Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
C-Arbre 0.6PR7 - 'ROOT_PATH' Remote File Inclusion
CVE-2007-1721webappsphp
Multiple PHP remote file inclusion vulnerabilities in C-Arbre 0.6PR7 and earlier allow remote attackers to execute arbit
28RISCO
abrir
ReferênciaVexDay Proof
IceBB 1.0-rc5 - Remote Create Admin
CVE-2007-1725webappsphp
SQL injection vulnerability in index.php in IceBB 1.0-rc5 allows remote authenticated users to execute arbitrary SQL com
23RISCO
abrir
ReferênciaVexDay Proof
NaviCOPA Web Server 2.01 - Remote Buffer Overflow (Metasploit)
CVE-2007-1733remotewindows
Buffer overflow in InterVations NaviCOPA HTTP Server 2.01 allows remote attackers to execute arbitrary code via a long (
28RISCO
abrir
ReferênciaVexDay Proof
Softerra Time-Assistant 6.2 - 'inc_dir' Remote File Inclusion
CVE-2007-1787webappsphp
Multiple PHP remote file inclusion vulnerabilities in lib/timesheet.class.php in Softerra Time-Assistant 6.2 and earlier
23RISCO
abrir
ReferênciaVexDay Proof
eXtremail 2.1.1 - DNS Parsing Bugs Remote (PoC)
CVE-2007-2187doslinux
Stack-based buffer overflow in eXtremail 2.1.1 and earlier allows remote attackers to execute arbitrary code via a long
23RISCO
abrir
ReferênciaVexDay Proof
Vizayn Haber - 'haberdetay.asp?id' SQL Injection
CVE-2007-0052webappsasp
SQL injection vulnerability in haberdetay.asp in Vizayn Haber allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
ReferênciaVexDay Proof
CCRP Folder Treeview Control (ccrpftv6.ocx) - IE Denial of Service
CVE-2007-0356doswindows
The Common Controls Replacement Project (CCRP) FolderTreeview (FTV) ActiveX control (ccrpftv6.ocx) allows remote attacke
28RISCO
abrir
ReferênciaVexDay Proof
Uberghey 0.3.1 - 'FrontPage.php' Remote File Inclusion
CVE-2007-0359webappsphp
PHP remote file inclusion vulnerability in frontpage.php in Uberghey CMS 0.3.1 allows remote attackers to execute arbitr
23RISCO
abrir
ReferênciaVexDay Proof
Oreon 1.2.3 RC4 - '/lang/index.php' Remote File Inclusion
CVE-2007-0360webappsphp
PHP remote file inclusion vulnerability in lang/index.php in Oreon 1.2.3 RC4 and earlier allows remote attackers to exec
23RISCO
abrir
ReferênciaVexDay Proof
MyNews 4.2.2 - 'themefunc.php' Remote File Inclusion
CVE-2007-0633webappsphp
PHP remote file inclusion vulnerability in include/themes/themefunc.php in MyNews 4.2.2 and earlier allows remote attack
23RISCO
abrir
ReferênciaVexDay Proof
ACDSee 9.0 - '.xpm' Local Buffer Overflow
CVE-2007-2193localwindows
Stack-based buffer overflow in the ID_X.apl plugin in ACDSee 9.0 Build 108, Pro 8.1 Build 99, and Photo Editor 4.0 Build
50RISCO
abrir
ReferênciaVexDay Proof
XnView 1.90.3 - '.xpm' Local Buffer Overflow
CVE-2007-2194localwindows
Stack-based buffer overflow in XnView 1.90.3 allows user-assisted remote attackers to execute arbitrary code via a craft
28RISCO
abrir
ReferênciaVexDay Proof
Joomla! 1.5.0 Beta - 'pcltar.php' Remote File Inclusion
CVE-2007-2199webappsphp
PHP remote file inclusion vulnerability in lib/pcltar.lib.php (aka pcltar.php) in the PclTar module 1.3 and 1.3.1 for Vi
35RISCO
abrir
ReferênciaVexDay Proof
Michelles L2J Dropcalc 4 - SQL Injection
CVE-2007-0687webappsphp
SQL injection vulnerability in i-search.php in Michelle's L2J Dropcalc 4 and earlier allows remote authenticated users t
23RISCO
abrir
ReferênciaVexDay Proof
NMDeluxe 1.0.1 - 'footer.php?template' Local File Inclusion
CVE-2007-2303webappsphp
Directory traversal vulnerability in includes/footer.php in News Manager Deluxe (NMDeluxe) 1.0.1 allows remote attackers
23RISCO
abrir
ReferênciaVexDay Proof
ACGVannu 1.3 - 'index2.php' Remote User Pass Change
CVE-2007-0697webappsphp
index2.php in ACGVannu 1.3 and earlier allows remote attackers to change the password or profile of a user via a modifie
23RISCO
abrir
ReferênciaVexDay Proof
Epistemon 1.0 - 'common.php?inc_path' Remote File Inclusion
CVE-2007-0701webappsphp
PHP remote file inclusion vulnerability in inc/common.inc.php in Epistemon 1.0 allows remote attackers to execute arbitr
23RISCO
abrir
ReferênciaVexDay Proof
Somery 0.4.6 - 'skin_dir' Remote File Inclusion
CVE-2007-0704webappsphp
PHP remote file inclusion vulnerability in install.php in Somery 0.4.6 allows remote attackers to execute arbitrary PHP
23RISCO
abrir
ReferênciaVexDay Proof
phpBB ezBoard Converter 0.2 - 'ezconvert_dir' Remote File Inclusion
CVE-2007-0761webappsphp
PHP remote file inclusion vulnerability in config.php in phpBB ezBoard converter (ezconvert) 0.2 allows remote attackers
23RISCO
abrir
ReferênciaVexDay Proof
phpBB++ Build 100 - 'phpbb_root_path' Remote File Inclusion
CVE-2007-0762webappsphp
PHP remote file inclusion vulnerability in includes/functions.php in phpBB++ Build 100 allows remote attackers to execut
23RISCO
abrir
ReferênciaVexDay Proof
F3Site 2.1 - Remote Code Execution
CVE-2007-0763webappsphp
Cross-site scripting (XSS) vulnerability in the news comment functionality in F3Site 2.1 and earlier allows remote attac
23RISCO
abrir
ReferênciaVexDay Proof
dB Masters Curium CMS 1.03 - 'c_id' SQL Injection
CVE-2007-0765webappsphp
SQL injection vulnerability in news.php in dB Masters Curium CMS 1.03 and earlier allows remote attackers to execute arb
23RISCO
abrir
ReferênciaVexDay Proof
Remotesoft .NET Explorer 2.0.1 - Local Stack Overflow (PoC)
CVE-2007-0766doswindows
Stack-based buffer overflow in Remotesoft .NET Explorer 2.0.1 allows user-assisted remote attackers to cause a denial of
23RISCO
abrir
ReferênciaVexDay Proof
Photoshop CS2/CS3 / Paint Shop Pro 11.20 - '.png' Local Buffer Overflow
CVE-2007-2365localwindows
Buffer overflow in Adobe Photoshop CS2 and CS3, Photoshop Elements 5.0, Illustrator CS3, and GoLive 9 allows user-assist
35RISCO
abrir
ReferênciaVexDay Proof
WebSPELL 4.01.02 - 'picture.php' File Disclosure
CVE-2007-2368webappsphp
picture.php in WebSPELL 4.01.02 and earlier allows remote attackers to read arbitrary files via the file parameter.
23RISCO
abrir
ReferênciaVexDay Proof
News-Letterman 1.1 - 'eintrag.php?sqllog' Remote File Inclusion
CVE-2007-1340webappsphp
PHP remote file inclusion vulnerability in eintrag.php in Weltennetz News-Letterman 1.1 allows remote attackers to execu
23RISCO
abrir
ReferênciaVexDay Proof
PHP 5.2.1 - 'substr_compare()' Information Leak
CVE-2007-1375localmultiple
Integer overflow in the substr_compare function in PHP 5.2.1 and earlier allows context-dependent attackers to read sens
23RISCO
abrir
ReferênciaVexDay Proof
XOOPS Module WF-Links 1.03 - 'cid' SQL Injection
CVE-2007-2373webappsphp
SQL injection vulnerability in viewcat.php in the WF-Links (wflinks) 1.03 and earlier module for XOOPS allows remote att
23RISCO
abrir
ReferênciaVexDay Proof
TinyIdentD 2.2 - Remote Buffer Overflow
CVE-2007-2711remotewindows
Stack-based buffer overflow in TinyIdentD 2.2 and earlier allows remote attackers to execute arbitrary code via a long s
50RISCO
abrir
ReferênciaVexDay Proof
Creative Files 1.2 - 'kommentare.php' SQL Injection
CVE-2007-1556webappsphp
SQL injection vulnerability in kommentare.php in Creative Files 1.2 allows remote attackers to execute arbitrary SQL com
23RISCO
abrir
anteriorpágina 133 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.