Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.526exploits catalogados
36.593CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
DomPHP 0.82 - 'index.php' Local File Inclusion
CVE-2008-0745webappsphp
Directory traversal vulnerability in aides/index.php in DomPHP 0.82 allows remote attackers to include and execute arbit
23RISCO
abrir
ReferênciaVexDay Proof
PHP < 4.4.5/5.2.1 - 'shmop' Local Code Execution
CVE-2007-1376locallinux
The shmop functions in PHP before 4.4.5, and before 5.2.1 in the 5.x series, do not verify that their arguments correspo
28RISCO
abrir
ReferênciaVexDay Proof
MyBulletinBoard (MyBB) 1.2.11 - 'private.php' SQL Injection (1)
CVE-2008-0787webappsphp
SQL injection vulnerability in inc/datahandlers/pm.php in MyBB before 1.2.12 allows remote authenticated users to execut
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component xfaq 1.2 - 'aid' SQL Injection
CVE-2008-0795webappsphp
SQL injection vulnerability in index.php in the MGFi XfaQ (com_xfaq) 1.2 component for Mambo and Joomla! allows remote a
23RISCO
abrir
ReferênciaVexDay Proof
nuBoard 0.5 - 'ssid' SQL Injection
CVE-2008-0796webappsphp
SQL injection vulnerability in threads.php in Nuboard 0.5 allows remote attackers to execute arbitrary SQL commands via
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component Quiz 0.81 - 'tid' SQL Injection
CVE-2008-0799webappsphp
SQL injection vulnerability in index.php in the Quiz (com_quiz) 0.81 and earlier component for Mambo and Joomla! allows
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component paxxgallery 0.2 - 'iid' SQL Injection
CVE-2008-0801webappsphp
SQL injection vulnerability in index.php in the PAXXGallery (com_paxxgallery) 0.2 component for Mambo and Joomla! allow
23RISCO
abrir
ReferênciaVexDay Proof
LookStrike Lan Manager 0.9 - Local/Remote File Inclusion
CVE-2008-0803webappsphp
Multiple PHP remote file inclusion vulnerabilities in LookStrike Lan Manager 0.9 allow remote attackers to execute arbit
35RISCO
abrir
ReferênciaVexDay Proof
Thecus N5200Pro NAS Server Control Panel - Remote File Inclusion
CVE-2008-0804remotehardware
PHP remote file inclusion vulnerability in usrgetform.html in Thecus N5200Pro NAS Server allows remote attackers to exec
23RISCO
abrir
ReferênciaVexDay Proof
Quintessential Player 4.50.1.82 - Playlist Denial of Service (PoC)
CVE-2006-6261doswindows
Buffer overflow in Quintessential Player 4.50.1.82 and earlier allows remote attackers to cause a denial of service (cra
23RISCO
abrir
ReferênciaVexDay Proof
mxBB Module mx_modsdb 1.0 - Remote File Inclusion
CVE-2006-6560webappsphp
PHP remote file inclusion vulnerability in includes/common.php in the mx_modsdb 1.0.0 module for MxBB (aka MX-System) Po
23RISCO
abrir
ReferênciaVexDay Proof
PgmReloaded 0.8.5 - Multiple Remote File Inclusions
CVE-2006-6710webappsphp
Multiple PHP remote file inclusion vulnerabilities in PgmReloaded 0.8.5 and earlier allow remote attackers to execute ar
23RISCO
abrir
ReferênciaVexDay Proof
Creative Software AutoUpdate Engine - ActiveX Stack Overflow
CVE-2008-0955remotewindows
Stack-based buffer overflow in the Creative Software AutoUpdate Engine ActiveX control in CTSUEng.ocx allows remote atta
50RISCO
abrir
ReferênciaVexDay Proof
SNMPv3 - HMAC Validation error Remote Authentication Bypass
CVE-2008-0960remotemultiple
SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-S
35RISCO
abrir
ReferênciaVexDay Proof
Sun Solaris 10 - snoop(1M) Utility Remote Command Execution
CVE-2008-0964remotesolaris
Multiple stack-based buffer overflows in snoop on Sun Solaris 8 through 10 and OpenSolaris before snv_96, when the -o op
28RISCO
abrir
ReferênciaVexDay Proof
DBHcms 1.1.4 - 'code' Remote File Inclusion
CVE-2008-1038webappsphp
PHP remote file inclusion vulnerability in mod/mod.extmanager.php in DBHcms 1.1.4 and earlier allows remote attackers to
23RISCO
abrir
ReferênciaVexDay Proof
PORAR WebBoard - 'question.asp' SQL Injection
CVE-2008-1039webappsasp
SQL injection vulnerability in question.asp in PORAR WEBBOARD allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
ReferênciaVexDay Proof
PHP Download Manager 1.1 - Local File Inclusion
CVE-2008-1042webappsphp
Directory traversal vulnerability in include/body.inc.php in Linux Web Shop (LWS) php Download Manager 1.0 and 1.1 allow
23RISCO
abrir
ReferênciaVexDay Proof
PHPUserBase 1.3b - 'unverified.inc.php' Remote File Inclusion
CVE-2008-1043webappsphp
PHP remote file inclusion vulnerability in templates/default/header.inc.php in Linux Web Shop (LWS) php User Base 1.3 BE
35RISCO
abrir
ReferênciaVexDay Proof
Quinsonnas Mail Checker 1.55 - 'footer.php' Remote File Inclusion
CVE-2008-1046webappsphp
PHP remote file inclusion vulnerability in footer.php in Quinsonnas Mail Checker 1.55 allows remote attackers to execute
28RISCO
abrir
ReferênciaVexDay Proof
PHP-Nuke Module Kose_Yazilari - 'artid' SQL Injection
CVE-2008-1053webappsphp
Multiple SQL injection vulnerabilities in the Kose_Yazilari module for PHP-Nuke allow remote attackers to execute arbitr
23RISCO
abrir
ReferênciaVexDay Proof
PHP 5.2.1 with PECL PHPDOC - Local Buffer Overflow
CVE-2007-1709localwindows
Buffer overflow in the confirm_phpdoc_compiled function in the phpDOC extension (PECL phpDOC) in PHP 5.2.1 allows contex
23RISCO
abrir
ReferênciaVexDay Proof
Active Auction Pro 7.1 - 'default.asp?catid' SQL Injection
CVE-2007-1712webappsasp
SQL injection vulnerability in default.asp in ActiveWebSoftwares Active Auction Pro 7.1 allows remote attackers to execu
23RISCO
abrir
ReferênciaVexDay Proof
C-Arbre 0.6PR7 - 'ROOT_PATH' Remote File Inclusion
CVE-2007-1721webappsphp
Multiple PHP remote file inclusion vulnerabilities in C-Arbre 0.6PR7 and earlier allow remote attackers to execute arbit
28RISCO
abrir
ReferênciaVexDay Proof
IceBB 1.0-rc5 - Remote Create Admin
CVE-2007-1725webappsphp
SQL injection vulnerability in index.php in IceBB 1.0-rc5 allows remote authenticated users to execute arbitrary SQL com
23RISCO
abrir
ReferênciaVexDay Proof
NaviCOPA Web Server 2.01 - Remote Buffer Overflow (Metasploit)
CVE-2007-1733remotewindows
Buffer overflow in InterVations NaviCOPA HTTP Server 2.01 allows remote attackers to execute arbitrary code via a long (
28RISCO
abrir
ReferênciaVexDay Proof
Softerra Time-Assistant 6.2 - 'inc_dir' Remote File Inclusion
CVE-2007-1787webappsphp
Multiple PHP remote file inclusion vulnerabilities in lib/timesheet.class.php in Softerra Time-Assistant 6.2 and earlier
23RISCO
abrir
ReferênciaVexDay Proof
eXtremail 2.1.1 - DNS Parsing Bugs Remote (PoC)
CVE-2007-2187doslinux
Stack-based buffer overflow in eXtremail 2.1.1 and earlier allows remote attackers to execute arbitrary code via a long
23RISCO
abrir
ReferênciaVexDay Proof
Vizayn Haber - 'haberdetay.asp?id' SQL Injection
CVE-2007-0052webappsasp
SQL injection vulnerability in haberdetay.asp in Vizayn Haber allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
ReferênciaVexDay Proof
PHPSherpa - '/include/config.inc.php' Remote File Inclusion
CVE-2007-0495webappsphp
PHP remote file inclusion vulnerability in include/config.inc.php in PhpSherpa allows remote attackers to execute arbitr
23RISCO
abrir
anteriorpágina 174 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.