Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.813exploits catalogados
35.788CVEs com exploração pública
24.695testados em laboratório
24.455 exploits
Exploit-DBVexDay Proof
SAP Web Application Server 6.x/7.0 - Error Page Cross-Site Scripting
CVE-2005-3636webappsphp09 nov 2005
Cross-site scripting (XSS) vulnerability in SAP Web Application Server (WAS) 6.10 allows remote attackers to inject arbi
23RISCO
abrir
Exploit-DBVexDay Proof
SAP Web Application Server 6.x/7.0 - 'frameset.htm?sap-syscmd' Cross-Site Scripting
CVE-2005-3635webappsphp09 nov 2005
Multiple cross-site scripting (XSS) vulnerabilities in SAP Web Application Server (WAS) 6.10 through 7.00 allow remote a
23RISCO
abrir
Exploit-DBVexDay Proof
Operator Shell (OSH) 1.7-14 - Local Privilege Escalation
CVE-2005-3346locallinux09 nov 2005
Buffer overflow in the environment variable substitution code in main.c in OSH 1.7-14 allows local users to inject arbit
23RISCO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.6.x - Sysctl Unregistration Local Denial of Service
CVE-2005-2709doslinux09 nov 2005
The sysctl functionality (sysctl.c) in Linux kernel before 2.6.14.1 allows local users to cause a denial of service (ker
23RISCO
abrir
Exploit-DBVexDay Proof
Linux chfn (SuSE 9.3/10) - Local Privilege Escalation
CVE-2005-3503locallinux08 nov 2005
chfn in pwdutils 3.0.4 and earlier on SuSE Linux, and possibly other operating systems, does not properly check argument
23RISCO
abrir
Exploit-DBVexDay Proof
PHPFM - Arbitrary File Upload
CVE-2005-4423webappsphp07 nov 2005
Unrestricted file upload vulnerability in PHPFM before 0.2.3 allows remote authenticated users to execute arbitrary code
23RISCO
abrir
Exploit-DBVexDay Proof
PHPList Mailing List Manager 2.x - '/admin/eventlog.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2005-3556webappsphp07 nov 2005
Multiple cross-site scripting (XSS) vulnerabilities in PHPlist 2.10.1 and earlier allow remote attackers to inject arbit
23RISCO
abrir
Exploit-DBVexDay Proof
F-Secure Internet GateKeeper for Linux < 2.15.484 / Gateway < 2.16 - Local Privilege Escalation
CVE-2005-3546locallinux07 nov 2005
suid.cgi scripts in F-Secure (1) Internet Gatekeeper for Linux before 2.15.484 and (2) Anti-Virus Linux Gateway before 2
23RISCO
abrir
Exploit-DBVexDay Proof
Asterisk 0.x/1.0/1.2 Voicemail - Unauthorized Access
CVE-2005-3559webappscgi07 nov 2005
Directory traversal vulnerability in vmail.cgi in Asterisk 1.0.9 through 1.2.0-beta1 allows remote attackers to access W
28RISCO
abrir
Exploit-DBVexDay Proof
PHPList Mailing List Manager 2.x - '/admin/users.php?find' Cross-Site Scripting
CVE-2005-3556webappsphp07 nov 2005
Multiple cross-site scripting (XSS) vulnerabilities in PHPlist 2.10.1 and earlier allow remote attackers to inject arbit
23RISCO
abrir
Exploit-DBVexDay Proof
F-Secure Internet GateKeeper for Linux < 2.15.484 / Gateway < 2.16 - Local Privilege Escalation
CVE-2006-3546locallinux07 nov 2005
Patrice Freydiere ImgSvr (aka ADA Image Server) allows remote attackers to cause a denial of service (daemon crash) via
23RISCO
abrir
Exploit-DBVexDay Proof
PHPList Mailing List Manager 2.x - '/admin/editattributes.php?id' SQL Injection
CVE-2005-3555webappsphp07 nov 2005
Multiple SQL injection vulnerabilities in PHPlist 2.10.1 and earlier allow authenticated remote attackers with administr
23RISCO
abrir
Exploit-DBVexDay Proof
OSTE 1.0 - Remote File Inclusion
CVE-2005-3558webappsphp07 nov 2005
PHP file inclusion vulnerability in index.php in OSTE 1.0 allows remote attackers to execute arbitrary code via the (1)
23RISCO
abrir
Exploit-DBVexDay Proof
XMB Forum 1.9.3 - 'u2u.php' Cross-Site Scripting
CVE-2005-3544webappsphp07 nov 2005
Cross-site scripting (XSS) vulnerability in u2u.php in XMB 1.9.3 allows remote attackers to inject arbitrary web script
23RISCO
abrir
Exploit-DBVexDay Proof
ATutor 1.5.1pl2 - SQL Injection / Command Execution
CVE-2005-4155webappsphp07 nov 2005
registration.PHP in ATutor 1.5.1 pl2 allows remote attackers to execute arbitrary SQL commands via an e-mail address tha
23RISCO
abrir
Exploit-DBVexDay Proof
Zone Labs Zone Alarm 6.0 - Advance Program Control Bypass
CVE-2005-3560localwindows07 nov 2005
Zone Labs (1) ZoneAlarm Pro 6.0, (2) ZoneAlarm Internet Security Suite 6.0, (3) ZoneAlarm Anti-Virus 6.0, (4) ZoneAlarm
28RISCO
abrir
Exploit-DBVexDay Proof
PHPList Mailing List Manager 2.x - '/admin/admin.php?id' SQL Injection
CVE-2005-3555webappsphp07 nov 2005
Multiple SQL injection vulnerabilities in PHPlist 2.10.1 and earlier allow authenticated remote attackers with administr
23RISCO
abrir
Exploit-DBVexDay Proof
Invision Power Board (IP.Board) 2.1 - 'admin.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2005-3547webappsphp07 nov 2005
Cross-site scripting (XSS) vulnerability in Invision Power Board 2.1 allows remote attackers to inject arbitrary web scr
23RISCO
abrir
Exploit-DBVexDay Proof
PHPList Mailing List Manager 2.x - '/admin/configure.php?id' Cross-Site Scripting
CVE-2005-3556webappsphp07 nov 2005
Multiple cross-site scripting (XSS) vulnerabilities in PHPlist 2.10.1 and earlier allow remote attackers to inject arbit
23RISCO
abrir
Exploit-DBVexDay Proof
ToendaCMS 0.6.1 - 'admin.php' Directory Traversal
CVE-2005-3550webappsphp07 nov 2005
Directory traversal vulnerability in admin.php in toendaCMS before 0.6.2 allows remote attackers to access arbitrary fil
23RISCO
abrir
Exploit-DBVexDay Proof
ibProArcade 2.x - module 'vBulletin/IPB' SQL Injection
CVE-2005-3545webappsphp06 nov 2005
SQL injection vulnerability in index.php of the report module in ibProArcade 2.5.2 and earlier allows remote attackers t
23RISCO
abrir
Exploit-DBVexDay Proof
Widget Property 1.1.19 - 'Property.php' SQL Injection
CVE-2005-4016webappsphp05 nov 2005
SQL injection vulnerability in Widget Property 1.1.19 allows remote attackers to execute arbitrary SQL commands via the
23RISCO
abrir
Exploit-DBVexDay Proof
linux-ftpd-ssl 0.17 - 'MKD'/'CWD' Remote Code Execution
CVE-2005-3524remotelinux05 nov 2005
Buffer overflow in the SSL-ready version of linux-ftpd (linux-ftpd-ssl) 0.17 allows remote attackers to execute arbitrar
28RISCO
abrir
Exploit-DBVexDay Proof
gpsdrive 2.09 (PPC) - 'friendsd2' Remote Format String
CVE-2005-3523remotelinux04 nov 2005
Format string vulnerability in friendsd2 in GpsDrive allows remote attackers to execute arbitrary code via the dir (dire
23RISCO
abrir
Exploit-DBVexDay Proof
JPortal Web Portal 2.2.1/2.3.1 - 'news.php' SQL Injection
CVE-2005-3509webappsphp04 nov 2005
Multiple SQL injection vulnerabilities in JPortal allow remote attackers to execute arbitrary SQL commands via (1) banne
23RISCO
abrir
Exploit-DBVexDay Proof
JPortal Web Portal 2.2.1/2.3.1 - 'comment.php' SQL Injection
CVE-2005-3509webappsphp04 nov 2005
Multiple SQL injection vulnerabilities in JPortal allow remote attackers to execute arbitrary SQL commands via (1) banne
23RISCO
abrir
Exploit-DBVexDay Proof
Ocean12 ASP Calendar Manager 1.0 - Authentication Bypass
CVE-2005-4657webappsasp04 nov 2005
Ocean12 Calendar Manager Pro 1.01 allows remote attackers to bypass authentication and obtain sensitive information via
23RISCO
abrir
Exploit-DBVexDay Proof
gpsdrive 2.09 (x86) - 'friendsd2' Remote Format String
CVE-2005-3523remotelinux_x8604 nov 2005
Format string vulnerability in friendsd2 in GpsDrive allows remote attackers to execute arbitrary code via the dir (dire
23RISCO
abrir
Exploit-DBVexDay Proof
WzdFTPD 0.5.4 - 'SITE' Remote Command Execution (Metasploit)
CVE-2005-3081remotemultiple04 nov 2005
wzdftpd 0.5.4 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the SITE comma
45RISCO
abrir
Exploit-DBVexDay Proof
CuteNews 1.4.1 - Shell Injection / Remote Command Execution
CVE-2009-4115webappsphp03 nov 2005
Multiple static code injection vulnerabilities in the Categories module in CutePHP CuteNews 1.4.6 allow remote authentic
23RISCO
abrir
anteriorpágina 645 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.