Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.057exploits catalogados
36.288CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
Joomla! Component Nice Talk 0.9.3 - 'tagid' SQL Injection
CVE-2007-4503webappsphp
SQL injection vulnerability in index.php in the Nice Talk component (com_nicetalk) 0.9.3 and earlier for Joomla! allows
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component NeoRecruit 1.4 - 'id' SQL Injection
CVE-2007-4506webappsphp
SQL injection vulnerability in index.php in the NeoRecruit component (com_neorecruit) 1.4 and earlier for Joomla! allows
23RISCO
abrir
ReferênciaVexDay Proof
PHP 5.2.3 - PHP_ntuser ntuser_getuserlist() Local Buffer Overflow (PoC)
CVE-2007-4507doswindows
Multiple buffer overflows in the php_ntuser component for PHP 5.2.3 allow context-dependent attackers to cause a denial
23RISCO
abrir
ReferênciaVexDay Proof
PHP 'FFI' Extension 5.0.5 - 'Safe_mode' Local Bypass
CVE-2007-4528localwindows
The Foreign Function Interface (ffi) extension in PHP 5.0.5 does not follow safe_mode restrictions, which allows context
23RISCO
abrir
ReferênciaVexDay Proof
plxAutoReminder 3.7 - 'id' SQL Injection
CVE-2009-0593webappsphp
SQL injection vulnerability in members.php in plx Auto Reminder 3.7 allows remote authenticated users to execute arbitra
23RISCO
abrir
ReferênciaVexDay Proof
phpskelsite 1.4 - Local File Inclusion / Remote File Inclusion / Cross-Site Scripting
CVE-2009-0594webappsphp
Cross-site scripting (XSS) vulnerability in index.php in phpSkelSite 1.4 allows remote attackers to inject arbitrary web
23RISCO
abrir
ReferênciaVexDay Proof
SunShop Shopping Cart 4.0 RC 6 - 'Search' Blind SQL Injection
CVE-2007-4597webappsphp
SQL injection vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 RC 6 allows remote attackers to ex
23RISCO
abrir
ReferênciaVexDay Proof
Micro CMS 3.5 - 'revert-content.php' SQL Injection
CVE-2007-4602webappsphp
SQL injection vulnerability in cms/revert-content.php in Implied by Design Micro CMS (Micro-CMS) 3.5 allows remote attac
23RISCO
abrir
ReferênciaVexDay Proof
ABC estore 3.0 - 'cat_id' Blind SQL Injection
CVE-2007-4627webappsphp
SQL injection vulnerability in index.php in ABC eStore 3.0 allows remote attackers to execute arbitrary SQL commands via
23RISCO
abrir
ReferênciaVexDay Proof
Yvora CMS 1.0 - 'error_view.php?ID' SQL Injection
CVE-2007-4714webappsphp
SQL injection vulnerability in error_view.php in Yvora 1.0 allows remote attackers to execute arbitrary SQL commands via
23RISCO
abrir
ReferênciaVexDay Proof
CKGold Shopping Cart 2.0 - 'category.php' Blind SQL Injection
CVE-2007-4736webappsphp
SQL injection vulnerability in category.php in CartKeeper CKGold Shopping Cart 2.0 allows remote attackers to execute ar
23RISCO
abrir
ReferênciaVexDay Proof
AnyInventory 2.0 - 'Environment.php' Remote File Inclusion
CVE-2007-4744webappsphp
PHP remote file inclusion vulnerability in environment.php in AnyInventory 1.9.1 and 2.0, when register_globals is enabl
35RISCO
abrir
ReferênciaVexDay Proof
PHPMytourney - 'menu.php' Remote File Inclusion
CVE-2007-4757webappsphp
PHP remote file inclusion vulnerability in menu.php in phpMytourney allows remote attackers to execute arbitrary PHP cod
35RISCO
abrir
ReferênciaVexDay Proof
GlobalLink 2.7.0.8 - 'glItemCom.dll SetInfo()' Heap Overflow
CVE-2007-4802remotewindows
Multiple heap-based buffer overflows in GlobalLink 2.7.0.8 allow remote attackers to execute arbitrary code via (1) a lo
23RISCO
abrir
ReferênciaVexDay Proof
GlobalLink 2.7.0.8 - 'glitemflat.dll SetClientInfo()' Heap Overflow
CVE-2007-4802remotewindows
Multiple heap-based buffer overflows in GlobalLink 2.7.0.8 allow remote attackers to execute arbitrary code via (1) a lo
23RISCO
abrir
ReferênciaVexDay Proof
AtomixMP3 2.3 - '.pls' Local Buffer Overflow
CVE-2007-4803localwindows
Buffer overflow in AtomixMP3 2.3 allows user-assisted remote attackers to execute arbitrary code via long strings in fil
23RISCO
abrir
ReferênciaVexDay Proof
Fuzzylime CMS 3.0 - Local File Inclusion
CVE-2007-4805webappsphp
Directory traversal vulnerability in getgalldata.php in fuzzylime (cms) 3.0 and earlier allows remote attackers to inclu
23RISCO
abrir
ReferênciaVexDay Proof
Ultra Crypto Component - 'CryptoX.dll 2.0 SaveToFile()' Insecure Method
CVE-2007-4902remotewindows
Absolute path traversal vulnerability in a certain ActiveX control in CryptoX.dll 2.0 and earlier in the Ultra Crypto Co
23RISCO
abrir
ReferênciaVexDay Proof
NuclearBB Alpha 2 - 'ROOT_PATH' Remote File Inclusion
CVE-2007-4906webappsphp
PHP remote file inclusion vulnerability in tasks/send_queued_emails.php in NuclearBB Alpha 2, when register_globals is e
35RISCO
abrir
ReferênciaVexDay Proof
Boa 0.93.15 - HTTP Basic Authentication Bypass
CVE-2007-4915remotelinux
The Intersil isl3893 extensions for Boa 0.93.15, as used on the FreeLan RO80211G-AP and other devices, do not prevent st
50RISCO
abrir
ReferênciaVexDay Proof
OpenH323 Opal SIP Protocol - Remote Denial of Service
CVE-2007-4924doswindows
The Open Phone Abstraction Library (opal), as used by (1) Ekiga before 2.0.10 and (2) OpenH323 before 2.2.4, allows remo
28RISCO
abrir
ReferênciaVexDay Proof
Shop-Script FREE 2.0 - Remote Command Execution
CVE-2007-4932webappsphp
admin.php in Shop-Script FREE 2.0 and earlier sends a redirect to the web browser but does not exit when administrative
23RISCO
abrir
ReferênciaVexDay Proof
phpFFL 1.24 - 'PHPFFL_FILE_ROOT' Remote File Inclusion
CVE-2007-4934webappsphp
Multiple PHP remote file inclusion vulnerabilities in phpFFL 1.24 allow remote attackers to execute arbitrary PHP code v
28RISCO
abrir
ReferênciaVexDay Proof
Omnistar Article Manager Software - 'article.php' SQL Injection
CVE-2007-4952webappsphp
SQL injection vulnerability in article.php in OmniStar Article Manager allows remote attackers to execute arbitrary SQL
23RISCO
abrir
ReferênciaVexDay Proof
SimpCMS - 'keyword' SQL Injection
CVE-2007-4953webappsphp
SQL injection vulnerability in index.php in SimpCMS allows remote attackers to execute arbitrary SQL commands via the ke
23RISCO
abrir
ReferênciaVexDay Proof
KwsPHP 1.0 sondages Module - SQL Injection
CVE-2007-4979webappsphp
SQL injection vulnerability in index.php in the sondages module in KwsPHP 1.0 allows remote attackers to execute arbitra
23RISCO
abrir
ReferênciaVexDay Proof
MW6 Technologies QRCode ActiveX 3.0 - Remote File Overwrite
CVE-2007-4982remotewindows
Multiple absolute path traversal vulnerabilities in the MW6QRCode.QRCode.1 ActiveX control in MW6QRCode.dll in MW6 Techn
28RISCO
abrir
ReferênciaVexDay Proof
Aqua CMS - 'Username' SQL Injection
CVE-2009-1317webappsphp
Multiple SQL injection vulnerabilities in Aqua CMS 1.1, when magic_quotes_gpc is disabled, allow remote attackers to exe
23RISCO
abrir
ReferênciaVexDay Proof
Teraway LiveHelp 2.0 - Insecure Cookie Handling
CVE-2009-1618webappsphp
Teraway LiveHelp 2.0 allows remote attackers to bypass authentication and gain administrative access via a pwd=&lvl=1&us
23RISCO
abrir
ReferênciaVexDay Proof
Easy Scripts Answer and Question Script - Multiple Vulnerabilities
CVE-2009-1664webappsphp
myaccount.php in Easy Scripts Answer and Question Script does not verify the original password before changing passwords
23RISCO
abrir
anteriorpágina 70 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.