Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.697exploits catalogados
36.715CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
awrate.com Message Board 1.0 - 'search.php' Remote File Inclusion
CVE-2006-6368webappsphp
PHP remote file inclusion vulnerability in login.php.inc in awrate 1.0 allows remote attackers to execute arbitrary PHP
23RISCO
abrir
ReferênciaVexDay Proof
Ultimate HelpDesk - Cross-Site Scripting / Local File Disclosure
CVE-2006-6380webappsasp
Cross-site scripting (XSS) vulnerability in index.asp in Ultimate HelpDesk allows remote attackers to inject arbitrary w
23RISCO
abrir
ReferênciaVexDay Proof
BlazeVideo HDTV Player 2.1 - '.PLF' Local Buffer Overflow
CVE-2006-6396localwindows
Stack-based buffer overflow in BlazeVideo HDTV Player 2.1, and possibly earlier, allows remote attackers to execute arbi
23RISCO
abrir
ReferênciaVexDay Proof
VMware 5.5.1 - 'ActiveX' Local Buffer Overflow
CVE-2006-6410localwindows
Buffer overflow in an ActiveX control in VMWare 5.5.1 allows local users to execute arbitrary code via a long VmdbDb par
23RISCO
abrir
ReferênciaVexDay Proof
J-OWAMP Web Interface 2.1b - 'link' Remote File Inclusion
CVE-2006-6453webappsphp
PHP remote file inclusion vulnerability in JOWAMP_ShowPage.php in J-OWAMP Web Interface 2.1 allows remote authenticated
23RISCO
abrir
ReferênciaVexDay Proof
D-Link DWL-2000AP 2.11 - ARP Flood Remote Denial of Service
CVE-2006-6538doshardware
D-LINK DWL-2000AP+ firmware 2.11 allows remote attackers to cause (1) a denial of service (device reset) via a flood of
23RISCO
abrir
ReferênciaVexDay Proof
Fantastic News 2.1.4 - 'news.php' SQL Injection
CVE-2006-6542webappsphp
SQL injection vulnerability in news.php in Fantastic News 2.1.4 and earlier allows remote attackers to execute arbitrary
23RISCO
abrir
ReferênciaVexDay Proof
SpotLight CRM 1.0 - 'login.asp' SQL Injection
CVE-2006-6543webappsasp
Multiple SQL injection vulnerabilities in login.asp in AppIntellect SpotLight CRM 1.0 allow remote attackers to execute
23RISCO
abrir
ReferênciaVexDay Proof
mxBB Module ErrorDocs 1.0 - 'common.php' Remote File Inclusion
CVE-2006-6545webappsphp
PHP remote file inclusion vulnerability in includes/common.php in the ErrorDocs 1.0.0 and earlier module for mxBB (mx_er
23RISCO
abrir
ReferênciaVexDay Proof
CuteNews aj-fork 167f - 'cutepath' Remote File Inclusion
CVE-2006-6546webappsphp
PHP remote file inclusion vulnerability in inc/shows.inc.php in cutenews aj-fork (CN:AJ) 167f and earlier allows remote
23RISCO
abrir
ReferênciaVexDay Proof
Phorum 3.2.11 - 'common.php' Remote File Inclusion
CVE-2006-6550webappsphp
PHP remote file inclusion vulnerability in common.php in Phorum 3.2.11 and earlier allows remote attackers to execute ar
23RISCO
abrir
ReferênciaVexDay Proof
Tucows Client Code Suite (CSS) 1.2.1015 - Remote File Inclusion
CVE-2006-6551webappsphp
PHP remote file inclusion vulnerability in libs/tucows/api/cartridges/crt_TUCOWS_domains/lib/domainutils.inc.php in Tuco
23RISCO
abrir
ReferênciaVexDay Proof
mxBB Module newssuite 1.03 - Remote File Inclusion
CVE-2006-6553webappsphp
PHP remote file inclusion vulnerability in includes/newssuite_constants.php in the NewsSuite 1.03 module for mxBB allows
23RISCO
abrir
ReferênciaVexDay Proof
AstonSoft DeepBurner 1.8.0 - '.dbr' File Parsing Buffer Overflow
CVE-2006-6665localwindows
Buffer overflow in Astonsoft DeepBurner Pro and Free 1.8.0 and earlier allows user-assisted remote attackers to execute
50RISCO
abrir
ReferênciaVexDay Proof
VerliAdmin 0.3 - 'index.php' Remote File Inclusion
CVE-2006-6666webappsphp
PHP remote file inclusion vulnerability in index.php in VerliAdmin 0.3 and earlier allows remote authenticated users to
23RISCO
abrir
ReferênciaVexDay Proof
TextSend 1.5 - '/config/sender.php' Remote File Inclusion
CVE-2006-6686webappsphp
PHP remote file inclusion vulnerability in sender.php in Carsen Klock TextSend 1.5 allows remote attackers to execute ar
23RISCO
abrir
ReferênciaVexDay Proof
Valdersoft Shopping Cart 3.0 - Multiple Remote File Inclusions
CVE-2006-6691webappsphp
Multiple PHP remote file inclusion vulnerabilities in Valdersoft Shopping Cart 3.0 and earlier allow remote attackers to
23RISCO
abrir
ReferênciaVexDay Proof
E-Uploader Pro 1.0 - Image Upload / Code Execution
CVE-2006-6694webappsphp
Directory traversal vulnerability in include/config.php in E-Uploader Pro 1.0 and earlier allows remote attackers to exe
23RISCO
abrir
ReferênciaVexDay Proof
Newxooper-PHP 0.9.1 - 'mapage.php' Remote File Inclusion
CVE-2006-6711webappsphp
PHP remote file inclusion vulnerability in compteur/mapage.php in Newxooper 0.9.1 allows remote attackers to execute arb
23RISCO
abrir
ReferênciaVexDay Proof
PowerClan 1.14a - 'footer.inc.php' Remote File Inclusion
CVE-2006-6715webappsphp
PHP remote file inclusion vulnerability in footer.inc.php in PowerClan 1.14a and earlier, when register_globals is enabl
23RISCO
abrir
ReferênciaVexDay Proof
Microsoft Windows - 'NetrWkstaUserEnum()' Remote Denial of Service
CVE-2006-6723doswindows
The Workstation service in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to cause a denial of service (m
35RISCO
abrir
ReferênciaVexDay Proof
BolinTech DreamFTP Server 1.0.2 - 'PORT' Remote Denial of Service
CVE-2006-6724doswindows
BolinTech Dream FTP Server 1.02 allows remote authenticated users, including anonymous users, to cause a denial of servi
23RISCO
abrir
ReferênciaVexDay Proof
cwmVote 1.0 - 'archive.php' Remote File Inclusion
CVE-2006-6732webappsphp
PHP remote file inclusion vulnerability in archive.php in cwmVote 1.0 allows remote attackers to execute arbitrary PHP c
23RISCO
abrir
ReferênciaVexDay Proof
Paristemi 0.8.3b - 'buycd.php' Remote File Inclusion
CVE-2006-6739webappsphp
PHP remote file inclusion vulnerability in buycd.php in Paristemi 0.8.3 allows remote attackers to execute arbitrary PHP
23RISCO
abrir
ReferênciaVexDay Proof
Ixprim CMS 1.2 - Blind SQL Injection
CVE-2006-6756webappsphp
The code function in install.fct.php in Ixprim 1.2 produces a guessable value of the confidential IXP_CODE in mainfile.p
23RISCO
abrir
ReferênciaVexDay Proof
cwmExplorer 1.0 - 'show_file' Source Code Disclosure
CVE-2006-6757webappsasp
Directory traversal vulnerability in index.php in cwmExplorer 1.0 allows remote attackers to read arbitrary files and so
23RISCO
abrir
ReferênciaVexDay Proof
Http explorer Web Server 1.02 - Directory Traversal
CVE-2006-6758remotewindows
Directory traversal vulnerability in Http explorer 1.02 allows remote attackers to read arbitrary files via a .. (dot do
23RISCO
abrir
ReferênciaVexDay Proof
Enthrallweb eCoupons 1.0 - 'myprofile.asp' Remote Pass Change
CVE-2006-6820webappsasp
myprofile.asp in Enthrallweb eCoupons does not properly validate the MM_recordId parameter during profile updates, which
23RISCO
abrir
ReferênciaVexDay Proof
Enthrallweb eNews 1.0 - Remote User Pass Change
CVE-2006-6821webappsasp
myprofile.asp in Enthrallweb eNews does not properly validate the MM_recordId parameter during profile updates, which al
23RISCO
abrir
ReferênciaVexDay Proof
Yrch 1.0 - 'plug.inc.phppath' Remote File Inclusion
CVE-2006-6823webappsphp
PHP remote file inclusion vulnerability in plugins/metasearch/plug.inc.php in Yrch! 1.0 allows remote attackers to execu
23RISCO
abrir
anteriorpágina 183 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.