Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.596exploits catalogados
36.656CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
FlaP 1.0b - 'pachtofile' Remote File Inclusion
CVE-2007-2940webappsphp
Multiple PHP remote file inclusion vulnerabilities in FlaP 1.0b (1.0 Beta) allow remote attackers to execute arbitrary P
23RISCO
abrir
ReferênciaVexDay Proof
vBulletin vBGSiteMap 2.41 - 'root' Remote File Inclusion
CVE-2007-2941webappsphp
Multiple PHP remote file inclusion vulnerabilities in the creator in vBulletin Google Yahoo Site Map (vBGSiteMap) 2.41 f
23RISCO
abrir
ReferênciaVexDay Proof
OpenBASE 0.6a - 'root_prefix' Remote File Inclusion
CVE-2007-2947webappsphp
Multiple PHP remote file inclusion vulnerabilities in OpenBASE Alpha 0.6 allow remote attackers to execute arbitrary PHP
23RISCO
abrir
ReferênciaVexDay Proof
Affiliate Market 0.1 Beta - Cross-Site Scripting / SQL Injection
CVE-2008-1177webappsphp
SQL injection vulnerability in shop/detail.php in Affiliate Market (affmarket) 0.1 BETA allows remote attackers to execu
23RISCO
abrir
ReferênciaVexDay Proof
Ripe Website Manager (CMS) 0.8.9 - Remote File Inclusion
CVE-2007-3524webappsphp
Multiple PHP remote file inclusion vulnerabilities in Ripe Website Manager 0.8.9 and earlier allow remote attackers to e
35RISCO
abrir
ReferênciaVexDay Proof
Buddy Zone 1.5 - Multiple SQL Injections
CVE-2007-3526webappsphp
Multiple SQL injection vulnerabilities in Buddy Zone 1.5 and earlier allow remote attackers to execute arbitrary SQL com
23RISCO
abrir
ReferênciaVexDay Proof
Traffic Stats - 'referralUrl.php?offset' SQL Injection
CVE-2007-3840webappsphp
SQL injection vulnerability in referralUrl.php in Traffic Stats allows remote attackers to execute arbitrary SQL command
23RISCO
abrir
ReferênciaVexDay Proof
Microsoft Windows RSH daemon 1.7 - Remote Buffer Overflow
CVE-2007-4005remotewindows
Stack-based buffer overflow in Mike Dubman Windows RSH daemon (rshd) 1.7 allows remote attackers to execute arbitrary co
28RISCO
abrir
ReferênciaVexDay Proof
paBugs 2.0 Beta 3 - 'main.php?cid' SQL Injection
CVE-2007-4183webappsphp
SQL injection vulnerability in main.php in paBugs 2.0 Beta 3 and earlier allows remote attackers to execute arbitrary SQ
23RISCO
abrir
ReferênciaVexDay Proof
Microsoft Windows - DHCP Client Broadcast (MS06-036)
CVE-2006-2372remotewindows
Buffer overflow in the DHCP Client service for Microsoft Windows 2000 SP4, Windows XP SP1 and SP2, and Server 2003 up to
45RISCO
abrir
ReferênciaVexDay Proof
PHP 5.2.0 (Windows x86) - 'PHP_win32sti' Local Buffer Overflow
CVE-2007-4441doswindows_x86
Buffer overflow in php_win32std.dll in the win32std extension for PHP 5.2.0 and earlier allows context-dependent attacke
23RISCO
abrir
ReferênciaVexDay Proof
Remote Mouse GUI 3.008 - Local Privilege Escalation
CVE-2021-35448localwindows
Emote Interactive Remote Mouse 3.008 on Windows allows attackers to execute arbitrary programs as Administrator by using
23RISCO
abrir
ReferênciaVexDay Proof
Friendly 1.0d1 - 'friendly_path' Remote File Inclusion
CVE-2007-2569webappsphp
Multiple PHP remote file inclusion vulnerabilities in Friendly 1.0d1 and earlier allow remote attackers to execute arbit
23RISCO
abrir
ReferênciaVexDay Proof
Wikivi5 - 'show.php?sous_rep' Remote File Inclusion
CVE-2007-2570webappsphp
PHP remote file inclusion vulnerability in handlers/page/show.php in Wikivi5 allows remote attackers to execute arbitrar
23RISCO
abrir
ReferênciaVexDay Proof
XOOPS Module wfquotes 1.0 - SQL Injection
CVE-2007-2571webappsphp
SQL injection vulnerability in index.php in the wfquotes 1.0 0 module for XOOPS allows remote attackers to execute arbit
23RISCO
abrir
ReferênciaVexDay Proof
NoAh 0.9 pre 1.2 - 'mfa_theme.php' Remote File Inclusion
CVE-2007-2572webappsphp
PHP remote file inclusion vulnerability in modules/noevents/templates/mfa_theme.php in NoAh (aka PHP Content Architect,
23RISCO
abrir
ReferênciaVexDay Proof
Notepad++ 4.1 (Windows x86) - '.ruby' File Processing Buffer Overflow
CVE-2007-2666localwindows_x86
Stack-based buffer overflow in LexRuby.cxx (SciLexer.dll) in Scintilla 1.73, as used by notepad++ 4.1.1 and earlier, all
28RISCO
abrir
ReferênciaVexDay Proof
webdesproxy 0.0.1 - GET Remote Buffer Overflow
CVE-2007-2668remotewindows
Buffer overflow in webdesproxy 0.0.1 allows remote attackers to execute arbitrary code via a long URL, possibly involvin
23RISCO
abrir
ReferênciaVexDay Proof
LeadTools Thumbnail Browser Control - 'lttmb14E.ocx' Remote Buffer Overflow
CVE-2007-2787remotewindows
Stack-based buffer overflow in the BrowseDir function in the (1) lttmb14E.ocx or (2) LTRTM14e.DLL ActiveX control in Lea
23RISCO
abrir
ReferênciaVexDay Proof
Dokeos 1.8.0 - 'my_progress.php?course' SQL Injection
CVE-2007-2901webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.0 and earlier allow remote attackers to inject arbitra
23RISCO
abrir
ReferênciaVexDay Proof
Quick.Cart 2.2 - Local/Remote File Inclusion / Remote Code Execution
CVE-2007-3138webappsphp
Directory traversal vulnerability in index.php in Open Solution Quick.Cart 2.2 and earlier allows remote attackers to in
23RISCO
abrir
ReferênciaVexDay Proof
Quick.Cart 2.2 - Local/Remote File Inclusion / Remote Code Execution
CVE-2007-3139webappsphp
config/general.php in Quick.Cart 2.2 and earlier uses a default username and password, which allows remote attackers to
23RISCO
abrir
ReferênciaVexDay Proof
Microsoft Windows Explorer - '.GIF' Image Denial of Service
CVE-2007-3958doswindows
Microsoft Windows Explorer (explorer.exe) allows user-assisted remote attackers to cause a denial of service via a certa
28RISCO
abrir
ReferênciaVexDay Proof
PHP 4.4.7/5.2.3 - MySQL/MySQLi 'Safe_Mode' Bypass
CVE-2007-3997localmultiple
The (1) MySQL and (2) MySQLi extensions in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to bypass
28RISCO
abrir
ReferênciaVexDay Proof
Nessus Vulnerability Scanner 3.0.6 - ActiveX Remote Delete File
CVE-2007-4031remotewindows
Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote attac
23RISCO
abrir
ReferênciaVexDay Proof
Adult Directory - 'cat_id' SQL Injection
CVE-2007-4056webappsphp
SQL injection vulnerability in directory.php in Prozilla Adult Directory allows remote attackers to execute arbitrary SQ
23RISCO
abrir
ReferênciaVexDay Proof
Seditio CMS 121 - 'pfs.php' Arbitrary File Upload
CVE-2007-4057webappsphp
Unrestricted file upload vulnerability in pfs.php in Neocrome Seditio 121 and earlier allows remote authenticated users
23RISCO
abrir
ReferênciaVexDay Proof
Envolution 1.1.0 - 'topic' SQL Injection
CVE-2007-4253webappsphp
SQL injection vulnerability in the News module in modules.php in Envolution 1.1.0 and earlier allows remote attackers to
23RISCO
abrir
ReferênciaVexDay Proof
Surgemail 38k - 'Search' Remote Buffer Overflow
CVE-2007-4377remotewindows
Stack-based buffer overflow in the IMAP service in SurgeMail 38k allows remote authenticated users to execute arbitrary
23RISCO
abrir
ReferênciaVexDay Proof
DL PayCart 1.01 - 'viewitem.php?ItemID' Blind SQL Injection
CVE-2007-4604webappsphp
SQL injection vulnerability in viewitem.php in DL PayCart 1.01 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
anteriorpágina 175 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.