Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.526exploits catalogados
36.593CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
SoftBB 0.1 - 'cmd' Remote Command Execution
CVE-2006-4633webappsphp
index.php in SoftBB 0.1, and possibly earlier, allows remote attackers to obtain the installation path via a null or inv
23RISCO
abrir
ReferênciaVexDay Proof
GeekLog 1.4.0sr3 - '_CONF[path]' Remote File Inclusion
CVE-2006-6225webappsphp
Multiple PHP remote file inclusion vulnerabilities in GeekLog 1.4 allow remote attackers to execute arbitrary code via a
23RISCO
abrir
ReferênciaVexDay Proof
Woltlab Burning Board Lite 1.0.2 - 'decode_cookie()' SQL Injection
CVE-2006-6237webappsphp
SQL injection vulnerability in the decode_cookie function in thread.php in Woltlab Burning Board Lite 1.0.2 allows remot
23RISCO
abrir
ReferênciaVexDay Proof
Magic News Pro 1.0.3 - 'script_path' Remote File Inclusion
CVE-2006-4823webappsphp
PHP remote file inclusion vulnerability in scripts/news_page.php in Reamday Enterprises Magic News Pro 1.0.3 and earlier
23RISCO
abrir
ReferênciaVexDay Proof
The Classified Ad System 1.0 - 'main' SQL Injection
CVE-2006-6349webappsasp
Multiple SQL injection vulnerabilities in PWP Technologies The Classified Ad System allow remote attackers to execute ar
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component ChronoForms 2.3.5 - Remote File Inclusion
CVE-2008-0567webappsphp
Multiple PHP remote file inclusion vulnerabilities in ChronoEngine ChronoForms (com_chronocontact) 2.3.5 component for J
35RISCO
abrir
ReferênciaVexDay Proof
Downstat 1.8 - 'art' Remote File Inclusion
CVE-2006-4827webappsphp
Multiple PHP remote file inclusion vulnerabilities in Vmist Downstat 1.8 and earlier allow remote attackers to execute a
23RISCO
abrir
ReferênciaVexDay Proof
Mindmeld 1.2.0.10 - Multiple Remote File Inclusions
CVE-2008-0572webappsphp
Multiple PHP remote file inclusion vulnerabilities in Mindmeld 1.2.0.10 allow remote attackers to execute arbitrary PHP
28RISCO
abrir
ReferênciaVexDay Proof
SafeNet 10.4.0.12 - 'IPSecDrv.sys' Local kernel Ring0 SYSTEM
CVE-2008-0573localwindows
IPSecDrv.sys 10.4.0.12 in SafeNET HighAssurance Remote and SoftRemote allows local users to gain privileges via a crafte
23RISCO
abrir
ReferênciaVexDay Proof
Libxine 1.14 - MPEG Stream Buffer Overflow (PoC)
CVE-2006-1664doslinux
Buffer overflow in xine_list_delete_current in libxine 1.14 and earlier, as distributed in xine-lib 1.1.1 and earlier, a
28RISCO
abrir
ReferênciaVexDay Proof
Crafty Syntax Image Gallery 3.1g - Remote Code Execution
CVE-2006-1667webappsphp
SQL injection vulnerability in slides.php in Eric Gerdes Crafty Syntax Image Gallery (CSIG) (aka PHP thumbnail Photo Gal
23RISCO
abrir
ReferênciaVexDay Proof
PhotoKorn Gallery 1.543 - 'pic' SQL Injection
CVE-2008-0614webappsphp
SQL injection vulnerability in index.php in Photokorn Gallery 1.543 allows remote attackers to execute arbitrary SQL com
23RISCO
abrir
ReferênciaVexDay Proof
NERO Media Player 1.4.0.35b - '.m3u' File Buffer Overflow (PoC)
CVE-2008-0619doswindows
Buffer overflow in NeroMediaPlayer.exe in Nero Media Player 1.4.0.35 and earlier allows remote attackers to execute arbi
28RISCO
abrir
ReferênciaVexDay Proof
GNUTURK 2G - 't_id' SQL Injection
CVE-2006-4867webappsphp
SQL injection vulnerability in mods.php in GNUTurk 2G and earlier allows remote attackers to execute arbitrary SQL comma
23RISCO
abrir
ReferênciaVexDay Proof
PHP-Update 2.7 - '/admin/uploads.php' Remote Code Execution
CVE-2006-6879webappsphp
Unrestricted file upload vulnerability in admin/uploads.php in PHP-Update 2.7 and earlier allows remote authenticated us
23RISCO
abrir
ReferênciaVexDay Proof
PHP-Update 2.7 - Multiple Vulnerabilities
CVE-2006-6879webappsphp
Unrestricted file upload vulnerability in admin/uploads.php in PHP-Update 2.7 and earlier allows remote authenticated us
23RISCO
abrir
ReferênciaVexDay Proof
phpunity.postcard - 'gallery_path' Remote File Inclusion
CVE-2006-4869webappsphp
PHP remote file inclusion vulnerability in phpunity-postcard.php in phpunity.postcard allows remote attackers to execute
23RISCO
abrir
ReferênciaVexDay Proof
Linux Kernel 2.6.x - 'sys_timer_create()' Local Denial of Service
CVE-2006-7051doslinux
The sys_timer_create function in posix-timers.c for Linux kernel 2.6.x allows local users to cause a denial of service (
23RISCO
abrir
ReferênciaVexDay Proof
Ipswitch WS_FTP LE 5.08 - PASV Response Remote Buffer Overflow
CVE-2006-4974remotewindows
Buffer overflow in Ipswitch WS_FTP Limited Edition (LE) 5.08 allows remote FTP servers to execute arbitrary code via a l
23RISCO
abrir
ReferênciaVexDay Proof
phpQuiz 0.1.2 - SQL Injection / Code Execution
CVE-2006-4977webappsphp
Multiple unrestricted file upload vulnerabilities in (1) back/upload_img.php and (2) admin/upload_img.php in Walter Besc
23RISCO
abrir
ReferênciaVexDay Proof
phpBB SpamBlocker Mod 1.0.2 - Remote File Inclusion
CVE-2006-5301webappsphp
PHP remote file inclusion vulnerability in includes/antispam.php in the SpamBlockerMODv 1.0.2 and earlier module for php
23RISCO
abrir
ReferênciaVexDay Proof
Redaction System 1.0 - 'lang_prefix' Remote File Inclusion
CVE-2006-5302webappsphp
Multiple PHP remote file inclusion vulnerabilities in Redaction System 1.0000 allow remote attackers to execute arbitrar
23RISCO
abrir
ReferênciaVexDay Proof
Transmit.app 3.5.5 - 'ftps://' URL Handler Heap Buffer Overflow (PoC)
CVE-2007-0020dososx
Heap-based buffer overflow in the SFTP protocol handler for Panic Transmit (Transmit.app) up to 3.5.5 allows remote atta
23RISCO
abrir
ReferênciaVexDay Proof
Yahoo! Music Jukebox 2.2 - 'AddImage()' ActiveX Remote Buffer Overflow (1)
CVE-2008-0623remotewindows
Stack-based buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! Music Jukebox 2.2.2.056 allows
23RISCO
abrir
ReferênciaVexDay Proof
Yahoo! Music Jukebox 2.2 - 'AddImage()' ActiveX Remote Buffer Overflow (2)
CVE-2008-0623remotewindows
Stack-based buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! Music Jukebox 2.2.2.056 allows
23RISCO
abrir
ReferênciaVexDay Proof
Yahoo! Music JukeBox 2.2 - 'AddButton()' ActiveX Remote Buffer Overflow
CVE-2008-0624remotewindows
Buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! JukeBox 2.2.2.56 allows remote attackers to
23RISCO
abrir
ReferênciaVexDay Proof
EPNadmin 0.7 - 'constantes.inc.php' Remote File Inclusion
CVE-2006-5555webappsphp
PHP remote file inclusion vulnerability in constantes.inc.php in EPNadmin 0.7 and 0.7.1 allows remote attackers to execu
23RISCO
abrir
ReferênciaVexDay Proof
HP-UX 11i - 'swmodify' Local Stack Overflow / Local Privilege Escalation
CVE-2006-5557localhp-ux
Stack-based buffer overflow in the (1) swpackage and (2) swmodify commands in HP-UX B.11.11 and possibly other versions
23RISCO
abrir
ReferênciaVexDay Proof
HP-UX 11i - 'swpackage' Local Stack Overflow / Local Privilege Escalation
CVE-2006-5557localhp-ux
Stack-based buffer overflow in the (1) swpackage and (2) swmodify commands in HP-UX B.11.11 and possibly other versions
23RISCO
abrir
ReferênciaVexDay Proof
phpProfiles 2.1 Beta - Multiple Remote File Inclusions
CVE-2006-5634webappsphp
Multiple PHP remote file inclusion vulnerabilities in phpProfiles 2.1 Beta allow remote attackers to execute arbitrary P
23RISCO
abrir
anteriorpágina 172 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.