Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.772exploits catalogados
35.760CVEs com exploração pública
24.695testados em laboratório
24.455 exploits
Exploit-DBVexDay Proof
IBM Tivoli Directory Server 6.0 - LDAP Memory Corruption
CVE-2006-0717dosmultiple11 fev 2006
IBM Tivoli Directory Server 6.0 allows remote attackers to cause a denial of service (crash) via a crafted LDAP request,
23RISCO
abrir
Exploit-DBVexDay Proof
ImageVue 0.16.1 - 'readfolder.php?path' Arbitrary Directory Listing
CVE-2006-0701webappsphp11 fev 2006
readfolder.php in imageVue 16.1 allows remote attackers to list directories via modified path and ext parameters.
23RISCO
abrir
Exploit-DBVexDay Proof
HiveMail 1.2.2/1.3 - 'addressbook.update.php?contactgroupid' Arbitrary PHP Command Execution
CVE-2006-0757webappsphp11 fev 2006
Multiple eval injection vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to execute arbitrary PHP code
23RISCO
abrir
Exploit-DBVexDay Proof
LinPHA 0.9.x/1.0 - 'forth_stage_install.php' Local File Inclusion
CVE-2006-0713webappsphp11 fev 2006
Directory traversal vulnerability in LinPHA 1.0 allows remote attackers to include arbitrary files via .. (dot dot) sequ
23RISCO
abrir
Exploit-DBVexDay Proof
HiveMail 1.2.2/1.3 - 'folders.update.php?folderid' Arbitrary PHP Command Execution
CVE-2006-0757webappsphp11 fev 2006
Multiple eval injection vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to execute arbitrary PHP code
23RISCO
abrir
Exploit-DBVexDay Proof
ImageVue 0.16.1 - 'upload.php' Unrestricted Arbitrary File Upload
CVE-2006-0702webappsphp11 fev 2006
admin/upload.php in imageVue 16.1 allows remote attackers to upload arbitrary files to certain allowed folders via .. (d
23RISCO
abrir
Exploit-DBVexDay Proof
ImageVue 0.16.1 - 'dir.php' Folder Permission Disclosure
CVE-2006-0700webappsphp11 fev 2006
imageVue 16.1 allows remote attackers to obtain folder permission settings via a direct request to dir.php, which return
23RISCO
abrir
Exploit-DBVexDay Proof
LinPHA 0.9.x/1.0 - 'install.php' Local File Inclusion
CVE-2006-0713webappsphp11 fev 2006
Directory traversal vulnerability in LinPHA 1.0 allows remote attackers to include arbitrary files via .. (dot dot) sequ
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft HTML Help Workshop - '.hhp' Local Buffer Overflow (2)
CVE-2006-0564localwindows11 fev 2006
Stack-based buffer overflow in Microsoft HTML Help Workshop 4.74.8702.0, and possibly earlier versions, and as included
60RISCO
abrir
Exploit-DBVexDay Proof
Microsoft HTML Help Workshop - '.hhp' Local Buffer Overflow (2)
CVE-2009-0133localwindows11 fev 2006
Buffer overflow in Microsoft HTML Help Workshop 4.74 and earlier allows context-dependent attackers to execute arbitrary
50RISCO
abrir
Exploit-DBVexDay Proof
LinPHA 0.9.x/1.0 - 'lang' Local File Inclusion
CVE-2006-0713webappsphp11 fev 2006
Directory traversal vulnerability in LinPHA 1.0 allows remote attackers to include arbitrary files via .. (dot dot) sequ
23RISCO
abrir
Exploit-DBVexDay Proof
HiveMail 1.2.2/1.3 - 'index.php' $_SERVER['PHP_SELF'] Cross-Site Scripting
CVE-2006-0758webappsphp11 fev 2006
Multiple cross-site scripting (XSS) vulnerabilities in HiveMail 1.3 and earlier allow remote attackers to inject arbitra
23RISCO
abrir
Exploit-DBVexDay Proof
DocMGR 0.54.2 - 'file_exists' Remote Command Execution
CVE-2006-0687webappsphp11 fev 2006
process.php in DocMGR 0.54.2 does not initialize the $siteModInfo variable when a direct request is made, which allows r
23RISCO
abrir
Exploit-DBVexDay Proof
Half-Life CSTRIKE Server 1.6 (Non Steam) - Denial of Service
CVE-2003-1325dosmultiple11 fev 2006
The SV_CheckForDuplicateNames function in Valve Software Half-Life CSTRIKE Dedicated Server 1.1.1.0 and earlier allows r
23RISCO
abrir
Exploit-DBVexDay Proof
Farsinews 2.1/2.5 - 'show_archives.php?template' Traversal Arbitrary File Access
CVE-2006-0660webappsphp10 fev 2006
Multiple directory traversal vulnerabilities in FarsiNews 2.5 and earlier allows remote attackers to (1) read arbitrary
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft HTML Help Workshop - '.hhp' Denial of Service
CVE-2009-0133doswindows10 fev 2006
Buffer overflow in Microsoft HTML Help Workshop 4.74 and earlier allows context-dependent attackers to execute arbitrary
50RISCO
abrir
Exploit-DBVexDay Proof
Power Daemon 2.0.2 - 'WHATIDO' Remote Format String
CVE-2006-0681remotelinux10 fev 2006
Format string vulnerability in powerd.c in Power Daemon (powerd) 2.0.2 and earlier allows remote attackers to execute ar
23RISCO
abrir
Exploit-DBVexDay Proof
IBM Lotus Domino 6.x/7.0 iNotes - Email Subject Cross-Site Scripting
CVE-2006-0663remotemultiple10 fev 2006
Multiple cross-site scripting (XSS) vulnerabilities in Lotus Domino iNotes Client 6.5.4 and 7.0 allow remote attackers t
23RISCO
abrir
Exploit-DBVexDay Proof
IBM Lotus Domino 6.x/7.0 - iNotes JavaScript: Filter Bypass
CVE-2006-0663remotemultiple10 fev 2006
Multiple cross-site scripting (XSS) vulnerabilities in Lotus Domino iNotes Client 6.5.4 and 7.0 allow remote attackers t
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft HTML Help Workshop - '.hhp' Denial of Service
CVE-2006-0564doswindows10 fev 2006
Stack-based buffer overflow in Microsoft HTML Help Workshop 4.74.8702.0, and possibly earlier versions, and as included
60RISCO
abrir
Exploit-DBVexDay Proof
OpenVMPSd 1.3 - Remote Format String
CVE-2005-4714remotelinux10 fev 2006
Format string vulnerability in the vmps_log function in OpenVMPS (VLAN Management Policy Server) 1.3 allows remote attac
23RISCO
abrir
Exploit-DBVexDay Proof
FCKEditor 2.0 < 2.2 - 'FileManager connector.php' Arbitrary File Upload
CVE-2006-0658webappsphp09 fev 2006
Incomplete blacklist vulnerability in connector.php in FCKeditor 2.0 and 2.2, as used in products such as RunCMS, allows
23RISCO
abrir
Exploit-DBVexDay Proof
RunCMS 1.2 - 'class.forumposts.php' Remote File Inclusion
CVE-2006-1793webappsphp09 fev 2006
Directory traversal vulnerability in runCMS 1.2 and earlier allows remote attackers to read arbitrary files via the bbPa
23RISCO
abrir
Exploit-DBVexDay Proof
RunCMS 1.2 - 'class.forumposts.php' Remote File Inclusion
CVE-2006-0659webappsphp09 fev 2006
Multiple PHP remote file include vulnerabilities in RunCMS 1.2 and earlier, with register_globals and allow_url_fopen en
23RISCO
abrir
Exploit-DBVexDay Proof
PwsPHP 1.2.3 - SQL Injection
CVE-2006-0942webappsphp09 fev 2006
SQL injection vulnerability in profil.php in PwsPHP 1.2.3, and possibly earlier versions, allows remote attackers to exe
23RISCO
abrir
Exploit-DBVexDay Proof
vwdev - 'index.php' SQL Injection
CVE-2006-0651webappsphp08 fev 2006
SQL injection vulnerability in index.php in vwdev allows remote attackers to execute arbitrary SQL commands via the UID
23RISCO
abrir
Exploit-DBVexDay Proof
QNX RTOS 6.3.0 - Insecure 'rc.local' Permissions System Crash / Privilege Escalation
CVE-2006-0623localqnx08 fev 2006
QNX Neutrino RTOS 6.3.0 ships /etc/rc.d/rc.local with world-writable permissions, which allows local users to modify the
23RISCO
abrir
Exploit-DBVexDay Proof
Webeveyn Whomp! Real Estate Manager 2005 - Login SQL Injection
CVE-2006-0624webappsasp08 fev 2006
SQL injection vulnerability in check.asp in Whomp Real Estate Manager XP 2005 allows remote attackers to execute arbitra
23RISCO
abrir
Exploit-DBVexDay Proof
SPIP 1.8.2g - Remote Command Execution
CVE-2006-0626webappsphp08 fev 2006
SQL injection vulnerability in spip_acces_doc.php3 in SPIP 1.8.2g and earlier allows remote attackers to execute arbitra
23RISCO
abrir
Exploit-DBVexDay Proof
Sun ONE Directory Server 5.2 - Remote Denial of Service
CVE-2006-0647dosmultiple08 fev 2006
LDAP service in Sun Java System Directory Server 5.2, running on Linux and possibly other platforms, allows remote attac
23RISCO
abrir
anteriorpágina 623 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.