Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.813exploits catalogados
35.788CVEs com exploração pública
24.695testados em laboratório
24.455 exploits
Exploit-DBVexDay Proof
Cyphor 0.19 - 'lostpwd.php?nick' SQL Injection
CVE-2005-3236webappsphp08 out 2005
Multiple SQL injection vulnerabilities in Cyphor 0.19 allow remote attackers to execute arbitrary SQL and obtain adminis
23RISCO
abrir
Exploit-DBVexDay Proof
Cyphor 0.19 - 'newmsg.php?fid' SQL Injection
CVE-2005-3236webappsphp08 out 2005
Multiple SQL injection vulnerabilities in Cyphor 0.19 allow remote attackers to execute arbitrary SQL and obtain adminis
23RISCO
abrir
Exploit-DBVexDay Proof
Cyphor 0.19 - 'footer.php?t_login' Cross-Site Scripting
CVE-2005-3237webappsphp08 out 2005
Cross-site scripting (XSS) vulnerability in Cyphor 0.19 allows remote attackers to inject arbitrary web script or HTML v
23RISCO
abrir
Exploit-DBVexDay Proof
Cyphor 0.19 - Board Takeover (SQL Injection)
CVE-2005-3575webappsphp08 out 2005
SQL injection vulnerability in show.php in Cyphor 0.19 and earlier allows remote attackers to execute arbitrary SQL comm
23RISCO
abrir
Exploit-DBVexDay Proof
Oracle Forms - Servlet TLS Listener Remote Denial of Service
CVE-2005-3207dosmultiple07 out 2005
The forms servlet (f90servlet) in Oracle Forms 4.5.10.22 allows remote attackers to cause a denial of service (TNS liste
28RISCO
abrir
Exploit-DBVexDay Proof
Utopia News Pro 1.1.3 - 'footer.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2005-3200webappsphp07 out 2005
Multiple cross-site scripting (XSS) vulnerabilities in Utopia News Pro (UNP) 1.1.3 and 1.1.4 allow remote attackers to i
23RISCO
abrir
Exploit-DBVexDay Proof
Oracle 9.0 iSQL*Plus - TLS Listener Remote Denial of Service
CVE-2005-3206dosmultiple07 out 2005
iSQL*Plus (isqlplus) for Oracle9i Database Server Release 2 9.0.2.4 allows remote attackers to cause a denial of service
28RISCO
abrir
Exploit-DBVexDay Proof
Oracle 9 - XML DB Cross-Site Scripting
CVE-2005-3204remotemultiple07 out 2005
Cross-site scripting (XSS) vulnerability in Oracle XML DB 9iR2 allows remote attackers to inject arbitrary web script or
28RISCO
abrir
Exploit-DBVexDay Proof
Utopia News Pro 1.1.3 - 'header.php?sitetitle' Cross-Site Scripting
CVE-2005-3200webappsphp07 out 2005
Multiple cross-site scripting (XSS) vulnerabilities in Utopia News Pro (UNP) 1.1.3 and 1.1.4 allow remote attackers to i
23RISCO
abrir
Exploit-DBVexDay Proof
Aenovo - '/Password/default.asp?Password' SQL Injection
CVE-2005-3208webappsasp07 out 2005
Multiple SQL injection vulnerabilities in (1) aeNovo, (2) aeNovoShop and (3) aeNovoWYSI allow remote attackers to execut
23RISCO
abrir
Exploit-DBVexDay Proof
Oracle HTML DB 1.5/1.6 - 'wwv_flow.accept?p_t02' Cross-Site Scripting
CVE-2005-3202remotemultiple07 out 2005
Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTML DB (HTMLDB) 1.3 through 1.3.6 allow remote attackers
28RISCO
abrir
Exploit-DBVexDay Proof
Aenovo - '/incs/searchdisplay.asp?strSQL' SQL Injection
CVE-2005-3208webappsasp07 out 2005
Multiple SQL injection vulnerabilities in (1) aeNovo, (2) aeNovoShop and (3) aeNovoWYSI allow remote attackers to execut
23RISCO
abrir
Exploit-DBVexDay Proof
Oracle HTML DB 1.5/1.6 - 'f?p=' Cross-Site Scripting
CVE-2005-3202remotemultiple07 out 2005
Multiple cross-site scripting (XSS) vulnerabilities in Oracle HTML DB (HTMLDB) 1.3 through 1.3.6 allow remote attackers
28RISCO
abrir
Exploit-DBVexDay Proof
Utopia News Pro 1.1.3 - 'news.php' SQL Injection
CVE-2005-3201webappsphp06 out 2005
SQL injection vulnerability in news.php for Utopia News Pro (UNP) 1.1.3, when magic_quotes_gpc is disabled and register_
23RISCO
abrir
Exploit-DBVexDay Proof
Mozilla Firefox 1.0.6/1.0.7 - iFrame Handling Denial of Service
CVE-2005-4720dosmultiple05 out 2005
Mozilla Firefox 1.0.7 and earlier on Linux allows remote attackers to cause a denial of service (client crash) via an IF
23RISCO
abrir
Exploit-DBVexDay Proof
TellMe 1.2 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2005-4698webappsphp05 out 2005
Cross-site scripting (XSS) vulnerability in TellMe 1.2 and earlier allows remote attackers to inject arbitrary web scrip
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows XP - Wireless Zero Configuration Service Information Disclosure
CVE-2005-4696localwindows04 out 2005
The Microsoft Wireless Zero Configuration system (WZCS) stores WEP keys and pair-wise Master Keys (PMK) of the WPA pre-s
23RISCO
abrir
Exploit-DBVexDay Proof
Gnome-PTY-Helper UTMP - Hostname Spoofing
CVE-2005-0023locallinux03 out 2005
gnome-pty-helper in GNOME libzvt2 and libvte4 allows local users to spoof the logon hostname via a modified DISPLAY envi
23RISCO
abrir
Exploit-DBVexDay Proof
Virtools Web Player 3.0.0.100 - Buffer Overflow (Denial of Service) (PoC)
CVE-2005-3135doswindows02 out 2005
Buffer overflow in Virtools Web Player 3.0.0.100 and earlier allows remote attackers to execute arbitrary code via a lon
23RISCO
abrir
Exploit-DBVexDay Proof
Prozilla 1.3.7.4 - 'ftpsearch' Results Handling Buffer Overflow
CVE-2005-2961remotelinux02 out 2005
Buffer overflow in the get_string_ahref function for ProZilla 1.3.7.4 and possibly earlier, with the -ftpsearch option e
23RISCO
abrir
Exploit-DBVexDay Proof
IceWarp Web Mail 5.5.1 - 'calendar_m.html?createdataCX' Cross-Site Scripting
CVE-2005-3131webappsphp30 set 2005
Multiple cross-site scripting (XSS) vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibl
23RISCO
abrir
Exploit-DBVexDay Proof
IceWarp Web Mail 5.5.1 - 'blank.html?id' Cross-Site Scripting
CVE-2005-3131webappsphp30 set 2005
Multiple cross-site scripting (XSS) vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibl
23RISCO
abrir
Exploit-DBVexDay Proof
IceWarp Web Mail 5.5.1 - 'calendar_d.html?createdataCX' Cross-Site Scripting
CVE-2005-3131webappsphp30 set 2005
Multiple cross-site scripting (XSS) vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibl
23RISCO
abrir
Exploit-DBVexDay Proof
IceWarp Web Mail 5.5.1 - 'calendar_w.html?createdataCX' Cross-Site Scripting
CVE-2005-3131webappsphp30 set 2005
Multiple cross-site scripting (XSS) vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibl
23RISCO
abrir
Exploit-DBVexDay Proof
Merak Mail Server 8.2.4 r - Arbitrary File Deletion
CVE-2005-3133webappsphp30 set 2005
Multiple directory traversal vulnerabilities in MERAK Mail Server 8.2.4r with Icewarp Web Mail 5.5.1, and possibly earli
23RISCO
abrir
Exploit-DBVexDay Proof
LucidCMS 2.0 - Login SQL Injection
CVE-2005-3130webappsphp29 set 2005
SQL injection vulnerability in lucidCMS 1.0.11 allows remote attackers to execute arbitrary SQL commands via the login f
23RISCO
abrir
Exploit-DBVexDay Proof
SquirrelMail 1.4.2 Address Add Plugin - 'add.php' Cross-Site Scripting
CVE-2005-3128webappsphp29 set 2005
Cross-site scripting (XSS) vulnerability in add.php in Address Add Plugin 1.9 and 2.0 for Squirrelmail allows remote att
38RISCO
abrir
Exploit-DBVexDay Proof
CubeCart 3.0.3 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2005-3152webappsphp28 set 2005
Multiple cross-site scripting (XSS) vulnerabilities in CubeCart 3.0.3 allow remote attackers to inject arbitrary web scr
23RISCO
abrir
Exploit-DBVexDay Proof
PHP-Fusion 6.00.109 - 'msg_send' SQL Injection
CVE-2005-3157webappsphp28 set 2005
SQL injection vulnerability in messages.php in PHP-Fusion 6.00.109 allows remote attackers to execute arbitrary SQL comm
23RISCO
abrir
Exploit-DBVexDay Proof
CubeCart 3.0.3 - 'cart.php?redir' Cross-Site Scripting
CVE-2005-3152webappsphp28 set 2005
Multiple cross-site scripting (XSS) vulnerabilities in CubeCart 3.0.3 allow remote attackers to inject arbitrary web scr
23RISCO
abrir
anteriorpágina 650 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.