Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.980exploits catalogados
36.899CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
GNU/Gallery 1.1.1.0 - 'admin.php' Local File Inclusion
CVE-2008-2353webappsphp
Directory traversal vulnerability in admin.php in GNU/Gallery 1.1.1.0 and earlier allows remote attackers to include and
23RISCO
abrir
ReferênciaVexDay Proof
Integramod Nederland 1.4.2 - Remote File Inclusion
CVE-2007-5140webappsphp
PHP remote file inclusion vulnerability in includes/archive/archive_topic.php in IntegraMOD Nederland 1.4.2 allows remot
23RISCO
abrir
ReferênciaVexDay Proof
teatro 1.6 - 'basePath' Remote File Inclusion
CVE-2007-5780webappsphp
PHP remote file inclusion vulnerability in pub/pub08_comments.php in teatro 1.6 allows remote attackers to execute arbit
23RISCO
abrir
ReferênciaVexDay Proof
MyBlog: PHP and MySQL Blog/CMS software - SQL Injection / Cross-Site Scripting
CVE-2008-2963webappsphp
Multiple SQL injection vulnerabilities in MyBlog allow remote attackers to execute arbitrary SQL commands via the (1) vi
23RISCO
abrir
ReferênciaVexDay Proof
Lithium CMS 4.04c - '/classes/index.php' Local File Inclusion
CVE-2006-5731webappsphp
Directory traversal vulnerability in classes/index.php in Lithium CMS 4.04c and earlier allows remote attackers to inclu
23RISCO
abrir
ReferênciaVexDay Proof
artmedic weblog 1.0 - Multiple Local File Inclusions
CVE-2008-0798webappsphp
Multiple directory traversal vulnerabilities in artmedic webdesign weblog 1.0, when magic_quotes_gpc is disabled, allow
23RISCO
abrir
ReferênciaVexDay Proof
moziloCMS 1.10.1 - 'download.php' Arbitrary Download File
CVE-2008-3589webappsphp
Directory traversal vulnerability in download.php in moziloCMS 1.10.1, when magic_quotes_gpc is disabled, allows remote
23RISCO
abrir
ReferênciaVexDay Proof
Ourspace 2.0.9 - 'uploadmedia.cgi' Arbitrary File Upload
CVE-2007-4647webappscgi
newswire/uploadmedia.cgi in 2coolcode Our Space (Ourspace) 2.0.9 allows remote attackers to upload certain files via uns
23RISCO
abrir
ReferênciaVexDay Proof
mBlog 1.2 - 'page' Remote File Disclosure
CVE-2007-6582webappsphp
Directory traversal vulnerability in index.php in mBlog 1.2 allows remote attackers to read arbitrary files via a .. (do
23RISCO
abrir
ReferênciaVexDay Proof
TinyCMS 1.1.2 - 'templater.php' Local File Inclusion
CVE-2008-4740webappsphp
Directory traversal vulnerability in templater.php in the ZZ_Templater module in TinyCMS 1.1.2, when register_globals is
23RISCO
abrir
ReferênciaVexDay Proof
Podcast Generator 1.1 - Remote Code Execution
CVE-2009-1226webappsphp
core/admin/delete.php in Podcast Generator 1.1 and earlier does not properly restrict access to administrative functions
23RISCO
abrir
ReferênciaVexDay Proof
PHP Net Tools 2.7.1 - Remote Code Execution
CVE-2006-1921webappsphp
nettools.php in PHP Net Tools 2.7.1 allows remote attackers to execute arbitrary commands via shell metacharacters in th
23RISCO
abrir
ReferênciaVexDay Proof
GuestCal 2.1 - 'index.php?lang' Local File Inclusion
CVE-2009-1319webappsphp
Directory traversal vulnerability in includes/ini.inc.php in GuestCal 2.1 allows remote attackers to include and execute
23RISCO
abrir
ReferênciaVexDay Proof
UploadImage/UploadScript 1.0 - Remote Change Admin Password
CVE-2008-0245webappsphp
admin.php in UploadImage 1.0 does not check for the original password before making a change to a new password, which al
23RISCO
abrir
ReferênciaVexDay Proof
CNStats 2.9 - 'who_r.php?bj' Remote File Inclusion
CVE-2007-2086webappsphp
Multiple PHP remote file inclusion vulnerabilities in CNStats 2.9 allow remote attackers to execute arbitrary PHP code v
23RISCO
abrir
ReferênciaVexDay Proof
Flip 3.0 - Remote Admin Creation
CVE-2007-5062webappsphp
account.php in Adam Scheinberg Flip 3.0 and earlier allows remote attackers to create administrative accounts via the un
23RISCO
abrir
ReferênciaVexDay Proof
Chipmunk Blog - (Authentication Bypass) Add Admin
CVE-2009-0399webappsphp
Chipmunk Blogger Script allows remote attackers to gain administrator privileges via a direct request to admin/reguser.p
23RISCO
abrir
ReferênciaVexDay Proof
Verlihub Control Panel 1.7.x - Local File Inclusion
CVE-2007-5321webappsphp
Directory traversal vulnerability in index.php in Verlihub Control Panel (VHCP) 1.7 and earlier allows remote attackers
23RISCO
abrir
ReferênciaVexDay Proof
Syntax Desktop 2.7 - 'synTarget' Local File Inclusion
CVE-2009-0448webappsphp
Directory traversal vulnerability in admin/modules/aa/preview.php in Syntax Desktop 2.7 allows remote attackers to inclu
23RISCO
abrir
ReferênciaVexDay Proof
Catviz 0.4.0 beta1 - Local File Inclusion / Cross-Site Scripting
CVE-2009-1748webappsphp
Multiple directory traversal vulnerabilities in index.php in Catviz 0.4.0 Beta 1 allow remote attackers to read arbitrar
23RISCO
abrir
ReferênciaVexDay Proof
CoAST 0.95 - 'sections_file' Remote File Inclusion
CVE-2008-4735webappsphp
PHP remote file inclusion vulnerability in header.php in Concord Asset, Software, and Ticket system (CoAST) 0.95 allows
23RISCO
abrir
ReferênciaVexDay Proof
The Net Guys ASPired2Poll - Remote Database Disclosure
CVE-2008-6354webappsasp
The Net Guys ASPired2poll stores sensitive information under the web root with insufficient access control, which allows
23RISCO
abrir
ReferênciaVexDay Proof
Mailist 3.0 - Insecure Backup / Local File Inclusion
CVE-2009-0571webappsphp
admin.php in Ninja Designs Mailist 3.0 stores backup copies of maillist.php under the web root with insufficient access
23RISCO
abrir
ReferênciaVexDay Proof
AV Tutorial Script 1.0 - Remote User Pass Change
CVE-2007-3630webappsphp
changePW.php in AV Tutorial Script (avtutorial) 1.0 does not require authentication or knowledge of an old password for
23RISCO
abrir
ReferênciaVexDay Proof
Easy Scripts Answer and Question Script - Multiple Vulnerabilities
CVE-2009-1665webappsphp
myaccount.php in Easy Scripts Answer and Question Script allows remote attackers to remove arbitrary user accounts via a
23RISCO
abrir
ReferênciaVexDay Proof
Sisfo Kampus 2006 - 'blanko.preview.php' Local File Disclosure
CVE-2007-4820webappsphp
Absolute path traversal vulnerability in blanko.preview.php in Sisfo Kampus 2006 allows remote attackers to read arbitra
23RISCO
abrir
ReferênciaVexDay Proof
yourplace 1.0.2 - Multiple Vulnerabilities / Remote Code Execution
CVE-2008-6772webappsphp
login/register_form.php in YourPlace 1.0.2 and earlier does not check that a username already exists when a new account
23RISCO
abrir
ReferênciaVexDay Proof
MySpeach 3.0.7 - Local/Remote File Inclusion
CVE-2007-1895webappsphp
PHP remote file inclusion vulnerability in chat.php in Sky GUNNING MySpeach 3.0.7 and earlier, when used with PHP 5, all
23RISCO
abrir
ReferênciaVexDay Proof
WWWISIS 7.1 - 'IsisScript' Local File Disclosure / Cross-Site Scripting
CVE-2007-5484webappscgi
Directory traversal vulnerability in wxis.exe in WWWISIS 7.1 allows local users to read arbitrary files via a .. (dot do
23RISCO
abrir
ReferênciaVexDay Proof
NavBoard 2.6.0 - Remote Code Execution
CVE-2007-2899webappsphp
Direct static code injection vulnerability in admin_config.php in NavBoard 2.6.0 allows remote attackers to inject arbit
23RISCO
abrir
anteriorpágina 91 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.