Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.449exploits catalogados
35.552CVEs com exploração pública
24.695testados em laboratório
24.451 exploits
Exploit-DBVexDay Proof
PHP < 4.4.5/5.2.1 - '_SESSION' Deserialization Overwrite
CVE-2007-1701locallinux25 mar 2007
PHP 4 before 4.4.5, and PHP 5 before 5.2.1, when register_globals is enabled, allows context-dependent attackers to exec
23RISCO
abrir
Exploit-DBVexDay Proof
Mercury/32 Mail Server 4.0.1 - 'LOGIN' Remote IMAP Stack Buffer Overflow
CVE-2004-1211remotewindows24 mar 2007
Multiple buffer overflows in the IMAP service in Mercury/32 4.01a allow remote authenticated users to cause a denial of
60RISCO
abrir
Exploit-DBVexDay Proof
Free File Hosting System 1.1 - 'login.php?AD_BODY_TEMP' Remote File Inclusion
CVE-2006-5763webappsphp24 mar 2007
Multiple PHP remote file inclusion vulnerabilities in Free File Hosting 1.1, and possibly earlier, when register_globals
23RISCO
abrir
Exploit-DBVexDay Proof
Free File Hosting System 1.1 - 'register.php?AD_BODY_TEMP' Remote File Inclusion
CVE-2006-5763webappsphp24 mar 2007
Multiple PHP remote file inclusion vulnerabilities in Free File Hosting 1.1, and possibly earlier, when register_globals
23RISCO
abrir
Exploit-DBVexDay Proof
Free File Hosting System 1.1 - 'contact.php?AD_BODY_TEMP' Remote File Inclusion
CVE-2006-5764webappsphp24 mar 2007
PHP remote file inclusion vulnerability in contact.php in Free File Hosting 1.1 and earlier allows remote attackers to e
23RISCO
abrir
Exploit-DBVexDay Proof
PHP 5.2.1 - 'Unserialize()' Local Information Leak
CVE-2007-1649localmultiple23 mar 2007
PHP 5.2.1 allows context-dependent attackers to read portions of heap memory by executing certain scripts with a seriali
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows Vista - Windows Mail Local File Execution
CVE-2007-1658remotewindows23 mar 2007
Windows Mail in Microsoft Windows Vista might allow user-assisted remote attackers to execute certain programs via a lin
35RISCO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.0.x/2.2.x/2.4.x (FreeBSD 4.x) - Network Device Driver Frame Padding Information Disclosure
CVE-2003-0001remotebsd23 mar 2007
Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote att
45RISCO
abrir
Exploit-DBVexDay Proof
dproxy 0.5 - Remote Buffer Overflow (Metasploit)
CVE-2007-1465remotelinux23 mar 2007
Stack-based buffer overflow in dproxy.c for dproxy 0.1 through 0.5 allows remote attackers to execute arbitrary code via
23RISCO
abrir
Exploit-DBVexDay Proof
MzK Blog - 'Katgoster.asp' SQL Injection
CVE-2007-3824webappsasp23 mar 2007
SQL injection vulnerability in katgoster.asp in MzK Blog (tr) allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
Exploit-DBVexDay Proof
Ethernet Device Drivers Frame Padding - 'Etherleak' Infomation Leakage
CVE-2003-0001remotemultiple23 mar 2007
Multiple ethernet Network Interface Card (NIC) device drivers do not pad frames with null bytes, which allows remote att
45RISCO
abrir
Exploit-DBVexDay Proof
eWebquiz 8 - 'eWebQuiz.asp' SQL Injection
CVE-2010-2359webappsasp23 mar 2007
SQL injection vulnerability in eWebQuiz.asp in ActiveWebSoftwares.com eWebquiz 8 allows remote attackers to execute arbi
23RISCO
abrir
Exploit-DBVexDay Proof
Asterisk 1.4 SIP T.38 SDP - Parsing Remote Stack Buffer Overflow (PoC) (2)
CVE-2007-2293dosmultiple21 mar 2007
Multiple stack-based buffer overflows in the process_sdp function in chan_sip.c of the SIP channel T.38 SDP parser in As
28RISCO
abrir
Exploit-DBVexDay Proof
Mercur Messaging 2005 < SP4 - IMAP Remote (Egghunter)
CVE-2006-1255remotewindows21 mar 2007
Stack-based buffer overflow in the IMAP service in Mercur Messaging 5.0 SP3 and earlier allows remote attackers to cause
50RISCO
abrir
Exploit-DBVexDay Proof
Opera 9.x - FTP PASV Port-Scanning
CVE-2007-1563remotelinux21 mar 2007
The FTP protocol implementation in Opera 9.10 allows remote attackers to allows remote servers to force the client to co
23RISCO
abrir
Exploit-DBVexDay Proof
Mozilla FireFox 1.5.x/2.0 - FTP PASV Port-Scanning
CVE-2007-1562remotelinux21 mar 2007
The FTP protocol implementation in Mozilla Firefox before 1.5.0.11 and 2.x before 2.0.0.3 allows remote attackers to for
28RISCO
abrir
Exploit-DBVexDay Proof
Asterisk 1.4 SIP T.38 SDP - Parsing Remote Stack Buffer Overflow (PoC) (1)
CVE-2007-2293dosmultiple21 mar 2007
Multiple stack-based buffer overflows in the process_sdp function in chan_sip.c of the SIP channel T.38 SDP parser in As
28RISCO
abrir
Exploit-DBVexDay Proof
KDE Konqueror 3.x/IOSlave - FTP PASV Port-Scanning
CVE-2007-1564remotelinux21 mar 2007
The FTP protocol implementation in Konqueror 3.5.5 allows remote servers to force the client to connect to other servers
23RISCO
abrir
Exploit-DBVexDay Proof
Grandstream Budge Tone-200 IP Phone - Digest domain Denial of Service
CVE-2007-1590doshardware21 mar 2007
The Grandstream BudgeTone 200 IP phone, with program 1.1.1.14 and bootloader 1.1.1.5, allows remote attackers to cause a
23RISCO
abrir
Exploit-DBVexDay Proof
Cisco Phone 7940/7960 - 'SIP INVITE' Remote Denial of Service
CVE-2007-1542doshardware20 mar 2007
Unspecified vulnerability in the Cisco IP Phone 7940 and 7960 running firmware before POS8-6-0 allows remote attackers t
23RISCO
abrir
Exploit-DBVexDay Proof
W-Agora 4.2.1 - 'change_password.php?userid' Cross-Site Scripting
CVE-2007-1606webappsphp20 mar 2007
Multiple cross-site scripting (XSS) vulnerabilities in w-Agora (Web-Agora) allow remote attackers to inject arbitrary we
23RISCO
abrir
Exploit-DBVexDay Proof
W-Agora 4.2.1 - Multiple Arbitrary File Upload Vulnerabilities
CVE-2007-1604webappsphp20 mar 2007
Multiple unrestricted file upload vulnerabilities in w-Agora (Web-Agora) allow remote attackers to upload and execute ar
23RISCO
abrir
Exploit-DBVexDay Proof
ZYXEL Router 3.40 Zynos - SMB Data Handling Denial of Service
CVE-2007-1586doshardware20 mar 2007
ZynOS 3.40 allows remote attackers to cause a denial of service (link restart) by sending a request for the name \M via
23RISCO
abrir
Exploit-DBVexDay Proof
Web Wiz Forums 8.05 - String Filtering SQL Injection
CVE-2007-1548webappsphp20 mar 2007
SQL injection vulnerability in functions/functions_filters.asp in Web Wiz Forums before 8.05a (MySQL version) does not p
23RISCO
abrir
Exploit-DBVexDay Proof
FTPDMIN 0.96 - 'LIST' Remote Denial of Service
CVE-2007-1580doswindows20 mar 2007
FTPDMIN 0.96 allows remote attackers to cause a denial of service (daemon crash) via a LIST command for a Windows drive
23RISCO
abrir
Exploit-DBVexDay Proof
W-Agora 4.2.1 - 'search.php?search_user' Cross-Site Scripting
CVE-2007-1606webappsphp20 mar 2007
Multiple cross-site scripting (XSS) vulnerabilities in w-Agora (Web-Agora) allow remote attackers to inject arbitrary we
23RISCO
abrir
Exploit-DBVexDay Proof
W-Agora 4.2.1 - 'profile.php?showuser' Cross-Site Scripting
CVE-2007-1606webappsphp20 mar 2007
Multiple cross-site scripting (XSS) vulnerabilities in w-Agora (Web-Agora) allow remote attackers to inject arbitrary we
23RISCO
abrir
Exploit-DBVexDay Proof
PHPX 3.5.15/3.5.16 - 'forums.php' SQL Injection
CVE-2007-1550webappsphp19 mar 2007
Multiple SQL injection vulnerabilities in phpx 3.5.15 allow remote attackers to execute arbitrary SQL commands via the (
23RISCO
abrir
Exploit-DBVexDay Proof
File(1) 4.13 - Command File_PrintF Integer Underflow
CVE-2007-1536remotelinux19 mar 2007
Integer underflow in the file_printf function in the "file" program before 4.20 allows user-assisted attackers to execut
28RISCO
abrir
Exploit-DBVexDay Proof
PHPX 3.5.15/3.5.16 - 'users.php' SQL Injection
CVE-2007-1550webappsphp19 mar 2007
Multiple SQL injection vulnerabilities in phpx 3.5.15 allow remote attackers to execute arbitrary SQL commands via the (
23RISCO
abrir
anteriorpágina 540 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.