Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.596exploits catalogados
36.656CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
TUTOS 1.3 - 'cmd.php' Remote Command Execution
CVE-2008-0149webappsphp
TUTOS 1.3 allows remote attackers to read system information via a direct request to php/admin/phpinfo.php, which calls
23RISCO
abrir
ReferênciaVexDay Proof
FlexBB 0.6.3 - Cookies SQL Injection
CVE-2008-0157webappsphp
SQL injection vulnerability in FlexBB 0.6.3 and earlier allows remote attackers to execute arbitrary SQL commands via th
23RISCO
abrir
ReferênciaVexDay Proof
Gateway Weblaunch - ActiveX Control Insecure Method
CVE-2008-0220remotewindows
Multiple stack-based buffer overflows in the WebLaunch.WeblaunchCtl.1 (aka CWebLaunchCtl) ActiveX control in weblaunch.o
28RISCO
abrir
ReferênciaVexDay Proof
Gateway WebLaunch - ActiveX Remote Buffer Overflow
CVE-2008-0220remotewindows
Multiple stack-based buffer overflows in the WebLaunch.WeblaunchCtl.1 (aka CWebLaunchCtl) ActiveX control in weblaunch.o
28RISCO
abrir
ReferênciaVexDay Proof
osData 2.08 Modules Php121 - Local File Inclusion
CVE-2008-0230webappsphp
PHP remote file inclusion vulnerability in php121db.php in osDate 2.0.8 and possibly earlier versions allows remote atta
23RISCO
abrir
ReferênciaVexDay Proof
ZeroCMS 1.0 Alpha - Arbitrary File Upload / SQL Injection
CVE-2008-0232webappsphp
Multiple SQL injection vulnerabilities in Zero CMS 1.0 Alpha allow remote attackers to execute arbitrary SQL commands vi
23RISCO
abrir
ReferênciaVexDay Proof
Binn SBuilder - 'nid' Blind SQL Injection
CVE-2008-0253webappsphp
SQL injection vulnerability in full_text.php in Binn SBuilder allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
ReferênciaVexDay Proof
TutorialCMS 1.02 - 'Username' SQL Injection
CVE-2008-0254webappsphp
SQL injection vulnerability in activate.php in TutorialCMS (aka Photoshop Tutorials) 1.02, when magic_quotes_gpc is disa
23RISCO
abrir
ReferênciaVexDay Proof
iGaming CMS 1.3.1/1.5 - SQL Injection
CVE-2008-0255webappsphp
SQL injection vulnerability in archive.php in iGaming 1.5, and 1.3.1 and earlier, allows remote attackers to execute arb
23RISCO
abrir
ReferênciaVexDay Proof
ASP Photo Gallery 1.0 - Multiple SQL Injections
CVE-2008-0256webappsasp
Multiple SQL injection vulnerabilities in Matteo Binda ASP Photo Gallery 1.0 allow remote attackers to execute arbitrary
23RISCO
abrir
ReferênciaVexDay Proof
minimal Gallery 0.8 - Remote File Disclosure
CVE-2008-0260webappsphp
minimal Gallery 0.8 allows remote attackers to obtain configuration information via a direct request to php_info.php, wh
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component Highwood Design hwdVideoShare - SQL Injection
CVE-2008-0916webappsphp
SQL injection vulnerability in the Highwood Design hwdVideoShare (com_hwdvideoshare) 1.1.3 Alpha component for Joomla!
23RISCO
abrir
ReferênciaVexDay Proof
OSSIM 0.9.9rc5 - Cross-Site Scripting / SQL Injection
CVE-2008-0920webappsphp
SQL injection vulnerability in port/modifyportform.php in Open Source Security Information Management (OSSIM) 0.9.9 rc5
23RISCO
abrir
ReferênciaVexDay Proof
BeContent 031 - 'id' SQL Injection
CVE-2008-0921webappsphp
SQL injection vulnerability in news.php in beContent 0.3.1 allows remote attackers to execute arbitrary SQL commands via
23RISCO
abrir
ReferênciaVexDay Proof
Microsoft Windows Server 2000 - UPNP 'getdevicelist' Memory Leak Denial of Service
CVE-2005-3644doswindows
PNP_GetDeviceList (upnp_getdevicelist) in UPnP for Microsoft Windows 2000 SP4 and earlier, and possibly Windows XP SP1 a
35RISCO
abrir
ReferênciaVexDay Proof
phpQLAdmin 2.2.7 - Multiple Remote File Inclusions
CVE-2008-1067webappsphp
Multiple PHP remote file inclusion vulnerabilities in phpQLAdmin 2.2.7 allow remote attackers to execute arbitrary PHP c
28RISCO
abrir
ReferênciaVexDay Proof
GROUP-E 1.6.41 - 'head_auth.php' Remote File Inclusion
CVE-2008-1074webappsphp
PHP remote file inclusion vulnerability in lib/head_auth.php in GROUP-E 1.6.41 allows remote attackers to execute arbitr
35RISCO
abrir
ReferênciaVexDay Proof
Microsoft Windows - GDI (CreateDIBPatternBrushPt) Heap Overflow (PoC)
CVE-2008-1083HIGHdoswindows
Heap-based buffer overflow in the CreateDIBPatternBrushPt function in GDI in Microsoft Windows 2000 SP4, XP SP2, Server
53RISCO
abrir
ReferênciaVexDay Proof
Cisco IP Phone 7940 - Reboot (Denial of Service)
CVE-2006-0179doshardware
The Cisco IP Phone 7940 allows remote attackers to cause a denial of service (reboot) via a large amount of TCP SYN pack
28RISCO
abrir
ReferênciaVexDay Proof
Winamp 5.12 - '.pls' Remote Buffer Overflow (Perl) (2)
CVE-2006-0476remotewindows
Buffer overflow in Nullsoft Winamp 5.12 allows remote attackers to execute arbitrary code via a playlist (pls) file with
60RISCO
abrir
ReferênciaVexDay Proof
phpBB Mod FileBase 2.0 - 'id' SQL Injection
CVE-2008-1305webappsphp
SQL injection vulnerability in filebase.php in the Filebase mod for phpBB allows remote attackers to execute arbitrary S
23RISCO
abrir
ReferênciaVexDay Proof
EasyCalendar 4.0tr - Multiple Vulnerabilities
CVE-2008-1345webappsphp
Cross-site scripting (XSS) vulnerability in plugins/calendar/calendar_backend.php in MyioSoft EasyCalendar 4.0tr and ear
23RISCO
abrir
ReferênciaVexDay Proof
Admbook 1.2.2 - 'x-forwarded-for' Remote Command Execution
CVE-2006-0852webappsphp
Direct static code injection vulnerability in write.php in Admbook 1.2.2 and earlier allows remote attackers to execute
23RISCO
abrir
ReferênciaVexDay Proof
vuBB 0.2 Final - 'cookie' SQL Injection
CVE-2006-0962webappsphp
SQL injection vulnerability in vuBB 0.2 allows remote attackers to execute arbitrary SQL commands via the pass parameter
23RISCO
abrir
ReferênciaVexDay Proof
Lansuite 2.1.0 Beta - 'fid' SQL Injection
CVE-2006-1001webappsphp
SQL injection vulnerability in the board module in LanSuite LanParty Intranet System 2.0.6 and 2.1.0 beta allows remote
23RISCO
abrir
ReferênciaVexDay Proof
PHP Ticket 0.71 - 'search.php' SQL Injection
CVE-2006-1481webappsphp
SQL injection vulnerability in search.php in PHP Ticket 0.71 allows remote authenticated users to execute arbitrary SQL
23RISCO
abrir
ReferênciaVexDay Proof
Microsoft Office Products - Array Index Bounds Error (PoC)
CVE-2006-1540doswindows
MSO.DLL in Microsoft Office 2000, Office XP (2002), and Office 2003 allows user-assisted attackers to cause a denial of
28RISCO
abrir
ReferênciaVexDay Proof
Python 2.4.2 - 'realpath()' Local Stack Overflow
CVE-2006-1542locallinux
Stack-based buffer overflow in Python 2.4.2 and earlier, running on Linux 2.6.12.5 under gcc 4.0.3 with libc 2.3.5, allo
23RISCO
abrir
ReferênciaVexDay Proof
Simplog 0.9.2 - 's' Remote Command Execution
CVE-2006-1778webappsphp
Multiple SQL injection vulnerabilities in Jeremy Ashcraft Simplog 0.9.2 and earlier allow remote attackers to execute ar
23RISCO
abrir
ReferênciaVexDay Proof
Monster Top List 1.4.2 - 'functions.php?root_path' Remote File Inclusion
CVE-2006-1781webappsphp
PHP remote file inclusion vulnerability in functions.php in Circle R Monster Top List (MTL) 1.4 allows remote attackers
23RISCO
abrir
anteriorpágina 178 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.