Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.858exploits catalogados
36.825CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
FlashBlog 0.31b - Arbitrary File Upload
CVE-2008-2574webappsphp
Unrestricted file upload vulnerability in admin/Editor/imgupload.php in FlashBlog 0.31 beta allows remote attackers to e
23RISCO
abrir
ReferênciaVexDay Proof
Magic CMS 4.2.747 - 'mysave.php' Remote File Inclusion
CVE-2007-1393webappsphp
PHP remote file inclusion vulnerability in mysave.php in Magic CMS 4.2.747 allows remote attackers to execute arbitrary
23RISCO
abrir
ReferênciaVexDay Proof
NUVICO DVR NVDV4 / PdvrAtl Module 'PdvrAtl.DLL 1.0.1.25' - Remote Buffer Overflow
CVE-2008-4547remotewindows
Heap-based buffer overflow in the PdvrAtl.PdvrOcx.1 ActiveX control (pdvratl.dll) in DVRHOST Web CMS OCX 1.0.1.25 allows
28RISCO
abrir
ReferênciaVexDay Proof
PHPMesFilms 1.0 - 'index.php?id' SQL Injection
CVE-2009-0598webappsphp
SQL injection vulnerability in index.php in PhpMesFilms 1.0 and 1.8 allows remote attackers to execute arbitrary SQL com
23RISCO
abrir
ReferênciaVexDay Proof
Amber Script 1.0 - 'show_content.php?id' Local File Inclusion
CVE-2007-6129webappsphp
Directory traversal vulnerability in scripts/include/show_content.php in Amber Script 1.0 allows remote attackers to inc
23RISCO
abrir
ReferênciaVexDay Proof
XOOPS mod_gallery Zend_Hash_key + Extract - Remote File Inclusion
CVE-2008-0138webappsphp
PHP remote file inclusion vulnerability in xoopsgallery/init_basic.php in the mod_gallery module for XOOPS, when registe
23RISCO
abrir
ReferênciaVexDay Proof
Omegaboard 1.0beta4 - 'functions.php' Remote File Inclusion
CVE-2007-0683webappsphp
PHP remote file inclusion vulnerability in includes/functions.php in Omegaboard 1.0beta4 and earlier allows remote attac
23RISCO
abrir
ReferênciaVexDay Proof
Scripteen Free Image Hosting Script 1.2 - 'cookie' Pass Grabber
CVE-2008-3211webappsphp
Scripteen Free Image Hosting Script 1.2 and 1.2.1 allows remote attackers to bypass authentication and gain administrati
23RISCO
abrir
ReferênciaVexDay Proof
Jaws 0.8.8 - Multiple Local File Inclusions
CVE-2009-0645webappsphp
Directory traversal vulnerability in index.php in Jaws 0.8.8 allows remote authenticated users to read arbitrary files v
23RISCO
abrir
ReferênciaVexDay Proof
4Site CMS 2.6 - Multiple SQL Injections
CVE-2009-0646webappsphp
Multiple SQL injection vulnerabilities in 4Site CMS 2.6 and earlier allow remote attackers to execute arbitrary SQL comm
23RISCO
abrir
ReferênciaVexDay Proof
Nokia N95-8 browser - 'setAttributeNode' Method Crash
CVE-2009-0649doshardware
The web browser in Symbian OS on the Nokia N95 cell phone allows remote attackers to cause a denial of service (crash) v
23RISCO
abrir
ReferênciaVexDay Proof
Nessus Vulnerability Scanner 3.0.6 - ActiveX Command Execution
CVE-2007-4061remotewindows
Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote attac
28RISCO
abrir
ReferênciaVexDay Proof
Microsoft DirectX SAMI File Parsing - Remote Stack Overflow
CVE-2007-3901remotewindows
Stack-based buffer overflow in the DirectShow Synchronized Accessible Media Interchange (SAMI) parser in quartz.dll for
50RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component Expose RC35 - Arbitrary File Upload
CVE-2007-3932webappsphp
uploadimg.php in the Expose RC35 and earlier (com_expose) component for Joomla! sends an error message but does not exit
23RISCO
abrir
ReferênciaVexDay Proof
Electronics Workbench - '.ewb' Local Stack Overflow (PoC)
CVE-2008-5383doswindows
Stack-based buffer overflow in National Instruments Electronics Workbench allows user-assisted attackers to cause a deni
23RISCO
abrir
ReferênciaVexDay Proof
ravennuke 2.3.0 - Multiple Vulnerabilities
CVE-2009-0672webappsphp
SQL injection vulnerability in the Resend_Email module in Raven Web Services RavenNuke 2.30 allows remote authenticated
23RISCO
abrir
ReferênciaVexDay Proof
Morovia Barcode ActiveX Professional 3.3.1304 - Arbitrary File Overwrite
CVE-2007-2644remotewindows
A certain ActiveX control in Morovia Barcode ActiveX Professional 3.3.1304 allows remote attackers to overwrite arbitrar
23RISCO
abrir
ReferênciaVexDay Proof
A-shop 0.70 - Remote File Deletion
CVE-2007-3937webappsasp
Multiple SQL injection vulnerabilities in A-shop 0.70 and earlier allow remote attackers to execute arbitrary SQL comman
23RISCO
abrir
ReferênciaVexDay Proof
ravennuke 2.3.0 - Multiple Vulnerabilities
CVE-2009-0677webappsphp
avatarlist.php in the Your Account module, reached through modules.php, in Raven Web Services RavenNuke 2.30 allows remo
23RISCO
abrir
ReferênciaVexDay Proof
Netgear SSL312 Router - Denial of Service
CVE-2009-0680doshardware
cgi-bin/welcome/VPN_only in the web interface in Netgear SSL312 allows remote attackers to cause a denial of service (de
23RISCO
abrir
ReferênciaVexDay Proof
Trend Micro Internet Security Pro 2009 - Priviliege Escalation
CVE-2009-0686localwindows
The TrendMicro Activity Monitor Module (tmactmon.sys) 2.52.0.1002 in Trend Micro Internet Pro 2008 and 2009, and Securit
23RISCO
abrir
ReferênciaVexDay Proof
LinkedIn Toolbar 3.0.2.1098 - Remote Buffer Overflow
CVE-2007-3955remotewindows
Buffer overflow in the IEToolbar.IEContextMenu.1 ActiveX control in LinkedInIEToolbar.dll in the LinkedIn Toolbar 3.0.2.
23RISCO
abrir
ReferênciaVexDay Proof
JBlog 1.0 - Create / Delete Admin Authentication Bypass
CVE-2007-3974webappsphp
admin/ajoutaut.php in JBlog 1.0 does not require authentication, which allows remote attackers to create arbitrary accou
23RISCO
abrir
ReferênciaVexDay Proof
Lms 1.8.9 - Vala Remote File Inclusion
CVE-2007-1643webappsphp
Multiple PHP remote file inclusion vulnerabilities in LAN Management System (LMS) 1.8.9 Vala and earlier allow remote at
28RISCO
abrir
ReferênciaVexDay Proof
EZWebAlbum - Remote File Disclosure
CVE-2008-3293webappsphp
Directory traversal vulnerability in download.php in EZWebAlbum allows remote attackers to read arbitrary files via the
23RISCO
abrir
ReferênciaVexDay Proof
Focus/SIS 1.0/2.2 - Remote File Inclusion
CVE-2007-4806webappsphp
PHP remote file inclusion vulnerability in modules/Discipline/CategoryBreakdownTime.php in Focus/SIS 1.0 allows remote a
23RISCO
abrir
ReferênciaVexDay Proof
Maian Recipe 1.2 - Insecure Cookie Handling
CVE-2008-3322webappsphp
admin/index.php in Maian Recipe 1.2 and earlier allows remote attackers to bypass authentication and gain administrative
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component ionFiles 4.4.2 - File Disclosure
CVE-2008-6080webappsphp
Directory traversal vulnerability in download.php in the ionFiles (com_ionfiles) 4.4.2 component for Joomla! allows remo
43RISCO
abrir
ReferênciaVexDay Proof
Coppermine Photo Gallery 1.4.18 - Local File Inclusion / Remote Code Execution
CVE-2008-3486webappsphp
Directory traversal vulnerability in the user_get_profile function in include/functions.inc.php in Coppermine Photo Gall
23RISCO
abrir
ReferênciaVexDay Proof
PHP 5.2.4 ionCube - 'ioncube_read_file' Safe Mode / disable_functions Bypass
CVE-2007-5447localwindows
ioncube_loader_win_5.2.dll in the ionCube Loader 6.5 extension for PHP 5.2.4 does not follow safe_mode and disable_funct
23RISCO
abrir
anteriorpágina 65 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.