Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.866exploits catalogados
35.812CVEs com exploração pública
24.695testados em laboratório
24.455 exploits
Exploit-DBVexDay Proof
ICUII 7.0 - Local Password Disclosure
CVE-2005-1411localwindows28 abr 2005
Cybration ICUII 7.0 stores passwords in plaintext in the world-readable icuii.ini file, which allows local users to gain
23RISCO
abrir
Exploit-DBVexDay Proof
FilePocket 1.2 - Local Proxy Password Disclosure
CVE-2005-1414localwindows28 abr 2005
ExoticSoft FilePocket 1.2 stores sensitive proxy information, including proxy passwords, in plaintext in the registry, w
23RISCO
abrir
Exploit-DBVexDay Proof
Oracle Application Server 9i - Webcache PartialPageErrorPage Cross-Site Scripting
CVE-2005-1381remotemultiple28 abr 2005
Multiple cross-site scripting (XSS) vulnerabilities in Oracle Webcache 9i allow remote attackers to inject arbitrary web
28RISCO
abrir
Exploit-DBVexDay Proof
Claroline 1.5/1.6 - 'myagenda.php?coursePath' Cross-Site Scripting
CVE-2005-1374webappsphp27 abr 2005
Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dok
23RISCO
abrir
Exploit-DBVexDay Proof
Claroline 1.5/1.6 - 'toolaccess_details.php?tool' Cross-Site Scripting
CVE-2005-1374webappsphp27 abr 2005
Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dok
23RISCO
abrir
Exploit-DBVexDay Proof
Claroline 1.5/1.6 - 'user_access_details.php?data' Cross-Site Scripting
CVE-2005-1374webappsphp27 abr 2005
Multiple cross-site scripting (XSS) vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dok
23RISCO
abrir
Exploit-DBVexDay Proof
Claroline E-Learning 1.5/1.6 - 'exercises_details.php?exo_id' SQL Injection
CVE-2005-1375webappsphp27 abr 2005
Multiple SQL injection vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow re
23RISCO
abrir
Exploit-DBVexDay Proof
Dream4 Koobi CMS 4.2.3 - 'index.php?P' SQL Injection
CVE-2005-0890webappsphp27 abr 2005
SQL injection vulnerability in Dream4 Koobi CMS 4.2.3 allows remote attackers to execute arbitrary SQL commands via the
23RISCO
abrir
Exploit-DBVexDay Proof
PHPCart - Input Validation
CVE-2005-1398webappsphp27 abr 2005
phpcart.php in PHPCart 3.2 allows remote attackers to change product price information by modifying the (1) price or (2)
23RISCO
abrir
Exploit-DBVexDay Proof
Dream4 Koobi CMS 4.2.3 - 'index.php?Q' SQL Injection
CVE-2005-0890webappsphp27 abr 2005
SQL injection vulnerability in Dream4 Koobi CMS 4.2.3 allows remote attackers to execute arbitrary SQL commands via the
23RISCO
abrir
Exploit-DBVexDay Proof
BakBone NetVault 7.1 - Local Privilege Escalation
CVE-2005-1372localwindows27 abr 2005
nvstatsmngr.exe process in BakBone NetVault 7.1 does not properly drop privileges before opening files, which allows loc
23RISCO
abrir
Exploit-DBVexDay Proof
Claroline E-Learning 1.5/1.6 - 'userInfo.php' Multiple SQL Injections
CVE-2005-1375webappsphp27 abr 2005
Multiple SQL injection vulnerabilities in Claroline 1.5.3 through 1.6 Release Candidate 1, and possibly Dokeos, allow re
23RISCO
abrir
Exploit-DBVexDay Proof
Convert-UUlib 1.04/1.05 Perl Module - Remote Buffer Overflow
CVE-2005-1349remotelinux26 abr 2005
Buffer overflow in Convert-UUlib (Convert::UUlib) before 1.051 allows remote attackers to execute arbitrary code via a m
28RISCO
abrir
Exploit-DBVexDay Proof
PHPMyVisites 1.3 - 'Set_Lang' File Inclusion
CVE-2005-1325webappsphp26 abr 2005
set_lang.php in phpMyVisites 1.3 allows remote attackers to read and include arbitrary files via the mylang parameter.
23RISCO
abrir
Exploit-DBVexDay Proof
Tcpdump 3.8.x/3.9.1 - 'isis_print' Infinite Loop Denial of Service
CVE-2005-1278doslinux26 abr 2005
The isis_print function, as called by isoclns_print, in tcpdump 3.9.1 and earlier allows remote attackers to cause a den
28RISCO
abrir
Exploit-DBVexDay Proof
NetFTPd 4.2.2 - User Authentication Remote Buffer Overflow
CVE-2005-1323remotewindows26 abr 2005
Buffer overflow in NetFtpd for NetTerm 5.1.1 and earlier allows remote attackers to execute arbitrary code via a long US
50RISCO
abrir
Exploit-DBVexDay Proof
BEA WebLogic Server 8.1 / WebLogic Express Administration Console - Cross-Site Scripting
CVE-2005-1380remotewindows26 abr 2005
Cross-site scripting (XSS) vulnerability in BEA Admin Console 8.1 allows remote attackers to execute arbitrary web scrip
23RISCO
abrir
Exploit-DBVexDay Proof
Ethereal 0.10.10 / tcpdump 3.9.1 - 'rsvp_print' Infinite Loop Denial of Service
CVE-2005-1280dosmultiple26 abr 2005
The rsvp_print function in tcpdump 3.9.1 and earlier allows remote attackers to cause a denial of service (infinite loop
28RISCO
abrir
Exploit-DBVexDay Proof
GrayCMS 1.1 - 'error.php' Remote File Inclusion
CVE-2005-1360webappsphp26 abr 2005
PHP remote file inclusion vulnerability in error.php in GrayCMS 1.1 allows remote attackers to execute arbitrary PHP cod
23RISCO
abrir
Exploit-DBVexDay Proof
Tcpdump 3.8.x - 'rt_routing_info' Infinite Loop Denial of Service
CVE-2005-1279doslinux26 abr 2005
tcpdump 3.8.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a crafted (1) BGP pac
28RISCO
abrir
Exploit-DBVexDay Proof
Tcpdump 3.8.x - 'ldp_print' Infinite Loop Denial of Service
CVE-2005-1279doslinux26 abr 2005
tcpdump 3.8.3 and earlier allows remote attackers to cause a denial of service (infinite loop) via a crafted (1) BGP pac
28RISCO
abrir
Exploit-DBVexDay Proof
OneWorldStore - IDOrder Information Disclosure
CVE-2005-1329webappsasp25 abr 2005
owOfflineCC.asp in OneWorldStore allows remote attackers to obtain sensitive information by modifying the idOrder parame
23RISCO
abrir
Exploit-DBVexDay Proof
StorePortal 2.63 - 'default.asp' Multiple SQL Injections
CVE-2005-1293webappsasp25 abr 2005
Multiple SQL injection vulnerabilities in default.asp in StorePortal 2.63 allow remote attackers to execute arbitrary SQ
23RISCO
abrir
Exploit-DBVexDay Proof
MailEnable Enterprise & Professional - https Remote Buffer Overflow
CVE-2005-1348remotewindows25 abr 2005
Buffer overflow in HTTPMail in MailEnable Enterprise 1.04 and earlier and Professional 1.54 and earlier allows remote at
60RISCO
abrir
Exploit-DBVexDay Proof
E-Cart 1.1 - 'index.cgi' Remote Command Execution
CVE-2005-1289webappscgi25 abr 2005
index.cgi in E-Cart 2004 1.1 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters
23RISCO
abrir
Exploit-DBVexDay Proof
Yager 5.24 - Remote Buffer Overflow
CVE-2005-1163remotewindows25 abr 2005
Multiple buffer overflows in Yager 5.24 and earlier allow remote attackers to execute arbitrary code via (1) a crafted n
28RISCO
abrir
Exploit-DBVexDay Proof
ImageMagick 6.x - '.PNM' Image Decoding Remote Buffer Overflow
CVE-2005-1275doslinux25 abr 2005
Heap-based buffer overflow in the ReadPNMImage function in pnm.c for ImageMagick 6.2.1 and earlier allows remote attacke
28RISCO
abrir
Exploit-DBVexDay Proof
PMSoftware Simple Web Server - GET Remote Buffer Overflow
CVE-2005-1173remotewindows24 abr 2005
Buffer overflow in PMSoftware Simple Web Server 1.0 allows remote attackers to execute arbitrary code via a long GET req
23RISCO
abrir
Exploit-DBVexDay Proof
CrystalFTP Pro 2.8 - Remote Buffer Overflow
CVE-2004-1327remotewindows24 abr 2005
Buffer overflow in Crystal FTP Client 2.8 allows remote malicious servers to execute arbitrary code via a response to a
23RISCO
abrir
Exploit-DBVexDay Proof
WoltLab Burning Board 2.3.1 - 'thread.php' Cross-Site Scripting
CVE-2005-1285webappsphp22 abr 2005
Cross-site scripting (XSS) vulnerability in thread.php in WoltLab Burning Board 2.3.1 and earlier allows remote attacker
23RISCO
abrir
anteriorpágina 670 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.