Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.958exploits catalogados
36.206CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
Joomla! Component imagebrowser 0.1.5 rc2 - Directory Traversal
CVE-2008-4668webappsphp
Directory traversal vulnerability in the Image Browser (com_imagebrowser) 0.1.5 component for Joomla! allows remote atta
43RISCO
abrir
ReferênciaVexDay Proof
E-Shop Shopping Cart Script - 'search_results.php' SQL Injection
CVE-2008-5838webappsphp
SQL injection vulnerability in search_results.php in E-Php Scripts E-Shop (aka E-Php Shopping Cart) Shopping Cart Script
23RISCO
abrir
ReferênciaVexDay Proof
PHP iCalendar 2.24 - Insecure Cookie Handling
CVE-2008-5840webappsphp
PHP iCalendar 2.24 and earlier allows remote attackers to bypass authentication by setting the phpicalendar and phpicale
23RISCO
abrir
ReferênciaVexDay Proof
MyPBS - 'seasonID' SQL Injection
CVE-2008-5851webappsphp
SQL injection vulnerability in index.php in My PHP Baseball Stats (MyPBS) allows remote attackers to execute arbitrary S
23RISCO
abrir
ReferênciaVexDay Proof
Emefa Guestbook 3.0 - Remote Database Disclosure
CVE-2008-5852webappsasp
Emefa Guestbook 3.0 stores sensitive information under the web root with insufficient access control, which allows remot
23RISCO
abrir
ReferênciaVexDay Proof
myPHPscripts Login Session 2.0 - Cross-Site Scripting / Database Disclosure
CVE-2008-5855webappsphp
myPHPscripts Login Session 2.0 stores sensitive information under the web root with insufficient access control, which a
23RISCO
abrir
ReferênciaVexDay Proof
EFS Easy Chat Server 2.2 - Remote Denial of Service
CVE-2004-2466doswindows
chat.ghp in Easy Chat Server 1.2 allows remote attackers to cause a denial of service (server crash) via a long username
60RISCO
abrir
ReferênciaVexDay Proof
WebcamXP 5.3.2.375 - Remote File Disclosure
CVE-2008-5862remotewindows
Directory traversal vulnerability in webcamXP 5.3.2.375 and 5.3.2.410 build 2132 allows remote attackers to read arbitra
23RISCO
abrir
ReferênciaVexDay Proof
Constructr CMS 3.02.5 stable - Multiple Vulnerabilities
CVE-2008-5859webappsphp
SQL injection vulnerability in index.php in Constructr CMS 3.02.5 and earlier, when register_globals is enabled and magi
23RISCO
abrir
ReferênciaVexDay Proof
Wireshark 1.0.6 - PN-DCP Format String (PoC)
CVE-2009-1210dosmultiple
Format string vulnerability in the PROFINET/DCP (PN-DCP) dissector in Wireshark 1.0.6 and earlier allows remote attacker
28RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component com_tophotelmodule 1.0 - Blind SQL Injection
CVE-2008-5864webappsphp
SQL injection vulnerability in the Top Hotel (com_tophotelmodule) component 1.0 in the Hotel Booking Reservation System
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component com_hbssearch 1.0 - Blind SQL Injection
CVE-2008-5865webappsphp
SQL injection vulnerability in the com_hbssearch component 1.0 in the Hotel Booking Reservation System (aka HBS) 1.0.0 f
23RISCO
abrir
ReferênciaVexDay Proof
IntelliTamper 2.07/2.08 - 'ProxyLogin' Local Stack Overflow
CVE-2008-5868localwindows
Stack-based buffer overflow in IntelliTamper 2.07 and 2.08 allows user-assisted attackers to execute arbitrary code via
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component 5starhotels - SQL Injection
CVE-2008-5874webappsphp
Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System (aka HBS) for Joomla! allow remote attack
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component com_allhotels - Blind SQL Injection
CVE-2008-5874webappsphp
Multiple SQL injection vulnerabilities in the Hotel Booking Reservation System (aka HBS) for Joomla! allow remote attack
23RISCO
abrir
ReferênciaVexDay Proof
RunCMS 1.6 - Multiple Vulnerabilities
CVE-2007-6547webappsphp
RunCMS before 1.6.1 does not require entry of the old password during a password change, which allows context-dependent
23RISCO
abrir
ReferênciaVexDay Proof
PlaySms 0.9.3 - Multiple Local/Remote File Inclusions
CVE-2008-5881webappsphp
Multiple directory traversal vulnerabilities in playSMS 0.9.3 allow remote attackers to include and execute arbitrary lo
23RISCO
abrir
ReferênciaVexDay Proof
Discussion Web 4 - Remote Database Disclosure
CVE-2008-5886webappsasp
TAKempis Discussion Web 4.0 stores sensitive information under the web root with insufficient access control, which allo
23RISCO
abrir
ReferênciaVexDay Proof
WebFileExplorer 3.1 - Authentication Bypass
CVE-2009-1314webappsphp
body.asp in Web File Explorer 3.1 allows remote attackers to create arbitrary files and execute arbitrary code via the s
28RISCO
abrir
ReferênciaVexDay Proof
Click&Rank - SQL Injection / Cross-Site Scripting
CVE-2008-5888webappsasp
Multiple SQL injection vulnerabilities in Click&Rank allow remote attackers to execute arbitrary SQL commands via the id
23RISCO
abrir
ReferênciaVexDay Proof
clickandemail - SQL Injection / Cross-Site Scripting
CVE-2008-5892webappsasp
Multiple SQL injection vulnerabilities in ClickAndEmail allow remote attackers to execute arbitrary SQL commands via (1)
23RISCO
abrir
ReferênciaVexDay Proof
Mediatheka 4.2 - 'lang' Local File Inclusion
CVE-2008-5894webappsphp
Directory traversal vulnerability in index.php in Mediatheka 4.2 allows remote attackers to include and execute arbitrar
23RISCO
abrir
ReferênciaVexDay Proof
CodeAvalanche Directory - Database Disclosure
CVE-2008-5898webappsasp
CodeAvalanche Directory stores sensitive information under the web root with insufficient access control, which allows r
23RISCO
abrir
ReferênciaVexDay Proof
CodeAvalanche FreeForAll - Database Disclosure
CVE-2008-5899webappsasp
CodeAvalanche FreeForAll stores sensitive information under the web root with insufficient access control, which allows
23RISCO
abrir
ReferênciaVexDay Proof
CodeAvalanche Articles - Database Disclosure
CVE-2008-5900webappsasp
CodeAvalanche Articles stores sensitive information under the web root with insufficient access control, which allows re
23RISCO
abrir
ReferênciaVexDay Proof
nicLOR CMS - 'sezione_news.php' SQL Injection
CVE-2007-6586webappsphp
SQL injection vulnerability in sezione_news.php in nicLOR-CMS allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
ReferênciaVexDay Proof
WebSVN 2.0 - Cross-Site Scripting / File Handling / Code Execution
CVE-2008-5918webappsphp
Cross-site scripting (XSS) vulnerability in the getParameterisedSelfUrl function in index.php in WebSVN 2.0 and earlier
23RISCO
abrir
ReferênciaVexDay Proof
Umer Inc Songs Portal Script - 'id' SQL Injection
CVE-2008-5921webappsphp
SQL injection vulnerability in albums.php in Umer Inc Songs Portal allows remote attackers to execute arbitrary SQL comm
23RISCO
abrir
ReferênciaVexDay Proof
ASP-DEV Internal E-Mail System - Authentication Bypass
CVE-2008-5926webappsasp
Multiple SQL injection vulnerabilities in login.asp in ASP-DEv Internal E-Mail System allow remote attackers to execute
23RISCO
abrir
ReferênciaVexDay Proof
FlexPHPNews 0.0.6 / PRO - Authentication Bypass
CVE-2008-5927webappsphp
Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPNews 0.0.6 allow remote attackers to execute arb
23RISCO
abrir
anteriorpágina 37 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.