Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.057exploits catalogados
36.288CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
Data Dynamics ActiveBar (Actbar3.ocx 3.2) - Multiple Insecure Methods
CVE-2007-3883remotewindows
The Data Dynamics ActiveBar ActiveX control (actbar3.ocx) 3.2 and earlier allows remote attackers to create or overwrite
23RISCO
abrir
ReferênciaVexDay Proof
CA BrightStor ARCserve Backup r11.5 - ActiveX Remote Buffer Overflow
CVE-2008-1472remotewindows
Stack-based buffer overflow in the ListCtrl ActiveX Control (ListCtrl.ocx), as used in multiple CA products including Br
50RISCO
abrir
ReferênciaVexDay Proof
Pluxml 0.3.1 - Remote Code Execution
CVE-2007-3432webappsphp
Unrestricted file upload vulnerability in admin/images.php in Pluxml 0.3.1 allows remote attackers to upload and execute
23RISCO
abrir
ReferênciaVexDay Proof
Simple Machines Forum (SMF) 1.1.6 - Code Execution
CVE-2008-6657webappsphp
Cross-site request forgery (CSRF) vulnerability in index.php in Simple Machines Forum (SMF) 1.0 before 1.0.15 and 1.1 be
23RISCO
abrir
ReferênciaVexDay Proof
phpAuction - 'profile.php' SQL Injection (1)
CVE-2008-6663webappsphp
SQL injection vulnerability in profile.php in PHPAuctions.info PHPAuctions (aka PHPAuctionSystem) allows remote attacker
23RISCO
abrir
ReferênciaVexDay Proof
PHP Live Helper 2.0 - 'abs_path' Remote File Inclusion
CVE-2006-4051webappsphp
PHP remote file inclusion vulnerability in global.php in Turnkey Web Tools PHP Live Helper 2.0 and earlier allows remote
23RISCO
abrir
ReferênciaVexDay Proof
XLPortal 2.2.4 - 'Search' SQL Injection
CVE-2008-1509webappsphp
SQL injection vulnerability in index.php in XLPortal 2.2.4 and earlier allows remote attackers to execute arbitrary SQL
23RISCO
abrir
ReferênciaVexDay Proof
nweb2fax 0.2.7 - Multiple Vulnerabilities
CVE-2008-6669webappsphp
viewrq.php in nweb2fax 0.2.7 and earlier allows remote attackers to execute arbitrary code via shell metacharacters in t
23RISCO
abrir
ReferênciaVexDay Proof
WebChat 0.77 - 'defines.php?WEBCHATPATH' Remote File Inclusion
CVE-2007-0485webappsphp
PHP remote file inclusion vulnerability in defines.php in WebChat 0.77 allows remote attackers to execute arbitrary PHP
23RISCO
abrir
ReferênciaVexDay Proof
Apartment Search Script - Arbitrary File Upload / Cross-Site Scripting
CVE-2008-6683webappsphp
Cross-site scripting (XSS) vulnerability in listtest.php in Apartment Search Script allows remote attackers to inject ar
23RISCO
abrir
ReferênciaVexDay Proof
TeamSpeak 2.0 (Windows Release) - Remote Denial of Service
CVE-2007-3956doswindows
TeamSpeak WebServer 2.0 for Windows does not validate parameter value lengths and does not expire TCP sessions, which al
23RISCO
abrir
ReferênciaVexDay Proof
Maian Weblog 4.0 - Insecure Cookie Handling
CVE-2008-3318webappsphp
admin/index.php in Maian Weblog 4.0 and earlier allows remote attackers to bypass authentication and gain administrative
23RISCO
abrir
ReferênciaVexDay Proof
mcGalleryPRO 2006 - 'path_to_folder' Remote File Inclusion
CVE-2006-4720webappsphp
PHP remote file inclusion vulnerability in random2.php in mcGalleryPRO 2006 allows remote attackers to execute arbitrary
23RISCO
abrir
ReferênciaVexDay Proof
xeCMS 1.0.0 RC2 - Insecure Cookie Handling
CVE-2008-6714webappsphp
admin.php in xeCMS 1.0.0 RC2 and earlier allows remote attackers to bypass authentication and access the admin panel by
28RISCO
abrir
ReferênciaVexDay Proof
Jasmine CMS 1.0 - SQL Injection / Remote Code Execution
CVE-2007-3313webappsphp
Multiple SQL injection vulnerabilities in Jasmine CMS 1.0 allow remote attackers to execute arbitrary SQL commands via (
23RISCO
abrir
ReferênciaVexDay Proof
BitDefender Online Scanner 8 - ActiveX Heap Overflow
CVE-2007-6189remotewindows
A certain ActiveX control in (1) OScan8.ocx and (2) Oscan81.ocx in BitDefender Online Anti-Virus Scanner 8.0 allows remo
23RISCO
abrir
ReferênciaVexDay Proof
Yahoo! JukeBox MediaGrid - 'AddBitmap()' ActiveX Buffer Overflow
CVE-2008-0625remotewindows
Buffer overflow in the MediaGrid ActiveX control (mediagrid.dll) in Yahoo! Music Jukebox 2.2.2.56 allows remote attacker
23RISCO
abrir
ReferênciaVexDay Proof
Pre ADS Portal 2.0 - Authentication Bypass / Cross-Site Scripting
CVE-2008-6715webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in Pre ADS Portal 2.0 and earlier allow remote attackers to inject a
23RISCO
abrir
ReferênciaVexDay Proof
TOSMO/Mambo 1.4.13a - 'absolute_path' Remote File Inclusion
CVE-2007-2317webappsphp
Multiple PHP remote file inclusion vulnerabilities in MiniBB Forum 1.5a and earlier, as used by TOSMO/Mambo 4.0.12 and p
23RISCO
abrir
ReferênciaVexDay Proof
Pre ADS Portal 2.0 - Authentication Bypass / Cross-Site Scripting
CVE-2008-6716webappsphp
homeadmin/adminhome.php in Pre ADS Portal 2.0 and earlier does not require administrative authentication, which allows r
23RISCO
abrir
ReferênciaVexDay Proof
FirmWorX 0.1.2 - Multiple Remote File Inclusions
CVE-2007-2891webappsphp
Multiple PHP remote file inclusion vulnerabilities in FirmWorX 0.1.2 allow remote attackers to execute arbitrary PHP cod
23RISCO
abrir
ReferênciaVexDay Proof
NVR SP2 2.0 'nvUtility.dll 1.0.14.0' - 'DeleteXMLFile()' Insecure Method
CVE-2007-4583remotewindows
Multiple absolute path traversal vulnerabilities in the nvUtility.Utility.1 ActiveX control in nvUtility.dll 1.0.14.0 in
23RISCO
abrir
ReferênciaVexDay Proof
MiGCMS 2.0.5 - Multiple Remote File Inclusions
CVE-2008-2888webappsphp
Multiple PHP remote file inclusion vulnerabilities in MiGCMS 2.0.5, when register_globals is enabled, allow remote attac
23RISCO
abrir
ReferênciaVexDay Proof
U&M Software Signup 1.1 - Authentication Bypass
CVE-2008-6717webappsphp
U&M Software Signup 1.0 and 1.1 does not require administrative authentication for all scripts in the admin/ directory,
23RISCO
abrir
ReferênciaVexDay Proof
U&M Software Event Lister 1.0 - Authentication Bypass
CVE-2008-6719webappsphp
U&M Software Event Lister (aka JustListIt) 1.0 does not require administrative authentication for all scripts in the adm
23RISCO
abrir
ReferênciaVexDay Proof
Durian Web Application Server 3.02 - Denial of Service
CVE-2006-6853doswindows
Buffer overflow in Durian Web Application Server 3.02 freeware on Windows allows remote attackers to execute arbitrary c
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component rekry 1.0.0 - 'op_id' SQL Injection
CVE-2008-1535webappsphp
SQL injection vulnerability in the Matti Kiviharju rekry (aka com_rekry or rekry!Joom) 1.0.0 component for Joomla! allow
23RISCO
abrir
ReferênciaVexDay Proof
DELTAScripts PHP Links 1.3 - Authentication Bypass
CVE-2008-6720webappsphp
SQL injection vulnerability in admin/adm_login.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to
23RISCO
abrir
ReferênciaVexDay Proof
AJ Article 1.0 - Authentication Bypass
CVE-2008-6721webappsphp
SQL injection vulnerability in index.php in AJ Square AJ Article allows remote attackers to execute arbitrary SQL comman
23RISCO
abrir
ReferênciaVexDay Proof
TurnkeyForms Entertainment Portal 2.0 - Insecure Cookie Handling
CVE-2008-6723webappsphp
TurnkeyForms Entertainment Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by
23RISCO
abrir
anteriorpágina 51 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.