Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.794exploits catalogados
36.057CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
Wysi Wiki Wyg 1.0 - Local File Inclusion / Cross-Site Scripting / PHPInfo
CVE-2008-5323webappsphp
Cross-site scripting (XSS) vulnerability in index.php in Wysi Wiki Wyg 1.0 allows remote attackers to inject arbitrary w
23RISCO
abrir
ReferênciaVexDay Proof
Nitrotech 0.0.3a - Remote File Inclusion / SQL Injection
CVE-2008-5334webappsphp
PHP remote file inclusion vulnerability in includes/common.php in NitroTech 0.0.3a allows remote attackers to execute ar
23RISCO
abrir
ReferênciaVexDay Proof
PHP FirstPost 0.1 - 'block.php?Include' Remote File Inclusion
CVE-2007-2665webappsphp
PHP remote file inclusion vulnerability in block.php in PhpFirstPost 0.1 allows remote attackers to execute arbitrary PH
23RISCO
abrir
ReferênciaVexDay Proof
DMXReady Secure Document Library 1.1 - SQL Injection
CVE-2009-0428webappsphp
SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Secure Document Library 1.1 and ear
23RISCO
abrir
ReferênciaVexDay Proof
PHP-Fusion 7.00.1 - 'messages.php' SQL Injection
CVE-2008-5335webappsphp
SQL injection vulnerability in messages.php in PHP-Fusion 6.01.15 and 7.00.1, when magic_quotes_gpc is disabled, allows
23RISCO
abrir
ReferênciaVexDay Proof
Cain & Abel 4.9.24 - '.rdp' Local Stack Overflow
CVE-2008-5405localwindows
Stack-based buffer overflow in the RDP protocol password decoder in Cain & Abel 4.9.23 and 4.9.24, and possibly earlier,
50RISCO
abrir
ReferênciaVexDay Proof
XOOPS myAds Module - 'lid' SQL Injection
CVE-2006-3341webappsphp
SQL injection vulnerability in annonces-p-f.php in MyAds module 2.04jp for Xoops allows remote attackers to execute arbi
23RISCO
abrir
ReferênciaVexDay Proof
Censura 1.15.04 - 'censura.php?vendorid' SQL Injection
CVE-2007-2673webappsphp
SQL injection vulnerability in includes/funcs_vendors.php in Censura 1.15.04, and other versions before 1.16.04, allows
23RISCO
abrir
ReferênciaVexDay Proof
Pre Classifieds Listings 1.0 - SQL Injection
CVE-2007-2675webappsphp
SQL injection vulnerability in search.php in Pre Classifieds Listings 1.0 allows remote attackers to execute arbitrary S
23RISCO
abrir
ReferênciaVexDay Proof
Microsoft SQL Server - 'sp_replwritetovarbin()' Heap Overflow
CVE-2008-5416localwindows
Heap-based buffer overflow in Microsoft SQL Server 2000 SP4, 8.00.2050, 8.00.2039, and earlier; SQL Server 2000 Desktop
60RISCO
abrir
ReferênciaVexDay Proof
Open Translation Engine (OTE) 0.7.8 - 'header.php?ote_home' Remote File Inclusion
CVE-2007-2676webappsphp
PHP remote file inclusion vulnerability in skins/header.php in Open Translation Engine (OTE) 0.7.8 allows remote attacke
35RISCO
abrir
ReferênciaVexDay Proof
yahoo answers - 'id' SQL Injection
CVE-2008-5490webappsphp
SQL injection vulnerability in index.php in PHPStore Yahoo Answers allows remote attackers to execute arbitrary SQL comm
23RISCO
abrir
ReferênciaVexDay Proof
SlimCMS 1.0.0 - 'edit.php' SQL Injection
CVE-2008-5491webappsphp
SQL injection vulnerability in edit.php in SlimCMS 1.0.0 and earlier allows remote attackers to execute arbitrary SQL co
23RISCO
abrir
ReferênciaVexDay Proof
linksnet newsfeed 1.0 - Remote File Inclusion
CVE-2007-2707webappsphp
PHP remote file inclusion vulnerability in linksnet_linkslog_rss.php in Linksnet Newsfeed 1.0 allows remote attackers to
35RISCO
abrir
ReferênciaVexDay Proof
SAP MaxDB 7.6.03.07 - Remote Command Execution
CVE-2008-0244remotemultiple
SAP MaxDB 7.6.03 build 007 and earlier allows remote attackers to execute arbitrary commands via "&&" and other shell me
60RISCO
abrir
ReferênciaVexDay Proof
WEBalbum 2.4b - 'id' Blind SQL Injection
CVE-2009-0446webappsphp
SQL injection vulnerability in photo.php in WEBalbum 2.4b allows remote attackers to execute arbitrary SQL commands via
23RISCO
abrir
ReferênciaVexDay Proof
SkaLinks 1.5 - Authentication Bypass
CVE-2009-0451webappsphp
SQL injection vulnerability in Skalfa SkaLinks 1.5 allows remote attackers to execute arbitrary SQL commands via the Adm
23RISCO
abrir
ReferênciaVexDay Proof
VeryPDF PDFView - OCX ActiveX OpenPDF Heap Overflow (PoC)
CVE-2008-5492doswindows
Heap-based buffer overflow in the PDFVIEW.PdfviewCtrl.1 ActiveX control in pdfview.ocx 2.0.0.1 in VeryDOC PDF Viewer OCX
50RISCO
abrir
ReferênciaVexDay Proof
PHPstore Wholesale - 'id' SQL Injection
CVE-2008-5493webappsphp
SQL injection vulnerability in track.php in PHPStore Wholesales (aka Wholesale) allows remote attackers to execute arbit
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component Contact Info 1.0 - SQL Injection
CVE-2008-5494webappsphp
SQL injection vulnerability in the Contact Information Module (com_contactinfo) component 1.0 for Joomla! allows remote
23RISCO
abrir
ReferênciaVexDay Proof
Alstrasoft Live Support 1.21 - Admin Credential Retrieve
CVE-2007-2775webappsphp
AlstraSoft Live Support 1.21 sends a redirect to the web browser but does not exit when administrative credentials are m
23RISCO
abrir
ReferênciaVexDay Proof
PozScripts Business Directory Script - 'cid' SQL Injection
CVE-2008-5496webappsphp
SQL injection vulnerability in showcategory.php in PozScripts Business Directory Script allows remote attackers to execu
23RISCO
abrir
ReferênciaVexDay Proof
Apache Geronimo 2.1.3 - Multiple Directory Traversal Vulnerabilities
CVE-2008-5518remotemultiple
Multiple directory traversal vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1
35RISCO
abrir
ReferênciaVexDay Proof
postecards - SQL Injection / File Disclosure
CVE-2008-5559webappsasp
SQL injection vulnerability in sendcard.cfm in PostEcards allows remote attackers to execute arbitrary SQL commands via
23RISCO
abrir
ReferênciaVexDay Proof
Euphonics Audio Player 1.0 (Windows XP SP3) - '.pls' Local Buffer Overflow
CVE-2009-0476localwindows
Stack-based buffer overflow in MultiMedia Soft AdjMmsEng.dll 7.11.1.0 and 7.11.2.7, as distributed in multiple MultiMedi
50RISCO
abrir
ReferênciaVexDay Proof
postecards - SQL Injection / File Disclosure
CVE-2008-5560webappsasp
PostEcards stores sensitive information under the web root with insufficient access control, which allows remote attacke
23RISCO
abrir
ReferênciaVexDay Proof
Netref 4.0 - Multiple SQL Injections
CVE-2008-5561webappsphp
SQL injection vulnerability in Netref 4.0 allows remote attackers to execute arbitrary SQL commands via the id parameter
23RISCO
abrir
ReferênciaVexDay Proof
DL PayCart 1.34 - Admin Password Changing
CVE-2008-5565webappsphp
Cross-site request forgery (CSRF) vulnerability in admin/settings.php in DL PayCart 1.34 and earlier allows remote attac
23RISCO
abrir
ReferênciaVexDay Proof
Bonza Cart 1.10 - Admin Password Changing
CVE-2008-5567webappsphp
Cross-site request forgery (CSRF) vulnerability in admin/ad_settings.php in Bonza Cart 1.10 and earlier allows remote at
23RISCO
abrir
ReferênciaVexDay Proof
Squid < 3.1 5 - HTTP Version Number Parsing Denial of Service
CVE-2009-0478dosmultiple
Squid 2.7 to 2.7.STABLE5, 3.0 to 3.0.STABLE12, and 3.1 to 3.1.0.4 allows remote attackers to cause a denial of service v
45RISCO
abrir
anteriorpágina 17 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.