Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.057exploits catalogados
36.288CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
Microsoft Windows Explorer - '.AVI' File Denial of Service
CVE-2007-0562doswindows
Windows Explorer (explorer.exe) 6.0.2900.2180 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause
28RISCO
abrir
ReferênciaVexDay Proof
phpEmployment - 'PHP Upload' Arbitrary File Upload
CVE-2008-6920webappsphp
Unrestricted file upload vulnerability in auth.php in phpEmployment 1.8 allows remote attackers to execute arbitrary cod
23RISCO
abrir
ReferênciaVexDay Proof
Maian Recipe 1.0 - 'path_to_folder' Remote File Inclusion
CVE-2007-0848webappsphp
PHP remote file inclusion vulnerability in classes/class_mail.inc.php in Maian Recipe 1.0 allows remote attackers to exe
23RISCO
abrir
ReferênciaVexDay Proof
Realtor 747 - 'index.php?categoryId' SQL Injection
CVE-2007-3810webappsphp
SQL injection vulnerability in index.php in Realtor 747 allows remote attackers to execute arbitrary SQL commands via th
23RISCO
abrir
ReferênciaVexDay Proof
WordPress Plugin Photoracer 1.0 - 'id' SQL Injection
CVE-2009-2122webappsphp
SQL injection vulnerability in viewimg.php in the Paolo Palmonari Photoracer plugin 1.0 for WordPress allows remote atta
23RISCO
abrir
ReferênciaVexDay Proof
eSyndiCat Directory Software - Multiple SQL Injections
CVE-2007-3811webappsphp
Multiple SQL injection vulnerabilities in eSyndiCat allow remote attackers to execute arbitrary SQL commands via (1) the
23RISCO
abrir
ReferênciaVexDay Proof
AJA Portal 1.2 (Windows) - Local File Inclusion
CVE-2009-0457webappsphp
Multiple directory traversal vulnerabilities in AJA Portal 1.2 allow remote attackers to include and execute arbitrary l
23RISCO
abrir
ReferênciaVexDay Proof
WebChamado 1.1 - Arbitrary Add Admin
CVE-2008-2907webappsphp
SQL injection vulnerability in admin/index.php in WebChamado 1.1, when magic_quotes_gpc is disabled, allows remote attac
23RISCO
abrir
ReferênciaVexDay Proof
Docebo 3.0.3 - Multiple Remote File Inclusions
CVE-2006-2576webappsphp
Multiple PHP remote file inclusion vulnerabilities in Docebo 3.0.3 and earlier, when register_globals is enabled, allow
23RISCO
abrir
ReferênciaVexDay Proof
WholeHogSoftware Ware Support - Authentication Bypass
CVE-2009-0458webappsphp
Multiple SQL injection vulnerabilities in admin/login_submit.php in Whole Hog Ware Support 1.x allow remote attackers to
23RISCO
abrir
ReferênciaVexDay Proof
MoviePlay 4.76 - '.lst' Local Buffer Overflow
CVE-2007-0016localwindows
Stack-based buffer overflow in MoviePlay 4.76 allows remote attackers to execute arbitrary code via a long filename in a
23RISCO
abrir
ReferênciaVexDay Proof
Advanced Login 0.7 - 'root' Remote File Inclusion
CVE-2007-1766webappsphp
PHP remote file inclusion vulnerability in login/engine/db/profiledit.php in Advanced Login 0.76 and earlier allows remo
23RISCO
abrir
ReferênciaVexDay Proof
TCExam 4.0.011 - 'SessionUserLang' Shell Injection
CVE-2007-2431webappsphp
Dynamic variable evaluation vulnerability in shared/config/tce_config.php in TCExam 4.0.011 and earlier allows remote at
23RISCO
abrir
ReferênciaVexDay Proof
Madirish Webmail 2.0 - 'addressbook.php' Remote File Inclusion
CVE-2007-2826webappsphp
PHP remote file inclusion vulnerability in lib/addressbook.php in Madirish Webmail 2.0 allows remote attackers to execut
23RISCO
abrir
ReferênciaVexDay Proof
PayProCart 1146078425 - Multiple Remote File Inclusions
CVE-2006-4672webappsphp
PHP remote file inclusion vulnerability in profitCode ppalCart 2.5 EE, possibly a component of PayProCart, allows remote
23RISCO
abrir
ReferênciaVexDay Proof
E-Smart Cart - 'productsofcat.asp' SQL Injection
CVE-2008-2917webappsasp
SQL injection vulnerability in productsofcat.asp in E-SMART CART allows remote attackers to execute arbitrary SQL comman
23RISCO
abrir
ReferênciaVexDay Proof
QK SMTP 3.01 - 'RCPT TO' Remote Denial of Service
CVE-2006-5551doswindows
Stack-based buffer overflow in QK SMTP 3.01 and earlier might allow remote attackers to execute arbitrary code via a lon
23RISCO
abrir
ReferênciaVexDay Proof
phpBLASTER CMS 1.0 RC1 - Multiple Local File Inclusions
CVE-2008-5171webappsphp
Multiple directory traversal vulnerabilities in admin/minibb/index.php in phpBLASTER CMS 1.0 RC1, when register_globals
23RISCO
abrir
ReferênciaVexDay Proof
Ultimate PHP Board 2.0 - 'header_simple.php' File Inclusion
CVE-2006-7169webappsphp
PHP remote file inclusion vulnerability in includes/header_simple.php in Ultimate PHP Board (UPB) 2.0 and earlier allows
23RISCO
abrir
ReferênciaVexDay Proof
KVIrc 3.4.2 Shiny - URI handler Remote Command Execution
CVE-2008-7070remotewindows
Argument injection vulnerability in the URI handler in KVIrc 3.4.2 Shiny allows remote attackers to execute arbitrary co
23RISCO
abrir
ReferênciaVexDay Proof
groone's Guestbook 2.0 - Remote File Inclusion
CVE-2009-0464webappsphp
PHP remote file inclusion vulnerability in includes/header.php in Groone GBook 2.0 allows remote attackers to execute ar
23RISCO
abrir
ReferênciaVexDay Proof
Euphonics Audio Player 1.0 - '.pls' Local Buffer Overflow
CVE-2009-0476localwindows
Stack-based buffer overflow in MultiMedia Soft AdjMmsEng.dll 7.11.1.0 and 7.11.2.7, as distributed in multiple MultiMedi
50RISCO
abrir
ReferênciaVexDay Proof
Extcalendar 2 - 'profile.php' Remote User Pass Change
CVE-2007-0681webappsphp
profile.php in ExtCalendar 2 and earlier allows remote attackers to change the passwords of arbitrary users without prov
23RISCO
abrir
ReferênciaVexDay Proof
Euphonics Audio Player 1.0 - '.pls' Universal Local Buffer Overflow
CVE-2009-0476localwindows
Stack-based buffer overflow in MultiMedia Soft AdjMmsEng.dll 7.11.1.0 and 7.11.2.7, as distributed in multiple MultiMedi
50RISCO
abrir
ReferênciaVexDay Proof
study planner (studiewijzer) 0.15 - Remote File Inclusion
CVE-2007-1628webappsphp
Multiple PHP remote file inclusion vulnerabilities in Study planner (Studiewijzer) 0.15 and earlier, when register_globa
23RISCO
abrir
ReferênciaVexDay Proof
XChat 2.6.7 (Windows) - Remote Denial of Service
CVE-2006-4455doswindows
Unspecified vulnerability in Xchat 2.6.7 and earlier allows remote attackers to cause a denial of service (crash) via un
23RISCO
abrir
ReferênciaVexDay Proof
ItCMS 2.1a - Authentication Bypass
CVE-2009-0493webappsphp
SQL injection vulnerability in login.php in IT!CMS 2.1a and earlier allows remote attackers to execute arbitrary SQL com
23RISCO
abrir
ReferênciaVexDay Proof
Mambo Module MambWeather 1.8.1 - Remote File Inclusion
CVE-2006-5519webappsphp
PHP remote file inclusion vulnerability in Savant2/Savant2_Plugin_options.php in the MambWeather 1.8.1 and earlier compo
23RISCO
abrir
ReferênciaVexDay Proof
Enigma 2 Coppermine Bridge - 'boarddir' Remote File Inclusion
CVE-2006-6864webappsphp
PHP remote file inclusion vulnerability in E2_header.inc.php in Enigma2 Coppermine Bridge 1.0 allows remote attackers to
23RISCO
abrir
ReferênciaVexDay Proof
GNU/Linux mbse-bbs 0.70.0 - Local Buffer Overflow
CVE-2007-0368locallinux
Stack-based buffer overflow in mbse-bbs 0.70 and earlier allows local users to execute arbitrary code via a long string
23RISCO
abrir
anteriorpágina 53 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.