Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.057exploits catalogados
36.288CVEs com exploração pública
24.695testados em laboratório
22.910 exploits
ReferênciaVexDay Proof
Axigen 2.0.0b1 - Remote Denial of Service (2)
CVE-2007-0887doslinux
axigen 1.2.6 through 2.0.0b1 does not properly parse login credentials, which allows remote attackers to cause a denial
28RISCO
abrir
ReferênciaVexDay Proof
philboard 1.14 - 'philboard_forum.asp' SQL Injection
CVE-2007-0920webappsasp
SQL injection vulnerability in philboard_forum.asp in Philboard 1.14 and earlier allows remote attackers to execute arbi
23RISCO
abrir
ReferênciaVexDay Proof
Jupiter CMS 1.1.5 - Arbitrary File Upload
CVE-2007-0972webappsphp
Unrestricted file upload vulnerability in modules/emoticons.php in Jupiter CMS 1.1.5 allows remote attackers to upload a
23RISCO
abrir
ReferênciaVexDay Proof
ActSoft DVD-Tools - 'dvdtools.ocx' Remote Buffer Overflow
CVE-2007-0976remotewindows
Buffer overflow in the ActSoft DVD-Tools ActiveX control (dvdtools.ocx) allows remote attackers to execute arbitrary cod
23RISCO
abrir
ReferênciaVexDay Proof
PollMentor 2.0 - 'pollmentorres.asp?id' SQL Injection
CVE-2007-0984webappsasp
SQL injection vulnerability in admin_poll.asp in PollMentor 2.0 allows remote attackers to execute arbitrary SQL command
23RISCO
abrir
ReferênciaVexDay Proof
PHPCC 4.2 Beta - 'nickpage.php?npid' SQL Injection
CVE-2007-0985webappsphp
SQL injection vulnerability in nickpage.php in phpCC 4.2 beta and earlier allows remote attackers to execute arbitrary S
23RISCO
abrir
ReferênciaVexDay Proof
Jupiter CMS 1.1.5 - '/index.php' Local/Remote File Inclusion
CVE-2007-0987webappsphp
Directory traversal vulnerability in index.php in Jupiter CMS 1.1.5 allows remote attackers to include and execute arbit
23RISCO
abrir
ReferênciaVexDay Proof
Htaccess Passwort Generator 1.1 - 'ht_pfad' Remote File Inclusion
CVE-2007-1013webappsphp
PHP remote file inclusion vulnerability in generate.php in VirtualSystem Htaccess Passwort Generator 1.1 allows remote a
23RISCO
abrir
ReferênciaVexDay Proof
webSPELL 4.01.02 - 'showonly' Blind SQL Injection
CVE-2007-1019webappsphp
SQL injection vulnerability in news.php in webSPELL 4.01.02, when register_globals is enabled, allows remote attackers t
23RISCO
abrir
ReferênciaVexDay Proof
Snitz Forums 2000 3.1 SR4 - 'pop_profile.asp' SQL Injection
CVE-2007-1023webappsasp
SQL injection vulnerability in pop_profile.asp in Snitz Forums 2000 3.1 SR4 allows remote attackers to execute arbitrary
23RISCO
abrir
ReferênciaVexDay Proof
XLAtunes 0.1 - 'album' SQL Injection
CVE-2007-1026webappsphp
SQL injection vulnerability in view.php in XLAtunes 0.1 and earlier allows remote attackers to execute arbitrary SQL com
23RISCO
abrir
ReferênciaVexDay Proof
Vivvo Article Manager 3.4 - 'root' Local File Inclusion
CVE-2007-1031webappsphp
Directory traversal vulnerability in include/db_conn.php in SpoonLabs Vivvo Article Management CMS 3.4 allows remote att
23RISCO
abrir
Referência
DirectAdmin 1.561 - Multiple Vulnerabilities
CVE-2019-11193webappsphp
The FileManager in InfinitumIT DirectAdmin through v1.561 has XSS via CMD_FILE_MANAGER, CMD_SHOW_USER, and CMD_SHOW_RESE
23RISCO
abrir
Referência
CVE-2019-11354
The client in Electronic Arts (EA) Origin 10.5.36 on Windows allows template injection in the title parameter of the Ori
28RISCO
abrir
Referência
CVE-2019-11354
The client in Electronic Arts (EA) Origin 10.5.36 on Windows allows template injection in the title parameter of the Ori
28RISCO
abrir
ReferênciaVexDay Proof
XM Easy Personal FTP Server 5.30 - 'ABOR' Format String Denial of Service
CVE-2007-1195doswindows
Multiple buffer overflows in XM Easy Personal FTP Server 5.3.0 allow remote attackers to execute arbitrary code via unsp
23RISCO
abrir
ReferênciaVexDay Proof
Admin Phorum 3.3.1a - 'del.php?include_path' Remote File Inclusion
CVE-2007-1219webappsphp
PHP remote file inclusion vulnerability in actions/del.php in Admin Phorum 3.3.1a allows remote attackers to execute arb
23RISCO
abrir
ReferênciaVexDay Proof
NetProxy 4.03 - Web Filter Evasion / Bypass Logging
CVE-2007-1225remotewindows
The connection log file implementation in Grok Developments NetProxy 4.03 does not record requests that omit http:// in
23RISCO
abrir
ReferênciaVexDay Proof
STWC-Counter 3.4.0 - 'downloadcounter.php' Remote File Inclusion
CVE-2007-1233webappsphp
PHP remote file inclusion vulnerability in downloadcounter.php in STWC-Counter 3.4.0.0 and earlier allows remote attacke
23RISCO
abrir
ReferênciaVexDay Proof
Connectix Boards 0.7 - 'p_skin' Multiple Vulnerabilities
CVE-2007-1255webappsphp
Unrestricted file upload vulnerability in admin.bbcode.php in Connectix Boards 0.7 and earlier allows remote authenticat
23RISCO
abrir
ReferênciaVexDay Proof
WebMod 0.48 - Content-Length Remote Buffer Overflow
CVE-2007-1260remotewindows
Stack-based buffer overflow in the connectHandle function in server.cpp in WebMod 0.48 allows remote attackers to execut
23RISCO
abrir
ReferênciaVexDay Proof
osTicket 1.11 - Cross-Site Scripting / Local File Inclusion
CVE-2019-11537webappsphp
In osTicket before 1.12, XSS exists via /upload/file.php, /upload/scp/users.php?do=import-users, and /upload/scp/ajax.ph
23RISCO
abrir
Referência
CVE-2019-11539
CVE-2019-11539HIGHsob ataqueransomware
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1R
100RISCO
abrir
Referência
CVE-2019-11539
CVE-2019-11539HIGHsob ataqueransomware
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1R
100RISCO
abrir
Referência
CVE-2019-11539
CVE-2019-11539HIGHsob ataqueransomware
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1R
100RISCO
abrir
Referência
CVE-2019-11599
The coredump implementation in the Linux kernel before 5.0.10 does not use locking or other mechanisms to prevent vma la
23RISCO
abrir
Referência
CVE-2019-11599
The coredump implementation in the Linux kernel before 5.0.10 does not use locking or other mechanisms to prevent vma la
23RISCO
abrir
Referência
CVE-2019-11599
The coredump implementation in the Linux kernel before 5.0.10 does not use locking or other mechanisms to prevent vma la
23RISCO
abrir
ReferênciaVexDay Proof
pNews 1.1.0 - 'nbs' Remote File Inclusion
CVE-2006-5022webappsphp
PHP remote file inclusion vulnerability in includes/global.php in Joshua Wilson pNews System 1.1.0 (aka PowerNews) allow
23RISCO
abrir
Referência
CVE-2019-12181
A privilege escalation vulnerability exists in SolarWinds Serv-U before 15.1.7 for Linux.
50RISCO
abrir
anteriorpágina 763 / 764próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.