Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.230exploits catalogados
36.424CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
Butterfly ORGanizer 2.0.1 - 'id' SQL Injection
CVE-2008-6328webappsphp
SQL injection vulnerability in view.php in Butterfly Organizer 2.0.0 and 2.0.1 allows remote attackers to execute arbitr
23RISCO
abrir
ReferênciaVexDay Proof
Backup Exec System Recovery Manager 7.0.1 - Arbitrary File Upload
CVE-2008-0457remotewindows
Unrestricted file upload vulnerability in the FileUpload class running on the Symantec LiveState Apache Tomcat server, a
28RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component ProDesk 1.0/1.2 - Local File Inclusion
CVE-2008-6222webappsphp
Directory traversal vulnerability in the Pro Desk Support Center (com_pro_desk) component 1.0 and 1.2 for Joomla! allows
43RISCO
abrir
ReferênciaVexDay Proof
Corel Paint Shop Pro Photo 11.20 - '.clp' Local Buffer Overflow
CVE-2007-2209localwindows
Buffer overflow in igcore15d.dll 15.1.2.0 and 15.2.0.0 for AccuSoft ImageGear, as used in Corel Paint Shop Pro Photo 11.
28RISCO
abrir
ReferênciaVexDay Proof
Text Lines Rearrange Script - 'Filename' File Disclosure
CVE-2008-6336webappsphp
Directory traversal vulnerability in download.php in Text Lines Rearrange Script 1.0, when register_globals is enabled,
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component com_noticias 1.0 - SQL Injection
CVE-2008-0670webappsphp
SQL injection vulnerability in index.php in the Noticias (com_noticias) 1.0 component for Joomla! allows remote attacker
23RISCO
abrir
ReferênciaVexDay Proof
Black Ice Software Annotation Plugin - 'BiAnno.ocx' Remote Buffer Overflow
CVE-2008-2745remotewindows
Stack-based buffer overflow in BiAnno ActiveX Control (BiAnno.ocx) in Black Ice Software Annotation Plugin 10.95 allows
28RISCO
abrir
ReferênciaVexDay Proof
BXCP 0.2.9.9 - 'tid' SQL Injection
CVE-2006-0821webappsphp
SQL injection vulnerability in index.php in BXCP 0.299 allows remote attackers to execute arbitrary SQL commands via the
23RISCO
abrir
ReferênciaVexDay Proof
TurnkeyForms Business Survey Pro 1.0 - 'id' SQL Injection
CVE-2008-6349webappsphp
SQL injection vulnerability in survey_results_text.php in TurnkeyForms Business Survey Pro 1.0 allows remote attackers t
23RISCO
abrir
ReferênciaVexDay Proof
Online Media Technologies 'AVSMJPEGFILE.DLL 1.1' - Remote Buffer Overflow (PoC)
CVE-2007-6327doswindows
Buffer overflow in a certain ActiveX control in Online Media Technologies AVSMJPEGFILE.DLL 1.1.1.102 allows remote attac
28RISCO
abrir
ReferênciaVexDay Proof
ASP-CMS 1.0 - 'cha' SQL Injection
CVE-2008-6353webappsasp
SQL injection vulnerability in index.asp in ASP-CMS 1.0 allows remote attackers to execute arbitrary SQL commands via th
23RISCO
abrir
ReferênciaVexDay Proof
Oracle Internet Directory 10.1.4 - Remote Denial of Service
CVE-2008-2595dosmultiple
Unspecified vulnerability in the Oracle Internet Directory component in Oracle Application Server 9.0.4.3, 10.1.2.3, and
28RISCO
abrir
ReferênciaVexDay Proof
WordPress Plugin st_newsletter - SQL Injection
CVE-2008-0683webappsphp
SQL injection vulnerability in shiftthis-preview.php in the ShiftThis Newsletter (st_newsletter) plugin for WordPress al
23RISCO
abrir
ReferênciaVexDay Proof
evCal Events Calendar - Database Disclosure
CVE-2008-6356webappsasp
evCal Events Calendar stores sensitive information under the web root with insufficient access control, which allows rem
23RISCO
abrir
ReferênciaVexDay Proof
Ad Management Java - Authentication Bypass
CVE-2008-6365webappsasp
SQL injection vulnerability in logon.jsp in Ad Server Solutions Ad Management Software Java allows remote attackers to e
23RISCO
abrir
ReferênciaVexDay Proof
ITechBids 5.0 - 'item_id' SQL Injection
CVE-2008-0692webappsphp
SQL injection vulnerability in bidhistory.php in iTechBids 3 Gold and 5.0 allows remote attackers to execute arbitrary S
23RISCO
abrir
ReferênciaVexDay Proof
Multi SEO phpBB 1.1.0 - Remote File Inclusion
CVE-2008-6377webappsphp
PHP remote file inclusion vulnerability in include/global.php in Multi SEO phpBB 1.1.0 allows remote attackers to execut
23RISCO
abrir
ReferênciaVexDay Proof
Quick Tree View .NET 3.1 - Database Disclosure
CVE-2008-6387webappsphp
Quick Tree View .NET 3.1 stores sensitive information under the web root with insufficient access control, which allows
23RISCO
abrir
ReferênciaVexDay Proof
Rapid Classified 3.1 - Database Disclosure
CVE-2008-6388webappsphp
Rapid Classified 3.1 and 3.15 stores sensitive information under the web root with insufficient access control, which al
23RISCO
abrir
ReferênciaVexDay Proof
Mambo Component com_gallery - SQL Injection
CVE-2008-0746webappsphp
SQL injection vulnerability in index.php in the Gallery (com_gallery) component for Mambo and Joomla! allows remote atta
23RISCO
abrir
ReferênciaVexDay Proof
HotScripts Clone - 'cid' SQL Injection
CVE-2008-6405webappsphp
SQL injection vulnerability in showcategory.php in Hotscripts Clone allows remote attackers to execute arbitrary SQL com
23RISCO
abrir
ReferênciaVexDay Proof
docpile:we 0.2.2 - 'INIT_PATH' Remote File Inclusion
CVE-2006-4075webappsphp
Multiple PHP remote file inclusion vulnerabilities in Wim Fleischhauer docpile: wim's edition (docpile:we) 0.2.2 and ear
28RISCO
abrir
ReferênciaVexDay Proof
GdPicture Pro - ActiveX 'gdpicture4s.ocx' File Overwrite / Exec
CVE-2008-4453remotewindows
The GdPicture (1) Light Imaging Toolkit 4.7.1 GdPicture4S.Imaging ActiveX control (gdpicture4s.ocx) 4.7.0.1 and (2) Pro
28RISCO
abrir
ReferênciaVexDay Proof
Social Site Generator 2.0 - 'sgc_id' SQL Injection
CVE-2008-6419webappsphp
Multiple SQL injection vulnerabilities in Social Site Generator (SSG) 2.0 allow remote attackers to execute arbitrary SQ
23RISCO
abrir
ReferênciaVexDay Proof
Social Site Generator 2.0 - Multiple Remote File Disclosure Vulnerabilities
CVE-2008-6420webappsphp
Social Site Generator (SSG) 2.0 allows remote attackers to read arbitrary files via the file parameter to (1) filedload.
23RISCO
abrir
ReferênciaVexDay Proof
Pagode 0.5.8 - 'navigator_ok.php?asolute' Remote File Disclosure
CVE-2007-2200webappsphp
Directory traversal vulnerability in navigator/navigator_ok.php in Pagode 0.5.8 allows remote attackers to read and poss
28RISCO
abrir
ReferênciaVexDay Proof
Sun jre1.6.0_X - isInstalled.dnsResolve Function Overflow
CVE-2007-5019dosmultiple
Buffer overflow in the Sun Java Web Start ActiveX control in Java Runtime Environment (JRE) 1.6.0_X allows remote attack
28RISCO
abrir
ReferênciaVexDay Proof
Linux Kernel 2.6.21.1 - IPv6 Jumbo Bug Remote Denial of Service
CVE-2008-0352doslinux
The Linux kernel 2.6.20 through 2.6.21.1 allows remote attackers to cause a denial of service (panic) via a certain IPv6
28RISCO
abrir
ReferênciaVexDay Proof
sflog! 0.96 - Remote File Disclosure
CVE-2008-0703webappsphp
Multiple directory traversal vulnerabilities in sflog! 0.96 allow remote attackers to read arbitrary files via a .. (dot
23RISCO
abrir
ReferênciaVexDay Proof
BloofoxCMS 0.3.4 - 'lang' Local File Inclusion
CVE-2008-5748webappsphp
Directory traversal vulnerability in plugins/spaw2/dialogs/dialog.php in BloofoxCMS 0.3.4 allows remote attackers to rea
28RISCO
abrir
anteriorpágina 124 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.