Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.230exploits catalogados
36.424CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
mxBB Module Meeting 1.1.2 - Remote File Inclusion
CVE-2006-6644webappsphp
PHP remote file inclusion vulnerability in pages/meeting_constants.php in the Meeting (mx_meeting) 1.1.2 and earlier mod
23RISCO
abrir
ReferênciaVexDay Proof
mxBB Module WebLinks 2.05 - Remote File Inclusion
CVE-2006-6645webappsphp
PHP remote file inclusion vulnerability in language/lang_english/lang_admin.php in the Web Links (mx_links) 2.05 and ear
23RISCO
abrir
ReferênciaVexDay Proof
mxbb module charts 1.0.0 - Remote File Inclusion
CVE-2006-6650webappsphp
PHP remote file inclusion vulnerability in charts_constants.php in the Charts (mx_charts) 1.0.0 and earlier module for m
23RISCO
abrir
ReferênciaVexDay Proof
Sambar FTP Server 6.4 - 'SIZE' Remote Denial of Service
CVE-2006-6624doswindows
The FTP Server in Sambar Server 6.4 allows remote authenticated users to cause a denial of service (application crash) v
23RISCO
abrir
ReferênciaVexDay Proof
Genepi 1.6 - 'genepi.php' Remote File Inclusion
CVE-2006-6632webappsphp
PHP remote file inclusion vulnerability in genepi.php in Genepi 1.6 and earlier allows remote attackers to execute arbit
23RISCO
abrir
ReferênciaVexDay Proof
JumbaCMS 0.0.1 - '/includes/functions.php' Remote File Inclusion
CVE-2006-6635webappsphp
PHP remote file inclusion vulnerability in includes/functions.php in JumbaCMS 0.0.1 allows remote attackers to execute a
23RISCO
abrir
ReferênciaVexDay Proof
PHP-Update 2.7 - 'extract()' Authentication Bypass / Shell Injection
CVE-2006-6661webappsphp
Variable overwrite vulnerability in blog.php in PHP-Update 2.7 and earlier allows remote attackers to overwrite arbitrar
23RISCO
abrir
ReferênciaVexDay Proof
Valdersoft Shopping Cart 3.0 - Multiple Remote File Inclusions
CVE-2006-6691webappsphp
Multiple PHP remote file inclusion vulnerabilities in Valdersoft Shopping Cart 3.0 and earlier allow remote attackers to
23RISCO
abrir
ReferênciaVexDay Proof
E-Uploader Pro 1.0 - Image Upload / Code Execution
CVE-2006-6694webappsphp
Directory traversal vulnerability in include/config.php in E-Uploader Pro 1.0 and earlier allows remote attackers to exe
23RISCO
abrir
ReferênciaVexDay Proof
Newxooper-PHP 0.9.1 - 'mapage.php' Remote File Inclusion
CVE-2006-6711webappsphp
PHP remote file inclusion vulnerability in compteur/mapage.php in Newxooper 0.9.1 allows remote attackers to execute arb
23RISCO
abrir
ReferênciaVexDay Proof
PowerClan 1.14a - 'footer.inc.php' Remote File Inclusion
CVE-2006-6715webappsphp
PHP remote file inclusion vulnerability in footer.inc.php in PowerClan 1.14a and earlier, when register_globals is enabl
23RISCO
abrir
ReferênciaVexDay Proof
Microsoft Windows - 'NetrWkstaUserEnum()' Remote Denial of Service
CVE-2006-6723doswindows
The Workstation service in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to cause a denial of service (m
35RISCO
abrir
ReferênciaVexDay Proof
BolinTech DreamFTP Server 1.0.2 - 'PORT' Remote Denial of Service
CVE-2006-6724doswindows
BolinTech Dream FTP Server 1.02 allows remote authenticated users, including anonymous users, to cause a denial of servi
23RISCO
abrir
ReferênciaVexDay Proof
cwmVote 1.0 - 'archive.php' Remote File Inclusion
CVE-2006-6732webappsphp
PHP remote file inclusion vulnerability in archive.php in cwmVote 1.0 allows remote attackers to execute arbitrary PHP c
23RISCO
abrir
ReferênciaVexDay Proof
Paristemi 0.8.3b - 'buycd.php' Remote File Inclusion
CVE-2006-6739webappsphp
PHP remote file inclusion vulnerability in buycd.php in Paristemi 0.8.3 allows remote attackers to execute arbitrary PHP
23RISCO
abrir
ReferênciaVexDay Proof
Ixprim CMS 1.2 - Blind SQL Injection
CVE-2006-6756webappsphp
The code function in install.fct.php in Ixprim 1.2 produces a guessable value of the confidential IXP_CODE in mainfile.p
23RISCO
abrir
ReferênciaVexDay Proof
cwmExplorer 1.0 - 'show_file' Source Code Disclosure
CVE-2006-6757webappsasp
Directory traversal vulnerability in index.php in cwmExplorer 1.0 allows remote attackers to read arbitrary files and so
23RISCO
abrir
ReferênciaVexDay Proof
Http explorer Web Server 1.02 - Directory Traversal
CVE-2006-6758remotewindows
Directory traversal vulnerability in Http explorer 1.02 allows remote attackers to read arbitrary files via a .. (dot do
23RISCO
abrir
ReferênciaVexDay Proof
Enthrallweb eCoupons 1.0 - 'myprofile.asp' Remote Pass Change
CVE-2006-6820webappsasp
myprofile.asp in Enthrallweb eCoupons does not properly validate the MM_recordId parameter during profile updates, which
23RISCO
abrir
ReferênciaVexDay Proof
Enthrallweb eNews 1.0 - Remote User Pass Change
CVE-2006-6821webappsasp
myprofile.asp in Enthrallweb eNews does not properly validate the MM_recordId parameter during profile updates, which al
23RISCO
abrir
ReferênciaVexDay Proof
Yrch 1.0 - 'plug.inc.phppath' Remote File Inclusion
CVE-2006-6823webappsphp
PHP remote file inclusion vulnerability in plugins/metasearch/plug.inc.php in Yrch! 1.0 allows remote attackers to execu
23RISCO
abrir
ReferênciaVexDay Proof
b2 Blog 0.5 - 'b2verifauth.php' Remote File Inclusion
CVE-2006-6830webappsphp
PHP remote file inclusion vulnerability in b2verifauth.php in b2 Blog 0.5 and earlier allows remote attackers to execute
23RISCO
abrir
ReferênciaVexDay Proof
aFAQ 1.0 - 'faqDsp.asp?catcode' SQL Injection
CVE-2006-6831webappsasp
SQL injection vulnerability in faqDsp.asp in aFAQ 1.0 allows remote attackers to execute arbitrary SQL commands via the
23RISCO
abrir
ReferênciaVexDay Proof
phpBB2 Plus 1.53 - Acronym Mod SQL Injection
CVE-2006-6842webappsphp
SQL injection vulnerability in admin/admin_acronyms.php in the Acronym Mod 0.9.5 for phpBB2 Plus 1.53 allows remote atta
23RISCO
abrir
ReferênciaVexDay Proof
wywo inout board 1.0 - Multiple Vulnerabilities
CVE-2006-6846webappsasp
Multiple SQL injection vulnerabilities in While You Were Out (WYWO) InOut Board 1.0 allow remote attackers to execute ar
23RISCO
abrir
ReferênciaVexDay Proof
RealPlayer 10.5 'ierpplug.dll' Internet Explorer 7 - Denial of Service
CVE-2006-6847doswindows
An ActiveX control in ierpplug.dll for RealNetworks RealPlayer 10.5 allows remote attackers to cause a denial of service
23RISCO
abrir
ReferênciaVexDay Proof
ASPTicker 1.0 - Authentication Bypass
CVE-2006-6848webappsasp
SQL injection vulnerability in admin.asp in ASPTicker 1.0 allows remote attackers to execute arbitrary SQL commands via
23RISCO
abrir
ReferênciaVexDay Proof
Shadowed Portal Module Character Roster - 'mod_root' Remote File Inclusion
CVE-2006-6850webappsphp
PHP remote file inclusion vulnerability in include.php in the Roster Module (character_roster) in Shadowed Portal 5.7 al
23RISCO
abrir
ReferênciaVexDay Proof
AIDeX Mini-WebServer 1.1 - Remote Crash (Denial of Service)
CVE-2006-6855doswindows
AIDeX Mini-WebServer 1.1 early release 3 allows remote attackers to cause a denial of service (daemon crash) via a flood
23RISCO
abrir
ReferênciaVexDay Proof
WordPress Plugin Enigma 2 Bridge - 'boarddir' Remote File Inclusion
CVE-2006-6863CRITICALwebappsphp
PHP remote file inclusion vulnerability in the Enigma2 plugin (Enigma2.php) in Enigma WordPress Bridge allows remote att
53RISCO
abrir
anteriorpágina 130 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.