Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.302exploits catalogados
35.469CVEs com exploração pública
24.695testados em laboratório
24.451 exploits
Exploit-DBVexDay Proof
Sentinel Protection Server 7.x/Keys Server 1.0.x - Backslash Directory Traversal
CVE-2008-0760remotewindows11 fev 2008
Directory traversal vulnerability in SafeNet Sentinel Protection Server 7.4.1.0 and earlier, and Sentinel Keys Server 1.
23RISCO
abrir
Exploit-DBVexDay Proof
Larson Network Print Server 9.4.2 build 105 (LstNPS) - 'NPSpcSVR.exe' License Command Remote Overflow
CVE-2008-0763doswindows11 fev 2008
Stack-based buffer overflow in NPSpcSVR.exe in Larson Network Print Server (LstNPS) 9.4.2 build 105 and earlier allows r
23RISCO
abrir
Exploit-DBVexDay Proof
F5 BIG-IP 9.4.3 - Web Management Interface Cross-Site Request Forgery
CVE-2008-7032remotehardware11 fev 2008
Web Management Console Cross-site request forgery (CSRF) vulnerability in the web management console in F5 BIG-IP 9.4.3
23RISCO
abrir
Exploit-DBVexDay Proof
cyan soft - Multiple Applications Format String / Denial of Service Vulnerabilities
CVE-2008-0756dosmultiple11 fev 2008
The LPD server in cyan soft Opium OPI Server 4.10.1028 and earlier; cyanPrintIP Easy OPI, Professional, and Basic 4.10.1
23RISCO
abrir
Exploit-DBVexDay Proof
VWar 1.5 - 'calendar.php' SQL Injection
CVE-2008-0753webappsphp11 fev 2008
SQL injection vulnerability in calendar.php in Virtual War (VWar) 1.5 allows remote attackers to execute arbitrary SQL c
23RISCO
abrir
Exploit-DBVexDay Proof
Group Logic ExtremeZ-IP File and Print Servers 5.1.2 x15 - Multiple Vulnerabilities
CVE-2008-0767remotehardware10 fev 2008
ExtremeZ-IP.exe in ExtremeZ-IP File and Print Server 5.1.2x15 and earlier does not verify that a certain "number of URLs
23RISCO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.6.23 < 2.6.24 - 'vmsplice' Local Privilege Escalation (1)
CVE-2008-0600locallinux09 fev 2008
The vmsplice_to_pipe function in Linux kernel 2.6.17 through 2.6.24.1 does not validate a certain userspace pointer befo
23RISCO
abrir
Exploit-DBVexDay Proof
Apache Tomcat 6.0.15 - Cookie Quote Handling Remote Information Disclosure
CVE-2007-5333remotemultiple09 fev 2008
Apache Tomcat 6.0.0 through 6.0.14, 5.5.0 through 5.5.25, and 4.1.0 through 4.1.36 does not properly handle (1) double q
35RISCO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.6.17 < 2.6.24.1 - 'vmsplice' Local Privilege Escalation (2)
CVE-2008-0009locallinux09 fev 2008
The vmsplice_to_user function in fs/splice.c in the Linux kernel 2.6.22 through 2.6.24 does not validate a certain users
23RISCO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.6.17 < 2.6.24.1 - 'vmsplice' Local Privilege Escalation (2)
CVE-2008-0010locallinux09 fev 2008
The copy_from_user_mmap_sem function in fs/splice.c in the Linux kernel 2.6.22 through 2.6.24 does not validate a certai
23RISCO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.6.23 < 2.6.24 - 'vmsplice' Local Privilege Escalation (1)
CVE-2008-0009locallinux09 fev 2008
The vmsplice_to_user function in fs/splice.c in the Linux kernel 2.6.22 through 2.6.24 does not validate a certain users
23RISCO
abrir
Exploit-DBVexDay Proof
Calimero.CMS 3.3 - 'id' Cross-Site Scripting
CVE-2008-0749webappsphp08 fev 2008
Cross-site scripting (XSS) vulnerability in index.php in Calimero.CMS 3.3 allows remote attackers to inject arbitrary we
23RISCO
abrir
Exploit-DBVexDay Proof
Managed Workplace Service Center 4.x/5.x/6.x - Installation Information Disclosure
CVE-2008-0636webappsphp08 fev 2008
Level Platforms, Inc. (LPI) Managed Workplace Service Center 4.x, 5.x and 6.x allows remote attackers to obtain sensitiv
23RISCO
abrir
Exploit-DBVexDay Proof
IEA Software (Multiple Products) - POST Denial of Service
CVE-2008-5284dosmultiple08 fev 2008
The web server in IEA Software RadiusNT and RadiusX 5.1.38 and other versions before 5.1.44, Emerald 5.0.49 and other ve
23RISCO
abrir
Exploit-DBVexDay Proof
Joovili 2.1 - 'members_help.php' Remote File Inclusion
CVE-2008-0743webappsphp08 fev 2008
PHP remote file inclusion vulnerability in members_help.php in Joovili 2.1 and earlier allows remote attackers to execut
23RISCO
abrir
Exploit-DBVexDay Proof
S9Y Serendipity Freetag-plugin 2.95 - 'style' Cross-Site Scripting
CVE-2008-0751webappsphp08 fev 2008
Cross-site scripting (XSS) vulnerability in the Freetag before 2.96 plugin for S9Y Serendipity, when using Internet Expl
23RISCO
abrir
Exploit-DBVexDay Proof
MODx 0.9.6 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2008-7242webappsphp07 fev 2008
Multiple cross-site scripting (XSS) vulnerabilities in MODx CMS 0.9.6.1 and 0.9.6.1p1 allo remote attackers to inject ar
23RISCO
abrir
Exploit-DBVexDay Proof
Ipswitch Instant Messaging 2.0.8.1 - Multiple Vulnerabilities
CVE-2008-0944doswindows07 fev 2008
Ipswitch Instant Messaging (IM) 2.0.8.1 and earlier allows remote attackers to cause a denial of service (NULL dereferen
28RISCO
abrir
Exploit-DBVexDay Proof
Adobe Acrobat and Reader 8.1.1 - Multiple Arbitrary Code Execution / Security Vulnerabilities
CVE-2007-5659HIGHsob ataquedoswindows06 fev 2008
Multiple buffer overflows in Adobe Reader and Acrobat 8.1.1 and earlier allow remote attackers to execute arbitrary code
100RISCO
abrir
Exploit-DBVexDay Proof
Ipswitch WS_FTP Server 6 - '/WSFTPSVR/FTPLogServer/LogViewer.asp' Authentication Bypass
CVE-2008-5692webappsasp06 fev 2008
Ipswitch WS_FTP Server Manager before 6.1.1, and possibly other Ipswitch products, allows remote attackers to bypass aut
28RISCO
abrir
Exploit-DBVexDay Proof
Pagetool 1.07 - 'search_term' Cross-Site Scripting
CVE-2008-0722webappsphp06 fev 2008
Cross-site scripting (XSS) vulnerability in index.php in Pagetool 1.0.7 allows remote attackers to inject arbitrary web
23RISCO
abrir
Exploit-DBVexDay Proof
TinTin++ / WinTin++ 1.97.9 - '#chat' Multiple Vulnerabilities
CVE-2008-0671remotemultiple06 fev 2008
Stack-based buffer overflow in the add_line_buffer function in TinTin++ 1.97.9 and WinTin++ 1.97.9 allows remote attacke
28RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Works 8.0 - File Converter Field Length Remote Code Execution
CVE-2008-0108remotewindows06 fev 2008
Stack-based buffer overflow in wkcvqd01.dll in Microsoft Works 6 File Converter, as used in Office 2003 SP2 and SP3, Wor
35RISCO
abrir
Exploit-DBVexDay Proof
MyNews 1.6.x - 'hash' Cross-Site Scripting
CVE-2008-0723webappsphp06 fev 2008
Cross-site scripting (XSS) vulnerability in mynews.inc.php in MyNews 1.6.4, and other earlier 1.6.x versions, allows rem
23RISCO
abrir
Exploit-DBVexDay Proof
Titan FTP Server 6.05 build 550 - 'DELE' Remote Buffer Overflow (PoC)
CVE-2008-5281doswindows04 fev 2008
Heap-based buffer overflow in Titan FTP Server 6.05 build 550 allows remote attackers to execute arbitrary code via a lo
38RISCO
abrir
Exploit-DBVexDay Proof
AstroSoft HelpDesk - '/operator/article/article_attachment.asp?Attach_Id' Cross-Site Scripting
CVE-2008-0605webappsasp04 fev 2008
Multiple cross-site scripting (XSS) vulnerabilities in AstroSoft HelpDesk before 1.95.228 allow remote attackers to inje
23RISCO
abrir
Exploit-DBVexDay Proof
MPlayer 1.0rc2 - 'demux_mov.c' Remote Code Execution
CVE-2008-0485remotelinux04 fev 2008
Array index error in libmpdemux/demux_mov.c in MPlayer 1.0 rc2 and earlier might allow remote attackers to execute arbit
23RISCO
abrir
Exploit-DBVexDay Proof
Anon Proxy Server 0.100/0.102 - Remote Authentication Buffer Overflow
CVE-2008-0633dosmultiple04 fev 2008
Buffer overflow in Anon Proxy Server 0.102 and earlier, when user authentication is enabled, allows remote attackers to
23RISCO
abrir
Exploit-DBVexDay Proof
Portail Web PHP 2.5.1 - 'item.php' Remote File Inclusion
CVE-2008-0645webappsphp04 fev 2008
Multiple PHP remote file inclusion vulnerabilities in Portail Web Php 2.5.1.1 allow remote attackers to execute arbitrar
35RISCO
abrir
Exploit-DBVexDay Proof
DevTracker Module For bcoos 1.1.11 and E-xoops 1.0.8 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2008-7036webappsphp04 fev 2008
Multiple cross-site scripting (XSS) vulnerabilities in index.php in DevTracker module 3.0 for bcoos 1.1.11 and earlier,
23RISCO
abrir
anteriorpágina 499 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.