Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.230exploits catalogados
36.424CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
ASP AutoDealer - Remote Database Disclosure
CVE-2008-5608webappsasp
ASP AutoDealer stores sensitive information under the web root with insufficient access control, which allows remote att
23RISCO
abrir
ReferênciaVexDay Proof
Microsoft Visual Studio 6.0 - 'PDWizard.ocx' Remote Command Execution
CVE-2007-4891remotewindows
A certain ActiveX control in PDWizard.ocx 6.0.0.9782 and earlier in Microsoft Visual Studio 6.0 exposes dangerous (1) St
35RISCO
abrir
ReferênciaVexDay Proof
GuppY 4.6.3 - 'index.php?selskin' Remote File Inclusion
CVE-2007-5844webappsphp
Directory traversal vulnerability in inc/includes.inc in GuppY 4.6.3 allows remote attackers to include and execute arbi
23RISCO
abrir
ReferênciaVexDay Proof
ASP AutoDealer - SQL Injection / File Disclosure
CVE-2008-5608webappsasp
ASP AutoDealer stores sensitive information under the web root with insufficient access control, which allows remote att
23RISCO
abrir
ReferênciaVexDay Proof
XOOPS Module XT-Conteudo - 'spaw_root' Remote File Inclusion
CVE-2007-3221webappsphp
PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the XT-Conteudo module for XOOPS allows
35RISCO
abrir
ReferênciaVexDay Proof
WholeHogSoftware Ware Support - Insecure Cookie Handling
CVE-2009-0460webappsphp
Whole Hog Ware Support 1.x allows remote attackers to bypass authentication and obtain administrative access via an inte
23RISCO
abrir
ReferênciaVexDay Proof
PHP::HTML 0.6.4 - 'PHPhtml.php' Remote File Inclusion
CVE-2007-3230webappsphp
PHP remote file inclusion vulnerability in phphtml.php in Idan Sofer PHP::HTML 0.6.4 allows remote attackers to execute
35RISCO
abrir
ReferênciaVexDay Proof
virtue news - SQL Injection / Cross-Site Scripting
CVE-2009-2020webappsphp
Cross-site scripting (XSS) vulnerability in news_detail.php in Virtue News Manager allows remote attackers to inject arb
23RISCO
abrir
ReferênciaVexDay Proof
GuppY 4.5.16 - Remote Command Execution
CVE-2007-5845webappsphp
Directory traversal vulnerability in error.php in GuppY 4.6.3, 4.5.16, and earlier allows remote attackers to include an
23RISCO
abrir
ReferênciaVexDay Proof
Fuzzylime Forum 1.0 - 'low.php?topic' SQL Injection
CVE-2007-3235webappsphp
Cross-site scripting (XSS) vulnerability in low.php in Fuzzylime Forum 1.0 allows remote attackers to inject arbitrary w
23RISCO
abrir
ReferênciaVexDay Proof
XOOPS Module horoscope 2.0 - Remote File Inclusion
CVE-2007-3236webappsphp
PHP remote file inclusion vulnerability in footer.php in the Horoscope 1.0 module for XOOPS allows remote attackers to e
45RISCO
abrir
ReferênciaVexDay Proof
Microsoft Windows Mobile 6.0 - Device Long Name Remote Reboot (Denial of Service)
CVE-2008-4295doshardware
Microsoft Windows Mobile 6.0 on HTC Wiza 200 and HTC MDA 8125 devices does not properly handle the first attempt to esta
35RISCO
abrir
ReferênciaVexDay Proof
Profense Web Application Firewall 2.6.2 - Cross-Site Request Forgery / Cross-Site Scripting
CVE-2009-0467remotewindows
Cross-site scripting (XSS) vulnerability in proxy.html in Profense Web Application Firewall 2.6.2 and 2.6.3 allows remot
23RISCO
abrir
ReferênciaVexDay Proof
xoops module tinycontent 1.5 - Remote File Inclusion
CVE-2007-3237webappsphp
PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the TinyContent 1.5 module for XOOPS all
35RISCO
abrir
ReferênciaVexDay Proof
tbdev 01-01-2008 - Multiple Vulnerabilities
CVE-2009-2138webappsphp
Multiple open redirect vulnerabilities in TBDev.NET 01-01-08 allow remote attackers to redirect users to arbitrary web s
23RISCO
abrir
ReferênciaVexDay Proof
Roundcube Webmail 0.2-3 Beta - Code Execution
CVE-2008-5619webappsphp
html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail)
35RISCO
abrir
ReferênciaVexDay Proof
XM Easy Personal FTP Server 5.6.0 - Remote Denial of Service
CVE-2008-5626doswindows
XM Easy Personal FTP Server 5.6.0 allows remote authenticated users to cause a denial of service via a crafted argument
50RISCO
abrir
ReferênciaVexDay Proof
PHPMyInventory 2.8 - 'global.inc.php' Remote File Inclusion
CVE-2007-3270webappsphp
PHP remote file inclusion vulnerability in Includes/global.inc.php in phpMyInventory 2.8 allows remote attackers to exec
23RISCO
abrir
ReferênciaVexDay Proof
campus virtual-lms - Cross-Site Scripting / SQL Injection
CVE-2009-2150webappsphp
Multiple cross-site request forgery (CSRF) vulnerabilities in Campus Virtual-LMS allow (1) remote attackers to hijack th
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component flash fun! 1.0 - Remote File Inclusion
CVE-2007-4955webappsphp
PHP remote file inclusion vulnerability in admin.joomlaflashfun.php in the Flash Fun! (com_joomlaflashfun) 1.0 component
28RISCO
abrir
ReferênciaVexDay Proof
PHPCOIN 1.2.3 - 'session_set.php' Remote File Inclusion
CVE-2006-4424webappsphp
PHP remote file inclusion vulnerability in coin_includes/constants.php in phpCOIN 1.2.3 allows remote attackers to execu
23RISCO
abrir
ReferênciaVexDay Proof
Microsoft Office - MSODataSourceControl COM-object Buffer Overflow (PoC)
CVE-2007-3282doswindows
Buffer overflow in the Microsoft Office MSODataSourceControl ActiveX object allows remote attackers to cause a denial of
35RISCO
abrir
ReferênciaVexDay Proof
XOOPS Module wiwimod 0.4 - Remote File Inclusion
CVE-2007-3289webappsphp
PHP remote file inclusion vulnerability in spaw/spaw_control.class.php in the WiwiMod 0.4 module for XOOPS allows remote
28RISCO
abrir
ReferênciaVexDay Proof
LiveCMS 3.4 - 'categoria.php?cid' SQL Injection
CVE-2007-3290webappsphp
categoria.php in LiveCMS 3.4 and earlier allows remote attackers to obtain sensitive information via a ' (quote) charact
23RISCO
abrir
ReferênciaVexDay Proof
Active Trade 2 - Authentication Bypass
CVE-2008-5627webappsasp
SQL injection vulnerability in account.asp in Active Trade 2 allows remote attackers to execute arbitrary SQL commands v
23RISCO
abrir
ReferênciaVexDay Proof
LiveCMS 3.4 - 'categoria.php?cid' SQL Injection
CVE-2007-3292webappsphp
Unrestricted file upload vulnerability in LiveCMS 3.4 and earlier allows remote attackers to upload and execute arbitrar
23RISCO
abrir
ReferênciaVexDay Proof
MiniBill 1.2.5 - 'run_billing.php' Remote File Inclusion
CVE-2007-3306webappsphp
PHP remote file inclusion vulnerability in crontab/run_billing.php in MiniBill 1.2.5 allows remote attackers to execute
35RISCO
abrir
ReferênciaVexDay Proof
Distinct TFTP 3.10 - Writable Directory Traversal Execution (Metasploit)
CVE-2012-6664CRITICALwebappswindows
Multiple directory traversal vulnerabilities in the TFTP Server in Distinct Intranet Servers 3.10 and earlier allow remo
68RISCO
abrir
ReferênciaVexDay Proof
CMS little 0.0.1 - 'term' SQL Injection
CVE-2008-5628webappsphp
SQL injection vulnerability in index.php in CMS little 0.0.1 allows remote attackers to execute arbitrary SQL commands v
23RISCO
abrir
ReferênciaVexDay Proof
AdaptCMS Lite 1.4 - Cross-Site Scripting / Remote File Inclusion
CVE-2009-0527webappsphp
PHP remote file inclusion vulnerability in plugins/rss_importer_functions.php in AdaptCMS Lite 1.4 allows remote attacke
23RISCO
abrir
anteriorpágina 129 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.