Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.449exploits catalogados
35.552CVEs com exploração pública
24.695testados em laboratório
24.451 exploits
Exploit-DBVexDay Proof
PHPX 3.5.15/3.5.16 - 'gallery.php' SQL Injection
CVE-2007-1550webappsphp19 mar 2007
Multiple SQL injection vulnerabilities in phpx 3.5.15 allow remote attackers to execute arbitrary SQL commands via the (
23RISCO
abrir
Exploit-DBVexDay Proof
PHPX 3.5.15/3.5.16 - 'news.php' SQL Injection
CVE-2007-1550webappsphp19 mar 2007
Multiple SQL injection vulnerabilities in phpx 3.5.15 allow remote attackers to execute arbitrary SQL commands via the (
23RISCO
abrir
Exploit-DBVexDay Proof
PHPX 3.5.15/3.5.16 - 'print.php' SQL Injection
CVE-2007-1550webappsphp19 mar 2007
Multiple SQL injection vulnerabilities in phpx 3.5.15 allow remote attackers to execute arbitrary SQL commands via the (
23RISCO
abrir
Exploit-DBVexDay Proof
PHPX 3.5.15/3.5.16 - 'users.php' SQL Injection
CVE-2007-1550webappsphp19 mar 2007
Multiple SQL injection vulnerabilities in phpx 3.5.15 allow remote attackers to execute arbitrary SQL commands via the (
23RISCO
abrir
Exploit-DBVexDay Proof
LedgerSMB1.0/1.1 / SQL-Ledger 2.6.x - 'Login' Local File Inclusion / Authentication Bypass
CVE-2007-1540webappscgi19 mar 2007
Directory traversal vulnerability in am.pl in (1) SQL-Ledger 2.6.27 and earlier, and (2) LedgerSMB before 1.2.0, allows
23RISCO
abrir
Exploit-DBVexDay Proof
NetVIOS Portal - 'page.asp' SQL Injection
CVE-2006-5954webappsasp19 mar 2007
SQL injection vulnerability in page.asp in NetVIOS 2.0 and earlier allows remote attackers to execute arbitrary SQL comm
23RISCO
abrir
Exploit-DBVexDay Proof
WordPress Core < 2.1.2 - 'PHP_Self' Cross-Site Scripting
CVE-2007-1622webappsphp19 mar 2007
Cross-site scripting (XSS) vulnerability in wp-admin/vars.php in WordPress before 2.0.10 RC2, and before 2.1.3 RC2 in th
23RISCO
abrir
Exploit-DBVexDay Proof
Net Portal Dynamic System (NPDS) 5.10 - Remote Code Execution (1)
CVE-2007-1634webappsphp18 mar 2007
Variable extraction vulnerability in grab_globals.php in Net Portal Dynamic System (NPDS) 5.10 and earlier allows remote
23RISCO
abrir
Exploit-DBVexDay Proof
Net Portal Dynamic System (NPDS) 5.10 - Remote Code Execution (1)
CVE-2007-1635webappsphp18 mar 2007
Static code injection vulnerability in admin/settings.php in Net Portal Dynamic System (NPDS) 5.10 and earlier allows re
23RISCO
abrir
Exploit-DBVexDay Proof
Oracle Portal 10g - 'P_OldURL' Cross-Site Scripting
CVE-2007-1506remotemultiple16 mar 2007
Cross-site scripting (XSS) vulnerability in PORTAL.wwv_main.render_warning_screen in the Oracle Portal 10g allows remote
23RISCO
abrir
Exploit-DBVexDay Proof
CA BrightStor ARCserve - 'msgeng.exe' Remote Stack Overflow
CVE-2006-5143remotewindows16 mar 2007
Multiple buffer overflows in CA BrightStor ARCserve Backup r11.5 SP1 and earlier, r11.1, and 9.01; BrightStor ARCserve B
60RISCO
abrir
Exploit-DBVexDay Proof
PHP 4.4.6/5.2.1 - 'array_user_key_compare()' ZVAL dtor Local Overflow
CVE-2007-1484locallinux16 mar 2007
The array_user_key_compare function in PHP 4.4.6 and earlier, and 5.x up to 5.2.1, makes erroneous calls to zval_dtor, w
23RISCO
abrir
Exploit-DBVexDay Proof
Holtstraeter Rot 13 - 'Enkrypt.php' Directory Traversal
CVE-2007-1509webappsphp16 mar 2007
Directory traversal vulnerability in enkrypt.php in Sascha Schroeder krypt (aka Holtstraeter Rot 13) allows remote attac
23RISCO
abrir
Exploit-DBVexDay Proof
DirectAdmin 1.292 - 'CMD_USER_STATS' Cross-Site Scripting
CVE-2007-1508webappsphp16 mar 2007
Cross-site scripting (XSS) vulnerability in CMD_USER_STATS in DirectAdmin allows remote attackers to inject arbitrary we
23RISCO
abrir
Exploit-DBVexDay Proof
Horde IMP Webmail 4.0.4 Client - Multiple Input Validation Vulnerabilities
CVE-2007-1515webappsphp15 mar 2007
Multiple cross-site scripting (XSS) vulnerabilities in Horde IMP H3 4.1.3, and possibly earlier, allow remote attackers
23RISCO
abrir
Exploit-DBVexDay Proof
Horde Framework 3.1.3 - 'login.php' Cross-Site Scripting
CVE-2007-1473webappsphp15 mar 2007
Cross-site scripting (XSS) vulnerability in framework/NLS/NLS.php in Horde Framework before 3.1.4 RC1, when the login pa
23RISCO
abrir
Exploit-DBVexDay Proof
Horde Framework and IMP 2.x/3.x - Cleanup Cron Script Arbitrary File Deletion
CVE-2007-1474locallinux15 mar 2007
Argument injection vulnerability in the cleanup cron script in Horde Project Horde and IMP before Horde Application Fram
23RISCO
abrir
Exploit-DBVexDay Proof
Symantec 'SYMTDI.SYS' Device Driver - Local Denial of Service
CVE-2007-1476doswindows15 mar 2007
The SymTDI device driver (SYMTDI.SYS) in Symantec Norton Personal Firewall 2006 9.1.1.7 and earlier, Internet Security 2
23RISCO
abrir
Exploit-DBVexDay Proof
WarFTP 1.65 (Windows 2000 SP4) - 'USER' Remote Buffer Overflow
CVE-2007-1567remotewindows15 mar 2007
Stack-based buffer overflow in War FTP Daemon 1.65, and possibly earlier, allows remote attackers to cause a denial of s
35RISCO
abrir
Exploit-DBVexDay Proof
Woltlab Burning Board 2.x - 'usergroups.php' SQL Injection
CVE-2007-1518webappsphp15 mar 2007
SQL injection vulnerability in usergroups.php in Woltlab Burning Board (wBB) 2.x allows remote attackers to execute arbi
23RISCO
abrir
Exploit-DBVexDay Proof
Viper Web Portal 0.1 - 'index.php' Remote File Inclusion
CVE-2007-1514webappsphp15 mar 2007
PHP remote file inclusion vulnerability in index.php in ViperWeb Portal alpha 0.1 allows remote attackers to execute arb
23RISCO
abrir
Exploit-DBVexDay Proof
Orion-Blog 2.0 - Remote Authentication Bypass
CVE-2007-1471webappsasp15 mar 2007
admin/default.asp in Orion-Blog 2.0 allows remote attackers to bypass authentication controls and gain privileges via a
23RISCO
abrir
Exploit-DBVexDay Proof
Absolute Image Gallery 2.0 - 'gallery.asp?categoryId' SQL Injection
CVE-2007-1469webappsasp15 mar 2007
SQL injection vulnerability in gallery.asp in Absolute Image Gallery 2.0 allows remote attackers to execute arbitrary SQ
23RISCO
abrir
Exploit-DBVexDay Proof
Zomplog 3.7.6 (Windows x86) - Local File Inclusion
CVE-2007-1524webappsphp14 mar 2007
Directory traversal vulnerability in themes/default/ in ZomPlog 3.7.6 and earlier allows remote attackers to include arb
23RISCO
abrir
Exploit-DBVexDay Proof
aBitWhizzy - 'whizzylink.php?d' Traversal Arbitrary Directory Listing
CVE-2007-1773webappsphp14 mar 2007
Multiple directory traversal vulnerabilities in aBitWhizzy allow remote attackers to list arbitrary directories via a ..
23RISCO
abrir
Exploit-DBVexDay Proof
aBitWhizzy - 'whizzypic.php?d' Traversal Arbitrary Directory Listing
CVE-2007-1773remotephp14 mar 2007
Multiple directory traversal vulnerabilities in aBitWhizzy allow remote attackers to list arbitrary directories via a ..
23RISCO
abrir
Exploit-DBVexDay Proof
MiniGZip - Controls File_Compress Buffer Overflow
CVE-2007-1657doswindows14 mar 2007
Stack-based buffer overflow in the file_compress function in minigzip (Modules/zlib) in Python 2.5 allows context-depend
23RISCO
abrir
Exploit-DBVexDay Proof
PHP 5.2.1 - 'session_regenerate_id()' Double-Free
CVE-2007-1521locallinux14 mar 2007
Double free vulnerability in PHP before 4.4.7, and 5.x before 5.2.2, allows context-dependent attackers to execute arbit
23RISCO
abrir
Exploit-DBVexDay Proof
WarFTP 1.65 (Windows 2000 SP4) - 'USER' Remote Buffer Overflow
CVE-2007-1567remotewindows14 mar 2007
Stack-based buffer overflow in War FTP Daemon 1.65, and possibly earlier, allows remote attackers to cause a denial of s
35RISCO
abrir
Exploit-DBVexDay Proof
Apache Tomcat 5.x/6.0.x - Directory Traversal
CVE-2007-0450remotelinux14 mar 2007
Directory traversal vulnerability in Apache HTTP Server and Tomcat 5.x before 5.5.22 and 6.x before 6.0.10, when using c
45RISCO
abrir
anteriorpágina 541 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.