Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.813exploits catalogados
35.788CVEs com exploração pública
24.695testados em laboratório
24.455 exploits
Exploit-DBVexDay Proof
Mambo 4.5.2 - Globals Overwrite / Remote Command Execution
CVE-2005-3738webappsphp22 nov 2005
globals.php in Mambo Site Server 4.0.14 and earlier, when register_globals is disabled, allows remote attackers to overw
23RISCO
abrir
Exploit-DBVexDay Proof
Cisco PIX - TCP SYN Packet Denial of Service
CVE-2005-3774doshardware22 nov 2005
Cisco PIX 6.3 and 7.0 allows remote attackers to cause a denial of service (blocked new connections) via spoofed TCP pac
28RISCO
abrir
Exploit-DBVexDay Proof
OTRS 2.0 - 'index.pl' Multiple Cross-Site Scripting Vulnerabilities
CVE-2005-3894webappscgi22 nov 2005
Multiple cross-site scripting (XSS) vulnerabilities in index.pl in Open Ticket Request System (OTRS) 1.0.0 through 1.3.2
23RISCO
abrir
Exploit-DBVexDay Proof
OTRS 2.0 - Login Function 'User' SQL Injection
CVE-2005-3893webappscgi22 nov 2005
Multiple SQL injection vulnerabilities in index.pl in Open Ticket Request System (OTRS) 1.0.0 through 1.3.2 and 2.0.0 th
23RISCO
abrir
Exploit-DBVexDay Proof
PHPPost 1.0 - 'mail.php?user' Cross-Site Scripting
CVE-2005-3770webappsphp21 nov 2005
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Post (PHPp) 1.0 allow remote attackers to inject arbitrary we
23RISCO
abrir
Exploit-DBVexDay Proof
APBoard - 'thread.php' SQL Injection
CVE-2005-3746webappsphp21 nov 2005
SQL injection vulnerability in thread.php in APBoard allows remote attackers to execute arbitrary SQL commands via the s
23RISCO
abrir
Exploit-DBVexDay Proof
PHPPost 1.0 - 'profile.php?user' Cross-Site Scripting
CVE-2005-3770webappsphp21 nov 2005
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Post (PHPp) 1.0 allow remote attackers to inject arbitrary we
23RISCO
abrir
Exploit-DBVexDay Proof
Advanced Poll 2.0.2/2.0.3 - 'popup.php' Cross-Site Scripting
CVE-2005-3742webappsphp21 nov 2005
Cross-site scripting (XSS) vulnerability in popup.php in Advanced Poll 2.0.3 and earlier allows remote attackers to inje
23RISCO
abrir
Exploit-DBVexDay Proof
SimplePoll - 'results.php' SQL Injection
CVE-2005-3743webappsphp21 nov 2005
SQL injection vulnerability in results.php in SimplePoll allows remote attackers to execute arbitrary SQL commands via t
23RISCO
abrir
Exploit-DBVexDay Proof
Tru-Zone Nuke ET 3.x - Search Module SQL Injection
CVE-2005-3748webappsphp21 nov 2005
SQL injection vulnerability in the Search module in Tru-Zone Nuke ET 3.2, and possibly earlier versions, allows remote a
23RISCO
abrir
Exploit-DBVexDay Proof
PHP Download Manager 1.1.x - 'files.php' SQL Injection
CVE-2005-3769webappsphp21 nov 2005
SQL injection vulnerability in files.php in PHP Download Manager 1.1.3 and earlier allows remote attackers to execute ar
23RISCO
abrir
Exploit-DBVexDay Proof
Apache Struts 1.2.7 - Error Response Cross-Site Scripting
CVE-2005-3745remotemultiple21 nov 2005
Cross-site scripting (XSS) vulnerability in Apache Struts 1.2.7, and possibly other versions allows remote attackers to
28RISCO
abrir
Exploit-DBVexDay Proof
Inkscape 0.41/0.42 - '.SVG' Image Buffer Overflow
CVE-2005-3737remotelinux21 nov 2005
Buffer overflow in the SVG importer (style.cpp) of inkscape 0.41 through 0.42.2 might allow remote attackers to execute
28RISCO
abrir
Exploit-DBVexDay Proof
FileZilla Server Terminal 0.9.4d - Buffer Overflow (PoC)
CVE-2005-3589doswindows21 nov 2005
Buffer overflow in FileZilla Server Terminal 0.9.4d may allow remote attackers to cause a denial of service (terminal cr
50RISCO
abrir
Exploit-DBVexDay Proof
MailEnable 1.54 Pro - Universal IMAPD W3C Logging Buffer Overflow (Metasploit)
CVE-2005-3155remotewindows20 nov 2005
Buffer overflow in the W3C logging for MailEnable Enterprise 1.1 and Professional 1.6 allows remote attackers to execute
50RISCO
abrir
Exploit-DBVexDay Proof
Google Search Appliance - proxystylesheet XSLT Java Code Execution (Metasploit)
CVE-2005-3757remotehardware20 nov 2005
The Saxon XSLT parser in Google Mini Search Appliance, and possibly Google Search Appliance, allows remote attackers to
50RISCO
abrir
Exploit-DBVexDay Proof
Macromedia Flash Plugin 7.0.19.0 - 'action' Denial of Service
CVE-2005-3591dosmultiple18 nov 2005
Macromedia Flash plugin (1) Flash.ocx 7.0.19.0 (Windows) and earlier and (2) libflashplayer.so before 7.0.25.0 (Unix) al
28RISCO
abrir
Exploit-DBVexDay Proof
Qualcomm WorldMail Server 3.0 - Directory Traversal
CVE-2005-3189remotelinux17 nov 2005
Directory traversal vulnerability in Qualcomm WorldMail IMAP Server allows remote attackers to read arbitrary email mess
23RISCO
abrir
Exploit-DBVexDay Proof
freeFTPd 1.0.8 - 'USER' Remote Buffer Overflow
CVE-2005-3684remotewindows17 nov 2005
Multiple buffer overflows in freeFTPd 1.0.8, without logging enabled, allow remote authenticated attackers to cause a de
28RISCO
abrir
Exploit-DBVexDay Proof
Litespeed 2.1.5 - 'ConfMgr.php' Cross-Site Scripting
CVE-2005-3695webappsphp17 nov 2005
Cross-site scripting (XSS) vulnerability in admin/config/confMgr.php in LiteSpeed Web Server 2.1.5 allows remote attacke
23RISCO
abrir
Exploit-DBVexDay Proof
Revize CMS HTTPTranslatorServlet - Cross-Site Scripting
CVE-2005-3730webappsjsp17 nov 2005
Multiple cross-site scripting (XSS) vulnerabilities in HTTPTranslatorServlet in Idetix Software Systems Revize CMS allow
23RISCO
abrir
Exploit-DBVexDay Proof
freeFTPd 1.0.8 - 'USER' Remote Buffer Overflow
CVE-2005-3683remotewindows17 nov 2005
Stack-based buffer overflow in freeFTPd before 1.0.9 with Logging enabled, allows remote attackers to cause a denial of
60RISCO
abrir
Exploit-DBVexDay Proof
VP-ASP Shopping Cart - 'Shopadmin.asp' HTML Injection
CVE-2005-3685webappsasp17 nov 2005
Cross-site scripting (XSS) vulnerability in shopadmin.asp in VP-ASP Shopping Cart 5.50 allows remote attackers to inject
23RISCO
abrir
Exploit-DBVexDay Proof
Revize CMS - 'Query_results.jsp' SQL Injection
CVE-2005-3727webappsjsp17 nov 2005
SQL injection vulnerability in debug/query_results.jsp in Idetix Software Systems Revize CMS allows remote attackers to
23RISCO
abrir
Exploit-DBVexDay Proof
Revize CMS - 'Revize.XML' Information Disclosure
CVE-2005-3728webappsjsp17 nov 2005
Idetix Software Systems Revize CMS stores conf/revize.xml under the web document root with insufficient access control,
23RISCO
abrir
Exploit-DBVexDay Proof
PHP-Nuke 7.8 Search Module - SQL Injection
CVE-2005-3792webappsphp16 nov 2005
Multiple SQL injection vulnerabilities in the Search module in PHP-Nuke 7.8, and possibly other versions before 7.9 with
35RISCO
abrir
Exploit-DBVexDay Proof
PHPWebThings 1.4 - 'forum' SQL Injection
CVE-2005-4218webappsphp16 nov 2005
SQL injection vulnerability in forum.php in PHPWebThings 1.4 allows remote attackers to execute arbitrary SQL commands v
23RISCO
abrir
Exploit-DBVexDay Proof
PHPWebThings 1.4 - 'msg'/'forum' SQL Injection
CVE-2005-4226webappsphp16 nov 2005
Multiple "potential" SQL injection vulnerabilities in phpWebThings 1.4 Patched might allow remote attackers to execute a
23RISCO
abrir
Exploit-DBVexDay Proof
PHPWebThings 1.4 - 'forum' SQL Injection
CVE-2005-4226webappsphp16 nov 2005
Multiple "potential" SQL injection vulnerabilities in phpWebThings 1.4 Patched might allow remote attackers to execute a
23RISCO
abrir
Exploit-DBVexDay Proof
FTGate4 Groupware Mail Server 4.1 - imapd Remote Buffer Overflow (PoC)
CVE-2005-3640doswindows16 nov 2005
Multiple buffer overflows in the IMAP Groupware Mail server of Floosietek FTGate (FTGate4) 4.1 allow remote attackers to
23RISCO
abrir
anteriorpágina 643 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.