Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.057exploits catalogados
36.288CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
eCentrex VOIP Client module - 'uacomx.ocx 2.0.1' Remote Buffer Overflow
CVE-2007-4489remotewindows
Buffer overflow in the IUAComFormX ActiveX control in uacomx.ocx 2.0.1 in the eCentrex VOIP Client module allows remote
23RISCO
abrir
ReferênciaVexDay Proof
dotCMS 1.6 - 'id' Local File Inclusion
CVE-2008-3708webappsphp
Multiple directory traversal vulnerabilities in dotCMS 1.6.0.9 allow remote attackers to read arbitrary files via a .. (
23RISCO
abrir
ReferênciaVexDay Proof
Advanced Electron Forum 1.0.6 - Remote Code Execution
CVE-2008-5090webappsphp
Electron Inc. Advanced Electron Forum before 1.0.7 allows remote attackers to execute arbitrary PHP code via PHP code em
23RISCO
abrir
ReferênciaVexDay Proof
Sejoong Namo ActiveSquare 6 - 'NamoInstaller.dll' ActiveX Buffer Overflow
CVE-2008-0634remotewindows
Buffer overflow in the NamoInstaller.NamoInstall.1 ActiveX control in NamoInstaller.dll 3.0.0.1, as used in Sejoong Namo
23RISCO
abrir
ReferênciaVexDay Proof
LinkedIn Toolbar 3.0.2.1098 - Remote Buffer Overflow
CVE-2007-3955remotewindows
Buffer overflow in the IEToolbar.IEContextMenu.1 ActiveX control in LinkedInIEToolbar.dll in the LinkedIn Toolbar 3.0.2.
23RISCO
abrir
ReferênciaVexDay Proof
JBlog 1.0 - Create / Delete Admin Authentication Bypass
CVE-2007-3974webappsphp
admin/ajoutaut.php in JBlog 1.0 does not require authentication, which allows remote attackers to create arbitrary accou
23RISCO
abrir
ReferênciaVexDay Proof
Lms 1.8.9 - Vala Remote File Inclusion
CVE-2007-1643webappsphp
Multiple PHP remote file inclusion vulnerabilities in LAN Management System (LMS) 1.8.9 Vala and earlier allow remote at
28RISCO
abrir
ReferênciaVexDay Proof
EZWebAlbum - Remote File Disclosure
CVE-2008-3293webappsphp
Directory traversal vulnerability in download.php in EZWebAlbum allows remote attackers to read arbitrary files via the
23RISCO
abrir
ReferênciaVexDay Proof
Focus/SIS 1.0/2.2 - Remote File Inclusion
CVE-2007-4806webappsphp
PHP remote file inclusion vulnerability in modules/Discipline/CategoryBreakdownTime.php in Focus/SIS 1.0 allows remote a
23RISCO
abrir
ReferênciaVexDay Proof
Maian Recipe 1.2 - Insecure Cookie Handling
CVE-2008-3322webappsphp
admin/index.php in Maian Recipe 1.2 and earlier allows remote attackers to bypass authentication and gain administrative
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component ionFiles 4.4.2 - File Disclosure
CVE-2008-6080webappsphp
Directory traversal vulnerability in download.php in the ionFiles (com_ionfiles) 4.4.2 component for Joomla! allows remo
43RISCO
abrir
ReferênciaVexDay Proof
GC Auction Platinum - 'cate_id' SQL Injection
CVE-2008-3413webappsphp
SQL injection vulnerability in category.php in Greatclone GC Auction Platinum allows remote attackers to execute arbitra
23RISCO
abrir
ReferênciaVexDay Proof
Ads Pro - 'dhtml.pl' Remote Command Execution
CVE-2008-6826webappscgi
dhtml.pl in MHF Media Pro allows remote attackers to execute arbitrary commands via shell metacharacters in the page par
23RISCO
abrir
ReferênciaVexDay Proof
Fuju News 1.0 - Authentication Bypass / SQL Injection
CVE-2006-1838webappsphp
edit_kategorie.php in Fuju News 1.0 allows remote attackers to bypass authentication by setting the authorized cookie.
23RISCO
abrir
ReferênciaVexDay Proof
WFTPD Pro Server 3.23.1.1 - 'APPE' Remote Buffer Overflow (PoC)
CVE-2006-5826doswindows
Buffer overflow in Texas Imperial Software WFTPD Pro Server 3.23.1.1 allows remote authenticated users to execute arbitr
28RISCO
abrir
ReferênciaVexDay Proof
meBiblio 0.4.5 - 'action' Remote File Inclusion
CVE-2007-6089webappsphp
PHP remote file inclusion vulnerability in index.php in meBiblio 0.4.5 allows remote attackers to execute arbitrary PHP
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component mosDirectory 2.3.2 - 'catid' SQL Injection
CVE-2008-0690webappsphp
SQL injection vulnerability in index.php in the mosDirectory (com_directory) 2.3.2 component for Joomla! allows remote a
23RISCO
abrir
ReferênciaVexDay Proof
Coppermine Photo Gallery 1.4.18 - Local File Inclusion / Remote Code Execution
CVE-2008-3486webappsphp
Directory traversal vulnerability in the user_get_profile function in include/functions.inc.php in Coppermine Photo Gall
23RISCO
abrir
ReferênciaVexDay Proof
PHP 5.2.4 ionCube - 'ioncube_read_file' Safe Mode / disable_functions Bypass
CVE-2007-5447localwindows
ioncube_loader_win_5.2.dll in the ionCube Loader 6.5 extension for PHP 5.2.4 does not follow safe_mode and disable_funct
23RISCO
abrir
ReferênciaVexDay Proof
WSN Guest 1.23 - 'Search' SQL Injection
CVE-2009-0704webappsphp
SQL injection vulnerability in search.php in WSN Guest 1.23 allows remote attackers to execute arbitrary SQL commands vi
23RISCO
abrir
ReferênciaVexDay Proof
phpAuction GPL Enhanced 2.51 - 'profile.php' SQL Injection
CVE-2008-3487webappsphp
SQL injection vulnerability in profile.php in PHPAuction GPL Enhanced 2.51 allows remote attackers to execute arbitrary
23RISCO
abrir
ReferênciaVexDay Proof
PowerNews 2.5.4 - 'newsid' SQL Injection
CVE-2009-0705webappsphp
SQL injection vulnerability in news.php in PowerScripts PowerNews 2.5.4, when magic_quotes_gpc is disabled, allows remot
23RISCO
abrir
ReferênciaVexDay Proof
PHPX 3.5.16 - Cookie Poisoning / Authentication Bypass
CVE-2008-3489webappsphp
SQL injection vulnerability in checkCookie function in includes/functions.inc.php in PHPX 3.5.16 allows remote attackers
23RISCO
abrir
ReferênciaVexDay Proof
iLife iPhoto Photocast - XML Title Remote Format String (PoC)
CVE-2007-0051dososx
Format string vulnerability in Apple iPhoto 6.0.5 (316), and other versions before 6.0.6, allows remote user-assisted at
23RISCO
abrir
ReferênciaVexDay Proof
HP Data Protector 4.00-SP1b43064 - Remote Memory Leak/Denial of Service
CVE-2009-0714doswindows
Unspecified vulnerability in the dpwinsup module (dpwinsup.dll) for dpwingad (dpwingad.exe) in HP Data Protector Express
35RISCO
abrir
ReferênciaVexDay Proof
Free Arcade Script 1.0 - Local File Inclusion Command Execution
CVE-2009-0731webappsphp
Directory traversal vulnerability in pages/play.php in Free Arcade Script 1.0 allows remote attackers to include and exe
23RISCO
abrir
ReferênciaVexDay Proof
Article Directory - 'index.php' Remote File Inclusion
CVE-2007-4007webappsphp
PHP remote file inclusion vulnerability in index.php in Article Directory (Article Site Directory) allows remote attacke
23RISCO
abrir
ReferênciaVexDay Proof
Axigen 5.0.2 - AXIMilter Remote Format String
CVE-2008-0434remotelinux
Format string vulnerability in the AXIMilter module in AXIGEN Mail Server 5.0.2 allows remote attackers to execute arbit
28RISCO
abrir
ReferênciaVexDay Proof
SimpleBlog 3.0 - 'comments_get.asp?id' SQL Injection
CVE-2007-4055webappsasp
SQL injection vulnerability in comments_get.asp in SimpleBlog 3.0 allows remote attackers to execute arbitrary SQL comma
23RISCO
abrir
ReferênciaVexDay Proof
AuthPhp 1.0 - Authentication Bypass
CVE-2009-0738webappsphp
SQL injection vulnerability in login.php in Auth Php 1.0 allows remote attackers to execute arbitrary SQL commands via t
23RISCO
abrir
anteriorpágina 72 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.