Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.107exploits catalogados
36.322CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
1024 CMS 1.3.1 - Local File Inclusion / SQL Injection
CVE-2007-6584webappsphp
Multiple directory traversal vulnerabilities in 1024 CMS 1.3.1 allow remote attackers to include and execute arbitrary l
23RISCO
abrir
ReferênciaVexDay Proof
NmnNewsletter 1.0.7 - 'output' Remote File Inclusion
CVE-2007-6585webappsphp
PHP remote file inclusion vulnerability in confirmUnsubscription.php in NmnNewsletter 1.0.7 allows remote attackers to e
23RISCO
abrir
ReferênciaVexDay Proof
SkyFex Client 1.0 - ActiveX 'Start()' Method Remote Stack Overflow
CVE-2007-6605doswindows
Buffer overflow in a certain ActiveX control in SkyFexClient.ocx 1.0.2.77 in SkyFex Client 1.0 allows remote attackers t
23RISCO
abrir
ReferênciaVexDay Proof
Haberx 1.02 < 1.1 - 'tr' SQL Injection
CVE-2006-4853webappsasp
SQL injection vulnerability in kategorix.asp in Haberx 1.02 through 1.1 allows remote attackers to execute arbitrary SQL
23RISCO
abrir
ReferênciaVexDay Proof
FaScript FaPersianHack 1.0 - SQL Injection
CVE-2008-0326webappsphp
SQL injection vulnerability in class/show.php in FaScript FaPersianHack 1.0 allows remote attackers to execute arbitrary
23RISCO
abrir
ReferênciaVexDay Proof
LulieBlog 1.02 - SQL Injection
CVE-2008-0446webappsphp
SQL injection vulnerability in voircom.php in LulieBlog 1.02 allows remote attackers to execute arbitrary SQL commands v
23RISCO
abrir
ReferênciaVexDay Proof
PHP Blue Dragon CMS 2.9.1 - Cross-Site Scripting / SQL Injection Code Execution
CVE-2006-4960webappsphp
Cross-site scripting (XSS) vulnerability in index.php Php Blue Dragon 2.9.1 and earlier allows remote attackers to injec
23RISCO
abrir
ReferênciaVexDay Proof
Agares phpAutoVideo 2.21 - Local/Remote File Inclusion
CVE-2007-6615webappsphp
Directory traversal vulnerability in includes/block.php in Agares Media phpAutoVideo 2.21 allows remote attackers to inc
23RISCO
abrir
ReferênciaVexDay Proof
ZeusCMS 0.3 - Blind SQL Injection
CVE-2007-6622webappsphp
SQL injection vulnerability in security.php in ZeusCMS 0.3 and earlier allows remote attackers to execute arbitrary SQL
23RISCO
abrir
ReferênciaVexDay Proof
IPTBB 0.5.4 - 'id' SQL Injection
CVE-2007-6639webappsphp
SQL injection vulnerability in index.php in IPTBB 0.5.4 and earlier allows remote attackers to execute arbitrary SQL com
23RISCO
abrir
ReferênciaVexDay Proof
Bitweaver 2.8.1 - Multiple Vulnerabilities
CVE-2012-5193webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in Bitweaver 2.8.1 and earlier allow remote attackers to inject arbi
23RISCO
abrir
ReferênciaVexDay Proof
exV2 < 2.0.4.3 - 'sort' SQL Injection
CVE-2006-5030webappsphp
SQL injection vulnerability in modules/messages/index.php in exV2 2.0.4.3 and earlier allows remote authenticated users
23RISCO
abrir
ReferênciaVexDay Proof
BrudaGB 1.1 - '/admin/index.php' Remote File Inclusion
CVE-2006-5068webappsphp
PHP remote file inclusion vulnerability in admin/index.php in Brudaswen (1) BrudaNews 1.1 and earlier and (2) BrudaGB 1.
23RISCO
abrir
ReferênciaVexDay Proof
BrudaNews 1.1 - '/admin/index.php' Remote File Inclusion
CVE-2006-5068webappsphp
PHP remote file inclusion vulnerability in admin/index.php in Brudaswen (1) BrudaNews 1.1 and earlier and (2) BrudaGB 1.
23RISCO
abrir
ReferênciaVexDay Proof
Linux Kernel 2.6.23 < 2.6.24 - 'vmsplice' Local Privilege Escalation (1)
CVE-2008-0010locallinux
The copy_from_user_mmap_sem function in fs/splice.c in the Linux kernel 2.6.22 through 2.6.24 does not validate a certai
23RISCO
abrir
ReferênciaVexDay Proof
Web//News 1.4 - 'parser.php' Remote File Inclusion (1)
CVE-2006-5100webappsphp
PHP remote file inclusion vulnerability in parse/parser.php in WEB//NEWS (aka webnews) 1.4 and earlier allows remote att
23RISCO
abrir
ReferênciaVexDay Proof
Site@School 2.4.10 - Blind SQL Injection
CVE-2008-0129webappsphp
SQL injection vulnerability in starnet/addons/slideshow_full.php in Site@School 2.3.10 and earlier allows remote attacke
23RISCO
abrir
ReferênciaVexDay Proof
Tribisur 2.0 - SQL Injection
CVE-2008-0133webappsphp
Multiple SQL injection vulnerabilities in Tribisur 2.1 and earlier allow remote attackers to execute arbitrary SQL comma
23RISCO
abrir
ReferênciaVexDay Proof
DivX Player 6.6.0 - ActiveX 'SetPassword()' Denial of Service (PoC)
CVE-2008-0090doswindows
A certain ActiveX control in npUpload.dll in DivX Player 6.6.0 allows remote attackers to cause a denial of service (Int
28RISCO
abrir
ReferênciaVexDay Proof
MyPHP Forum 3.0 - 'Final' SQL Injection
CVE-2008-0099webappsphp
Multiple SQL injection vulnerabilities in MyPHP Forum 3.0 and earlier allow remote attackers to execute arbitrary SQL co
23RISCO
abrir
ReferênciaVexDay Proof
Microsoft Office 2003 - '.wps' Local Stack Overflow (MS08-011)
CVE-2008-0108localwindows
Stack-based buffer overflow in wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Wor
35RISCO
abrir
ReferênciaVexDay Proof
LoudBlog 0.6.1 - 'parsedpage' Remote Code Execution
CVE-2008-0139webappsphp
Eval injection vulnerability in loudblog/inc/parse_old.php in Loudblog 0.8.0 and earlier allows remote attackers to exec
28RISCO
abrir
ReferênciaVexDay Proof
WebPortal CMS 0.6-beta - Remote Password Change
CVE-2008-0142webappsphp
Multiple SQL injection vulnerabilities in WebPortal CMS 0.6-beta allow remote attackers to execute arbitrary SQL command
23RISCO
abrir
ReferênciaVexDay Proof
phpMyWebmin 1.0 - 'window.php' Remote File Inclusion
CVE-2006-5124webappsphp
Multiple PHP remote file inclusion vulnerabilities in Joshua Muheim phpMyWebmin 1.0 allow remote attackers to execute ar
23RISCO
abrir
ReferênciaVexDay Proof
phpMyWebmin 1.0 - 'window.php' Remote File Inclusion
CVE-2006-5125webappsphp
Directory traversal vulnerability in window.php, possibly used by home.php, in Joshua Muheim phpMyWebmin 1.0 allows remo
23RISCO
abrir
ReferênciaVexDay Proof
SmallNuke 2.0.4 - Pass Recovery SQL Injection
CVE-2008-0147webappsphp
SQL injection vulnerability in index.php in SmallNuke 2.0.4 and earlier, when magic_quotes_gpc is disabled, allows remot
23RISCO
abrir
ReferênciaVexDay Proof
OpenSSL 0.9.8c-1 < 0.9.8g-9 (Debian and Derivatives) - Predictable PRNG Brute Force SSH
CVE-2008-0166remotelinux
OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that ge
45RISCO
abrir
ReferênciaVexDay Proof
OpenSSL 0.9.8c-1 < 0.9.8g-9 (Debian and Derivatives) - Predictable PRNG Brute Force SSH
CVE-2008-0166remotelinux
OpenSSL 0.9.8c-1 up to versions before 0.9.8g-9 on Debian-based operating systems uses a random number generator that ge
45RISCO
abrir
ReferênciaVexDay Proof
NetRisk 1.9.7 - Cross-Site Scripting / SQL Injection
CVE-2008-0185webappsphp
SQL injection vulnerability in index.php in NetRisk 1.9.7 and possibly earlier versions allows remote attackers to execu
23RISCO
abrir
ReferênciaVexDay Proof
samPHPweb 4.2.2 - 'songinfo.php' SQL Injection
CVE-2008-0187webappsphp
SQL injection vulnerability in songinfo.php in SAM Broadcaster samPHPweb, possibly 4.2.2 and earlier, allows remote atta
23RISCO
abrir
anteriorpágina 107 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.