Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.230exploits catalogados
36.424CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
HydraIrc 0.3.164 - Remote Denial of Service
CVE-2008-3578doswindows
HydraIRC 0.3.164 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and applicat
23RISCO
abrir
ReferênciaVexDay Proof
BabbleBoard 1.1.6 - Cross-Site Request Forgery/Cookie Grabber
CVE-2008-6905webappsphp
Cross-site request forgery (CSRF) vulnerability in index.php in BabbleBoard 1.1.6 allows remote authenticated users to h
23RISCO
abrir
ReferênciaVexDay Proof
Quantum Game Library 0.7.2c - Remote File Inclusion
CVE-2008-1069webappsphp
Multiple PHP remote file inclusion vulnerabilities in Quantum Game Library 0.7.2c allow remote attackers to execute arbi
28RISCO
abrir
ReferênciaVexDay Proof
zeeproperty 1.0 - Arbitrary File Upload / Cross-Site Scripting
CVE-2008-6915webappsphp
Cross-site scripting (XSS) vulnerability in view_prop_details.php in Zeeways ZEEPROPERTY 1.0 allows remote attackers to
23RISCO
abrir
ReferênciaVexDay Proof
SpeedStream 5200 - Authentication Bypass Configuration Download
CVE-2008-6916remotehardware
Siemens SpeedStream 5200 with NetPort Software 1.1 allows remote attackers to bypass authentication via an invalid Host
23RISCO
abrir
ReferênciaVexDay Proof
PHPAddressBook 2.11 - 'view.php' SQL Injection
CVE-2008-1847webappsphp
SQL injection vulnerability in view.php in CoronaMatrix phpAddressBook 2.11 allows remote attackers to execute arbitrary
23RISCO
abrir
ReferênciaVexDay Proof
RealPlayer 10 - '.ra' Remote Denial of Service
CVE-2007-2497doswindows
RealNetworks RealPlayer 10 Gold allows remote attackers to cause a denial of service (memory consumption) via a certain
23RISCO
abrir
ReferênciaVexDay Proof
PHP Multiple Newsletters 2.7 - Local File Inclusion / Cross-Site Scripting
CVE-2008-5566webappsphp
Cross-site scripting (XSS) vulnerability in index.php in Triangle Solutions PHP Multiple Newsletters 2.7 allows remote a
23RISCO
abrir
ReferênciaVexDay Proof
WordPress Plugin E-Commerce 3.4 - Arbitrary File Upload
CVE-2008-6811webappsphp
Unrestricted file upload vulnerability in image_processing.php in the e-Commerce Plugin 3.4 and earlier for Wordpress al
23RISCO
abrir
ReferênciaVexDay Proof
Alstrasoft SendIt Pro - Arbitrary File Upload
CVE-2008-6932webappsphp
Unrestricted file upload vulnerability in submit_file.php in AlstraSoft SendIt Pro allows remote attackers to execute ar
23RISCO
abrir
ReferênciaVexDay Proof
eZip Wizard 3.0 - Local Stack Buffer Overflow (PoC) (SEH)
CVE-2009-1057doswindows
MicroSmarts Enterprise ZipItFast! 3.0 allows remote attackers to execute arbitrary code via a crafted .zip file that tri
23RISCO
abrir
ReferênciaVexDay Proof
Mcafee EPO 4.0 - 'FrameworkService.exe' Remote Denial of Service
CVE-2008-1855doswindows
FrameworkService.exe in McAfee Common Management Agent (CMA) 3.6.0.574 Patch 3 and earlier, as used by ePolicy Orchestra
23RISCO
abrir
ReferênciaVexDay Proof
BS.Player 2.27 Build 959 - '.srt' File Buffer Overflow (PoC)
CVE-2008-6583doswindows
Buffer overflow in BS.player 2.27 build 959 allows remote attackers to cause a denial of service (crash) and possibly ex
23RISCO
abrir
ReferênciaVexDay Proof
RGameScript Pro - 'page.php?id' Remote File Inclusion
CVE-2007-3980webappsphp
PHP remote file inclusion vulnerability in page.php in RCMS Pro RGameScript Pro allows remote attackers to execute arbit
23RISCO
abrir
ReferênciaVexDay Proof
Pi3Web 2.0.3 - 'ISAPI' Remote Denial of Service
CVE-2008-6938doswindows
Pi3Web 2.0.3 before PL2, when installed on Windows as a desktop application and without using the Pi3Web/Conf/Intenet.pi
43RISCO
abrir
ReferênciaVexDay Proof
EasyMail MessagePrinter Object - 'emprint.dll 6.0.1.0' Remote Buffer Overflow
CVE-2007-5070remotewindows
Heap-based buffer overflow in the EasyMailMessagePrinter ActiveX control in emprint.DLL 6.0.1.0 in the Quiksoft EasyMail
23RISCO
abrir
ReferênciaVexDay Proof
P-Book 1.17 - 'pb_lang' Remote File Inclusion
CVE-2006-5667webappsphp
Multiple PHP remote file inclusion vulnerabilities in P-Book 1.17 and earlier allow remote attackers to execute arbitrar
23RISCO
abrir
ReferênciaVexDay Proof
Collabtive 0.4.8 - Cross-Site Scripting / Authentication Bypass / Arbitrary File Upload
CVE-2008-6948webappsphp
Unrestricted file upload vulnerability in Collabtive 0.4.8 allows remote authenticated users to execute arbitrary code b
23RISCO
abrir
ReferênciaVexDay Proof
Virtual DJ 5.0 - '.m3u' Local Buffer Overflow
CVE-2007-4735localwindows
Buffer overflow in Next Generation Software Virtual DJ (VDJ) 5.0 allows user-assisted remote attackers to execute arbitr
23RISCO
abrir
ReferênciaVexDay Proof
Wireshark < 0.99.5 - DNP3 Dissector Infinite Loop
CVE-2007-6113doslinux
Integer signedness error in the DNP3 dissector in Wireshark (formerly Ethereal) 0.10.12 to 0.99.6 allows remote attacker
23RISCO
abrir
ReferênciaVexDay Proof
Site Sift Listings - 'id' SQL Injection
CVE-2008-1869webappsphp
SQL injection vulnerability in Site Sift Listings allows remote attackers to execute arbitrary SQL commands via the id p
23RISCO
abrir
ReferênciaVexDay Proof
PMB Services 3.0.13 - Multiple Remote File Inclusions
CVE-2007-1415webappsphp
Multiple PHP remote file inclusion vulnerabilities in PMB Services 3.0.13 and earlier allow remote attackers to execute
23RISCO
abrir
ReferênciaVexDay Proof
Friendly Technologies - 'fwRemoteCfg.dll' ActiveX Remote Buffer Overflow
CVE-2008-4048remotewindows
Heap-based buffer overflow in a certain ActiveX control in fwRemoteCfg.dll 3.3.3.1 in Friendly Technologies FriendlyPPPo
23RISCO
abrir
ReferênciaVexDay Proof
X10media Mp3 Search Engine 1.6 - Remote File Disclosure
CVE-2008-6960webappsphp
download.php in X10media x10 Automatic Mp3 Search Engine Script 1.5.5 through 1.6 allows remote attackers to read arbitr
23RISCO
abrir
ReferênciaVexDay Proof
X7 Chat 2.0.5 - Authentication Bypass
CVE-2008-6964webappsphp
SQL injection vulnerability in the login page in X7 Chat 2.0.5 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
ReferênciaVexDay Proof
PassWiki 0.9.16 RC3 - 'site_id' Local File Inclusion
CVE-2008-6423webappsphp
Directory traversal vulnerability in passwiki.php in PassWiki 0.9.16 RC3 and earlier allows remote attackers to read arb
23RISCO
abrir
ReferênciaVexDay Proof
SkaLinks 1.5 - 'register.php' Arbitrary Add Editor
CVE-2008-7010webappsphp
Skalfa Software SkaLinks Exchange Script 1.5 allows remote attackers to add new administrators and gain privileges via a
23RISCO
abrir
ReferênciaVexDay Proof
visualpic 0.3.1 - Remote File Inclusion
CVE-2008-1876webappsphp
PHP remote file inclusion vulnerability in index.php in VisualPic 0.3.1 allows remote attackers to execute arbitrary PHP
28RISCO
abrir
ReferênciaVexDay Proof
FreshView 7.15 - '.psp' Local Buffer Overflow
CVE-2007-2283localwindows
Buffer overflow in Fresh View 7.15 allows user-assisted remote attackers to execute arbitrary code via a crafted .PSP fi
23RISCO
abrir
ReferênciaVexDay Proof
Autodesk DWF Viewer Control / LiveUpdate Module - Remote Code Execution
CVE-2008-4471remotewindows
Directory traversal vulnerability in the CExpressViewerControl class in the DWF Viewer ActiveX control (AdView.dll 9.0.0
23RISCO
abrir
anteriorpágina 123 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.