Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.533exploits catalogados
35.607CVEs com exploração pública
24.695testados em laboratório
24.455 exploits
Exploit-DBVexDay Proof
WoltLab Burning Book 1.1.2 - SQL Injection
CVE-2006-5509webappsphp16 out 2006
Eval injection vulnerability in addentry.php in WoltLab Burning Book 1.1.2 allows remote attackers to execute arbitrary
23RISCO
abrir
Exploit-DBVexDay Proof
WoltLab Burning Book 1.1.2 - SQL Injection
CVE-2006-5508webappsphp16 out 2006
Multiple SQL injection vulnerabilities in addentry.php in WoltLab Burning Book 1.1.2 allow remote attackers to execute a
23RISCO
abrir
Exploit-DBVexDay Proof
KMail 1.x - HTML Element Handling Denial of Service
CVE-2006-7139doslinux16 out 2006
Kmail 1.9.1 on KDE 3.5.2, with "Prefer HTML to Plain Text" enabled, allows remote attackers to cause a denial of service
23RISCO
abrir
Exploit-DBVexDay Proof
Comdev One Admin 4.1 - 'Adminfoot.php' Remote Code Execution
CVE-2006-6045webappsphp16 out 2006
Multiple PHP remote file inclusion vulnerabilities in Comdev One Admin Pro 4.1 allow remote attackers to execute arbitra
23RISCO
abrir
Exploit-DBVexDay Proof
Nvidia Graphics Driver 8774 - Local Buffer Overflow
CVE-2006-5379locallinux16 out 2006
The accelerated rendering functionality of NVIDIA Binary Graphics Driver (binary blob driver) For Linux v8774 and v8762,
28RISCO
abrir
Exploit-DBVexDay Proof
Internet Security Systems 3.6 - 'ZWDeleteFile()' Arbitrary File Deletion
CVE-2006-7129localmultiple16 out 2006
ISS BlackICE PC Protection 3.6 cpj and cpu, and possibly earlier versions, allows local users to bypass the protection s
23RISCO
abrir
Exploit-DBVexDay Proof
Maintain 3.0.0-RC2 - 'Example6.php' Remote File Inclusion
CVE-2006-7120webappsphp16 out 2006
PHP remote file inclusion vulnerability in lib/php/phphtmllib-2.5.4/examples/example6.php for maintain 3.0.0-RC2 allows
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Class Package Export Tool 5.0.2752 - 'Clspack.exe' Local Buffer Overflow (PoC)
CVE-2006-5395doswindows16 out 2006
Buffer overflow in Microsoft Class Package Export Tool (aka clspack.exe) allows context-dependent attackers to execute a
23RISCO
abrir
Exploit-DBVexDay Proof
CampSite 2.6.1 - 'g_documentRoot' Remote File Inclusion
CVE-2006-5910webappsphp15 out 2006
Multiple PHP remote file inclusion vulnerabilities in Campware Campsite before 20061110 allow remote attackers to execut
23RISCO
abrir
Exploit-DBVexDay Proof
Bloq 0.5.4 - '/files/mainfile.php?page[path]' Remote File Inclusion
CVE-2006-6592webappsphp13 out 2006
Multiple PHP remote file inclusion vulnerabilities in Bloq 0.5.4 allow remote attackers to execute arbitrary PHP code vi
23RISCO
abrir
Exploit-DBVexDay Proof
FreeBSD 6.1-RELEASE-p10 - 'scheduler' Local Denial of Service
CVE-2006-5483dosbsd13 out 2006
p1003_1b.c in FreeBSD 6.1 allows local users to cause an unspecified denial of service by setting a scheduler policy, wh
23RISCO
abrir
Exploit-DBVexDay Proof
FreeBSD 6.1-RELEASE-p10 - 'ftruncate' Local Denial of Service
CVE-2006-5482dosbsd13 out 2006
ufs_vnops.c in FreeBSD 6.1 allows local users to cause an unspecified denial of service by calling the ftruncate functio
23RISCO
abrir
Exploit-DBVexDay Proof
Bloq 0.5.4 - 'admin.php?page[path]' Remote File Inclusion
CVE-2006-6592webappsphp13 out 2006
Multiple PHP remote file inclusion vulnerabilities in Bloq 0.5.4 allow remote attackers to execute arbitrary PHP code vi
23RISCO
abrir
Exploit-DBVexDay Proof
phpBB Add Name Module - 'Not_Mem.php' Remote File Inclusion
CVE-2006-7168webappsphp13 out 2006
PHP remote file inclusion vulnerability in includes/not_mem.php in the Add Name module for PHP allows remote attackers t
23RISCO
abrir
Exploit-DBVexDay Proof
phpBB Amazonia Mod - 'zufallscodepart.php' Remote File Inclusion
CVE-2006-6593webappsphp13 out 2006
PHP remote file inclusion vulnerability in zufallscodepart.php in AMAZONIA MOD for phpBB allows remote attackers to exec
23RISCO
abrir
Exploit-DBVexDay Proof
Sun Solaris Netscape Portable Runtime API 4.6.1 - Local Privilege Escalation (1)
CVE-2006-4842localsolaris13 out 2006
The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment v
38RISCO
abrir
Exploit-DBVexDay Proof
Solaris 10 libnspr - 'LD_PRELOAD' Arbitrary File Creation Privilege Escalation (1)
CVE-2006-4842localsolaris13 out 2006
The Netscape Portable Runtime (NSPR) API 4.6.1 and 4.6.2, as used in Sun Solaris 10, trusts user-specified environment v
38RISCO
abrir
Exploit-DBVexDay Proof
Bloq 0.5.4 - 'index.php?page[path]' Remote File Inclusion
CVE-2006-6592webappsphp13 out 2006
Multiple PHP remote file inclusion vulnerabilities in Bloq 0.5.4 allow remote attackers to execute arbitrary PHP code vi
23RISCO
abrir
Exploit-DBVexDay Proof
Bloq 0.5.4 - 'rdf.php?page[path]' Remote File Inclusion
CVE-2006-6592webappsphp13 out 2006
Multiple PHP remote file inclusion vulnerabilities in Bloq 0.5.4 allow remote attackers to execute arbitrary PHP code vi
23RISCO
abrir
Exploit-DBVexDay Proof
Bloq 0.5.4 - 'rss.php?page[path]' Remote File Inclusion
CVE-2006-6592webappsphp13 out 2006
Multiple PHP remote file inclusion vulnerabilities in Bloq 0.5.4 allow remote attackers to execute arbitrary PHP code vi
23RISCO
abrir
Exploit-DBVexDay Proof
Bloq 0.5.4 - 'rss2.php?page[path]' Remote File Inclusion
CVE-2006-6592webappsphp13 out 2006
Multiple PHP remote file inclusion vulnerabilities in Bloq 0.5.4 allow remote attackers to execute arbitrary PHP code vi
23RISCO
abrir
Exploit-DBVexDay Proof
YaPiG 0.9x - 'Thanks_comment.php' Cross-Site Scripting
CVE-2006-4421webappsphp13 out 2006
Cross-site scripting (XSS) vulnerability in template/default/thanks_comment.php in Yet Another PHP Image Gallery (YaPIG)
23RISCO
abrir
Exploit-DBVexDay Proof
maluinfo 206.2.38 - 'bb_usage_stats.php' Remote File Inclusion
CVE-2006-7148webappsphp13 out 2006
PHP remote file inclusion vulnerability in includes/bb_usage_stats.php in maluinfo 206.2.38 for Brazilian PHPBB allows r
23RISCO
abrir
Exploit-DBVexDay Proof
MamboLaiThai ExtCalThai 0.9.1 - 'admin_events.php?CONFIG_EXT[LANGUAGES_DIR]' Remote File Inclusion
CVE-2006-6634webappsphp12 out 2006
Multiple PHP remote file inclusion vulnerabilities in the ExtCalThai (com_extcalendar) 0.9.1 and earlier component for M
23RISCO
abrir
Exploit-DBVexDay Proof
MamboLaiThai ExtCalThai 0.9.1 - 'mail.inc.php?CONFIG_EXT[LIB_DIR]' Remote File Inclusion
CVE-2006-6634webappsphp12 out 2006
Multiple PHP remote file inclusion vulnerabilities in the ExtCalThai (com_extcalendar) 0.9.1 and earlier component for M
23RISCO
abrir
Exploit-DBVexDay Proof
PHP TopSites FREE 1.022b - 'config.php' Remote File Inclusion
CVE-2006-7091webappsphp12 out 2006
PHP remote file inclusion vulnerability in config.php in phpht Topsites FREE 1.022b allows remote attackers to execute a
23RISCO
abrir
Exploit-DBVexDay Proof
FreeBSD 5.4/6.0 - 'ptrace PT_LWPINFO' Local Denial of Service
CVE-2006-4516dosbsd12 out 2006
Integer signedness error in FreeBSD 6.0-RELEASE allows local users to cause a denial of service (memory corruption and k
23RISCO
abrir
Exploit-DBVexDay Proof
Download-Engine 1.4.2 - 'spaw' Remote File Inclusion
CVE-2006-4656webappsphp12 out 2006
PHP remote file inclusion vulnerability in admin/editeur/spaw_control.class.php in Web Provence SL_Site 1.0 and earlier
28RISCO
abrir
Exploit-DBVexDay Proof
FreeWPS 2.11 - 'upload.php' Remote Command Execution
CVE-2006-5411webappsphp12 out 2006
Unrestricted file upload vulnerability in upload.php for Free Web Publishing System (FreeWPS), possibly 2.11 and earlier
23RISCO
abrir
Exploit-DBVexDay Proof
phpList 2.x - Public Pages MultipleCross-Site Scripting Vulnerabilities
CVE-2006-5294webappsphp12 out 2006
Cross-site scripting (XSS) vulnerability in index.php in phplist before 2.10.3 allows remote attackers to inject arbitra
23RISCO
abrir
anteriorpágina 571 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.