Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.900exploits catalogados
36.847CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
Trionic Cite CMS 1.2rev9 - Remote File Inclusion
CVE-2007-5271webappsphp
Multiple PHP remote file inclusion vulnerabilities in Trionic Cite CMS 1.2 rev9 and earlier allow remote attackers to ex
28RISCO
abrir
ReferênciaVexDay Proof
Zomplog 3.8.1 - Arbitrary File Upload
CVE-2007-5278webappsphp
Zomplog 3.8.1 and earlier stores potentially sensitive information under the web root with insufficient access control,
23RISCO
abrir
ReferênciaVexDay Proof
MG-SOFT Net Inspector 6.5.0.828 - Multiple Vulnerabilities
CVE-2008-1401remotewindows
Format string vulnerability in the Net Inspector HTTP server (mghttpd) in MG-SOFT Net Inspector 6.5.0.828 and earlier fo
23RISCO
abrir
ReferênciaVexDay Proof
Ocean FTP Server 1.00 - Denial of Service
CVE-2005-0847doswindows
Code Ocean FTP server 1.0 allows remote attackers to cause a denial of service via a large number of connections.
23RISCO
abrir
ReferênciaVexDay Proof
WordPress Plugin Spreadsheet 0.6 - SQL Injection
CVE-2008-1982webappsphp
SQL injection vulnerability in ss_load.php in the Spreadsheet (wpSS) 0.6 and earlier plugin for WordPress allows remote
23RISCO
abrir
ReferênciaVexDay Proof
phpCC 4.2 Beta - 'base_dir' Remote File Inclusion
CVE-2006-4073webappsphp
Multiple PHP remote file inclusion vulnerabilities in Fabian Hainz phpCC Beta 4.2 allow remote attackers to execute arbi
23RISCO
abrir
ReferênciaVexDay Proof
MyPHPcommander 2.0 - 'package.php' Remote File Inclusion
CVE-2007-0568webappsphp
PHP remote file inclusion vulnerability in system/lib/package.php in MyPHPCommander 2.0 allows remote attackers to execu
23RISCO
abrir
ReferênciaVexDay Proof
RSS-aggregator - 'path' Remote File Inclusion
CVE-2008-2884webappsphp
PHP remote file inclusion vulnerability in display.php in RSS-aggregator allows remote attackers to execute arbitrary PH
23RISCO
abrir
ReferênciaVexDay Proof
Cisco Router - HTTP Administration Cross-Site Request Forgery / Command Execution (1)
CVE-2008-4128MEDIUMsob ataqueremotehardware
Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the
75RISCO
abrir
ReferênciaVexDay Proof
Versado CMS 1.07 - 'ajax_listado.php?urlModulo' Remote File Inclusion
CVE-2007-2541webappsphp
PHP remote file inclusion vulnerability in includes/ajax_listado.php in Versado CMS 1.07 allows remote attackers to exec
23RISCO
abrir
ReferênciaVexDay Proof
Media Commands - '.m3u' / '.m3l' / '.TXT' / '.LRC' Local Heap Overflow (PoC)
CVE-2009-0885doswindows
Multiple heap-based buffer overflows in Media Commands 1.0 allow remote attackers to execute arbitrary code or cause a d
23RISCO
abrir
ReferênciaVexDay Proof
OneOrZero Helpdesk 1.6.5.7 - Local File Inclusion
CVE-2009-0886webappsphp
Directory traversal vulnerability in login.php in OneOrZero Helpdesk 1.6.5.7 and earlier allows remote attackers to read
23RISCO
abrir
ReferênciaVexDay Proof
phpAddressBook 2.11 - Multiple Local File Inclusions
CVE-2008-1492webappsphp
Multiple directory traversal vulnerabilities in CoronaMatrix phpAddressBook 2.11 allow remote attackers to include and e
23RISCO
abrir
ReferênciaVexDay Proof
OTSCMS 2.1.3 - Multiple Remote File Inclusions
CVE-2006-5546webappsphp
PHP remote file inclusion vulnerability in OTSCMS/OTSCMS.php in Open Tibia Server Content Management System (OTSCMS) 1.3
23RISCO
abrir
ReferênciaVexDay Proof
Interact 2.4.1 - 'help.php' Local File Inclusion
CVE-2008-3384webappsphp
Multiple directory traversal vulnerabilities in help/help.php in Interact Learning Community Environment Interact 2.4.1
23RISCO
abrir
ReferênciaVexDay Proof
PHPPeanuts 1.3 Beta - 'Inspect.php' Remote File Inclusion
CVE-2006-5948webappsphp
PHP remote file inclusion vulnerability in pntUnit/Inspect.php in phpPeanuts 1.1 and earlier allows remote attackers to
23RISCO
abrir
ReferênciaVexDay Proof
phpRealty 0.3 - 'INC' Remote File Inclusion
CVE-2008-4134webappsphp
PHP remote file inclusion vulnerability in manager/static/view.php in phpRealty 0.03 and earlier, and possibly other ver
23RISCO
abrir
ReferênciaVexDay Proof
MDForum 2.0.1 - 'PNSVlang' Remote Code Execution
CVE-2006-6869webappsphp
Directory traversal vulnerability in includes/search/search_mdforum.php in MAXdev MDForum 2.0.1 and earlier, when magic_
23RISCO
abrir
ReferênciaVexDay Proof
VerliAdmin 0.3 - 'language.php' Local File Inclusion
CVE-2007-0098webappsphp
Directory traversal vulnerability in language.php in VerliAdmin 0.3 and earlier, when magic_quotes_gpc is disabled, allo
23RISCO
abrir
ReferênciaVexDay Proof
Natterchat 1.1 - Remote Authentication Bypass
CVE-2008-7047webappsphp
NatterChat 1.1 allows remote attackers to bypass authentication and gain administrator privileges to read or delete room
23RISCO
abrir
ReferênciaVexDay Proof
pragmaMX Module Landkarten 2.1 (Windows) - Local File Inclusion
CVE-2007-1539webappsphp
Directory traversal vulnerability in inc/map.func.php in pragmaMX Landkarten 2.1 module allows remote attackers to inclu
23RISCO
abrir
ReferênciaVexDay Proof
CandyPress eCommerce suite 4.1.1.26 - Multiple Vulnerabilities
CVE-2008-0546webappsasp
Multiple SQL injection vulnerabilities in CandyPress (CP) 4.1.1.26, and earlier 4.1.x versions, allow remote attackers t
23RISCO
abrir
ReferênciaVexDay Proof
ACG-ScriptShop - 'cid' SQL Injection
CVE-2008-4144webappsphp
SQL injection vulnerability in index.php in ACG-ScriptShop E-Gold Script Shop allows remote attackers to execute arbitra
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! 1.5.x - 'Token' Remote Admin Change Password
CVE-2008-3681webappsphp
components/com_user/models/reset.php in Joomla! 1.5 through 1.5.5 does not properly validate reset tokens, which allows
23RISCO
abrir
ReferênciaVexDay Proof
Anthologia 0.5.2 - 'index.php?ads_file' Remote File Inclusion
CVE-2007-2094webappsphp
PHP remote file inclusion vulnerability in index.php in Anthologia 0.5.2 allows remote attackers to execute arbitrary PH
23RISCO
abrir
ReferênciaVexDay Proof
wbstreet 1.0 - SQL Injection / File Disclosure
CVE-2008-5956webappsphp
Wbstreet (aka PHPSTREET Webboard) 1.0 stores sensitive information under the web root with insufficient access control,
23RISCO
abrir
ReferênciaVexDay Proof
PHP-Generics 1.0.0 Beta - Multiple Remote File Inclusions
CVE-2007-2346webappsphp
Multiple PHP remote file inclusion vulnerabilities in PHP-Generics 1.0 beta allow remote attackers to execute arbitrary
23RISCO
abrir
ReferênciaVexDay Proof
Glossword 1.8.1 - 'custom_vars.php' Remote File Inclusion
CVE-2007-2743webappsphp
PHP remote file inclusion vulnerability in custom_vars.php in GlossWord 1.8.1 allows remote attackers to execute arbitra
23RISCO
abrir
ReferênciaVexDay Proof
CounterPath X-Lite 3.x - SIP phone Remote Denial of Service
CVE-2007-4382doswindows
CounterPath X-Lite 3.0 34025, and possibly eyeBeam, allows remote attackers to cause a denial of service (device crash)
23RISCO
abrir
ReferênciaVexDay Proof
addalink 4 Beta - Write Approved Links
CVE-2008-4146webappsphp
Addalink 1.0 beta 4 and earlier allows remote attackers to (1) approve web-site additions via a modified approved field
23RISCO
abrir
anteriorpágina 72 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.