Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.781exploits catalogados
36.771CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
Aigaion 1.3.3 - 'topic topic_id' SQL Injection
CVE-2007-3683webappsphp
SQL injection vulnerability in pagetopic.php in Aigaion 1.3.3 and earlier allows remote attackers to execute arbitrary S
23RISCO
abrir
ReferênciaVexDay Proof
Quate CMS 0.3.4 - Multiple Vulnerabilities
CVE-2008-2496webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in Quate CMS 0.3.4 allow remote attackers to inject arbitrary web sc
23RISCO
abrir
ReferênciaVexDay Proof
CoreHTTP 0.5.3alpha - HTTPd Remote Buffer Overflow
CVE-2007-4060remotelinux
Multiple buffer overflows in the HttpSprockMake function in http.c in Frank Yaul corehttp 0.5.3alpha allow remote attack
23RISCO
abrir
ReferênciaVexDay Proof
Simple Machines Forum (SMF) 1.1.6 - Local File Inclusion / Code Execution
CVE-2008-6659webappsphp
Directory traversal vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 before 1.1.7 all
23RISCO
abrir
ReferênciaVexDay Proof
ZeusCMS 0.3 - Blind SQL Injection
CVE-2007-6623webappsphp
Absolute path traversal vulnerability in ZeusCMS 0.3 and earlier might allow remote attackers to list arbitrary director
23RISCO
abrir
ReferênciaVexDay Proof
blogit! - SQL Injection / File Disclosure / Cross-Site Scripting
CVE-2009-0336webappsphp
Katy Whitton BlogIt! stores sensitive information under the web root with insufficient access control, which allows remo
23RISCO
abrir
ReferênciaVexDay Proof
Advanced Links Management (ALM) 1.52 - SQL Injection
CVE-2008-2529webappsphp
SQL injection vulnerability in read.php in Advanced Links Management (ALM) 1.5.2 allows remote attackers to execute arbi
23RISCO
abrir
ReferênciaVexDay Proof
FTPShell Server 4.3 - Licence Key Remote Buffer Overflow (PoC)
CVE-2009-0349doswindows
Stack-based buffer overflow in FTPShell Server 4.3 allows user-assisted remote attackers to cause a denial of service (p
23RISCO
abrir
ReferênciaVexDay Proof
CDex 1.70b2 (Windows XP SP3) - '.ogg' Local Buffer Overflow
CVE-2009-1039localwindows
Buffer overflow in CDex 1.70b2 allows remote attackers to execute arbitrary code via a crafted Info header in an Ogg Vor
23RISCO
abrir
ReferênciaVexDay Proof
JV2 Folder Gallery 3.0 - Remote File Inclusion
CVE-2007-0682webappsphp
PHP remote file inclusion vulnerability in theme/include_mode/template.php in JV2 Folder Gallery 3.0.2 and earlier allow
23RISCO
abrir
ReferênciaVexDay Proof
Phoenix View CMS Pre Alpha2 - SQL Injection / Local File Inclusion / Cross-Site Scripting
CVE-2008-2535webappsphp
Multiple SQL injection vulnerabilities in Phoenix View CMS Pre Alpha2 and earlier allow remote attackers to execute arbi
23RISCO
abrir
ReferênciaVexDay Proof
Merak Media Player 3.2 - '.m3u' File Local Buffer Overflow (PoC)
CVE-2009-0350doswindows
Stack-based buffer overflow in Merak Media Player 3.2 allows remote attackers to execute arbitrary code via a long strin
28RISCO
abrir
ReferênciaVexDay Proof
wavewoo 0.1.1 - 'loading.php?path_include' Remote File Inclusion
CVE-2007-2273webappsphp
PHP remote file inclusion vulnerability in include/loading.php in Alessandro Lulli wavewoo 0.1.1 allows remote attackers
23RISCO
abrir
ReferênciaVexDay Proof
Mail Machine 3.989 - Local File Inclusion
CVE-2007-3702webappsphp
Directory traversal vulnerability in the load function in cgi-bin/mail/mailmachine.cgi in Mail Machine 3.989 and earlier
23RISCO
abrir
ReferênciaVexDay Proof
WinFTP Server 2.3.0 - 'LIST' (Authenticated) Remote Buffer Overflow
CVE-2009-0351remotewindows
Stack-based buffer overflow in WFTPSRV.exe in WinFTP 2.3.0 allows remote authenticated users to execute arbitrary code v
23RISCO
abrir
ReferênciaVexDay Proof
Snircd 1.3.4 - 'send_user_mode' Denial of Service
CVE-2008-1501dosmultiple
The send_user_mode function in s_user.c in (1) Undernet ircu 2.10.12.12 and earlier, (2) snircd 1.3.4 and earlier, and u
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component EasyBook 1.1 - 'gbid' SQL Injection
CVE-2008-2569webappsphp
SQL injection vulnerability in the EasyBook (com_easybook) component 1.1 for Joomla! allows remote attackers to execute
23RISCO
abrir
ReferênciaVexDay Proof
Microsoft Internet Explorer 7 - Clickjacking
CVE-2009-0369remotewindows
Microsoft Internet Explorer 7 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick acti
28RISCO
abrir
ReferênciaVexDay Proof
SiteXS CMS 0.1.1 - Local File Inclusion
CVE-2009-0371webappsphp
Directory traversal vulnerability in post.php in SiteXS CMS 0.1.1 and earlier allows remote attackers to include and exe
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component ElearningForce Flash Magazine Deluxe - SQL Injection
CVE-2009-0373webappsphp
SQL injection vulnerability in the ElearningForce Flash Magazine Deluxe (com_flashmagazinedeluxe) component for Joomla!
23RISCO
abrir
ReferênciaVexDay Proof
PLog 1.0.6 - 'albumID' SQL Injection
CVE-2008-2629webappsphp
SQL injection vulnerability in the LifeType (formerly pLog) module for Drupal allows remote attackers to execute arbitra
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component beamospetition 1.0.12 - SQL Injection / Cross-Site Scripting
CVE-2009-0377webappsphp
SQL injection vulnerability in the beamospetition (com_beamospetition) 1.0.12 component for Joomla! allows remote attack
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component beamospetition 1.0.12 - SQL Injection / Cross-Site Scripting
CVE-2009-0378webappsphp
Cross-site scripting (XSS) vulnerability in index.php in the beamospetition (com_beamospetition) 1.0.12 component for Jo
23RISCO
abrir
ReferênciaVexDay Proof
mebiblio 0.4.7 - SQL Injection / Arbitrary File Upload / Cross-Site Scripting
CVE-2008-2648webappsphp
Unrestricted file upload vulnerability in upload/uploader.html in meBiblio 0.4.7 allows remote attackers to execute arbi
23RISCO
abrir
ReferênciaVexDay Proof
ezusermanager 1.6 - Remote File Inclusion
CVE-2006-2424webappsphp
PHP remote file inclusion vulnerability in ezUserManager 1.6 and earlier, when register_globals is enabled, allows remot
23RISCO
abrir
ReferênciaVexDay Proof
TightVNC - Authentication Failure Integer Overflow (PoC)
CVE-2009-0388doswindows
Multiple integer signedness errors in (1) UltraVNC 1.0.2 and 1.0.5 and (2) TightVnc 1.3.9 allow remote VNC servers to ca
28RISCO
abrir
ReferênciaVexDay Proof
UltraVNC/TightVNC (Multiple VNC Clients) - Multiple Integer Overflows (PoC)
CVE-2009-0388doswindows
Multiple integer signedness errors in (1) UltraVNC 1.0.2 and 1.0.5 and (2) TightVnc 1.3.9 allow remote VNC servers to ca
28RISCO
abrir
ReferênciaVexDay Proof
WOW Web On Windows ActiveX Control 2 - Remote Code Execution
CVE-2009-0389remotewindows
Multiple insecure method vulnerabilities in the Web On Windows (WOW) ActiveX control in WOW ActiveX 2 allow remote attac
23RISCO
abrir
ReferênciaVexDay Proof
Community CMS 0.4 - 'id' Blind SQL Injection
CVE-2009-0406webappsphp
SQL injection vulnerability in index.php in Community CMS 0.4 and earlier allows remote attackers to execute arbitrary S
23RISCO
abrir
ReferênciaVexDay Proof
CodeBB 1.0 Beta 2 - 'phpbb_root_path' Remote File Inclusion
CVE-2007-1839webappsphp
Multiple PHP remote file inclusion vulnerabilities in CodeBB 1.1b3 and earlier allow remote attackers to execute arbitra
23RISCO
abrir
anteriorpágina 58 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.