Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

76.565exploits catalogados
34.981CVEs com exploração pública
24.695testados em laboratório
21.899 exploits
ReferênciaVexDay Proof
LushiNews 1.01 - 'comments.php' SQL Injection
CVE-2007-0865webappsphp
SQL injection vulnerability in comments.php in LushiNews 1.01 and earlier allows remote authenticated users to inject ar
23RISCO
abrir
Referência
CVE-2018-0296
CVE-2018-0296HIGHsob ataque
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remo
100RISCO
abrir
Referência
CVE-2021-22986
CVE-2021-22986CRITICALsob ataqueransomware
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISCO
abrir
Referência
CVE-2021-22986
CVE-2021-22986CRITICALsob ataqueransomware
On BIG-IP versions 16.0.x before 16.0.1.1, 15.1.x before 15.1.2.1, 14.1.x before 14.1.4, 13.1.x before 13.1.3.6, and 12.
100RISCO
abrir
ReferênciaVexDay Proof
μTorrent (uTorrent) 1.6 build 474 - 'announce' Key Remote Heap Overflow
CVE-2007-0927remotewindows
Heap-based buffer overflow in uTorrent 1.6 allows remote attackers to execute arbitrary code via a torrent file with a c
35RISCO
abrir
ReferênciaVexDay Proof
Total Video Player 1.20 - '.m3u' File Local Stack Buffer Overflow
CVE-2007-0949localwindows
Stack-based buffer overflow in iTinySoft Studio Total Video Player 1.03, and possibly earlier, allows remote attackers t
28RISCO
abrir
ReferênciaVexDay Proof
Jupiter CMS 1.1.5 - Arbitrary File Upload
CVE-2007-0972webappsphp
Unrestricted file upload vulnerability in modules/emoticons.php in Jupiter CMS 1.1.5 allows remote attackers to upload a
23RISCO
abrir
ReferênciaVexDay Proof
Snitz Forums 2000 3.1 SR4 - 'pop_profile.asp' SQL Injection
CVE-2007-1023webappsasp
SQL injection vulnerability in pop_profile.asp in Snitz Forums 2000 3.1 SR4 allows remote attackers to execute arbitrary
23RISCO
abrir
ReferênciaVexDay Proof
PHP-Nuke Module Emporium 2.3.0 - SQL Injection
CVE-2007-1034webappsphp
SQL injection vulnerability in the category file in modules.php in the Emporium 2.3.0 and earlier module for PHP-Nuke al
23RISCO
abrir
ReferênciaVexDay Proof
Nortel SSL VPN Linux Client 6.0.3 - Local Privilege Escalation
CVE-2007-1057locallinux
The Net Direct client for Linux before 6.0.5 in Nortel Application Switch 2424, VPN 3050 and 3070, and SSL VPN Module 10
23RISCO
abrir
ReferênciaVexDay Proof
TurboFTP Server 5.30 Build 572 - 'newline/LIST' Multiple Remote Denial of Service Vulnerabilities
CVE-2007-1075doswindows
TurboFTP 5.30 Build 572 allows remote servers to cause a denial of service (CPU consumption) via a response with a large
23RISCO
abrir
ReferênciaVexDay Proof
TurboFTP Server 5.30 Build 572 - 'newline/LIST' Multiple Remote Denial of Service Vulnerabilities
CVE-2007-1080doswindows
Multiple heap-based buffer overflows in TurboFTP 5.30 Build 572 allow remote servers to cause a denial of service via (1
23RISCO
abrir
ReferênciaVexDay Proof
PHP-MIP 0.1 - 'top.php?laypath' Remote File Inclusion
CVE-2007-1104webappsphp
PHP remote file inclusion vulnerability in top.php in PHP Module Implementation (PHP-MIP) 0.1 allows remote attackers to
23RISCO
abrir
ReferênciaVexDay Proof
Extreme phpBB 3.0.1 - 'functions.php' Remote File Inclusion
CVE-2007-1105webappsphp
PHP remote file inclusion vulnerability in functions.php in Extreme phpBB (aka phpBB Extreme) 3.0.1 allows remote attack
23RISCO
abrir
Referência
CVE-2007-1107
SQL injection vulnerability in thumbnails.php in Coppermine Photo Gallery (CPG) 1.3.x allows remote authenticated users
23RISCO
abrir
ReferênciaVexDay Proof
Coppermine Photo Gallery 1.3.x - Blind SQL Injection
CVE-2007-1107webappsphp
SQL injection vulnerability in thumbnails.php in Coppermine Photo Gallery (CPG) 1.3.x allows remote authenticated users
23RISCO
abrir
ReferênciaVexDay Proof
webSPELL 4.01.02 - 'topic' SQL Injection
CVE-2007-1163webappsphp
SQL injection vulnerability in printview.php in webSPELL 4.01.02 and earlier allows remote attackers to execute arbitrar
23RISCO
abrir
ReferênciaVexDay Proof
Plan 9 Kernel - 'devenv.c OTRUNC/pwrite' Local Privilege Escalation
CVE-2007-1189localplan9
Integer overflow in the envwrite function in the Alcatel-Lucent Bell Labs Plan 9 kernel allows local users to overwrite
23RISCO
abrir
ReferênciaVexDay Proof
Admin Phorum 3.3.1a - 'del.php?include_path' Remote File Inclusion
CVE-2007-1219webappsphp
PHP remote file inclusion vulnerability in actions/del.php in Admin Phorum 3.3.1a allows remote attackers to execute arb
23RISCO
abrir
ReferênciaVexDay Proof
Angel Lms 7.1 - 'default.asp?id' SQL Injection
CVE-2007-1250webappsasp
SQL injection vulnerability in section/default.asp in ANGEL Learning Management Suite (LMS) 7.1 allows remote attackers
23RISCO
abrir
ReferênciaVexDay Proof
wbblog - Cross-Site Scripting / SQL Injection
CVE-2007-1481webappsphp
SQL injection vulnerability in index.php in WBBlog allows remote attackers to execute arbitrary SQL commands via the e_i
23RISCO
abrir
Referência
CVE-2009-4862
Multiple SQL injection vulnerabilities in Alwasel 1.5 allow remote attackers to execute arbitrary SQL commands via the i
23RISCO
abrir
ReferênciaVexDay Proof
wbblog - Cross-Site Scripting / SQL Injection
CVE-2007-1482webappsphp
Cross-site scripting (XSS) vulnerability in index.php in WBBlog allows remote attackers to inject arbitrary web script o
23RISCO
abrir
ReferênciaVexDay Proof
WebLog - 'index.php' Remote File Disclosure
CVE-2007-1487webappsphp
Directory traversal vulnerability in index.php in Sascha Schroeder (aka CyberTeddy or Cyber-inside) WebLog allows remote
23RISCO
abrir
ReferênciaVexDay Proof
NetVIOS Portal - 'page.asp' SQL Injection
CVE-2007-1566webappsasp
SQL injection vulnerability in News/page.asp in NetVIOS Portal allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
ReferênciaVexDay Proof
News Bin Pro 4.32 - Article Grabbing Remote Unicode Buffer Overflow
CVE-2007-1569doswindows
Stack-based buffer overflow in NewsBin Pro 4.32 allows remote attackers to cause a denial of service or execute arbitrar
23RISCO
abrir
ReferênciaVexDay Proof
Mercur IMAPD 5.00.14 (Windows x86) - Remote Denial of Service
CVE-2007-1578doswindows_x86
Multiple integer signedness errors in the NTLM implementation in Atrium MERCUR IMAPD (mcrimap4.exe) 5.00.14, with SP4, a
28RISCO
abrir
ReferênciaVexDay Proof
Mercur Messaging 2005 (Windows 2000 SP4) - IMAP 'Subscribe' Remote Overflow
CVE-2007-1579remotewindows
Stack-based buffer overflow in Atrium MERCUR IMAPD allows remote attackers to have an unknown impact via a certain SUBSC
35RISCO
abrir
Referência
CVE-2009-4870
Multiple SQL injection vulnerabilities in login.php in PHPCityPortal allow remote attackers to execute arbitrary SQL com
23RISCO
abrir
ReferênciaVexDay Proof
PHP 5.2.0 (OSX) - 'header()' Space Trimming Buffer Underflow
CVE-2007-1584localosx
Buffer underflow in the header function in PHP 5.2.0 allows context-dependent attackers to execute arbitrary code by pas
23RISCO
abrir
anteriorpágina 362 / 730próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.