Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.813exploits catalogados
35.788CVEs com exploração pública
24.695testados em laboratório
24.455 exploits
Exploit-DBVexDay Proof
Walla TeleSite 3.0 - 'ts.exe?tsurl' Arbitrary Article Access
CVE-2005-3576webappscgi15 nov 2005
ts.exe in Walla TeleSite 3.0 and earlier allows remote attackers to access privileged information by entering the articl
23RISCO
abrir
Exploit-DBVexDay Proof
Walla TeleSite 3.0 - 'ts.exe?sug' Cross-Site Scripting
CVE-2005-3577webappscgi15 nov 2005
Cross-site scripting vulnerability (XSS) in ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attacker
23RISCO
abrir
Exploit-DBVexDay Proof
Ekinboard 1.0.3 - 'profile.php' Cross-Site Scripting
CVE-2005-3638webappsphp15 nov 2005
Cross-site scripting (XSS) vulnerabilities in Ekinboard 1.0.3 allow remote attackers to inject arbitrary web script or H
23RISCO
abrir
Exploit-DBVexDay Proof
PHPWCMS 1.2.5 -DEV - 'login.php?form_lang' Traversal Arbitrary File Access
CVE-2005-3789webappsphp15 nov 2005
Multiple directory traversal vulnerabilities in phpwcms 1.2.5 allow remote attackers to read arbitrary files via a .. (d
23RISCO
abrir
Exploit-DBVexDay Proof
Pearl Forums 2.0 - 'index.php' Multiple SQL Injections
CVE-2005-4647webappsphp15 nov 2005
Multiple SQL injection vulnerabilities in PEARLINGER Pearl Forums 2.4 allow remote attackers to execute arbitrary SQL co
23RISCO
abrir
Exploit-DBVexDay Proof
Alstrasoft Template Seller Pro 3.25 - Remote File Inclusion
CVE-2005-3797webappsphp15 nov 2005
PHP remote file inclusion vulnerability in payment_paypal.php in AlstraSoft Template Seller Pro 3.25 allows remote attac
23RISCO
abrir
Exploit-DBVexDay Proof
PHPWCMS 1.2.5 -DEV - Multiple Cross-Site Scripting Vulnerabilities
CVE-2005-3790webappsphp15 nov 2005
Multiple cross-site scripting (XSS) vulnerabilities in act_newsletter.php in phpwcms 1.2.5 allow remote attackers to inj
23RISCO
abrir
Exploit-DBVexDay Proof
PHPWCMS 1.2.5 -DEV - 'imgdir' Traversal Arbitrary File Access
CVE-2005-3789webappsphp15 nov 2005
Multiple directory traversal vulnerabilities in phpwcms 1.2.5 allow remote attackers to read arbitrary files via a .. (d
23RISCO
abrir
Exploit-DBVexDay Proof
Walla TeleSite 3.0 - 'ts.cgi' File Existence Enumeration
CVE-2005-3579webappscgi15 nov 2005
ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to access arbitrary local files via the qu
23RISCO
abrir
Exploit-DBVexDay Proof
Pearl Forums 2.0 - 'index.php' Local File Inclusion
CVE-2005-4646webappsphp15 nov 2005
Unspecified vulnerability in index.php in PEARLINGER Pearl Forums 2.4 allows remote attackers to include arbitrary files
23RISCO
abrir
Exploit-DBVexDay Proof
Walla TeleSite 3.0 - 'ts.exe?sug' SQL Injection
CVE-2005-3578webappscgi15 nov 2005
SQL injection vulnerability in ts.exe (aka ts.cgi) in Walla TeleSite 3.0 and earlier allows remote attackers to inject a
23RISCO
abrir
Exploit-DBVexDay Proof
Help Center Live 1.0/1.2/2.0 - 'module.php' Local File Inclusion
CVE-2005-3639webappsphp14 nov 2005
PHP file inclusion vulnerability in the osTicket module in Help Center Live before 2.0.3 allows remote attackers to acce
23RISCO
abrir
Exploit-DBVexDay Proof
Wizz Forum - 'ForumAuthDetails.php?AuthID' SQL Injection
CVE-2005-3682webappsphp14 nov 2005
Multiple SQL injection vulnerabilities in Wizz Forum 1.20 allow remote attackers to execute arbitrary SQL commands via (
23RISCO
abrir
Exploit-DBVexDay Proof
Wizz Forum 1.20 - 'TopicID' SQL Injection
CVE-2005-3682webappsphp14 nov 2005
Multiple SQL injection vulnerabilities in Wizz Forum 1.20 allow remote attackers to execute arbitrary SQL commands via (
23RISCO
abrir
Exploit-DBVexDay Proof
Unclassified NewsBoard 1.5.3 Patch 3 - Blind SQL Injection
CVE-2005-3686webappsphp14 nov 2005
SQL injection vulnerability in search.inc.php in Unclassified NewsBoard before 1.5.3 Patch 4 allows remote attackers to
23RISCO
abrir
Exploit-DBVexDay Proof
Arki-DB 1.0 - 'catid' SQL Injection
CVE-2005-3696webappsphp14 nov 2005
SQL injection vulnerability in Arki-DB 1.0 and 2.0 allows remote attackers to execute arbitrary SQL commands via the cat
23RISCO
abrir
Exploit-DBVexDay Proof
Wizz Forum - 'forumreply.php?TopicID' SQL Injection
CVE-2005-3682webappsphp14 nov 2005
Multiple SQL injection vulnerabilities in Wizz Forum 1.20 allow remote attackers to execute arbitrary SQL commands via (
23RISCO
abrir
Exploit-DBVexDay Proof
Codegrrl - 'Protection.php' Code Execution
CVE-2005-3571webappsphp14 nov 2005
PHP file inclusion vulnerability in protection.php in CodeGrrl (a) PHPCalendar 1.0, (b) PHPClique 1.0, (c) PHPCurrently
23RISCO
abrir
Exploit-DBVexDay Proof
Cyphor 0.19 - 'show.php?id' SQL Injection
CVE-2005-3575webappsphp14 nov 2005
SQL injection vulnerability in show.php in Cyphor 0.19 and earlier allows remote attackers to execute arbitrary SQL comm
23RISCO
abrir
Exploit-DBVexDay Proof
PHPWebThings 1.4 - 'download.php?File' SQL Injection
CVE-2005-3676webappsphp12 nov 2005
SQL injection vulnerability in download.php in PhpWebThings 1.4.4 allows remote attackers to execute arbitrary SQL comma
23RISCO
abrir
Exploit-DBVexDay Proof
ActiveCampaign 1-2-All Broadcast Email 4.0 - Admin Control Panel 'Username' SQL Injection
CVE-2005-3679webappsphp12 nov 2005
SQL injection vulnerability in admin/index.php in ActiveCampaign 1-2-All Broadcast Email allows remote attackers to exec
23RISCO
abrir
Exploit-DBVexDay Proof
Veritas Storage Foundation 4.0 - VCSI18N_LANG Local Overflow
CVE-2005-3566locallinux12 nov 2005
Buffer overflow in various ha commands of VERITAS Cluster Server for UNIX before 4.0MP2 allows local users to execute ar
23RISCO
abrir
Exploit-DBVexDay Proof
XOOPS (wfdownloads) 2.05 Module - Multiple Vulnerabilities
CVE-2005-3681webappsphp12 nov 2005
SQL injection vulnerability in viewcat.php in XOOPS WF-Downloads module 2.05 allows remote attackers to execute arbitrar
23RISCO
abrir
Exploit-DBVexDay Proof
Snort 2.4.2 - Back Orifice Pre-Preprocessor Remote (3)
CVE-2005-3252remotewindows11 nov 2005
Stack-based buffer overflow in the Back Orifice (BO) preprocessor for Snort before 2.4.3 allows remote attackers to exec
60RISCO
abrir
Exploit-DBVexDay Proof
Snort 2.4.2 - Back Orifice Pre-Preprocessor Remote (4)
CVE-2005-3252remotelinux11 nov 2005
Stack-based buffer overflow in the Back Orifice (BO) preprocessor for Snort before 2.4.3 allows remote attackers to exec
60RISCO
abrir
Exploit-DBVexDay Proof
Sudo Perl 1.6.x - Environment Variable Handling Security Bypass
CVE-2005-4158locallinux11 nov 2005
Sudo before 1.6.8 p12, when the Perl taint flag is off, does not clear the (1) PERLLIB, (2) PERL5LIB, and (3) PERL5OPT e
23RISCO
abrir
Exploit-DBVexDay Proof
RealNetworks RealOne Player/RealPlayer - '.RM' Local Stack Buffer Overflow
CVE-2005-2629localwindows10 nov 2005
Integer overflow in RealNetworks RealPlayer 8, 10, and 10.5, RealOne Player 1 and 2, and Helix Player 10.0.0 allows remo
28RISCO
abrir
Exploit-DBVexDay Proof
Moodle 1.6dev - SQL Injection / Command Execution
CVE-2005-3649webappsphp10 nov 2005
jumpto.php in Moodle 1.5.2 allows remote attackers to redirect users to other sites via the jump parameter.
23RISCO
abrir
Exploit-DBVexDay Proof
SAP Web Application Server 6.x/7.0 - Error Page Cross-Site Scripting
CVE-2005-3636webappsphp09 nov 2005
Cross-site scripting (XSS) vulnerability in SAP Web Application Server (WAS) 6.10 allows remote attackers to inject arbi
23RISCO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.6.x - Sysctl Unregistration Local Denial of Service
CVE-2005-2709doslinux09 nov 2005
The sysctl functionality (sysctl.c) in Linux kernel before 2.6.14.1 allows local users to cause a denial of service (ker
23RISCO
abrir
anteriorpágina 644 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.