Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.055exploits catalogados
35.925CVEs com exploração pública
24.695testados em laboratório
24.458 exploits
Exploit-DBVexDay Proof
PHP-Nuke Error Manager Module 2.1 - 'error.php?language' Full Path Disclosure
CVE-2004-1830webappsphp18 mar 2004
error.php in Error Manager 2.1 for PHP-Nuke 6.0 allows remote attackers to obtain sensitive information via an invalid (
23RISCO
abrir
Exploit-DBVexDay Proof
PHP-Nuke Error Manager Module 2.1 - 'error.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2004-1829webappsphp18 mar 2004
Multiple cross-site scripting (XSS) vulnerabilities in error.php in Gijza.net Error Manager 2.1 for PHP-Nuke 6.0 allow r
23RISCO
abrir
Exploit-DBVexDay Proof
Symantec Client Firewall Products 5 - 'SYMNDIS.SYS' Driver Remote Denial of Service
CVE-2004-0375doswindows18 mar 2004
SYMNDIS.SYS in Symantec Norton Internet Security 2003 and 2004, Norton Personal Firewall 2003 and 2004, Client Firewall
23RISCO
abrir
Exploit-DBVexDay Proof
IBM Lotus Domino 6/7 - HTTP webadmin.nsf Directory Traversal
CVE-2004-2311remotewindows17 mar 2004
Directory traversal vulnerability in webadmin.nsf in Lotus Domino R6 6.5.1 allows local users to create folders or deter
23RISCO
abrir
Exploit-DBVexDay Proof
AIX 4.3.3/5.x - Getlvcb Command Line Argument Buffer Overflow (2)
CVE-2004-0544localaix17 mar 2004
Multiple buffer overflows in LVM for AIX 5.1 and 5.2 allow local users to gain privileges via the (1) putlvcb or (2) get
23RISCO
abrir
Exploit-DBVexDay Proof
Belchior Foundry VCard 2.8 - Authentication Bypass
CVE-2004-1828webappsphp17 mar 2004
Vcard 2.9 and possibly other versions does not require authorization to run uninstall.php, which could allow remote atta
23RISCO
abrir
Exploit-DBVexDay Proof
GlobalScape Secure FTP Server 2.0 Build 03.11.2004.2 - Site Command Remote Buffer Overflow
CVE-2004-2366doswindows17 mar 2004
Buffer overflow in GlobalSCAPE Secure FTP Server 2.0 B03.11.2004.2 allows remote attackers to cause a denial of service
23RISCO
abrir
Exploit-DBVexDay Proof
WFTPD Server GUI 3.21 - Remote Denial of Service
CVE-2004-2367doswindows17 mar 2004
The Control Panel applet in WFTPD and WFTPD Pro 3.21 R1 and R2 allows remote authenticated users to cause a denial of se
23RISCO
abrir
Exploit-DBVexDay Proof
IBM Lotus Domino 6.5.1 - HTTP webadmin.nsf Quick Console Cross-Site Scripting
CVE-2004-2310remotewindows17 mar 2004
Cross-site scripting (XSS) vulnerability in webadmin.nsf in Lotus Domino R6 6.5.1 allows remote attackers to inject arbi
23RISCO
abrir
Exploit-DBVexDay Proof
vBulletin 3.0 - 'showthread.php' Cross-Site Scripting
CVE-2004-1823webappsphp16 mar 2004
Multiple cross-site scripting (XSS) vulnerabilities in Jelsoft vBulletin 2.0 beta 3 through 3.0 can4 allows remote attac
23RISCO
abrir
Exploit-DBVexDay Proof
Mambo Open Source 4.5 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2004-1825webappsphp16 mar 2004
Cross-site scripting (XSS) vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote at
23RISCO
abrir
Exploit-DBVexDay Proof
vBulletin 3.0 - 'forumdisplay.php' Cross-Site Scripting
CVE-2004-1823webappsphp16 mar 2004
Multiple cross-site scripting (XSS) vulnerabilities in Jelsoft vBulletin 2.0 beta 3 through 3.0 can4 allows remote attac
23RISCO
abrir
Exploit-DBVexDay Proof
PHP-Nuke 6.x/7.0/7.1 - Image Tag Admin Command Execution
CVE-2004-1842webappsphp16 mar 2004
Cross-site request forgery (CSRF) vulnerability in Php-Nuke 6.x through 7.1.0 allows remote attackers to gain administra
23RISCO
abrir
Exploit-DBVexDay Proof
Mambo Open Source 4.5 - 'index.php' SQL Injection
CVE-2004-1826webappsphp16 mar 2004
SQL injection vulnerability in index.php in Mambo Open Source 4.5 stable 1.0.3 and earlier allows remote attackers to ex
23RISCO
abrir
Exploit-DBVexDay Proof
Phorum 3.x - 'register.php' HTTP_REFERER Cross-Site Scripting
CVE-2004-1822webappsphp15 mar 2004
Multiple cross-site scripting (XSS) vulnerabilities in Phorum 3.1 through 5.0.3 beta allow remote attackers to inject ar
23RISCO
abrir
Exploit-DBVexDay Proof
PHP-Nuke 7.1 Recommend_Us Module - 'fname' Cross-Site Scripting
CVE-2004-1817webappsphp15 mar 2004
Cross-site scripting (XSS) vulnerability in modules.php in Php-Nuke 7.1.0 allows remote attackers to inject arbitrary we
23RISCO
abrir
Exploit-DBVexDay Proof
WarpSpeed 4nAlbum Module 0.92 - 'displaycategory.php?basepath' Remote File Inclusion
CVE-2004-1820webappsphp15 mar 2004
PHP remote file inclusion vulnerability in displaycategory.php in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remot
23RISCO
abrir
Exploit-DBVexDay Proof
Phorum 3.x - 'profile.php?target' Cross-Site Scripting
CVE-2004-1822webappsphp15 mar 2004
Multiple cross-site scripting (XSS) vulnerabilities in Phorum 3.1 through 5.0.3 beta allow remote attackers to inject ar
23RISCO
abrir
Exploit-DBVexDay Proof
VocalTec VGW4/8 Telephony Gateway - Remote Authentication Bypass
CVE-2004-1813webappsasp15 mar 2004
VocalTec VGW4/8 Gateway 8.0 allows remote attackers to bypass authentication via an HTTP request to home.asp with a trai
23RISCO
abrir
Exploit-DBVexDay Proof
Phorum 3.x - 'login.php' HTTP_REFERER Cross-Site Scripting
CVE-2004-1822webappsphp15 mar 2004
Multiple cross-site scripting (XSS) vulnerabilities in Phorum 3.1 through 5.0.3 beta allow remote attackers to inject ar
23RISCO
abrir
Exploit-DBVexDay Proof
WarpSpeed 4nAlbum Module 0.92 - 'modules.php?gid' SQL Injection
CVE-2004-1821webappsphp15 mar 2004
SQL injection vulnerability in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attackers to gain privileges or p
23RISCO
abrir
Exploit-DBVexDay Proof
WarpSpeed 4nAlbum Module 0.92 - 'nmimage.php?z' Cross-Site Scripting
CVE-2004-1818webappsphp15 mar 2004
Cross-site scripting (XSS) vulnerability in nmimage.php in 4nalbum 0.92 for PHP-Nuke 6.5 through 7.0 allows remote attac
23RISCO
abrir
Exploit-DBVexDay Proof
YABB SE 1.5.1 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2004-1827webappsphp15 mar 2004
Cross-site scripting (XSS) vulnerability in YaBB 1 Gold(SP1.3) and YaBB SE 1.5.1 Final allows remote attackers to inject
23RISCO
abrir
Exploit-DBVexDay Proof
cPanel 5/6/7/8/9 - 'dir' Cross-Site Scripting
CVE-2004-2308webappscgi12 mar 2004
Cross-site scripting (XSS) vulnerability in cPanel 9.1.0 and possibly earlier allows remote attackers to inject arbitrar
23RISCO
abrir
Exploit-DBVexDay Proof
Emumail EMU Webmail 5.2.7 - 'emumail.fcgi' Multiple Cross-Site Scripting Vulnerabilities
CVE-2004-2334webappscgi12 mar 2004
Multiple cross-site scripting (XSS) vulnerabilities in EMU Webmail 5.2.7 allow remote attackers to inject arbitrary web
23RISCO
abrir
Exploit-DBVexDay Proof
IP3 Networks IP3 NetAccess Appliance - SQL Injection
CVE-2004-2326remotehardware12 mar 2004
SQL injection vulnerability in IP3 Networks NetAccess Appliance before firmware 3.1.18b13 allows remote attackers to byp
23RISCO
abrir
Exploit-DBVexDay Proof
Emumail EMU Webmail 5.2.7 - nit.emu Information Disclosure
CVE-2004-2385webappscgi12 mar 2004
EMU Webmail 5.2.7 allows remote attackers to obtain sensitive path information (home directory) via an HTTP request for
23RISCO
abrir
Exploit-DBVexDay Proof
cPanel 5/6/7/8/9 - Login Script Remote Command Execution
CVE-2004-1770webappscgi12 mar 2004
The login page for cPanel 9.1.0, and possibly other versions, allows remote attackers to execute arbitrary code via shel
28RISCO
abrir
Exploit-DBVexDay Proof
cPanel 5/6/7/8/9 - Resetpass Remote Command Execution
CVE-2004-1769remotecgi11 mar 2004
The "Allow cPanel users to reset their password via email" feature in cPanel 9.1.0 build 34 and earlier, including 8.x,
35RISCO
abrir
Exploit-DBVexDay Proof
Pegasi Web Server 0.2.2 - Error Page Cross-Site Scripting
CVE-2004-2618remotelinux11 mar 2004
Cross-site scripting (XSS) vulnerability in Pegasi Web Server (PWS) 0.2.2 allows remote attackers to inject arbitrary we
23RISCO
abrir
anteriorpágina 710 / 816próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.