Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.131exploits catalogados
35.957CVEs com exploração pública
24.695testados em laboratório
22.640 exploits
Referência
CVE-2019-1170
Windows NTFS Elevation of Privilege Vulnerability
41RISCO
abrir
Referência
CVE-2013-0803
A PHP File Upload Vulnerability exists in PolarBear CMS 2.5 via upload.php, which could let a malicious user execute arb
60RISCO
abrir
Referência
CVE-2010-1740
SQL injection vulnerability in newsletter.php in GuppY 4.5.18 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
Referência
CVE-2010-1740
SQL injection vulnerability in newsletter.php in GuppY 4.5.18 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
Referência
CVE-2017-14618
Cross-site scripting (XSS) vulnerability in inc/PMF/Faq.php in phpMyFAQ through 2.9.8 allows remote attackers to inject
23RISCO
abrir
ReferênciaVexDay Proof
Cartweaver 3 - 'prodId' Blind SQL Injection
CVE-2008-2918webappsphp
SQL injection vulnerability in details.php in Application Dynamics Cartweaver 3.0 allows remote attackers to execute arb
23RISCO
abrir
Referência
CVE-2019-0555
An elevation of privilege vulnerability exists in the Microsoft XmlDocument class that could allow an attacker to escape
23RISCO
abrir
ReferênciaVexDay Proof
WebAlbum 2.02pl - COOKIE[skin2] Remote Code Execution
CVE-2006-1480webappsphp
Directory traversal vulnerability in start.php in WebAlbum 2.02 allows remote attackers to include arbitrary files and e
23RISCO
abrir
ReferênciaVexDay Proof
PHP Ticket 0.71 - 'search.php' SQL Injection
CVE-2006-1481webappsphp
SQL injection vulnerability in search.php in PHP Ticket 0.71 allows remote authenticated users to execute arbitrary SQL
23RISCO
abrir
Referência
CVE-2013-0803
A PHP File Upload Vulnerability exists in PolarBear CMS 2.5 via upload.php, which could let a malicious user execute arb
60RISCO
abrir
ReferênciaVexDay Proof
iWare Pro 5.0.4 - 'chat_panel.php' Remote Code Execution
CVE-2006-5837webappsphp
Static code injection vulnerability in chat_panel.php in the SimpleChat 1.0.0 module for iWare Professional CMS allows r
23RISCO
abrir
ReferênciaVexDay Proof
TorrentFlux 2.2 - 'downloaddetails.php' Local File Disclosure
CVE-2006-6598webappsphp
Directory traversal vulnerability in viewnfo.php in (1) TorrentFlux before 2.2 and (2) torrentflux-b4rt before 2.1-b4rt-
23RISCO
abrir
ReferênciaVexDay Proof
NewsCMSLite - 'newsCMS.mdb' Remote Password Disclosure
CVE-2007-0091webappsasp
newsCMSlite stores sensitive information under the web root with insufficient access control, which allows remote attack
23RISCO
abrir
ReferênciaVexDay Proof
Pakupaku CMS 0.4 - Arbitrary File Upload / Local File Inclusion
CVE-2007-4640webappsphp
Unrestricted file upload vulnerability in index.php in Pakupaku CMS 0.4 and earlier allows remote attackers to upload an
23RISCO
abrir
Referência
CVE-2021-40577
A Stored Cross Site Scripting (XSS) vulnerability exists in Sourcecodester Online Enrollment Management System in PHP an
23RISCO
abrir
ReferênciaVexDay Proof
Phoenix View CMS Pre Alpha2 - SQL Injection / Local File Inclusion / Cross-Site Scripting
CVE-2008-2534webappsphp
Directory traversal vulnerability in admin/admin_frame.php in Phoenix View CMS Pre Alpha2 and earlier allows remote atta
23RISCO
abrir
Referência
CVE-2010-5057
SQL injection vulnerability in detResolucion.php in CMS Ariadna 1.1 allows remote attackers to execute arbitrary SQL com
23RISCO
abrir
Referência
CVE-2009-3064
Directory traversal vulnerability in debugger/debug_php.php in Ve-EDIT 0.1.4 allows remote attackers to include and exec
23RISCO
abrir
ReferênciaVexDay Proof
Poppler 0.8.4 - libpoppler Uninitialized pointer Code Execution
CVE-2008-2950locallinux
The Page destructor in Page.cc in libpoppler in Poppler 0.8.4 and earlier deletes a pageWidgets object even if it is not
28RISCO
abrir
ReferênciaVexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
CVE-2007-6501webappsasp
Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to enable
23RISCO
abrir
Referência
CVE-2013-1306
Use-after-free vulnerability in Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code via a cr
35RISCO
abrir
Referência
CVE-2009-3824
Directory traversal vulnerability in include/processor.php in Greenwood PHP Content Manager 0.3.2 allows remote attacker
23RISCO
abrir
Referência
CVE-2010-2905
SQL injection vulnerability in info.php in ScriptsFeed and BrotherScripts (BS) Scripts Directory allows remote attackers
23RISCO
abrir
Referência
CVE-2007-1580
FTPDMIN 0.96 allows remote attackers to cause a denial of service (daemon crash) via a LIST command for a Windows drive
23RISCO
abrir
Referência
CVE-2015-4039
Multiple cross-site scripting (XSS) vulnerabilities in the WP Membership plugin 1.2.3 for WordPress allow remote authent
23RISCO
abrir
Referência
CVE-2019-18859
Digi AnywhereUSB 14 allows XSS via a link for the Digi Page.
23RISCO
abrir
ReferênciaVexDay Proof
CubeCart 3.0.6 - Remote Command Execution
CVE-2006-0064webappsphp
PHP remote file include vulnerability in includes/orderSuccess.inc.php in CubeCart allows remote attackers to execute ar
23RISCO
abrir
ReferênciaVexDay Proof
inertianews 0.02b - 'inertianews_main.php' Remote File Inclusion
CVE-2006-6726webappsphp
PHP remote file inclusion vulnerability in inertianews_main.php in inertianews 0.02 beta allows remote attackers to exec
23RISCO
abrir
ReferênciaVexDay Proof
EQdkp 1.3.1 - 'Referer Spoof' Remote Database Backup
CVE-2007-0760webappsphp
EQdkp 1.3.1 and earlier authenticates administrative requests by verifying that the HTTP Referer header specifies an adm
23RISCO
abrir
ReferênciaVexDay Proof
The Everything Development System Pre-1.0 - SQL Injection
CVE-2008-0724webappsphp
The Everything Development Engine in The Everything Development System Pre-1.0 and earlier stores passwords in cleartext
23RISCO
abrir
anteriorpágina 627 / 755próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.