Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.226exploits catalogados
36.422CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
BaoFeng2 - 'mps.dll' ActiveX Multiple Remote Buffer Overflows (PoC)
CVE-2007-4816doswindows
Multiple buffer overflows in the BaoFeng2 storm ActiveX control in Mps.dll allow remote attackers to have an unknown imp
23RISCO
abrir
ReferênciaVexDay Proof
X-Cart - Multiple Remote File Inclusions
CVE-2007-4907webappsphp
Multiple PHP remote file inclusion vulnerabilities in X-Cart allow remote attackers to execute arbitrary PHP code via a
23RISCO
abrir
ReferênciaVexDay Proof
JetCast Server 2.0.0.4308 - Remote Denial of Service
CVE-2007-4911doswindows
JSMP3OGGWt.dll in JetCast Server 2.0.0.4308 allows remote attackers to cause a denial of service (daemon crash) via a lo
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component joom12pic 1.0 - Remote File Inclusion
CVE-2007-4954webappsphp
PHP remote file inclusion vulnerability in admin.joom12pic.php in the joom12Pic (com_joom12pic) 1.0 component for Joomla
28RISCO
abrir
ReferênciaVexDay Proof
KwsPHP 1.0 - 'login.php' SQL Injection
CVE-2007-4956webappsphp
Multiple SQL injection vulnerabilities in KwsPHP 1.0 allow remote attackers to execute arbitrary SQL commands via (1) th
23RISCO
abrir
ReferênciaVexDay Proof
Chupix CMS 0.2.3 - 'download.php' Remote File Disclosure
CVE-2007-4957webappsphp
Multiple directory traversal vulnerabilities in download.php in Chupix CMS 0.2.3 allow remote attackers to read or overw
23RISCO
abrir
ReferênciaVexDay Proof
Xforum 1.4 - 'topic' SQL Injection
CVE-2008-0279webappsphp
SQL injection vulnerability in liretopic.php in Xforum 1.4 and possibly others allows remote attackers to execute arbitr
23RISCO
abrir
ReferênciaVexDay Proof
DomPHP 0.81 - Remote Add Administrator
CVE-2008-0282webappsphp
SQL injection vulnerability in welcome/inscription.php in DomPHP 0.81 and earlier allows remote attackers to execute arb
23RISCO
abrir
ReferênciaVexDay Proof
Foojan Wms 1.0 - 'story' SQL Injection
CVE-2008-0447webappsphp
SQL injection vulnerability in index.php in Foojan WMS PHP Weblog 1.0 allows remote attackers to execute arbitrary SQL c
23RISCO
abrir
ReferênciaVexDay Proof
Easysitenetwork Recipe - 'categoryId' SQL Injection
CVE-2008-0453webappsphp
SQL injection vulnerability in list.php in Easysitenetwork Recipe allows remote attackers to execute arbitrary SQL comma
23RISCO
abrir
ReferênciaVexDay Proof
Liquid-Silver CMS 0.1 - 'update' Local File Inclusion
CVE-2008-0459webappsphp
Directory traversal vulnerability in update/index.php in Liquid-Silver CMS 0.35, when magic_quotes_gpc is disabled, allo
23RISCO
abrir
ReferênciaVexDay Proof
OneCMS 2.4 - 'abc' SQL Injection
CVE-2007-5016webappsphp
SQL injection vulnerability in userreviews.php in OneCMS 2.4 allows remote attackers to execute arbitrary SQL commands v
23RISCO
abrir
ReferênciaVexDay Proof
Airsensor M520 - HTTPd Remote Denial of Service / Buffer Overflow (PoC)
CVE-2007-5036doshardware
Multiple buffer overflows in the AirDefense Airsensor M520 with firmware 4.3.1.1 and 4.4.1.4 allow remote authenticated
23RISCO
abrir
ReferênciaVexDay Proof
neuron news 1.0 - 'index.php?q' Local File Inclusion
CVE-2007-5050webappsphp
Directory traversal vulnerability in index.php in Neuron News 1.0 allows remote attackers to include and execute arbitra
23RISCO
abrir
ReferênciaVexDay Proof
ActiveKB KnowledgeBase 2.x - 'catId' SQL Injection
CVE-2007-5131webappsphp
SQL injection vulnerability in index.php in Interspire ActiveKB NX 2.x allows remote attackers to execute arbitrary SQL
23RISCO
abrir
ReferênciaVexDay Proof
Mambo Component com_downloads - SQL Injection
CVE-2008-0652webappsphp
SQL injection vulnerability in index.php in the Downloads (com_downloads) component for Mambo and Joomla! allows remote
23RISCO
abrir
ReferênciaVexDay Proof
FaceBook PhotoUploader - 'ImageUploader4.ocx 4.5.57.0' Remote Buffer Overflow
CVE-2008-0660remotewindows
Multiple stack-based buffer overflows in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.6.17.0, 4.5.70.0,
35RISCO
abrir
ReferênciaVexDay Proof
The Everything Development System Pre-1.0 - SQL Injection
CVE-2008-0675webappsphp
SQL injection vulnerability in cms/index.pl in The Everything Development Engine in The Everything Development System Pr
23RISCO
abrir
ReferênciaVexDay Proof
FSFDT v3.000 d9 - 'HELP' Remote Buffer Overflow
CVE-2007-5256remotewindows
Multiple stack-based buffer overflows in FSD 2.052 d9 and earlier, and FSFDT FSD 3.000 d9 and earlier, allow (1) remote
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component com_Marketplace 1.1.1 - SQL Injection
CVE-2008-0689webappsphp
SQL injection vulnerability in index.php in the Marketplace (com_marketplace) 1.1.1 and 1.1.1-pl1 component for Joomla!
23RISCO
abrir
ReferênciaVexDay Proof
BookmarkX script 2007 - 'topicid' SQL Injection
CVE-2008-0695webappsphp
SQL injection vulnerability in index.php in BookmarkX script 2007 allows remote attackers to execute arbitrary SQL comma
23RISCO
abrir
ReferênciaVexDay Proof
ImageStation - 'SonyISUpload.cab 1.0.0.38' ActiveX Buffer Overflow (PoC)
CVE-2008-0748doswindows
Buffer overflow in the Sony AxRUploadServer.AxRUploadControl.1 ActiveX control in AxRUploadServer.dll 1.0.0.38 in SonyIS
28RISCO
abrir
ReferênciaVexDay Proof
1024 CMS 1.4.2 - Local File Inclusion / Blind SQL Injection
CVE-2008-1911webappsphp
SQL injection vulnerability in includes/system.php in 1024 CMS 1.4.2 beta and earlier, when magic_quotes_gpc is disabled
23RISCO
abrir
ReferênciaVexDay Proof
Smeego 1.0 - 'Cookie lang' Local File Inclusion
CVE-2008-2352webappsphp
Directory traversal vulnerability in index.php in Smeego 1.0, when magic_quotes_gpc is disabled, allows remote attackers
23RISCO
abrir
ReferênciaVexDay Proof
Archangel Weblog 0.90.02 - 'post_id' SQL Injection
CVE-2008-2356webappsphp
SQL injection vulnerability in index.php in Archangel Weblog 0.90.02 and earlier allows remote attackers to execute arbi
23RISCO
abrir
ReferênciaVexDay Proof
Flatnuke 3 - Remote Cookie Manipulation / Privilege Escalation
CVE-2007-5771webappsphp
Flatnuke 3 (aka FlatnuX) allows remote attackers to obtain administrative access via a myforum%00 cookie.
23RISCO
abrir
ReferênciaVexDay Proof
Flatnuke 3 - Remote Command Execution / Privilege Escalation
CVE-2007-5773webappsphp
Cross-site request forgery (CSRF) vulnerability in index.php in the File Manager module in Flatnuke 3 allows remote atta
23RISCO
abrir
ReferênciaVexDay Proof
1Book Guestbook Script 1.0.1 - Code Execution
CVE-2008-2638webappsphp
Static code injection vulnerability in guestbook.php in 1Book 1.0.1 and earlier allows remote attackers to upload arbitr
23RISCO
abrir
ReferênciaVexDay Proof
emagiC CMS.Net 4.0 - 'emc.asp' SQL Injection
CVE-2007-5783webappsasp
SQL injection vulnerability in emc.asp in emagiC CMS.Net 4.0 allows remote attackers to execute arbitrary SQL commands v
23RISCO
abrir
ReferênciaVexDay Proof
CaupoShop Pro 2.x - 'action' Remote File Inclusion
CVE-2007-5784webappsphp
PHP remote file inclusion vulnerability in index.php in CaupoShop Pro 2.x allows remote attackers to execute arbitrary P
23RISCO
abrir
anteriorpágina 116 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.