Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.813exploits catalogados
35.788CVEs com exploração pública
24.695testados em laboratório
24.455 exploits
Exploit-DBVexDay Proof
TWiki TWikiUsers - INCLUDE Function Arbitrary Command Execution
CVE-2005-2877webappsphp28 set 2005
The history (revision control) function in TWiki 02-Sep-2004 and earlier allows remote attackers to execute arbitrary co
60RISCO
abrir
Exploit-DBVexDay Proof
Novell Groupwise Client 6.5.3 - Local Integer Overflow
CVE-2005-2804doswindows27 set 2005
Integer overflow in the registry parsing code in GroupWise 6.5.3, and possibly earlier version, allows remote attackers
23RISCO
abrir
Exploit-DBVexDay Proof
Barracuda Spam Firewall < 3.1.18 - Command Execution (Metasploit)
CVE-2005-2847webappscgi27 set 2005
img.pl in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote attackers to execute arbitrary comman
50RISCO
abrir
Exploit-DBVexDay Proof
LucidCMS 2.0 - 'index.php' Cross-Site Scripting
CVE-2005-3127webappsphp27 set 2005
Cross-site scripting (XSS) vulnerability in index.php in lucidCMS 1.0.11 allows remote attackers to inject arbitrary web
23RISCO
abrir
Exploit-DBVexDay Proof
Barracuda Spam Firewall < 3.1.18 - Command Execution (Metasploit)
CVE-2005-2848webappscgi27 set 2005
Directory traversal vulnerability in img.pl in Barracuda Spam Firewall running firmware 3.1.16 and 3.1.17 allows remote
23RISCO
abrir
Exploit-DBVexDay Proof
CMS Made Simple 0.10 - 'index.php' Cross-Site Scripting
CVE-2005-3083webappsphp26 set 2005
Cross-site scripting (XSS) vulnerability in index.php in CMS Made Simple 0.10 allows remote attackers to inject arbitrar
23RISCO
abrir
Exploit-DBVexDay Proof
RealPlayer/Helix Player (Linux) - Remote Format String
CVE-2005-2710remotelinux26 set 2005
Format string vulnerability in Real HelixPlayer and RealPlayer 10 allows remote attackers to execute arbitrary code via
28RISCO
abrir
Exploit-DBVexDay Proof
MultiTheftAuto 0.5 patch 1 - Server Crash / MOTD Deletion
CVE-2005-3064doswindows26 set 2005
MultiTheftAuto 0.5 patch 1 and earlier does not properly verify client privileges when running command 40, which allows
23RISCO
abrir
Exploit-DBVexDay Proof
GNU Mailutils imap4d 0.6 (FreeBSD) - 'Search' Remote Format String
CVE-2005-2878remotebsd26 set 2005
Format string vulnerability in search.c in the imap4d server in GNU Mailutils 0.6 allows remote authenticated users to e
28RISCO
abrir
Exploit-DBVexDay Proof
WzdFTPD 0.5.4 - Remote Command Execution
CVE-2005-3081remotelinux24 set 2005
wzdftpd 0.5.4 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the SITE comma
45RISCO
abrir
Exploit-DBVexDay Proof
Qpopper 4.0.8 (Linux) - 'poppassd' Local Privilege Escalation
CVE-2005-3098locallinux24 set 2005
poppassd in Qualcomm qpopper 4.0.8 allows local users to modify arbitrary files and gain privileges via the -t (trace fi
23RISCO
abrir
Exploit-DBVexDay Proof
Qpopper 4.0.8 (FreeBSD) - Local Privilege Escalation
CVE-2005-3098localbsd24 set 2005
poppassd in Qualcomm qpopper 4.0.8 allows local users to modify arbitrary files and gain privileges via the -t (trace fi
23RISCO
abrir
Exploit-DBVexDay Proof
MailGust 1.9 - Board Takeover (SQL Injection)
CVE-2005-3063webappsphp24 set 2005
SQL injection vulnerability in MailGust 1.9 allows remote attackers to execute arbitrary SQL commands via the email fiel
23RISCO
abrir
Exploit-DBVexDay Proof
phpMyFAQ 1.5.1 - 'User-Agent' Remote Shell Injection
CVE-2005-3048webappsphp23 set 2005
Directory traversal vulnerability in index.php in PhpMyFaq 1.5.1 allows remote attackers to read arbitrary files or incl
23RISCO
abrir
Exploit-DBVexDay Proof
Nokia Symbian 60 - 'BlueTooth Nickname' Remote Restart (2)
CVE-2005-0681doshardware23 set 2005
Nokia Symbian 60 allows remote attackers to cause a denial of service (phone restart) via a Bluetooth nickname.
23RISCO
abrir
Exploit-DBVexDay Proof
Mozilla Browsers - 0xAD (HOST:) Remote Heap Buffer Overrun (2)
CVE-2005-2871remotewindows22 set 2005
Buffer overflow in the International Domain Name (IDN) support in Mozilla Firefox 1.0.6 and earlier, and Netscape 8.0.3.
28RISCO
abrir
Exploit-DBVexDay Proof
My Little Forum 1.5 - 'SearchString' SQL Injection
CVE-2005-3045webappsphp22 set 2005
SQL injection vulnerability in search.php in My Little Forum 1.5 and 1.6 beta allows remote attackers to execute arbitra
23RISCO
abrir
Exploit-DBVexDay Proof
Mercury/32 Mail Server 4.01a (Pegasus) - IMAP Buffer Overflow
CVE-2007-1373remotewindows20 set 2005
Stack-based buffer overflow in Mercury/32 (aka Mercury Mail Transport System) 4.01b and earlier allows remote attackers
50RISCO
abrir
Exploit-DBVexDay Proof
Mozilla Browser/Firefox - Arbitrary Command Execution
CVE-2005-2968remotelinux20 set 2005
Firefox 1.0.6 and Mozilla 1.7.10 allows attackers to execute arbitrary commands via shell metacharacters in a URL that i
28RISCO
abrir
Exploit-DBVexDay Proof
Hesk 0.92/0.93 - Session ID Authentication Bypass
CVE-2005-3005webappsphp20 set 2005
Helpdesk Software Hesk allows remote attackers to bypass authentication for (1) admin.php and (2) admin_main.php by modi
23RISCO
abrir
Exploit-DBVexDay Proof
Mercury/32 Mail Server 4.01a (Pegasus) - IMAP Buffer Overflow
CVE-2006-5961remotewindows20 set 2005
Buffer overflow in Mercury Mail Transport System 4.01b for Windows has unknown impact and attack vectors, as originally
23RISCO
abrir
Exploit-DBVexDay Proof
vBulletin 1.0.1 lite/2.x/3.0 - '/admincp/usertools.php?ids' SQL Injection
CVE-2005-3019webappsphp19 set 2005
Multiple SQL injection vulnerabilities in vBulletin before 3.0.9 allow remote attackers to execute arbitrary SQL command
23RISCO
abrir
Exploit-DBVexDay Proof
vBulletin 1.0.1 lite/2.x/3.0 - '/admincp/modlog.php?orderby' Cross-Site Scripting
CVE-2005-3020webappsphp19 set 2005
Multiple cross-site scripting (XSS) vulnerabilities in vBulletin before 3.0.9 allow remote attackers to inject arbitrary
23RISCO
abrir
Exploit-DBVexDay Proof
EPay Pro 2.0 - 'index.php' Directory Traversal
CVE-2005-3026webappsphp19 set 2005
Directory traversal vulnerability in index.php in Alstrasoft Epay Pro 2.0 and earlier allows remote attackers to read ar
23RISCO
abrir
Exploit-DBVexDay Proof
vBulletin 1.0.1 lite/2.x/3.0 - '/admincp/user.php' Multiple SQL Injections
CVE-2005-3019webappsphp19 set 2005
Multiple SQL injection vulnerabilities in vBulletin before 3.0.9 allow remote attackers to execute arbitrary SQL command
23RISCO
abrir
Exploit-DBVexDay Proof
MCCS (Multi-Computer Control Systems) Command - Denial of Service
CVE-2005-3002doswindows19 set 2005
Multi-Computer Control System (MCCS) 1.0 allows remote attackers to cause a denial of service via a malformed UDP packet
23RISCO
abrir
Exploit-DBVexDay Proof
vBulletin 1.0.1 lite/2.x/3.0 - '/admincp/language.php?goto' Cross-Site Scripting
CVE-2005-3020webappsphp19 set 2005
Multiple cross-site scripting (XSS) vulnerabilities in vBulletin before 3.0.9 allow remote attackers to inject arbitrary
23RISCO
abrir
Exploit-DBVexDay Proof
vBulletin 1.0.1 lite/2.x/3.0 - 'joinrequests.php?request' SQL Injection
CVE-2005-3019webappsphp19 set 2005
Multiple SQL injection vulnerabilities in vBulletin before 3.0.9 allow remote attackers to execute arbitrary SQL command
23RISCO
abrir
Exploit-DBVexDay Proof
vBulletin 1.0.1 lite/2.x/3.0 - '/admincp/template.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2005-3020webappsphp19 set 2005
Multiple cross-site scripting (XSS) vulnerabilities in vBulletin before 3.0.9 allow remote attackers to inject arbitrary
23RISCO
abrir
Exploit-DBVexDay Proof
vBulletin 1.0.1 lite/2.x/3.0 - '/admincp/css.php?group' Cross-Site Scripting
CVE-2005-3020webappsphp19 set 2005
Multiple cross-site scripting (XSS) vulnerabilities in vBulletin before 3.0.9 allow remote attackers to inject arbitrary
23RISCO
abrir
anteriorpágina 651 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.