Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.620exploits catalogados
35.647CVEs com exploração pública
24.695testados em laboratório
24.455 exploits
Exploit-DBVexDay Proof
News Evolution 3.0.3 - _NE[AbsPath] Remote File Inclusion
CVE-2006-4678webappsphp07 set 2006
PHP remote file inclusion vulnerability in News Evolution 3.0.3 allows remote attackers to execute arbitrary PHP code vi
23RISCO
abrir
Exploit-DBVexDay Proof
BinGo News 3.01 - 'bnrep' Remote File Inclusion
CVE-2006-4649webappsphp06 set 2006
PHP remote file inclusion vulnerability in bp_news.php in BinGo News (BP News) 3.01 and earlier allows remote attackers
23RISCO
abrir
Exploit-DBVexDay Proof
Uni-vert PHPLeague 0.82 - 'Joueurs.php' SQL Injection
CVE-2006-4643webappsphp06 set 2006
SQL injection vulnerability in consult/joueurs.php in Uni-Vert PhpLeague 0.82 and earlier allows remote attackers to exe
23RISCO
abrir
Exploit-DBVexDay Proof
DSocks 1.3 - 'Name' Buffer Overflow (PoC)
CVE-2006-4611dosmultiple05 set 2006
Buffer overflow in the _tor_resolve function in dsocks.c in dsocks before 1.4 allows remote attackers to execute arbitra
23RISCO
abrir
Exploit-DBVexDay Proof
SoftBB 0.1 - 'Page' Cross-Site Scripting
CVE-2006-4593webappsphp05 set 2006
Cross-site scripting (XSS) vulnerability in index.php in SoftBB 0.1 and earlier allows remote attackers to inject arbitr
23RISCO
abrir
Exploit-DBVexDay Proof
AnnonceV News Script 1.1 - 'page' Remote File Inclusion
CVE-2006-4622webappsphp05 set 2006
PHP remote file inclusion vulnerability in annonce.php in AnnonceV (aka annoncesV) 1.1 allows remote attackers to execut
23RISCO
abrir
Exploit-DBVexDay Proof
Zix Forum 1.12 - 'RepId' SQL Injection (1)
CVE-2006-4612webappsasp05 set 2006
SQL injection vulnerability in ReplyNew.asp in ZIXForum 1.12 allows remote attackers to execute arbitrary SQL commands v
23RISCO
abrir
Exploit-DBVexDay Proof
PHP-Nuke MyHeadlines 4.3.1 Module - Cross-Site Scripting
CVE-2006-4563webappsphp04 set 2006
Cross-site scripting (XSS) vulnerability in the MyHeadlines before 4.3.2 module for PHP-Nuke allows remote attackers to
23RISCO
abrir
Exploit-DBVexDay Proof
Easy Address Book Web Server 1.2 - Remote Format String
CVE-2006-4654remotewindows04 set 2006
Format string vulnerability in Easy Address Book Web Server 1.2 allows remote attackers to cause a denial of service (cr
23RISCO
abrir
Exploit-DBVexDay Proof
PHP-Proxima 6.0 - 'BB_Smilies.php' Local File Inclusion
CVE-2006-4631webappsphp04 set 2006
Direct static code injection vulnerability in admin/save_opt.php in SoftBB 0.1, and possibly earlier, allows remote auth
23RISCO
abrir
Exploit-DBVexDay Proof
Yappa-ng 2.3.1 - 'admin_modules' Remote File Inclusion
CVE-2005-1312webappsphp03 set 2006
PHP remote file inclusion vulnerability in Yappa-NG before 2.3.2 allows remote attackers to execute arbitrary PHP code v
23RISCO
abrir
Exploit-DBVexDay Proof
Annuaire 1Two 2.2 - SQL Injection
CVE-2006-4601webappsphp02 set 2006
SQL injection vulnerability in index.php in Annuaire 1Two 2.2 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
Exploit-DBVexDay Proof
Autentificator 2.01 - 'Aut_Verifica.Inc.php' SQL Injection
CVE-2006-4599webappsphp02 set 2006
SQL injection vulnerability in aut_verifica.inc.php in Autentificator 2.01 allows remote attackers to execute arbitrary
23RISCO
abrir
Exploit-DBVexDay Proof
MyBace Light - 'login_check.php' Remote File
CVE-2006-4596webappsphp01 set 2006
PHP remote file inclusion in MyBace Light Skrip, when register_globals is enabled, allows remote attackers to execute ar
23RISCO
abrir
Exploit-DBVexDay Proof
Internet Security Systems 3.6 BlackICE - Local Denial of Service
CVE-2006-4541doswindows01 set 2006
RapDrv.sys in BlackICE PC Protection 3.6.cpn, cpj, cpiE, and possibly 3.6 and earlier, allows local users to cause a den
23RISCO
abrir
Exploit-DBVexDay Proof
PowerZip 7.06.38950 - 'Filename Handling' Local Buffer Overflow
CVE-2006-4359localwindows01 set 2006
Stack-based buffer overflow in Trident Software PowerZip 7.06 Build 3895 on Windows 2000 allows remote attackers to exec
23RISCO
abrir
Exploit-DBVexDay Proof
VBZoom 1.11 - 'profile.php' Cross-Site Scripting
CVE-2006-4634webappsphp01 set 2006
Cross-site scripting (XSS) vulnerability in index.php in VBZooM allows remote attackers to inject arbitrary web script o
23RISCO
abrir
Exploit-DBVexDay Proof
YACS CMS 6.6.1 - context[path_to_root] Remote File Inclusion
CVE-2006-4559webappsphp31 ago 2006
Multiple PHP remote file inclusion vulnerabilities in Yet Another Community System (YACS) CMS 6.6.1 allow remote attacke
23RISCO
abrir
Exploit-DBVexDay Proof
HLstats 1.34 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2006-4543webappsphp30 ago 2006
Cross-site scripting (XSS) vulnerability in index.php in HLStats 1.34 allows remote attackers to inject arbitrary web sc
23RISCO
abrir
Exploit-DBVexDay Proof
Alstrasoft Template Seller - 'Config[Template_Path]' Multiple Remote File Inclusions
CVE-2006-4591webappsphp30 ago 2006
Multiple PHP remote file inclusion vulnerabilities in AlstraSoft Template Seller, and possibly AltraSoft Template Seller
23RISCO
abrir
Exploit-DBVexDay Proof
Learn.com - 'Learncenter.asp' Cross-Site Scripting
CVE-2006-4540webappsphp30 ago 2006
Cross-site scripting (XSS) vulnerability in learncenter.asp in Learn.com LearnCenter allows remote attackers to inject a
23RISCO
abrir
Exploit-DBVexDay Proof
phpAtm 1.21 - 'include_location' Remote File Inclusion
CVE-2006-4749webappsphp30 ago 2006
Multiple PHP remote file inclusion vulnerabilities in PHP Advanced Transfer Manager (phpATM) 1.20 allow remote attackers
23RISCO
abrir
Exploit-DBVexDay Proof
EZContents 2.0.3 - 'search.php?GLOBALS[language_home]' Remote File Inclusion
CVE-2006-4477webappsphp30 ago 2006
Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute
23RISCO
abrir
Exploit-DBVexDay Proof
EZContents 2.0.3 - 'showguestbook.php?GLOBALS[admin_home]' Remote File Inclusion
CVE-2006-4477webappsphp30 ago 2006
Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute
23RISCO
abrir
Exploit-DBVexDay Proof
VisualShapers EZContents 2.0.3 - 'Loginreq2.php' Cross-Site Scripting
CVE-2006-4479webappsphp30 ago 2006
Cross-site scripting (XSS) vulnerability in loginreq2.php in Visual Shapers ezContents 2.0.3 allows remote attackers to
23RISCO
abrir
Exploit-DBVexDay Proof
EZContents 2.0.3 - 'showpoll.php?GLOBALS[admin_home]' Remote File Inclusion
CVE-2006-4477webappsphp30 ago 2006
Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute
23RISCO
abrir
Exploit-DBVexDay Proof
EZContents 2.0.3 - 'shownews.php?GLOBALS[admin_home]' Remote File Inclusion
CVE-2006-4477webappsphp30 ago 2006
Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute
23RISCO
abrir
Exploit-DBVexDay Proof
EZContents 2.0.3 - 'showlinks.php?GLOBALS[admin_home]' Remote File Inclusion
CVE-2006-4477webappsphp30 ago 2006
Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute
23RISCO
abrir
Exploit-DBVexDay Proof
IwebNegar 1.1 - 'comments.php' SQL Injection
CVE-2006-4497webappsphp30 ago 2006
SQL injection vulnerability in comments.php in IwebNegar 1.1 allows remote attackers to execute arbitrary SQL commands v
23RISCO
abrir
Exploit-DBVexDay Proof
ZipCentral 4.01 - '.ZIP' File Handling Local Buffer Overflow
CVE-2006-2439localwindows30 ago 2006
Stack-based buffer overflow in ZipCentral 4.01 allows remote user-assisted attackers to execute arbitrary code via a ZIP
23RISCO
abrir
anteriorpágina 581 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.