Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.057exploits catalogados
36.288CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
runawaysoft haber portal 1.0 - 'tr' Multiple Vulnerabilities
CVE-2007-2753webappsasp
RunawaySoft Haber portal 1.0 stores sensitive information under the web root with insufficient access control, which all
23RISCO
abrir
ReferênciaVexDay Proof
ASP PORTAL - Remote Database Disclosure
CVE-2008-5562webappsasp
ASPPortal stores sensitive information under the web root with insufficient access control, which allows remote attacker
23RISCO
abrir
ReferênciaVexDay Proof
Total Video Player 1.31 - 'DefaultSkin.ini' Local Stack Overflow
CVE-2009-0261localwindows
Stack-based buffer overflow in EffectMatrix Total Video Player 1.31 allows user-assisted attackers to execute arbitrary
43RISCO
abrir
ReferênciaVexDay Proof
PHPbbBook 1.3 - 'bbcode.php?l' Local File Inclusion
CVE-2009-0442webappsphp
Directory traversal vulnerability in bbcode.php in PHPbbBook 1.3 and 1.3h allows remote attackers to include and execute
23RISCO
abrir
ReferênciaVexDay Proof
DreamPics Photo/Video Gallery - Blind SQL Injection
CVE-2009-0445webappsphp
SQL injection vulnerability in index.php in Dreampics Gallery Builder allows remote attackers to execute arbitrary SQL c
23RISCO
abrir
ReferênciaVexDay Proof
FipsCMS Light 2.1 - 'db.mdb' Remote Database Disclosure
CVE-2009-2022webappsasp
fipsCMS Light 2.1 stores sensitive information under the web root with insufficient access control, which allows remote
23RISCO
abrir
ReferênciaVexDay Proof
CMS-BRD - 'menuclick' SQL Injection
CVE-2008-2837webappsphp
SQL injection vulnerability in index.php in CMS-BRD allows remote attackers to execute arbitrary SQL commands via the me
23RISCO
abrir
ReferênciaVexDay Proof
MyDesing Sayac 2.0 - Authentication Bypass
CVE-2009-0447webappsasp
Multiple SQL injection vulnerabilities in default.asp in MyDesign Sayac 2.0 allow remote attackers to execute arbitrary
23RISCO
abrir
ReferênciaVexDay Proof
WebMatic 2.6 - 'index_album.php' Remote File Inclusion
CVE-2007-0839webappsphp
Multiple PHP remote file inclusion vulnerabilities in index/index_album.php in Valarsoft WebMatic 2.6 allow remote attac
23RISCO
abrir
ReferênciaVexDay Proof
Carscripts Classifieds - 'cat' SQL Injection
CVE-2008-2844webappsphp
SQL injection vulnerability in index.php in Carscripts Classifieds allows remote attackers to execute arbitrary SQL comm
23RISCO
abrir
ReferênciaVexDay Proof
Agora 1.4 RC1 - 'MysqlfinderAdmin.php' Remote File Inclusion
CVE-2006-7194webappsphp
PHP remote file inclusion vulnerability in modules/Mysqlfinder/MysqlfinderAdmin.php in Agora 1.4 RC1, when register_glob
23RISCO
abrir
ReferênciaVexDay Proof
Microsoft Windows Explorer - '.AVI' File Denial of Service
CVE-2007-0562doswindows
Windows Explorer (explorer.exe) 6.0.2900.2180 in Microsoft Windows XP SP2 allows user-assisted remote attackers to cause
28RISCO
abrir
ReferênciaVexDay Proof
phpEmployment - 'PHP Upload' Arbitrary File Upload
CVE-2008-6920webappsphp
Unrestricted file upload vulnerability in auth.php in phpEmployment 1.8 allows remote attackers to execute arbitrary cod
23RISCO
abrir
ReferênciaVexDay Proof
Maian Recipe 1.0 - 'path_to_folder' Remote File Inclusion
CVE-2007-0848webappsphp
PHP remote file inclusion vulnerability in classes/class_mail.inc.php in Maian Recipe 1.0 allows remote attackers to exe
23RISCO
abrir
ReferênciaVexDay Proof
Realtor 747 - 'index.php?categoryId' SQL Injection
CVE-2007-3810webappsphp
SQL injection vulnerability in index.php in Realtor 747 allows remote attackers to execute arbitrary SQL commands via th
23RISCO
abrir
ReferênciaVexDay Proof
WordPress Plugin Photoracer 1.0 - 'id' SQL Injection
CVE-2009-2122webappsphp
SQL injection vulnerability in viewimg.php in the Paolo Palmonari Photoracer plugin 1.0 for WordPress allows remote atta
23RISCO
abrir
ReferênciaVexDay Proof
eSyndiCat Directory Software - Multiple SQL Injections
CVE-2007-3811webappsphp
Multiple SQL injection vulnerabilities in eSyndiCat allow remote attackers to execute arbitrary SQL commands via (1) the
23RISCO
abrir
ReferênciaVexDay Proof
shibby shop 2.2 - Multiple Vulnerabilities
CVE-2008-2882webappsphp
upgrade.asp in sHibby sHop 2.2 and earlier does not require administrative authentication, which allows remote attackers
23RISCO
abrir
ReferênciaVexDay Proof
PUMA 1.0 RC 2 - 'config.php' Remote File Inclusion
CVE-2006-4713webappsphp
PHP remote file inclusion vulnerability in config.php in PSYWERKS PUMA 1.0 RC2 allows remote attackers to execute arbitr
23RISCO
abrir
ReferênciaVexDay Proof
emuCMS 0.3 - 'cat_id' SQL Injection
CVE-2008-2891webappsphp
SQL injection vulnerability in index.php in eMuSOFT emuCMS 0.3 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
ReferênciaVexDay Proof
Microsoft Windows Vista - Access Violation from Limited Account (Blue Screen of Death)
CVE-2008-4510doswindows
Microsoft Windows Vista Home and Ultimate Edition SP1 and earlier allows local users to cause a denial of service (page
23RISCO
abrir
ReferênciaVexDay Proof
Segue CMS 1.5.8 - 'themesdir' Remote File Inclusion
CVE-2006-5497webappsphp
PHP remote file inclusion vulnerability in themes/program/themesettings.inc.php in Segue CMS 1.5.8 and earlier, when reg
23RISCO
abrir
ReferênciaVexDay Proof
Zeeways PHOTOVIDEOTUBE 1.1 - Authentication Bypass
CVE-2008-5042webappsphp
Zeeways PhotoVideoTube 1.1 and earlier allows remote attackers to bypass authentication and perform administrative tasks
23RISCO
abrir
ReferênciaVexDay Proof
BlazeVideo HDTV Player 3.5 - '.PLF' Playlist File Local Overflow
CVE-2009-0450localwindows
Stack-based buffer overflow in BlazeVideo HDTV Player 3.5 and earlier allows remote attackers to execute arbitrary code
28RISCO
abrir
ReferênciaVexDay Proof
SkaLinks 1.5 - Authentication Bypass
CVE-2009-0451webappsphp
SQL injection vulnerability in Skalfa SkaLinks 1.5 allows remote attackers to execute arbitrary SQL commands via the Adm
23RISCO
abrir
ReferênciaVexDay Proof
Online Grades 3.2.4 - Authentication Bypass
CVE-2009-0452webappsphp
Multiple SQL injection vulnerabilities in parents/login.php in Online Grades 3.2.4, when magic_quotes_gpc is disabled, a
23RISCO
abrir
ReferênciaVexDay Proof
a-ConMan 3.2b - 'common.inc.php' Remote File Inclusion
CVE-2006-6078webappsphp
PHP remote file inclusion vulnerability in common.inc.php in a-ConMan 3.2 beta allows remote attackers to execute arbitr
23RISCO
abrir
ReferênciaVexDay Proof
Macromedia Flash 8 (Flash8b.ocx) Internet Explorer 7 - Denial of Service
CVE-2006-6827doswindows
Flash8b.ocx in Macromedia Flash 8 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a
23RISCO
abrir
ReferênciaVexDay Proof
AJA Portal 1.2 (Windows) - Local File Inclusion
CVE-2009-0457webappsphp
Multiple directory traversal vulnerabilities in AJA Portal 1.2 allow remote attackers to include and execute arbitrary l
23RISCO
abrir
ReferênciaVexDay Proof
WebChamado 1.1 - Arbitrary Add Admin
CVE-2008-2907webappsphp
SQL injection vulnerability in admin/index.php in WebChamado 1.1, when magic_quotes_gpc is disabled, allows remote attac
23RISCO
abrir
anteriorpágina 67 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.