Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.794exploits catalogados
36.057CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
Yourownbux 3.1/3.2 Beta - SQL Injection
CVE-2008-4093webappsphp
SQL injection vulnerability in memberstats.php in YourOwnBux 3.1 and 3.2 beta, when magic_quotes_gpc is disabled, allows
23RISCO
abrir
ReferênciaVexDay Proof
Microsoft Windows - 'WRITE_ANDX' SMB Command Handling Kernel Denial of Service (Metasploit)
CVE-2008-4114doswindows
srv.sys in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1
50RISCO
abrir
ReferênciaVexDay Proof
Zeeways ZeeJobsite 2.0 - Arbitrary File Upload
CVE-2008-6913webappsphp
Unrestricted file upload vulnerability in editresume_next.php in Zeeways ZEEJOBSITE 2.0 allows remote authenticated user
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component Content 1.0.0 - 'itemID' SQL Injection
CVE-2008-6923webappsphp
SQL injection vulnerability in the content component (com_content) 1.0.0 for Joomla! allows remote attackers to execute
23RISCO
abrir
ReferênciaVexDay Proof
Nokia e90/n82 (s60v3) - Remote Denial of Service
CVE-2008-4135doshardware
Symbian OS S60 3rd edition on the Nokia E90 Communicator 07.40.1.2 Ra-6 and Nseries N82 allows remote attackers to cause
23RISCO
abrir
ReferênciaVexDay Proof
The Personal FTP Server 6.0f - RETR Denial of Service
CVE-2008-4136doswindows
Michael Roth Software Personal FTP Server (PFT) 6.0f allows remote attackers to cause a denial of service (service crash
23RISCO
abrir
ReferênciaVexDay Proof
X10media Mp3 Search Engine 1.5.5 - Remote File Inclusion
CVE-2008-4141webappsphp
Multiple PHP remote file inclusion vulnerabilities in x10Media x10 Automatic MP3 Script 1.5.5 allow remote attackers to
23RISCO
abrir
ReferênciaVexDay Proof
E-PHP CMS - 'article.php' SQL Injection
CVE-2008-4142webappsphp
SQL injection vulnerability in article.php in E-Php CMS allows remote attackers to execute arbitrary SQL commands via th
23RISCO
abrir
ReferênciaVexDay Proof
addalink 4 - 'category_id' SQL Injection
CVE-2008-4145webappsphp
SQL injection vulnerability in user_read_links.php in Addalink 1.0 beta 4 and earlier, when magic_quotes_gpc is disabled
23RISCO
abrir
ReferênciaVexDay Proof
Diesel Joke Site - 'picture_category.php' SQL Injection
CVE-2008-4150webappsphp
SQL injection vulnerability in picture_category.php in Diesel Joke Site allows remote attackers to execute arbitrary SQL
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component mosmedia 1.0.8 - Remote File Inclusion
CVE-2007-2043webappsphp
Multiple PHP remote file inclusion vulnerabilities in the Avant-Garde Solutions MOSMedia (com_mosmedia) 1.08 and earlier
23RISCO
abrir
ReferênciaVexDay Proof
CYASK 3.x - 'neturl' Local File Disclosure
CVE-2008-4151webappsphp
Directory traversal vulnerability in collect.php in CYASK 3.x allows remote attackers to read arbitrary files via a .. (
23RISCO
abrir
ReferênciaVexDay Proof
CustomCMS 4.0 - 'print.php' SQL Injection
CVE-2008-4156webappsphp
SQL injection vulnerability in print.php in CustomCms (CCMS) Gaming Portal 4.0, when magic_quotes_gpc is disabled, allow
23RISCO
abrir
ReferênciaVexDay Proof
Zanfi CMS lite / Jaw Portal free - 'page' SQL Injection
CVE-2008-4159webappsphp
SQL injection vulnerability in index.php in Jaw Portal and Zanfi CMS lite and allows remote attackers to execute arbitra
23RISCO
abrir
ReferênciaVexDay Proof
Collabtive 0.4.8 - Cross-Site Scripting / Authentication Bypass / Arbitrary File Upload
CVE-2008-6947webappsphp
Collabtive 0.4.8 allows remote attackers to bypass authentication and create new users, including administrators, via un
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component com_pcchess - Blind SQL Injection
CVE-2009-0379webappsphp
SQL injection vulnerability in the Prince Clan Chess Club (com_pcchess) component for Joomla! allows remote attackers to
23RISCO
abrir
ReferênciaVexDay Proof
iScripts EasyIndex - 'produid' SQL Injection
CVE-2008-4169webappsphp
SQL injection vulnerability in detaillist.php in iScripts EasyIndex, possibly 1.0, allows remote attackers to execute ar
23RISCO
abrir
ReferênciaVexDay Proof
ProArcadeScript 1.3 - 'random' SQL Injection
CVE-2008-4173webappsphp
SQL injection vulnerability in ProArcadeScript 1.3 allows remote attackers to execute arbitrary SQL commands via the ran
23RISCO
abrir
ReferênciaVexDay Proof
Pre Real Estate Listings - 'search.php' SQL Injection
CVE-2008-4177webappsphp
SQL injection vulnerability in search.php in Pre Real Estate Listings allows remote attackers to execute arbitrary SQL c
23RISCO
abrir
ReferênciaVexDay Proof
XAMPP for Windows 1.6.0a - 'mssql_connect()' Remote Buffer Overflow
CVE-2007-2080remotewindows
Multiple SQL injection vulnerabilities in XAMPP 1.6.0a for Windows allow remote attackers to execute arbitrary SQL comma
23RISCO
abrir
ReferênciaVexDay Proof
Discuz! 6.x/7.x - Remote Code Execution
CVE-2008-6958webappsphp
wap/index.php in Crossday Discuz! Board 6.x and 7.x allows remote authenticated users to execute arbitrary PHP code via
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! / Mambo Component New Article 1.1 - Remote File Inclusion
CVE-2007-2089webappsphp
Multiple PHP remote file inclusion vulnerabilities in the Jx Development Article 1.1 and earlier component for Mambo and
23RISCO
abrir
ReferênciaVexDay Proof
Downline Goldmine Category Addon - SQL Injection
CVE-2008-4178webappsphp
SQL injection vulnerability in tr.php in DownlineGoldmine Special Category Addon, Downline Builder Pro, New Addon, and D
23RISCO
abrir
ReferênciaVexDay Proof
PHP infoBoard 7 - Plus Insecure Cookie Handling
CVE-2008-4334webappsphp
PHP infoBoard V.7 Plus allows remote attackers to bypass authentication and gain administrative access by setting the in
23RISCO
abrir
ReferênciaVexDay Proof
Talkback 2.3.6 - Multiple Local File Inclusion / PHPInfo Disclosure Vulnerabilities
CVE-2008-4346webappsphp
Directory traversal vulnerability in TalkBack 2.3.6 and 2.3.6.4 allows remote attackers to include and execute arbitrary
23RISCO
abrir
ReferênciaVexDay Proof
pNews 2.03 - 'newsid' SQL Injection
CVE-2008-4347webappsphp
SQL injection vulnerability in newskom.php in Powie pNews 2.03 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
ReferênciaVexDay Proof
phpsmartcom 0.2 - Local File Inclusion / SQL Injection
CVE-2008-4352webappsphp
SQL injection vulnerability in inc/pages/viewprofile.php in phpSmartCom 0.2 allows remote attackers to execute arbitrary
23RISCO
abrir
ReferênciaVexDay Proof
iBoutique 4.0 - 'cat' SQL Injection
CVE-2008-4354webappsphp
SQL injection vulnerability in the products module in NetArt Media iBoutique 4.0 allows remote attackers to execute arbi
23RISCO
abrir
ReferênciaVexDay Proof
pForum 1.30 - 'showprofil.php' SQL Injection
CVE-2008-4355webappsphp
SQL injection vulnerability in showprofil.php in Powie PSCRIPT Forum (aka PHP Forum or pForum) 1.30 and earlier allows r
23RISCO
abrir
ReferênciaVexDay Proof
DESlock+ < 3.2.7 - 'probe read' Local Kernel Denial of Service (PoC)
CVE-2008-4363doswindows
DLMFENC.sys 1.0.0.28 in DESlock+ 3.2.7 allows local users to cause a denial of service (system crash) or potentially exe
23RISCO
abrir
anteriorpágina 11 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.