Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.697exploits catalogados
36.715CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
Microsoft Internet Explorer 6 - 'Content-Type' Stack Overflow Crash
CVE-2006-5162doswindows
wininet.dll in Microsoft Internet Explorer 6.0 SP2 and earlier allows remote attackers to cause a denial of service (unh
35RISCO
abrir
ReferênciaVexDay Proof
PPA Gallery 1.0 - 'functions.inc.php' Remote File Inclusion
CVE-2006-5165webappsphp
PHP remote file inclusion vulnerability in inc/functions.inc.php in Skrypty PPA Gallery 1.0 and earlier allows remote at
23RISCO
abrir
ReferênciaVexDay Proof
BasiliX 1.1.1 - 'BSX_LIBDIR' Remote File Inclusion
CVE-2006-5167webappsphp
Multiple PHP remote file inclusion vulnerabilities in BasiliX 1.1.1 and earlier allow remote attackers to execute arbitr
23RISCO
abrir
ReferênciaVexDay Proof
Newswriter SW 1.4.2 - 'main.inc.php' Remote File Inclusion
CVE-2006-5180webappsphp
PHP remote file inclusion vulnerability in include/main.inc.php in Sebastian Baumann and Philipp Wolfer Newswriter SW 1.
23RISCO
abrir
ReferênciaVexDay Proof
Dimension of phpBB 0.2.6 - 'phpbb_root_path' Remote File Inclusions
CVE-2006-5222webappsphp
Multiple PHP remote file inclusion vulnerabilities in Dimension of phpBB 0.2.6 and earlier allow remote attackers to exe
23RISCO
abrir
ReferênciaVexDay Proof
FreeForum 0.9.7 - 'forum.php' Remote File Inclusion
CVE-2006-5230webappsphp
PHP remote file inclusion vulnerability in forum.php in FreeForum 0.9.7 and earlier allows remote attackers to execute a
23RISCO
abrir
ReferênciaVexDay Proof
Ciamos CMS 0.9.6b - 'config.php' Remote File Inclusion
CVE-2006-5257webappsphp
PHP remote file inclusion vulnerability in modules/forum/include/config.php in Ciamos Content Management System (CMS) 0.
23RISCO
abrir
ReferênciaVexDay Proof
compteur 2.0 - 'param_editor.php' Remote File Inclusion
CVE-2006-5259webappsphp
PHP remote file inclusion vulnerability in param_editor.php in Compteur 2 allows remote attackers to execute arbitrary P
23RISCO
abrir
ReferênciaVexDay Proof
PHPMyNews 1.4 - 'cfg_include_dir' Remote File Inclusion
CVE-2006-5261webappsphp
Multiple PHP remote file inclusion vulnerabilities in PHPMyNews 1.4 and earlier allow remote attackers to execute arbitr
23RISCO
abrir
ReferênciaVexDay Proof
phpMyAgenda 3.1 - '/templates/header.php3' Local File Inclusion
CVE-2006-5263webappsphp
Directory traversal vulnerability in templates/header.php3 in phpMyAgenda 3.1 and earlier allows remote attackers to inc
23RISCO
abrir
ReferênciaVexDay Proof
Snort 2.6.1 - DCE/RPC Preprocessor Remote Buffer Overflow (Denial of Service) (PoC)
CVE-2006-5276dosmultiple
Stack-based buffer overflow in the DCE/RPC preprocessor in Snort before 2.6.1.3, and 2.7 before beta 2; and Sourcefire I
60RISCO
abrir
ReferênciaVexDay Proof
n@board 3.1.9e - 'naboard_pnr.php' Remote File Inclusion
CVE-2006-5281webappsphp
PHP remote file inclusion vulnerability in naboard_pnr.php in n@board 3.1.9e and earlier allows remote attackers to exec
23RISCO
abrir
ReferênciaVexDay Proof
SH-News 3.1 - 'scriptpath' Remote File Inclusion
CVE-2006-5282webappsphp
Multiple PHP remote file inclusion vulnerabilities in SH-News 3.1 and earlier allow remote attackers to execute arbitrar
23RISCO
abrir
ReferênciaVexDay Proof
PHP News Reader 2.6.4 - 'phpBB.inc.php' Remote File Inclusion
CVE-2006-5284webappsphp
PHP remote file inclusion vulnerability in auth/phpbb.inc.php in Shen Cheng-Da PHP News Reader (aka pnews) 2.6.4 and ear
23RISCO
abrir
ReferênciaVexDay Proof
vTiger CRM 4.2 - 'calpath' Multiple Remote File Inclusions
CVE-2006-5289webappsphp
Multiple PHP remote file inclusion vulnerabilities in Vtiger CRM 4.2 and earlier allow remote attackers to execute arbit
23RISCO
abrir
ReferênciaVexDay Proof
Xfire 1.6.4 - Remote Denial of Service
CVE-2006-5391doswindows
Xfire 1.64 and earlier allows remote attackers to cause a denial of service (client application crash) via a long string
23RISCO
abrir
ReferênciaVexDay Proof
WSN Forum 1.3.4 - 'prestart.php' Remote Code Execution
CVE-2006-5421webappsphp
WSN Forum 1.3.4 and earlier allows remote attackers to execute arbitrary PHP code via a modified pathname in the pathtoc
23RISCO
abrir
ReferênciaVexDay Proof
LoCal Calendar 1.1 - 'lcUser.php' Remote File Inclusion
CVE-2006-5426webappsphp
PHP remote file inclusion vulnerability in lib/lcUser.php in LoCal Calendar System 1.1 remote attackers to execute arbit
23RISCO
abrir
ReferênciaVexDay Proof
webSPELL 4.01.01 - 'getsquad' SQL Injection
CVE-2006-5388webappsphp
SQL injection vulnerability in index.php in WebSPELL 4.01.01 and earlier allows remote attackers to execute arbitrary SQ
23RISCO
abrir
ReferênciaVexDay Proof
phpBB ACP User Registration Mod 1.0 - Remote File Inclusion
CVE-2006-5390webappsphp
PHP remote file inclusion vulnerability in includes/functions_mod_user.php in the ACP User Registration (MMW) 1.00 modul
23RISCO
abrir
ReferênciaVexDay Proof
ALiCE-CMS 0.1 - 'CONFIG[local_root]' Remote File Inclusion
CVE-2006-5433webappsphp
PHP remote file inclusion vulnerability in modules/guestbook/index.php in ALiCE-CMS 0.1 allows remote attackers to execu
23RISCO
abrir
ReferênciaVexDay Proof
P-News 1.16 - Remote File Inclusion
CVE-2006-5434webappsphp
PHP remote file inclusion vulnerability in p-news.php in P-News 1.16 and 1.17 allows remote attackers to execute arbitra
23RISCO
abrir
ReferênciaVexDay Proof
SazCart 1.5 - 'cart.php' Remote File Inclusion
CVE-2006-5727webappsphp
PHP remote file inclusion vulnerability in admin/controls/cart.php in sazcart 1.5 allows remote attackers to execute arb
23RISCO
abrir
ReferênciaVexDay Proof
XM Easy Personal FTP Server 5.2.1 - Remote Denial of Service
CVE-2006-5728doswindows
XM Easy Personal FTP Server 5.2.1 and earlier allows remote authenticated users to cause a denial of service via a long
23RISCO
abrir
ReferênciaVexDay Proof
T.G.S. CMS 0.1.7 - 'logout.php' SQL Injection
CVE-2006-5732webappsphp
SQL injection vulnerability in logout.php in T.G.S. CMS 0.1.7 and earlier allows remote attackers to execute arbitrary S
23RISCO
abrir
ReferênciaVexDay Proof
PostNuke 0.763 - 'PNSV lang' Remote Code Execution
CVE-2006-5733webappsphp
Directory traversal vulnerability in error.php in PostNuke 0.763 and earlier allows remote attackers to include and exec
23RISCO
abrir
ReferênciaVexDay Proof
Microsoft Internet Explorer 6/7 - XML Core Services Remote Code Execution (1)
CVE-2006-5745remotewindows
Unspecified vulnerability in the setRequestHeader method in the XMLHTTP (XML HTTP) ActiveX Control 4.0 in Microsoft XML
60RISCO
abrir
ReferênciaVexDay Proof
QnECMS 2.5.6 - 'adminfolderpath' Remote File Inclusion
CVE-2006-5627webappsphp
Multiple PHP remote file inclusion vulnerabilities in QnECMS 2.5.6 and earlier allow remote attackers to execute arbitra
28RISCO
abrir
ReferênciaVexDay Proof
Free Image Hosting 1.0 - 'forgot_pass.php' File Inclusion
CVE-2006-5670webappsphp
PHP remote file inclusion vulnerability in forgot_pass.php in Free Image Hosting 1.0 and earlier allows remote attackers
23RISCO
abrir
ReferênciaVexDay Proof
MySource CMS 2.16.2 - 'init_mysource.php' Remote File Inclusion
CVE-2006-5672webappsphp
PHP remote file inclusion vulnerability in web/init_mysource.php in MySource CMS 2.16.2 and earlier allows remote attack
23RISCO
abrir
anteriorpágina 182 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.