Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.794exploits catalogados
36.057CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
PHPWebGallery 1.7.2 - Session Hijacking / Code Execution
CVE-2008-4645webappsphp
plugins/event_tracer/event_list.php in PhpWebGallery 1.7.2 and earlier allows remote authenticated administrators to exe
23RISCO
abrir
ReferênciaVexDay Proof
Real Estate Manager 1.01 - 'cat_id' SQL Injection
CVE-2008-4674webappsphp
SQL injection vulnerability in realestate-index.php in Conkurent Real Estate Manager 1.01 allows remote attackers to exe
23RISCO
abrir
ReferênciaVexDay Proof
PHPcounter 1.3.2 - 'index.php' SQL Injection
CVE-2008-4675webappsphp
SQL injection vulnerability in index.php in PHPcounter 1.3.2 and earlier allows remote attackers to execute arbitrary SQ
23RISCO
abrir
ReferênciaVexDay Proof
Wireshark 1.0.x - '.ncf' Packet Capture Local Denial of Service
CVE-2008-4682dosmultiple
wtap.c in Wireshark 0.99.7 through 1.0.3 allows remote attackers to cause a denial of service (application abort) via a
23RISCO
abrir
ReferênciaVexDay Proof
Mantis Bug Tracker 1.1.3 - Remote Code Execution
CVE-2008-4687webappsphp
manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort param
50RISCO
abrir
ReferênciaVexDay Proof
Opera 9.60 - Persistent Cross-Site Scripting
CVE-2008-4696remotewindows
Cross-site scripting (XSS) vulnerability in Opera.dll in Opera before 9.61 allows remote attackers to inject arbitrary w
50RISCO
abrir
ReferênciaVexDay Proof
Peachtree Accounting 2004 - 'PAWWeb11.ocx' ActiveX Insecure Method
CVE-2008-4699remotewindows
Insecure method vulnerability in the ActiveX control (PAWWeb11.ocx) in Peachtree Accounting 2004 allows remote attackers
28RISCO
abrir
ReferênciaVexDay Proof
Vbgooglemap Hotspot Edition 1.0.3 - SQL Injection
CVE-2008-4706webappsphp
SQL injection vulnerability in VBGooglemap Hotspot Edition 1.0.3, a vBulletin module, allows remote attackers to execute
23RISCO
abrir
ReferênciaVexDay Proof
Pilot Group eTraining - 'news_read.php' SQL Injection
CVE-2008-4709webappsphp
SQL injection vulnerability in news_read.php in Pilot Group (PG) eTraining allows remote attackers to execute arbitrary
23RISCO
abrir
ReferênciaVexDay Proof
Joovili 3.0 - Multiple SQL Injections
CVE-2008-4711webappsphp
SQL injection vulnerability in Joovili 3.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to ex
23RISCO
abrir
ReferênciaVexDay Proof
212Cafe Board 0.07 - 'qID' SQL Injection
CVE-2008-4713webappsphp
SQL injection vulnerability in view.php in 212cafe Board 0.07 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component JPad 1.0 - (Authenticated) SQL Injection
CVE-2008-4715webappsphp
SQL injection vulnerability in the Jpad (com_jpad) 1.0 component for Joomla! allows remote attackers to execute arbitrar
23RISCO
abrir
ReferênciaVexDay Proof
PHP-Lance 1.52 - 'catid' SQL Injection
CVE-2008-4716webappsphp
SQL injection vulnerability in show.php in BitmixSoft PHP-Lance 1.52 allows remote attackers to execute arbitrary SQL co
23RISCO
abrir
ReferênciaVexDay Proof
Post Comments 3.0 - Insecure Cookie Handling
CVE-2008-4721webappsphp
PHP Jabbers Post Comment 3.0 allows remote attackers to bypass authentication and gain administrative access by setting
23RISCO
abrir
ReferênciaVexDay Proof
Opera 9.60 - Persistent Cross-Site Scripting
CVE-2008-4725remotewindows
Cross-site scripting (XSS) vulnerability in Opera.dll in Opera 9.52 allows remote attackers to inject arbitrary web scri
23RISCO
abrir
ReferênciaVexDay Proof
WordPress Plugin WP Comment Remix 1.4.3 - SQL Injection
CVE-2008-4732webappsphp
SQL injection vulnerability in ajax_comments.php in the WP Comment Remix plugin before 1.4.4 for WordPress allows remote
23RISCO
abrir
ReferênciaVexDay Proof
PlugSpace 0.1 - 'navi' Local File Inclusion
CVE-2008-4739webappsphp
Directory traversal vulnerability in index.php in PlugSpace 0.1, when magic_quotes_gpc is disabled, allows remote attack
23RISCO
abrir
ReferênciaVexDay Proof
KVIrc 3.4.0 - Virgo Remote Format String (PoC)
CVE-2008-4748doswindows
Format string vulnerability in the URI handler in KVirc 3.4.0, when set as the default application for processing IRC UR
23RISCO
abrir
ReferênciaVexDay Proof
db Software Laboratory VImpX - 'VImpX.ocx' Multiple Vulnerabilities
CVE-2008-4749remotewindows
Multiple insecure method vulnerabilities in the VImpX.VImpAX ActiveX control (VImpX.ocx) 4.8.8.0 in DB Software Laborato
23RISCO
abrir
ReferênciaVexDay Proof
GNUBoard 4.31.03 (08.12.29) - Local File Inclusion
CVE-2009-0290webappsphp
Directory traversal vulnerability in common.php in SIR GNUBoard 4.31.03 allows remote attackers to include and execute a
23RISCO
abrir
ReferênciaVexDay Proof
Wazzum Dating Software - 'userid' SQL Injection
CVE-2009-0293webappsphp
SQL injection vulnerability in profile_view.php in Wazzum Dating Software, possibly 2.0, allows remote attackers to exec
23RISCO
abrir
ReferênciaVexDay Proof
phpdaily - SQL Injection / Cross-Site Scripting / Local File Download
CVE-2008-4758webappsphp
Directory traversal vulnerability in download_file.php in PHP-Daily allows remote attackers to read arbitrary local file
23RISCO
abrir
ReferênciaVexDay Proof
freeSSHd 1.2.1 - (Authenticated) SFTP 'realpath' Remote Buffer Overflow (PoC)
CVE-2008-4762doswindows
Stack-based buffer overflow in freeSSHd 1.2.1 allows remote authenticated users to cause a denial of service (service cr
28RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component com_extplorer 2.0.0 RC2 - Local Directory Traversal
CVE-2008-4764webappsphp
Directory traversal vulnerability in the eXtplorer module (com_extplorer) 2.0.0 RC2 and earlier in Joomla! allows remote
43RISCO
abrir
ReferênciaVexDay Proof
QuestCMS - Cross-Site Scripting / Directory Traversal / SQL Injection
CVE-2008-4773webappsphp
Directory traversal vulnerability in main/main.php in QuestCMS allows remote attackers to read arbitrary local files via
23RISCO
abrir
ReferênciaVexDay Proof
Dream4 Koobi Pro 6.25 Showimages - 'galid' SQL Injection
CVE-2008-4778webappsphp
SQL injection vulnerability in the gallery module in Koobi CMS 4.3.0 allows remote attackers to execute arbitrary SQL co
23RISCO
abrir
ReferênciaVexDay Proof
TugZip 3.00 Archiver - '.zip' Local Buffer Overflow
CVE-2008-4779localwindows
Stack-based buffer overflow in TUGzip 3.5.0.0 allows remote attackers to denial of service (crash) or execute arbitrary
50RISCO
abrir
ReferênciaVexDay Proof
e107 Plugin alternate_profiles - 'id' SQL Injection
CVE-2008-4785webappsphp
SQL injection vulnerability in newuser.php in the alternate_profiles plugin, possibly 0.2, for e107 allows remote attack
23RISCO
abrir
ReferênciaVexDay Proof
e107 Plugin EasyShop - 'category_id' Blind SQL Injection
CVE-2008-4786webappsphp
SQL injection vulnerability in easyshop.php in the EasyShop plugin for e107 allows remote attackers to execute arbitrary
23RISCO
abrir
ReferênciaVexDay Proof
ITLPoll 2.7 Stable2 - Blind SQL Injection
CVE-2009-0295webappsphp
SQL injection vulnerability in index.php in Information Technology Light Poll Information (ITLPoll) 2.7 Stable 2, when m
23RISCO
abrir
anteriorpágina 14 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.