Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.772exploits catalogados
35.760CVEs com exploração pública
24.695testados em laboratório
24.455 exploits
Exploit-DBVexDay Proof
SPIP 1.8.2 - 'Spip_RSS.php' Remote Command Execution
CVE-2006-0625webappsphp08 fev 2006
Directory traversal vulnerability in Spip_RSS.PHP in SPIP 1.8.2g and earlier allows remote attackers to read or include
23RISCO
abrir
Exploit-DBVexDay Proof
QNX RTOS 6.3.0 - Insecure 'rc.local' Permissions System Crash / Privilege Escalation
CVE-2006-0623localqnx08 fev 2006
QNX Neutrino RTOS 6.3.0 ships /etc/rc.d/rc.local with world-writable permissions, which allows local users to modify the
23RISCO
abrir
Exploit-DBVexDay Proof
Mozilla Firefox 1.5 (OSX) - 'location.QueryInterface()' Code Execution (Metasploit)
CVE-2006-0295remoteosx08 fev 2006
Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attac
60RISCO
abrir
Exploit-DBVexDay Proof
CPGNuke Dragonfly 9.0.6.1 - Remote Command Execution
CVE-2006-0644webappsphp08 fev 2006
Multiple directory traversal vulnerabilities in install.php in CPG-Nuke Dragonfly CMS (aka CPG Dragonfly CMS) 9.0.6.1 al
23RISCO
abrir
Exploit-DBVexDay Proof
Sun ONE Directory Server 5.2 - Remote Denial of Service
CVE-2006-0647dosmultiple08 fev 2006
LDAP service in Sun Java System Directory Server 5.2, running on Linux and possibly other platforms, allows remote attac
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 7.0 Beta 2 - 'urlmon.dll' Denial of Service
CVE-2006-0544doswindows07 fev 2006
urlmon.dll in Microsoft Internet Explorer 7.0 beta 2 (aka 7.0.5296.0) allows remote attackers to cause a denial of servi
28RISCO
abrir
Exploit-DBVexDay Proof
Mozilla Firefox 1.5 (Linux) - 'location.QueryInterface()' Code Execution (Metasploit)
CVE-2006-0295remotelinux07 fev 2006
Mozilla Firefox 1.5, Thunderbird 1.5 if Javascript is enabled in mail, and SeaMonkey before 1.0 might allow remote attac
60RISCO
abrir
Exploit-DBVexDay Proof
GA's Forum Light - 'Archive.asp' SQL Injection
CVE-2006-0669webappsasp07 fev 2006
Multiple SQL injection vulnerabilities in archive.asp in GA's Forum Light allow remote attackers to execute arbitrary SQ
23RISCO
abrir
Exploit-DBVexDay Proof
QNX 6.2/6.3 - Multiple Privilege Escalation / Denial of Service Vulnerabilities
CVE-2005-1528localqnx07 fev 2006
Untrusted search path vulnerability in the crttrap command in QNX Neutrino RTOS 6.2.1 allows local users to load arbitra
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft HTML Help Workshop - '.hhp' Local Buffer Overflow (1)
CVE-2009-0133localwindows06 fev 2006
Buffer overflow in Microsoft HTML Help Workshop 4.74 and earlier allows context-dependent attackers to execute arbitrary
50RISCO
abrir
Exploit-DBVexDay Proof
MyQuiz 1.01 - 'PATH_INFO' Arbitrary Command Execution
CVE-2006-0628webappscgi06 fev 2006
myquiz.pl in Dale Ray MyQuiz 1.01 allows remote attackers to execute arbitrary commands via shell metacharacters in the
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft HTML Help Workshop - '.hhp' Local Buffer Overflow (1)
CVE-2006-0564localwindows06 fev 2006
Stack-based buffer overflow in Microsoft HTML Help Workshop 4.74.8702.0, and possibly earlier versions, and as included
60RISCO
abrir
Exploit-DBVexDay Proof
Sony/Ericsson Bluetooth - Reset Display Denial of Service
CVE-2006-0671doshardware06 fev 2006
Buffer overflow in Sony Ericsson K600i, V600i, W800i, and T68i cell phone allows remote attackers to cause a denial of s
23RISCO
abrir
Exploit-DBVexDay Proof
IBM Tivoli Access Manager Plugin - Directory Traversal
CVE-2006-0513webappscgi04 fev 2006
Directory traversal vulnerability in pkmslogout in Tivoli Web Server Plug-in 5.1.0.10 in Tivoli Access Manager (TAM) 5.1
23RISCO
abrir
Exploit-DBVexDay Proof
Clever Copy 3.0 - Admin Auth Details / SQL Injection
CVE-2006-0583webappsphp04 fev 2006
SQL injection vulnerability in mailarticle.php in Clever Copy 3.0 and earlier allows remote attackers to execute arbitra
23RISCO
abrir
Exploit-DBVexDay Proof
LoudBlog 0.4 - Remote File Inclusion
CVE-2006-0565webappsphp03 fev 2006
PHP remote file include vulnerability in inc/backend_settings.php in Loudblog 0.4 and earlier allows remote attackers to
23RISCO
abrir
Exploit-DBVexDay Proof
CyberShop Ultimate E-Commerce - Multiple Cross-Site Scripting Vulnerabilities
CVE-2006-0534webappsasp02 fev 2006
Multiple cross-site scripting (XSS) vulnerabilities in default.asp in CyberShop Ultimate E-commerce allow remote attacke
23RISCO
abrir
Exploit-DBVexDay Proof
Arescom NetDSL-1000 - 'TelnetD' Remote Denial of Service
CVE-2002-0256doshardware02 fev 2006
The telnet port in Arescom NetDSL 1000 router allows remote attackers to cause a denial of service via a series of conne
23RISCO
abrir
Exploit-DBVexDay Proof
SoftMaker Shop - Multiple Cross-Site Scripting Vulnerabilities
CVE-2006-0532webappsasp02 fev 2006
Cross-site scripting (XSS) vulnerability in resultat.asp in SoftMaker Shop allows remote attackers to inject arbitrary w
23RISCO
abrir
Exploit-DBVexDay Proof
SoftiaCom wMailServer 1.0 - SMTP Remote Buffer Overflow (Metasploit)
CVE-2005-2287remotewindows01 fev 2006
SoftiaCom wMailServer 1.0 and 2.0 allows remote attackers to cause a denial of service (application crash) via a large T
50RISCO
abrir
Exploit-DBVexDay Proof
Fcron 3.0 - Convert-FCronTab Local Buffer Overflow
CVE-2006-0539dosmultiple01 fev 2006
The convert-fcrontab program in fcron 3.0.0 might allow local users to gain privileges via a long command-line argument,
23RISCO
abrir
Exploit-DBVexDay Proof
SZUserMgnt 1.4 - 'Username' SQL Injection
CVE-2006-0491webappsphp01 fev 2006
SQL injection vulnerability in SZUserMgnt.class.php in SZUserMgnt 1.4 allows remote attackers to execute arbitrary SQL c
23RISCO
abrir
Exploit-DBVexDay Proof
SPIP 1.8/1.9 - 'index.php3' Cross-Site Scripting
CVE-2006-0518webappsphp01 fev 2006
Cross-site scripting (XSS) vulnerability in index.php3 in SPIP 1.8.2-e and earlier and 1.9 Alpha 2 (5539) and earlier al
23RISCO
abrir
Exploit-DBVexDay Proof
MyBB 1.0/1.1 - 'index.php' Referrer Cookie SQL Injection
CVE-2006-1974webappsphp31 jan 2006
SQL injection vulnerability in index.php in MyBB (MyBulletinBoard) before 1.04 allows remote attackers to execute arbitr
23RISCO
abrir
Exploit-DBVexDay Proof
Cerberus Helpdesk 2.7 - 'Clients.php' Cross-Site Scripting
CVE-2006-0509webappsphp31 jan 2006
Multiple cross-site scripting (XSS) vulnerabilities in clients.php in Cerberus Helpdesk, possibly 2.7, allow remote atta
23RISCO
abrir
Exploit-DBVexDay Proof
KarjaSoft Sami FTP Server 2.0.1 - Remote Buffer Overflow (cpp)
CVE-2006-0441remotewindows31 jan 2006
Stack-based buffer overflow in Sami FTP Server 2.0.1 allows remote attackers to execute arbitrary code via a long USER c
60RISCO
abrir
Exploit-DBVexDay Proof
Winamp 5.12 - '.pls' Remote Buffer Overflow (Metasploit)
CVE-2006-0476remotewindows31 jan 2006
Buffer overflow in Nullsoft Winamp 5.12 allows remote attackers to execute arbitrary code via a playlist (pls) file with
60RISCO
abrir
Exploit-DBVexDay Proof
Invision Power Board Dragoran Portal Mod 1.3 - SQL Injection
CVE-2006-0520webappsphp31 jan 2006
SQL injection vulnerability index.php in Dragoran Portal module 1.3 for Invision Power Board (IPB) allows remote attacke
23RISCO
abrir
Exploit-DBVexDay Proof
Farsinews 2.1 - 'Loginout.php' Remote File Inclusion
CVE-2006-0502webappsphp31 jan 2006
PHP remote file inclusion vulnerability in loginout.php in FarsiNews 2.1 Beta 2 and earlier, with register_globals enabl
23RISCO
abrir
Exploit-DBVexDay Proof
PmWiki 2.1 - Multiple Input Validation Vulnerabilities
CVE-2006-0479webappsphp30 jan 2006
pmwiki.php in PmWiki 2.1 beta 20, with register_globals enabled, allows remote attackers to bypass protection mechanisms
23RISCO
abrir
anteriorpágina 624 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.