Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.057exploits catalogados
36.288CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
asg-sentry 7.0.0 - Multiple Vulnerabilities
CVE-2008-1321dosmultiple
The FxIAList service in ASG-Sentry Network Manager 7.0.0 and earlier does require authentication, which allows remote at
23RISCO
abrir
ReferênciaVexDay Proof
Cerulean Portal System 0.7b - Remote File Inclusion
CVE-2007-0684webappsphp
PHP remote file inclusion vulnerability in portal.php in Cerulean Portal System 0.7b allows remote attackers to execute
23RISCO
abrir
ReferênciaVexDay Proof
BBS E-Market - 'postscript.php?p_mode' Remote File Inclusion
CVE-2007-3934webappsphp
PHP remote file inclusion vulnerability in postscript/postscript.php in BBS E-Market allows remote attackers to execute
23RISCO
abrir
ReferênciaVexDay Proof
WEBBDOMAIN Post Card 1.02 - 'catid' SQL Injection
CVE-2008-6622webappsphp
SQL injection vulnerability in choosecard.php in WEBBDOMAIN Post Card (aka Web Postcards) 1.02, 1.01, and earlier allows
23RISCO
abrir
ReferênciaVexDay Proof
HP Compaq Notebooks - ActiveX Remote Code Execution
CVE-2007-6332remotewindows
The HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 i
23RISCO
abrir
ReferênciaVexDay Proof
ashNews 0.83 - 'pathtoashnews' Remote File Inclusion
CVE-2003-1292webappsphp
PHP remote file include vulnerability in Derek Ashauer ashNews 0.83 allows remote attackers to include and execute arbit
23RISCO
abrir
ReferênciaVexDay Proof
eXV2 Module MyAnnonces - 'lid' SQL Injection
CVE-2008-1406webappsphp
SQL injection vulnerability in annonces-p-f.php in the MyAnnonces 1.8 module for eXV2 allows remote attackers to execute
23RISCO
abrir
ReferênciaVexDay Proof
eXV2 Module WebChat 1.60 - 'roomid' SQL Injection
CVE-2008-1407webappsphp
SQL injection vulnerability in index.php in the WebChat 1.60 module for eXV2 allows remote attackers to execute arbitrar
23RISCO
abrir
ReferênciaVexDay Proof
WEBBDOMAIN Petition 1.02/2.0/3.0 - Authentication Bypass
CVE-2008-6624webappsphp
SQL injection vulnerability in getin.php in WEBBDOMAIN Petition 1.02, 2.0, and 3.0 allows remote attackers to execute ar
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component LMO 1.0b2 - Remote File Inclusion
CVE-2006-3970webappsphp
PHP remote file inclusion vulnerability in lmo.php in the LMO Component (com_lmo) 1.0b2 and earlier for Joomla! allows r
23RISCO
abrir
ReferênciaVexDay Proof
WEBBDOMAIN Polls 1.01 - Authentication Bypass
CVE-2008-6625webappsphp
SQL injection vulnerability in getin.php in WEBBDOMAIN Polls (aka Poll) 1.0 and 1.01 allows remote attackers to execute
23RISCO
abrir
ReferênciaVexDay Proof
RoomPHPlanning 1.5 - Multiple SQL Injections
CVE-2008-6634webappsphp
SQL injection vulnerability in RoomPHPlanning 1.5 allows remote attackers to execute arbitrary SQL commands via the idro
23RISCO
abrir
ReferênciaVexDay Proof
UNAK-CMS 1.5 - 'dirroot' Remote File Inclusion
CVE-2006-4890webappsphp
Multiple PHP remote file inclusion vulnerabilities in UNAK-CMS 1.5 and earlier allow remote attackers to execute arbitra
23RISCO
abrir
ReferênciaVexDay Proof
CWB PRO 1.5 - 'INCLUDE_PATH' Remote File Inclusion
CVE-2007-1809webappsphp
Multiple PHP remote file inclusion vulnerabilities in GraFX Company WebSite Builder (CWB) PRO 1.5 allow remote attackers
23RISCO
abrir
ReferênciaVexDay Proof
XnView 1.92.1 - 'FontName' Slideshow Buffer Overflow
CVE-2008-0069localwindows
Stack-based buffer overflow in XnView 1.92 and 1.92.1 allows user-assisted remote attackers to execute arbitrary code vi
23RISCO
abrir
ReferênciaVexDay Proof
ASPapp Knowledge Base - 'CatId' SQL Injection (1)
CVE-2008-1430webappsasp
SQL injection vulnerability in links.asp in ASPapp allows remote attackers to execute arbitrary SQL commands via the Cat
23RISCO
abrir
ReferênciaVexDay Proof
SysInfo 1.21 - 'sysinfo.cgi' Remote Command Execution
CVE-2006-1831webappscgi
Direct static code injection vulnerability in sysinfo.cgi in sysinfo 1.21 and possibly other versions before 2.25 allows
23RISCO
abrir
ReferênciaVexDay Proof
Shader TV (Beta) - Multiple SQL Injections
CVE-2008-6641webappsasp
Multiple SQL injection vulnerabilities in Shader TV (Beta) allow remote authenticated administrators to execute arbitrar
23RISCO
abrir
ReferênciaVexDay Proof
Simple Web Content Management System - SQL Injection
CVE-2007-0093webappsphp
SQL injection vulnerability in page.php in Simple Web Content Management System allows remote attackers to execute arbit
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component Alberghi 2.1.3 - 'id' SQL Injection
CVE-2008-1459webappsphp
SQL injection vulnerability in the Alberghi (com_alberghi) 2.1.3 and earlier component for Mambo and Joomla! allows remo
23RISCO
abrir
ReferênciaVexDay Proof
FluentCMS - 'view.php' SQL Injection
CVE-2008-6642webappsphp
SQL injection vulnerability in view.php in DotContent FluentCMS 4.x allows remote attackers to execute arbitrary SQL com
23RISCO
abrir
ReferênciaVexDay Proof
Bitweaver 1.3 - 'tmpImagePath' Attachment mod_mime
CVE-2006-3102webappsphp
Race condition in articles/BitArticle.php in Bitweaver 1.3, when run on Apache with the mod_mime extension, allows remot
23RISCO
abrir
ReferênciaVexDay Proof
Eznet 3.5.0 - Remote Stack Overflow / Denial of Service
CVE-2003-1339remotewindows
Stack-based buffer overflow in eZnet.exe, as used in eZ (a) eZphotoshare, (b) eZmeeting, (c) eZnetwork, and (d) eZshare
35RISCO
abrir
ReferênciaVexDay Proof
SkaDate Online 5.0/6.0 - Remote File Disclosure
CVE-2007-5299webappsphp
Multiple directory traversal vulnerabilities in SkaDate 5.0 and 6.0, and possibly later versions such as 6.482, allow re
23RISCO
abrir
ReferênciaVexDay Proof
Ktools Photostore 3.5.2 - Multiple SQL Injections
CVE-2008-6648webappsphp
SQL injection vulnerability in crumbs.php in Ktools PhotoStore 3.4.3 and 3.5.2 allows remote attackers to execute arbitr
23RISCO
abrir
ReferênciaVexDay Proof
OneCMS 2.5 - Blind SQL Injection
CVE-2008-6652webappsphp
SQL injection vulnerability in asd.php in OneCMS 2.5 allows remote attackers to execute arbitrary SQL commands via the s
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component Webhosting - 'catid' Blind SQL Injection
CVE-2008-6653webappsphp
SQL injection vulnerability in webhosting.php in the Webhosting Component (com_webhosting) module before 1.1 RC7 for Joo
23RISCO
abrir
ReferênciaVexDay Proof
Foxit Reader 2.0 - 'PDF' Remote Denial of Service
CVE-2007-2186doswindows
Foxit Reader 2.0 allows remote attackers to cause a denial of service (application crash) via a crafted PDF document.
23RISCO
abrir
ReferênciaVexDay Proof
Opera Web Browser 9.00 - 'iframe' Remote Denial of Service
CVE-2006-3353dosmultiple
Opera 9 allows remote attackers to cause a denial of service (crash) via a crafted web page that triggers an out-of-boun
23RISCO
abrir
ReferênciaVexDay Proof
Opera 9.2 - '.torrent' Remote Denial of Service
CVE-2007-2274dosmultiple
The BitTorrent implementation in Opera 9.2 allows remote attackers to cause a denial of service (CPU consumption and app
23RISCO
abrir
anteriorpágina 50 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.