04 abr 2007
PHP remote file inclusion vulnerability in customize.php for phpMyNewsletter 0.6.10 allows remote attackers to execute a
23RISCO
abrir
Exploit-DBVexDay Proof
ACDSee 9.0 Photo Manager - Multiple '.BMP' Denial of Service Vulnerabilities
CVE-2007-1943doswindows04 abr 2007
Integer overflow in ACDSee Photo Manager 9.0 allows context-dependent attackers to cause a denial of service and possibl
23RISCO
abrir
Exploit-DBVexDay Proof
TrueCrypt 4.3 - 'setuid' Local Privilege Escalation
CVE-2007-1738localwindows04 abr 2007
TrueCrypt 4.3, when installed setuid root, allows local users to cause a denial of service (filesystem unavailability) o
23RISCO
abrir
Exploit-DBVexDay Proof
IrfanView 3.99 - Multiple .BMP Denial of Service Vulnerabilities
CVE-2007-1948doswindows04 abr 2007
Buffer overflow in IrfanView 3.99 allows context-dependent attackers to cause a denial of service and possibly execute a
23RISCO
abrir
Exploit-DBVexDay Proof
AOL SuperBuddy - ActiveX Control Remote Code Execution (Metasploit)
CVE-2006-5820remotewindows04 abr 2007
The LinkSBIcons method in the SuperBuddy ActiveX control (Sb.SuperBuddy.1) in America Online 9.0 Security Edition derefe
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Animated Cursor '.ani' Local Overflow (Hardware DEP)
CVE-2007-1765localwindows03 abr 2007
Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code
50RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Animated Cursor '.ani' Universal Generator
CVE-2007-1765remotewindows03 abr 2007
Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code
50RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Animated Cursor '.ani' Universal Generator
CVE-2007-0038remotewindows03 abr 2007
Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attack
60RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Animated Cursor '.ani' Local Overflow (Hardware DEP)
CVE-2007-0038localwindows03 abr 2007
Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attack
60RISCO
abrir
Exploit-DBVexDay Proof
HP Mercury Quality Center 9.0 build 9.1.0.4352 - SQL Execution
CVE-2007-1882remotemultiple03 abr 2007
qcbin/servlet/tdservlet/TDAPI_GeneralWebTreatment in HP Mercury Quality Center 9.0 build 9.1.0.4352 allows remote authen
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Animated Cursor '.ani' Local Buffer Overflow
CVE-2007-0038localwindows02 abr 2007
Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attack
60RISCO
abrir
Exploit-DBVexDay Proof
XOOPS Module WF-Section 1.01 - 'articleId' SQL Injection
CVE-2005-0725webappsphp02 abr 2007
SQL injection vulnerability in the getAllbyArticle function in wfsfiles.php for WF-Sections (wfsections) 1.07 allows rem
23RISCO
abrir
Exploit-DBVexDay Proof
PulseAudio 0.9.5 - 'Assert()' Remote Denial of Service
CVE-2007-1804doslinux02 abr 2007
PulseAudio 0.9.5 allows remote attackers to cause a denial of service (daemon crash) via (1) a PA_PSTREAM_DESCRIPTOR_LEN
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Animated Cursor '.ani' Local Buffer Overflow
CVE-2007-1765localwindows02 abr 2007
Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code
50RISCO
abrir
Exploit-DBVexDay Proof
XOOPS Module Zmagazine 1.0 - 'print.php' SQL Injection
CVE-2005-0725webappsphp02 abr 2007
SQL injection vulnerability in the getAllbyArticle function in wfsfiles.php for WF-Sections (wfsections) 1.07 allows rem
23RISCO
abrir
Exploit-DBVexDay Proof
XOOPS Module XFsection 1.07 - 'articleId' Blind SQL Injection
CVE-2005-0725webappsphp02 abr 2007
SQL injection vulnerability in the getAllbyArticle function in wfsfiles.php for WF-Sections (wfsections) 1.07 allows rem
23RISCO
abrir
Exploit-DBVexDay Proof
Frontbase 4.2.7 - (Authenticated) Remote Buffer Overflow (2.2)
CVE-2007-1511remotewindows02 abr 2007
Buffer overflow in FrontBase Relational Database Server 4.2.7 and earlier allows remote authenticated users, with privil
23RISCO
abrir
Exploit-DBVexDay Proof
IPSwitch IMail Server 8.20 - IMAPD Remote Buffer Overflow
CVE-2005-1255remotewindows01 abr 2007
Multiple stack-based buffer overflows in the IMAP server in IMail 8.12 and 8.13 in Ipswitch Collaboration Suite (ICS), a
35RISCO
abrir
Exploit-DBVexDay Proof
Symantec (Multiple Products) - 'SPBBCDrv' Driver Local Denial of Service
CVE-2007-1793doswindows01 abr 2007
SPBBCDrv.sys in Symantec Norton Personal Firewall 2006 9.1.0.33 and 9.1.1.7 does not validate certain arguments before b
23RISCO
abrir
Exploit-DBVexDay Proof
HP Instant Support - ActiveX Control Driver Check Buffer Overflow
CVE-2007-3554remotewindows01 abr 2007
Stack-based buffer overflow in the HPSDDX Class (SDD) ActiveX control in sdd.dll in HP Instant Support - Driver Check be
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Animated Cursor '.ani' Remote (eeye patch Bypass)
CVE-2007-0038remotewindows01 abr 2007
Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attack
60RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows XP - Animated Cursor '.ani' Remote Overflow (2)
CVE-2007-0038remotewindows01 abr 2007
Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attack
60RISCO
abrir
Exploit-DBVexDay Proof
WinMail Server 4.4 build 1124 - 'WebMail' Remote Add Super User
CVE-2005-3811webappsphp01 abr 2007
Directory traversal vulnerability in admin/main.php in AMAX Magic Winmail Server 4.2 (build 0824) and earlier allows rem
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows XP/Vista - Animated Cursor '.ani' Remote Overflow
CVE-2007-0038remotewindows01 abr 2007
Stack-based buffer overflow in the animated cursor code in Microsoft Windows 2000 SP4 through Vista allows remote attack
60RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - Animated Cursor '.ani' Remote (eeye patch Bypass)
CVE-2007-1765remotewindows01 abr 2007
Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code
50RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows XP - Animated Cursor '.ani' Remote Overflow (2)
CVE-2007-1765remotewindows01 abr 2007
Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code
50RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows XP/Vista - Animated Cursor '.ani' Remote Overflow
CVE-2007-1765remotewindows01 abr 2007
Unspecified vulnerability in Microsoft Windows 2000 SP4 through Vista allows remote attackers to execute arbitrary code
50RISCO
abrir
anteriorpágina 538 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.