Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

75.445exploits catalogados
34.432CVEs com exploração pública
24.695testados em laboratório
21.497 exploits
Referência
CVE-2015-7259
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow user accounts to have multiple valid
23RISCO
abrir
ReferênciaVexDay Proof
Aztek Forum 4.00 - Cross-Site Scripting / SQL Injection
CVE-2006-1111webappsphp
Aztek Forum 4.0 allows remote attackers to obtain sensitive information via a "*/*" in the msg parameter to index.php, w
23RISCO
abrir
ReferênciaVexDay Proof
Aztek Forum 4.00 - Cross-Site Scripting / SQL Injection
CVE-2006-1112webappsphp
Aztek Forum 4.0 allows remote attackers to obtain sensitive information via a long login value in a register form, which
23RISCO
abrir
Referência
CVE-2010-3856
ld.so in the GNU C Library (aka glibc or libc6) before 2.11.3, and 2.12.x before 2.12.2, does not properly restrict use
43RISCO
abrir
Referência
CVE-2010-3856
ld.so in the GNU C Library (aka glibc or libc6) before 2.11.3, and 2.12.x before 2.12.2, does not properly restrict use
43RISCO
abrir
Referência
CVE-2010-3856
ld.so in the GNU C Library (aka glibc or libc6) before 2.11.3, and 2.12.x before 2.12.2, does not properly restrict use
43RISCO
abrir
ReferênciaVexDay Proof
SunShop Shopping Cart 3.5 - 'abs_path' Remote File Inclusion
CVE-2007-2070webappsphp
Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools SunShop Shopping Cart before 3.5.1 allow remote
23RISCO
abrir
ReferênciaVexDay Proof
Firefly 1.1.01 - 'doc_root' Remote File Inclusion
CVE-2007-2456webappsphp
Multiple PHP remote file inclusion vulnerabilities in FireFly 1.1.01 allow remote attackers to execute arbitrary PHP cod
23RISCO
abrir
Referência
CVE-2017-15965
The NS Download Shop (aka com_ns_downloadshop) component 2.2.6 for Joomla! allows SQL Injection via the id parameter in
23RISCO
abrir
ReferênciaVexDay Proof
PHP 5.2.0 (Windows x86) - 'PHP_iisfunc.dll' Local Buffer Overflow
CVE-2007-4586doswindows_x86
Multiple buffer overflows in php_iisfunc.dll in the iisfunc extension for PHP 5.2.0 and earlier allow context-dependent
23RISCO
abrir
Referência
CVE-2016-2087
Directory traversal vulnerability in the client in HexChat 2.11.0 allows remote IRC servers to read or modify arbitrary
23RISCO
abrir
Referência
CVE-2016-2087
Directory traversal vulnerability in the client in HexChat 2.11.0 allows remote IRC servers to read or modify arbitrary
23RISCO
abrir
ReferênciaVexDay Proof
Mantis Bug Tracker 1.1.1 - Code Execution / Cross-Site Scripting / Cross-Site Request Forgery
CVE-2008-3332webappsphp
Eval injection vulnerability in adm_config_set.php in Mantis before 1.1.2 allows remote authenticated administrators to
23RISCO
abrir
ReferênciaVexDay Proof
Gravity GTD 0.4.5 - Local File Inclusion / Remote Code Execution
CVE-2008-5963webappsphp
Eval injection vulnerability in library/setup/rpc.php in Gravity Getting Things Done (GTD) 0.4.5 and earlier allows remo
23RISCO
abrir
Referência
CVE-2015-3203
Unrestricted file upload vulnerability in h5ai before 0.25.0 allows remote attackers to execute arbitrary code by upload
23RISCO
abrir
Referência
CVE-2012-2208
Directory traversal vulnerability in upgrade.php in Piwigo before 2.3.4 allows remote attackers to include and execute a
23RISCO
abrir
Referência
CVE-2010-2507
Directory traversal vulnerability in the Picasa2Gallery (com_picasa2gallery) component 1.2.8 and earlier for Joomla! all
38RISCO
abrir
Referência
CVE-2010-2507
Directory traversal vulnerability in the Picasa2Gallery (com_picasa2gallery) component 1.2.8 and earlier for Joomla! all
38RISCO
abrir
Referência
CVE-2015-0009
The Group Policy Security Configuration policy implementation in Microsoft Windows Server 2003 SP2, Windows Vista SP2, W
23RISCO
abrir
Referência
CVE-2016-4309
Session fixation vulnerability in Symphony CMS 2.6.7, when session.use_only_cookies is disabled, allows remote attackers
23RISCO
abrir
Referência
CVE-2012-6050
The winbox service in MikroTik RouterOS 5.15 and earlier allows remote attackers to cause a denial of service (CPU consu
23RISCO
abrir
Referência
CVE-2009-2535
Mozilla Firefox before 2.0.0.19 and 3.x before 3.0.5, SeaMonkey, and Thunderbird allow remote attackers to cause a denia
23RISCO
abrir
Referência
CVE-2009-3705
PHP remote file inclusion vulnerability in debugger.php in Achievo before 1.4.0 allows remote attackers to execute arbit
23RISCO
abrir
Referência
CVE-2017-6553
Buffer Overflow in Quest One Identity Privilege Manager for Unix before 6.0.0.061 allows remote attackers to obtain full
50RISCO
abrir
Referência
CVE-2017-15965
The NS Download Shop (aka com_ns_downloadshop) component 2.2.6 for Joomla! allows SQL Injection via the id parameter in
23RISCO
abrir
Referência
CVE-2011-4715
Directory traversal vulnerability in cgi-bin/koha/mainpage.pl in Koha 3.4 before 3.4.7 and 3.6 before 3.6.1, and LibLime
23RISCO
abrir
Referência
CVE-2010-1719
Directory traversal vulnerability in the MT Fire Eagle (com_mtfireeagle) component 1.2 for Joomla! allows remote attacke
38RISCO
abrir
Referência
CVE-2010-1719
Directory traversal vulnerability in the MT Fire Eagle (com_mtfireeagle) component 1.2 for Joomla! allows remote attacke
38RISCO
abrir
ReferênciaVexDay Proof
WEBInsta CMS 0.3.1 - 'templates_dir' Remote File Inclusion
CVE-2006-4196webappsphp
PHP remote file inclusion vulnerability in index.php in WEBInsta CMS 0.3.1 and possibly earlier allows remote attackers
23RISCO
abrir
ReferênciaVexDay Proof
PNPHPBB2 < 1.2g - 'phpbb_root_path' Remote File Inclusion
CVE-2006-4968webappsphp
PHP remote file inclusion vulnerability in includes/functions_admin.php in PNphpBB 1.2g allows remote attackers to execu
23RISCO
abrir
anteriorpágina 158 / 717próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.