Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
Webmin 1.910 - 'Package Updates' Remote Command Execution (Metasploit)
CVE-2019-12840remotelinux
In Webmin through 1.910, any user authorized to the "Package Updates" module can execute arbitrary commands with root pr
60RISCO
abrir
ReferênciaVexDay Proof
Guestbara 1.2 - Change Admin Login and Password
CVE-2007-1553webappsphp
admin/configuration.php in Guestbara 1.2 and earlier allows remote attackers to modify the e-mail, name, and password of
23RISCO
abrir
ReferênciaVexDay Proof
NetVIOS Portal - 'page.asp' SQL Injection
CVE-2007-1566webappsasp
SQL injection vulnerability in News/page.asp in NetVIOS Portal allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
ReferênciaVexDay Proof
NewsReactor 20070220 - Article Grabbing Remote Buffer Overflow (1)
CVE-2007-1568remotewindows
Stack-based buffer overflow in DaanSystems NewsReactor 20070220.21 allows remote attackers to execute arbitrary code via
23RISCO
abrir
ReferênciaVexDay Proof
NewsReactor 20070220 - Article Grabbing Remote Buffer Overflow (2)
CVE-2007-1568remotewindows
Stack-based buffer overflow in DaanSystems NewsReactor 20070220.21 allows remote attackers to execute arbitrary code via
23RISCO
abrir
ReferênciaVexDay Proof
News Bin Pro 4.32 - Article Grabbing Remote Unicode Buffer Overflow
CVE-2007-1569doswindows
Stack-based buffer overflow in NewsBin Pro 4.32 allows remote attackers to cause a denial of service or execute arbitrar
23RISCO
abrir
ReferênciaVexDay Proof
Mercur IMAPD 5.00.14 (Windows x86) - Remote Denial of Service
CVE-2007-1578doswindows_x86
Multiple integer signedness errors in the NTLM implementation in Atrium MERCUR IMAPD (mcrimap4.exe) 5.00.14, with SP4, a
28RISCO
abrir
ReferênciaVexDay Proof
Mercur Messaging 2005 (Windows 2000 SP4) - IMAP 'Subscribe' Remote Overflow
CVE-2007-1579remotewindows
Stack-based buffer overflow in Atrium MERCUR IMAPD allows remote attackers to have an unknown impact via a certain SUBSC
35RISCO
abrir
ReferênciaVexDay Proof
PHP 5.2.0 (OSX) - 'header()' Space Trimming Buffer Underflow
CVE-2007-1584localosx
Buffer underflow in the header function in PHP 5.2.0 allows context-dependent attackers to execute arbitrary code by pas
23RISCO
abrir
ReferênciaVexDay Proof
MPM Chat 2.5 - 'view.php?logi' Local File Inclusion
CVE-2007-1613webappsphp
Directory traversal vulnerability in view.php in MPM Chat 2.5 allows remote attackers to include and execute arbitrary l
23RISCO
abrir
ReferênciaVexDay Proof
ScriptMagix Lyrics 2.0 - 'index.php?recid' SQL Injection
CVE-2007-1616webappsphp
SQL injection vulnerability in index.php in ScriptMagix Lyrics 2.0 and earlier allows remote attackers to execute arbitr
23RISCO
abrir
ReferênciaVexDay Proof
ScriptMagix Recipes 2.0 - 'index.php?catid' SQL Injection
CVE-2007-1617webappsphp
SQL injection vulnerability in index.php in ScriptMagix Recipes 2.0 and earlier allows remote attackers to execute arbit
23RISCO
abrir
ReferênciaVexDay Proof
ScriptMagix Photo Rating 2.0 - SQL Injection
CVE-2007-1619webappsphp
SQL injection vulnerability in viewcomments.php in ScriptMagix Photo Rating 2.0 and earlier allows remote attackers to e
23RISCO
abrir
ReferênciaVexDay Proof
PHP DB Designer 1.02 - Remote File Inclusion
CVE-2007-1620webappsphp
Multiple PHP remote file inclusion vulnerabilities in PHP DB Designer 1.02 and earlier allow remote attackers to execute
28RISCO
abrir
ReferênciaVexDay Proof
Active Photo Gallery - 'catid' SQL Injection
CVE-2007-1629webappsasp
SQL injection vulnerability in default.asp in ActiveWebSoftwares Active Photo Gallery allows remote attackers to execute
23RISCO
abrir
ReferênciaVexDay Proof
PHP-Nuke Module Eve-Nuke 0.1 - 'mysql.php' Remote File Inclusion
CVE-2007-1778webappsphp
PHP remote file inclusion vulnerability in db/mysql.php in the Eve-Nuke 0.1 (EN-Forums) module for PHP-Nuke allows remot
23RISCO
abrir
ReferênciaVexDay Proof
Kaqoo Auction - 'install_root' Multiple Remote File Inclusions
CVE-2007-1790webappsphp
Multiple PHP remote file inclusion vulnerabilities in Kaqoo Auction Software Free Edition allow remote attackers to exec
23RISCO
abrir
ReferênciaVexDay Proof
Picture-Engine 1.2.0 - 'wall.php?cat' SQL Injection
CVE-2007-1791webappsphp
SQL injection vulnerability in wall.php in Picture-Engine 1.2.0 and earlier allows remote attackers to execute arbitrary
23RISCO
abrir
ReferênciaVexDay Proof
XOOPS Module RM+Soft Gallery 1.0 - Blind SQL Injection
CVE-2007-1806webappsphp
SQL injection vulnerability in categos.php in the RM+Soft Gallery (rmgallery) 1.0 module for Xoops allows remote attacke
23RISCO
abrir
ReferênciaVexDay Proof
XOOPS Module Kshop 1.17 - 'id' SQL Injection
CVE-2007-1810webappsphp
SQL injection vulnerability in product_details.php in the Kshop 1.17 and earlier module for Xoops allows remote attacker
23RISCO
abrir
ReferênciaVexDay Proof
XOOPS Module Tiny Event 1.01 - 'id' SQL Injection
CVE-2007-1811webappsphp
SQL injection vulnerability in index.php in the Tiny Event (tinyevent) 1.01 and earlier module for Xoops allows remote a
23RISCO
abrir
ReferênciaVexDay Proof
BT-sondage 1.12 - 'gestion_sondage.php' Remote File Inclusion
CVE-2007-1812webappsphp
PHP remote file inclusion vulnerability in utilitaires/gestion_sondage.php in BT-Sondage 112 allows remote attackers to
23RISCO
abrir
ReferênciaVexDay Proof
XOOPS Module MyAds Bug Fix 2.04jp - 'index.php' SQL Injection
CVE-2007-1846webappsphp
SQL injection vulnerability in index.php in the MyAds 2.04jp and earlier module for Xoops allows remote attackers to exe
23RISCO
abrir
ReferênciaVexDay Proof
Really Simple PHP and Ajax (RSPA) 2007-03-23 - Remote File Inclusion
CVE-2007-1851webappsphp
Multiple directory traversal vulnerabilities in Really Simple PHP and Ajax (RSPA) 2007-03-23 allow remote attackers to i
23RISCO
abrir
ReferênciaVexDay Proof
Pathos CMS 0.92-2 - 'warn.php' Remote File Inclusion
CVE-2007-1907webappsphp
PHP remote file inclusion vulnerability in warn.php in Pathos Content Management System (CMS) 0.92-2 allows remote attac
23RISCO
abrir
ReferênciaVexDay Proof
PHP121 Instant Messenger 2.2 - Local File Inclusion
CVE-2007-1908webappsphp
PHP file inclusion vulnerability in php121db.php in PHP121 Instant Messenger 2.2 allows remote attackers to execute arbi
23RISCO
abrir
ReferênciaVexDay Proof
Microsoft Word 2007 - Multiple Vulnerabilities
CVE-2007-1910doswindows
Buffer overflow in wwlib.dll in Microsoft Word 2007 allows remote attackers to cause a denial of service (application cr
28RISCO
abrir
ReferênciaVexDay Proof
Microsoft Windows - '.hlp' Local HEAP Overflow (PoC)
CVE-2007-1912doswindows
Heap-based buffer overflow in Microsoft Windows allows user-assisted remote attackers to have an unknown impact via a cr
28RISCO
abrir
ReferênciaVexDay Proof
Beryo 2.0 - 'downloadpic.php?chemin' Remote File Disclosure
CVE-2007-1929webappsphp
Directory traversal vulnerability in downloadpic.php in Beryo 2.0, and possibly other versions including 2.4, allows rem
23RISCO
abrir
ReferênciaVexDay Proof
SmodCMS 2.10 - Slownik ssid SQL Injection
CVE-2007-1931webappsphp
SQL injection vulnerability in index.php in the slownik module in SmodCMS 2.10 and earlier allows remote attackers to ex
23RISCO
abrir
anteriorpágina 132 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.