Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.620exploits catalogados
35.647CVEs com exploração pública
24.695testados em laboratório
24.455 exploits
Exploit-DBVexDay Proof
EZContents 2.0.3 - 'calendar.php?GLOBALS[language_home]' Remote File Inclusion
CVE-2006-4477webappsphp30 ago 2006
Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute
23RISCO
abrir
Exploit-DBVexDay Proof
EZContents 2.0.3 - 'event_list.php?GLOBALS[admin_home]' Remote File Inclusion
CVE-2006-4477webappsphp30 ago 2006
Multiple PHP remote file inclusion vulnerabilities in Visual Shapers ezContents 2.0.3 allow remote attackers to execute
23RISCO
abrir
Exploit-DBVexDay Proof
HLstats 1.34 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2006-4543webappsphp30 ago 2006
Cross-site scripting (XSS) vulnerability in index.php in HLStats 1.34 allows remote attackers to inject arbitrary web sc
23RISCO
abrir
Exploit-DBVexDay Proof
VisualShapers EZContents 2.0.3 - 'Headeruserdata.php' SQL Injection
CVE-2006-4478webappsphp30 ago 2006
SQL injection vulnerability in headeruserdata.php in Visual Shapers ezContents 2.0.3 allows remote attackers to execute
23RISCO
abrir
Exploit-DBVexDay Proof
ZipCentral 4.01 - '.ZIP' File Handling Local Buffer Overflow
CVE-2006-2439localwindows30 ago 2006
Stack-based buffer overflow in ZipCentral 4.01 allows remote user-assisted attackers to execute arbitrary code via a ZIP
23RISCO
abrir
Exploit-DBVexDay Proof
Digiappz Freekot 1.01 - ASP SQL Injection
CVE-2006-4524webappsasp30 ago 2006
Multiple SQL injection vulnerabilities in login_verif.asp in Digiappz Freekot 1.01 allow remote attackers to execute arb
23RISCO
abrir
Exploit-DBVexDay Proof
phpAtm 1.21 - 'include_location' Remote File Inclusion
CVE-2006-4749webappsphp30 ago 2006
Multiple PHP remote file inclusion vulnerabilities in PHP Advanced Transfer Manager (phpATM) 1.20 allow remote attackers
23RISCO
abrir
Exploit-DBVexDay Proof
ModuleBased CMS - Multiple Remote File Inclusions
CVE-2006-4545webappsphp29 ago 2006
PHP remote file inclusion vulnerability in ModuleBased CMS Pre-Alpha allows remote attackers to execute arbitrary PHP co
23RISCO
abrir
Exploit-DBVexDay Proof
Streamripper 1.61.25 - HTTP Header Parsing Buffer Overflow (2)
CVE-2006-3124remotewindows29 ago 2006
Buffer overflow in the HTTP header parsing in Streamripper before 1.61.26 allows remote attackers to cause a denial of s
28RISCO
abrir
Exploit-DBVexDay Proof
Streamripper 1.61.25 - HTTP Header Parsing Buffer Overflow (1)
CVE-2006-3124remotelinux29 ago 2006
Buffer overflow in the HTTP header parsing in Streamripper before 1.61.26 allows remote attackers to cause a denial of s
28RISCO
abrir
Exploit-DBVexDay Proof
HLstats 1.34 - 'hlstats.php' Cross-Site Scripting
CVE-2006-4454webappsphp29 ago 2006
Cross-site scripting (XSS) vulnerability in hlstats.php in HLstats 1.34 allows remote attackers to inject arbitrary web
23RISCO
abrir
Exploit-DBVexDay Proof
Cybuzu Garoon 2.1.0 - Multiple SQL Injections
CVE-2006-4444webappscgi28 ago 2006
Multiple SQL injection vulnerabilities in Cybozu Garoon 2.1.0 for Windows allow remote authenticated users to execute ar
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 5.0.1 - Daxctle.OCX Spline Method Heap Buffer Overflow
CVE-2006-4446remotewindows28 ago 2006
Heap-based buffer overflow in DirectAnimation.PathControl COM object (daxctle.ocx) in Microsoft Internet Explorer 6.0 SP
35RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows - NetpIsRemote() Remote Overflow (MS06-040) (2)
CVE-2006-3439remotewindows28 ago 2006
Buffer overflow in the Server Service in Microsoft Windows 2000 SP4, XP SP1 and SP2, and Server 2003 SP1 allows remote a
60RISCO
abrir
Exploit-DBVexDay Proof
Cybozu Products - 'id' Arbitrary File Retrieval
CVE-2006-4490webappscgi28 ago 2006
Multiple directory traversal vulnerabilities in Cybozu Office before 6.6 Build 1.3 and Share 360 before 2.5 Build 0.3 al
23RISCO
abrir
Exploit-DBVexDay Proof
Ay System CMS 2.6 - 'main.php' Remote File Inclusion
CVE-2006-4441webappsphp27 ago 2006
Multiple PHP remote file inclusion vulnerabilities in Ay System Solutions CMS 2.6 and earlier allow remote attackers to
23RISCO
abrir
Exploit-DBVexDay Proof
BigACE 1.8.2 - 'admin.cmd.php' Remote File Inclusion
CVE-2006-4423webappsphp26 ago 2006
Multiple PHP remote file inclusion vulnerabilities in Bigace 1.8.2 allow remote attackers to execute arbitrary PHP code
23RISCO
abrir
Exploit-DBVexDay Proof
BigACE 1.8.2 - 'download.cmd.php' Remote File Inclusion
CVE-2006-4423webappsphp26 ago 2006
Multiple PHP remote file inclusion vulnerabilities in Bigace 1.8.2 allow remote attackers to execute arbitrary PHP code
23RISCO
abrir
Exploit-DBVexDay Proof
MyBB 1.1.7 - Multiple HTML Injection Vulnerabilities
CVE-2006-4449webappsphp26 ago 2006
Cross-site scripting (XSS) vulnerability in attachment.php in MyBulletinBoard (MyBB) 1.1.7 and possibly other versions a
23RISCO
abrir
Exploit-DBVexDay Proof
Jupiter CMS 1.1.5 - 'index.php' Remote File Inclusion
CVE-2006-4428CRITICALwebappsphp26 ago 2006
PHP remote file inclusion vulnerability in index.php in Jupiter CMS 1.1.5 allows remote attackers to execute arbitrary P
48RISCO
abrir
Exploit-DBVexDay Proof
Joomla! / Mambo Component Comprofiler 1.0 - 'class.php' Remote File Inclusion
CVE-2006-4553webappsphp26 ago 2006
PHP remote file inclusion vulnerability in plugin.class.php in the com_comprofiler Components 1.0 RC2 for Mambo and Joom
23RISCO
abrir
Exploit-DBVexDay Proof
Alt-N MDaemon POP3 Server < 9.06 - 'USER' Remote Heap Overflow
CVE-2006-4364remotewindows26 ago 2006
Multiple heap-based buffer overflows in the POP3 server in Alt-N Technologies MDaemon before 9.0.6 allow remote attacker
35RISCO
abrir
Exploit-DBVexDay Proof
BigACE 1.8.2 - 'item_main.php' Remote File Inclusion
CVE-2006-4423webappsphp26 ago 2006
Multiple PHP remote file inclusion vulnerabilities in Bigace 1.8.2 allow remote attackers to execute arbitrary PHP code
23RISCO
abrir
Exploit-DBVexDay Proof
BigACE 1.8.2 - 'upload_form.php' Remote File Inclusion
CVE-2006-4423webappsphp26 ago 2006
Multiple PHP remote file inclusion vulnerabilities in Bigace 1.8.2 allow remote attackers to execute arbitrary PHP code
23RISCO
abrir
Exploit-DBVexDay Proof
Symantec AntiVirus - IOCTL Kernel Privilege Escalation (1)
CVE-2006-4927localwindows26 ago 2006
The (a) NAVENG (NAVENG.SYS) and (b) NAVEX15 (NAVEX15.SYS) device drivers 20061.3.0.12 and later, as used in Symantec Ant
23RISCO
abrir
Exploit-DBVexDay Proof
Alstrasoft Video Share Enterprise 4.x - 'MyajaxPHP.php' Remote File Inclusion
CVE-2006-4443webappsphp26 ago 2006
PHP remote file inclusion vulnerability in myajaxphp.php in AlstraSoft Video Share Enterprise allows remote attackers to
23RISCO
abrir
Exploit-DBVexDay Proof
Symantec AntiVirus - IOCTL Kernel Privilege Escalation (2)
CVE-2006-4927localwindows26 ago 2006
The (a) NAVENG (NAVENG.SYS) and (b) NAVEX15 (NAVEX15.SYS) device drivers 20061.3.0.12 and later, as used in Symantec Ant
23RISCO
abrir
Exploit-DBVexDay Proof
Jetbox CMS 2.1 - 'Search_function.php' Remote File Inclusion
CVE-2006-4422webappsphp26 ago 2006
PHP remote file inclusion vulnerability in includes/phpdig/libs/search_function.php in Jetbox CMS 2.1 allows remote atta
23RISCO
abrir
Exploit-DBVexDay Proof
BlackBoard Products 6 - Multiple HTML Injection Vulnerabilities
CVE-2006-4308webappsphp24 ago 2006
Multiple cross-site scripting (XSS) vulnerabilities in Blackboard Learning System 6, Blackboard Learning and Community P
23RISCO
abrir
Exploit-DBVexDay Proof
Apache 1.3.35/2.0.58/2.2.2 - Arbitrary HTTP Request Headers Security
CVE-2006-3918remotelinux24 ago 2006
http_protocol.c in (1) IBM HTTP Server 6.0 before 6.0.2.13 and 6.1 before 6.1.0.1, and (2) Apache HTTP Server 1.3 before
45RISCO
abrir
anteriorpágina 582 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.