Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.305exploits catalogados
36.465CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
PHP 5.2.0 (OSX) - 'header()' Space Trimming Buffer Underflow
CVE-2007-1584localosx
Buffer underflow in the header function in PHP 5.2.0 allows context-dependent attackers to execute arbitrary code by pas
23RISCO
abrir
ReferênciaVexDay Proof
MPM Chat 2.5 - 'view.php?logi' Local File Inclusion
CVE-2007-1613webappsphp
Directory traversal vulnerability in view.php in MPM Chat 2.5 allows remote attackers to include and execute arbitrary l
23RISCO
abrir
ReferênciaVexDay Proof
ScriptMagix Lyrics 2.0 - 'index.php?recid' SQL Injection
CVE-2007-1616webappsphp
SQL injection vulnerability in index.php in ScriptMagix Lyrics 2.0 and earlier allows remote attackers to execute arbitr
23RISCO
abrir
ReferênciaVexDay Proof
ScriptMagix Recipes 2.0 - 'index.php?catid' SQL Injection
CVE-2007-1617webappsphp
SQL injection vulnerability in index.php in ScriptMagix Recipes 2.0 and earlier allows remote attackers to execute arbit
23RISCO
abrir
ReferênciaVexDay Proof
ScriptMagix Photo Rating 2.0 - SQL Injection
CVE-2007-1619webappsphp
SQL injection vulnerability in viewcomments.php in ScriptMagix Photo Rating 2.0 and earlier allows remote attackers to e
23RISCO
abrir
ReferênciaVexDay Proof
PHP DB Designer 1.02 - Remote File Inclusion
CVE-2007-1620webappsphp
Multiple PHP remote file inclusion vulnerabilities in PHP DB Designer 1.02 and earlier allow remote attackers to execute
28RISCO
abrir
ReferênciaVexDay Proof
Active Photo Gallery - 'catid' SQL Injection
CVE-2007-1629webappsasp
SQL injection vulnerability in default.asp in ActiveWebSoftwares Active Photo Gallery allows remote attackers to execute
23RISCO
abrir
ReferênciaVexDay Proof
ApowerManager 3.1.7 - Phone Manager Remote Denial of Service (PoC)
CVE-2019-9601dosandroid
The ApowerManager application through 3.1.7 for Android allows remote attackers to cause a denial of service via many si
23RISCO
abrir
ReferênciaVexDay Proof
Active Link Engine - 'default.asp?catid' SQL Injection
CVE-2007-1630webappsasp
SQL injection vulnerability in default.asp in ActiveWebSoftwares Active Link Engine allows remote attackers to execute a
23RISCO
abrir
ReferênciaVexDay Proof
ClassWeb 2.0.3 - 'BASE' Remote File Inclusion
CVE-2007-1640webappsphp
Multiple PHP remote file inclusion vulnerabilities in ClassWeb 2.03 and earlier allow remote attackers to execute arbitr
23RISCO
abrir
ReferênciaVexDay Proof
PortailPhp 2.0 - 'idnews' SQL Injection
CVE-2007-1641webappsphp
SQL injection vulnerability in index.php in PortailPHP 2.0 allows remote attackers to execute arbitrary SQL commands via
23RISCO
abrir
ReferênciaVexDay Proof
Active NewsLetter 4.3 - 'ViewNewspapers.asp' SQL Injection
CVE-2007-1696webappsasp
SQL injection vulnerability in ViewNewspapers.asp in Active Newsletter 4.3 and earlier allows remote attackers to execut
23RISCO
abrir
ReferênciaVexDay Proof
Philex 0.2.3 - Remote File Inclusion / File Disclosure
CVE-2007-1698webappsphp
download.php in Philex 0.2.3 and earlier allows remote attackers to read arbitrary files and source code, and obtain sen
23RISCO
abrir
ReferênciaVexDay Proof
Mambo Module Flatmenu 1.07 - Remote File Inclusion
CVE-2007-1702webappsphp
PHP remote file inclusion vulnerability in mod_flatmenu.php in the Flatmenu 1.07 and earlier Mambo module allows remote
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component RWCards 2.4.3 - SQL Injection
CVE-2007-1703webappsphp
SQL injection vulnerability in index.php in the RWCards (com_rwcards) 2.4.3 and earlier component for Joomla! allows rem
23RISCO
abrir
ReferênciaVexDay Proof
Active Trade 2 - 'catid' SQL Injection
CVE-2007-1705webappsasp
SQL injection vulnerability in default.asp in Active Trade 2 allows remote attackers to execute arbitrary SQL commands v
23RISCO
abrir
ReferênciaVexDay Proof
eWebquiz 8 - 'eWebQuiz.asp' SQL Injection
CVE-2007-1706webappsasp
SQL injection vulnerability in eWebQuiz.asp in eWebQuiz 8 allows remote attackers to execute arbitrary SQL commands via
23RISCO
abrir
ReferênciaVexDay Proof
ttCMS 4 - 'ez_sql.php?lib_path' Remote File Inclusion
CVE-2007-1708webappsphp
PHP remote file inclusion vulnerability in lib/db/ez_sql.php in ttCMS 4 and earlier allows remote attackers to execute a
23RISCO
abrir
ReferênciaVexDay Proof
Corel WordPerfect X3 13.0.0.565 - '.prs' Local Buffer Overflow
CVE-2007-1735localwindows
Stack-based buffer overflow in Corel WordPerfect Office X3 (13.0.0.565) allows user-assisted remote attackers to execute
23RISCO
abrir
ReferênciaVexDay Proof
PHP-Nuke Module Eve-Nuke 0.1 - 'mysql.php' Remote File Inclusion
CVE-2007-1778webappsphp
PHP remote file inclusion vulnerability in db/mysql.php in the Eve-Nuke 0.1 (EN-Forums) module for PHP-Nuke allows remot
23RISCO
abrir
ReferênciaVexDay Proof
Kaqoo Auction - 'install_root' Multiple Remote File Inclusions
CVE-2007-1790webappsphp
Multiple PHP remote file inclusion vulnerabilities in Kaqoo Auction Software Free Edition allow remote attackers to exec
23RISCO
abrir
ReferênciaVexDay Proof
Picture-Engine 1.2.0 - 'wall.php?cat' SQL Injection
CVE-2007-1791webappsphp
SQL injection vulnerability in wall.php in Picture-Engine 1.2.0 and earlier allows remote attackers to execute arbitrary
23RISCO
abrir
ReferênciaVexDay Proof
XOOPS Module RM+Soft Gallery 1.0 - Blind SQL Injection
CVE-2007-1806webappsphp
SQL injection vulnerability in categos.php in the RM+Soft Gallery (rmgallery) 1.0 module for Xoops allows remote attacke
23RISCO
abrir
ReferênciaVexDay Proof
XOOPS Module Kshop 1.17 - 'id' SQL Injection
CVE-2007-1810webappsphp
SQL injection vulnerability in product_details.php in the Kshop 1.17 and earlier module for Xoops allows remote attacker
23RISCO
abrir
ReferênciaVexDay Proof
XOOPS Module Tiny Event 1.01 - 'id' SQL Injection
CVE-2007-1811webappsphp
SQL injection vulnerability in index.php in the Tiny Event (tinyevent) 1.01 and earlier module for Xoops allows remote a
23RISCO
abrir
ReferênciaVexDay Proof
BT-sondage 1.12 - 'gestion_sondage.php' Remote File Inclusion
CVE-2007-1812webappsphp
PHP remote file inclusion vulnerability in utilitaires/gestion_sondage.php in BT-Sondage 112 allows remote attackers to
23RISCO
abrir
ReferênciaVexDay Proof
XOOPS Module MyAds Bug Fix 2.04jp - 'index.php' SQL Injection
CVE-2007-1846webappsphp
SQL injection vulnerability in index.php in the MyAds 2.04jp and earlier module for Xoops allows remote attackers to exe
23RISCO
abrir
ReferênciaVexDay Proof
Really Simple PHP and Ajax (RSPA) 2007-03-23 - Remote File Inclusion
CVE-2007-1851webappsphp
Multiple directory traversal vulnerabilities in Really Simple PHP and Ajax (RSPA) 2007-03-23 allow remote attackers to i
23RISCO
abrir
ReferênciaVexDay Proof
Pathos CMS 0.92-2 - 'warn.php' Remote File Inclusion
CVE-2007-1907webappsphp
PHP remote file inclusion vulnerability in warn.php in Pathos Content Management System (CMS) 0.92-2 allows remote attac
23RISCO
abrir
ReferênciaVexDay Proof
PHP121 Instant Messenger 2.2 - Local File Inclusion
CVE-2007-1908webappsphp
PHP file inclusion vulnerability in php121db.php in PHP121 Instant Messenger 2.2 allows remote attackers to execute arbi
23RISCO
abrir
anteriorpágina 140 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.