Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

77.866exploits catalogados
35.812CVEs com exploração pública
24.695testados em laboratório
24.458 exploits
Exploit-DBVexDay Proof
Icecast 2.x - XSL Parser Multiple Vulnerabilities
CVE-2005-0838remotemultiple18 mar 2005
Multiple buffer overflows in the XSL parser for IceCast 2.20 may allow attackers to cause a denial of service and possib
23RISCO
abrir
Exploit-DBVexDay Proof
PHPOpenChat 3.0.1 - Multiple HTML Injection Vulnerabilities
CVE-2005-0863webappsphp18 mar 2005
Cross-site scripting (XSS) vulnerability in PHPOpenChat v3.x allows remote attackers to inject arbitrary web script or H
23RISCO
abrir
Exploit-DBVexDay Proof
RunCMS 1.1 - Database Configuration Information Disclosure
CVE-2005-0828webappsphp18 mar 2005
highlight.php in (1) RUNCMS 1.1A, (2) CIAMOS 0.9.2 RC1, (3) e-Xoops 1.05 Rev3, and possibly other products based on e-Xo
23RISCO
abrir
Exploit-DBVexDay Proof
ACS Blog 0.8/0.9/1.0/1.1 - 'search.asp' Cross-Site Scripting
CVE-2005-0802webappsasp17 mar 2005
Cross-site scripting (XSS) vulnerability in search.asp in ACS Blog 0.8 through 1.1b allows remote attackers to execute a
23RISCO
abrir
Exploit-DBVexDay Proof
Microsoft Windows XP/2000/2003 - Graphical Device Interface Library Denial of Service
CVE-2005-0803doswindows17 mar 2005
The GetEnhMetaFilePaletteEntries API in GDI32.DLL in Windows 2000 allows remote attackers to cause a denial of service (
35RISCO
abrir
Exploit-DBVexDay Proof
McNews 1.x - 'install.php' Arbitrary File Inclusion
CVE-2005-0800webappsphp17 mar 2005
PHP remote file inclusion vulnerability in install.php in mcNews 1.3 and earlier allows remote attackers to execute arbi
23RISCO
abrir
Exploit-DBVexDay Proof
MailEnable 1.8 - Remote Format String Denial of Service
CVE-2005-0804doswindows17 mar 2005
Format string vulnerability in MailEnable 1.8 allows remote attackers to cause a denial of service (application crash) v
23RISCO
abrir
Exploit-DBVexDay Proof
Linux Kernel 2.4.x/2.6.x - Multiple ISO9660 Filesystem Handling Vulnerabilities
CVE-2005-0815doslinux17 mar 2005
Multiple "range checking flaws" in the ISO9660 filesystem handler in Linux 2.6.11 and earlier may allow attackers to cau
28RISCO
abrir
Exploit-DBVexDay Proof
iPool 1.6.81 - Local Password Disclosure
CVE-2005-0823localwindows16 mar 2005
ThePoolClub (1) iPool and (2) iSnooker 1.6.81 and earlier stores usernames and passwords in cleartext in the MyDetails.t
23RISCO
abrir
Exploit-DBVexDay Proof
iSnooker 1.6.8 - Local Password Disclosure
CVE-2005-0823localwindows16 mar 2005
ThePoolClub (1) iPool and (2) iSnooker 1.6.81 and earlier stores usernames and passwords in cleartext in the MyDetails.t
23RISCO
abrir
Exploit-DBVexDay Proof
PunBB 1.2.3 - Multiple HTML Injection Vulnerabilities
CVE-2005-0818webappsphp16 mar 2005
Cross-site scripting (XSS) vulnerability in PunBB 1.2.3 allows remote attackers to inject arbitrary web script or HTML v
23RISCO
abrir
Exploit-DBVexDay Proof
PHPOpenChat 2.3.4/3.0.1 - 'ENGLISH_poc.php' Remote File Inclusion
CVE-2005-0862webappsphp15 mar 2005
Multiple PHP remote file inclusion vulnerabilities in PHPOpenChat 3.0.1 and earlier allow remote attackers to execute ar
28RISCO
abrir
Exploit-DBVexDay Proof
PHPOpenChat 2.3.4/3.0.1 - 'poc.php' Remote File Inclusion
CVE-2005-0862webappsphp15 mar 2005
Multiple PHP remote file inclusion vulnerabilities in PHPOpenChat 3.0.1 and earlier allow remote attackers to execute ar
28RISCO
abrir
Exploit-DBVexDay Proof
PHPOpenChat 2.3.4/3.0.1 - 'poc_loginform.php?phpbb_root_path' Remote File Inclusion
CVE-2005-0862webappsphp15 mar 2005
Multiple PHP remote file inclusion vulnerabilities in PHPOpenChat 3.0.1 and earlier allow remote attackers to execute ar
28RISCO
abrir
Exploit-DBVexDay Proof
ZPanel 2.5 - SQL Injection
CVE-2005-0792webappsphp15 mar 2005
SQL injection vulnerability in ZPanel 2.0 allows remote attackers to execute arbitrary SQL commands via the (1) uname pa
23RISCO
abrir
Exploit-DBVexDay Proof
GoodTech Telnet Server < 5.0.7 - Buffer Overflow Crash
CVE-2005-0768doswindows15 mar 2005
Buffer overflow in the administration web server for GoodTech Telnet Server 4.0 and 5.0, and possibly all versions befor
50RISCO
abrir
Exploit-DBVexDay Proof
PaX - Double-Mirrored VMA munmap Privilege Escalation
CVE-2005-0666locallinux14 mar 2005
Unknown vulnerability in PaX from the September 2003 release to 2.2 before 2005.03.05, related to SEGMEXEC or RANDEXEC a
23RISCO
abrir
Exploit-DBVexDay Proof
LimeWire 4.1.2 < 4.5.6 - 'GET' Remote File Read
CVE-2005-0788remotemultiple14 mar 2005
LimeWire 4.1.2 through 4.5.6 allows remote attackers to read arbitrary files by specifying the full pathname in a Gnutel
23RISCO
abrir
Exploit-DBVexDay Proof
PHPAdsNew 2.0.4 - 'AdFrame.php' Cross-Site Scripting
CVE-2005-0791webappsphp14 mar 2005
Cross-site scripting (XSS) vulnerability in adframe.php in phpAdsNew 2.0.4-pr1, when register_globals is enabled, allows
23RISCO
abrir
Exploit-DBVexDay Proof
Frank McIngvale LuxMan 0.41 - Local Buffer Overflow
CVE-2005-0385locallinux14 mar 2005
Buffer overflow in luxman before 0.41, if used with certain insecure svgalib libraries, allows local users to execute ar
23RISCO
abrir
Exploit-DBVexDay Proof
SimpGB 1.0 - 'Guestbook.php' SQL Injection
CVE-2005-0786webappsphp14 mar 2005
SQL injection vulnerability in gb_new.inc in SimpGB allows remote attackers to execute arbitrary SQL commands via the qu
23RISCO
abrir
Exploit-DBVexDay Proof
Phorum 5.0.14 - Multiple Subject and Attachment HTML Injection Vulnerabilities
CVE-2005-0783webappsphp14 mar 2005
Cross-site scripting (XSS) vulnerability in Phorum before 5.0.14a allows remote attackers to inject arbitrary web script
23RISCO
abrir
Exploit-DBVexDay Proof
Mozilla Suite/Firefox/Thunderbird - Nested Anchor Tag Status Bar Spoofing
CVE-2005-4809remotelinux14 mar 2005
Mozilla Firefox 1.0.1 and possibly other versions, including Mozilla and Thunderbird, allows remote attackers to spoof t
23RISCO
abrir
Exploit-DBVexDay Proof
HolaCMS 1.2.x/1.4.x Voting Module - Directory Traversal Remote File Corruption
CVE-2005-0796webappsphp13 mar 2005
Directory traversal vulnerability in HolaCMS 1.4.9-1 allows remote attackers to overwrite arbitrary files via a "holaDB/
23RISCO
abrir
Exploit-DBVexDay Proof
Sentinel LM 7.x - UDP License Service Remote Buffer Overflow
CVE-2005-0353remotewindows13 mar 2005
Buffer overflow in the Sentinel LM (Lservnt) service in the Sentinel License Manager 7.2.0.2 allows remote attackers to
60RISCO
abrir
Exploit-DBVexDay Proof
PAFileDB 1.1.3/2.1.1/3.0/3.1 - 'category.php?start' Cross-Site Scripting
CVE-2005-0782webappsphp12 mar 2005
Cross-site scripting (XSS) vulnerability in (1) viewall.php and (2) category.php for paFileDB 3.1 and earlier allows rem
23RISCO
abrir
Exploit-DBVexDay Proof
Ethereal 0.10.9 (Windows) - '3G-A11' Remote Buffer Overflow
CVE-2005-0739doswindows12 mar 2005
The IAPP dissector (packet-iapp.c) for Ethereal 0.9.1 to 0.10.9 does not properly use certain routines for formatting st
23RISCO
abrir
Exploit-DBVexDay Proof
HolaCMS 1.2/1.4.x Voting Module - Remote File Corruption
CVE-2005-0795webappsphp12 mar 2005
HolaCMS 1.4.9 does not restrict file access to the holaDB/votes directory, which allows remote attackers to overwrite ar
23RISCO
abrir
Exploit-DBVexDay Proof
PAFileDB 1.1.3/2.1.1/3.0/3.1 - 'viewall.php?start' Cross-Site Scripting
CVE-2005-0782webappsphp12 mar 2005
Cross-site scripting (XSS) vulnerability in (1) viewall.php and (2) category.php for paFileDB 3.1 and earlier allows rem
23RISCO
abrir
Exploit-DBVexDay Proof
PAFileDB 1.1.3/2.1.1/3.0/3.1 - 'category.php?start' SQL Injection
CVE-2005-0781webappsphp12 mar 2005
SQL injection vulnerability in (1) viewall.php and (2) category.php in paFileDB 3.1 and earlier allows remote attackers
23RISCO
abrir
anteriorpágina 678 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.