Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

78.794exploits catalogados
36.057CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
Geeklog 2 - 'BaseView.php' Remote File Inclusion
CVE-2007-0810webappsphp
PHP remote file inclusion vulnerability in MVCnPHP/BaseView.php in GeekLog 2 and earlier allows remote attackers to exec
23RISCO
abrir
ReferênciaVexDay Proof
MojoAuto - Blind SQL Injection
CVE-2008-3383webappscgi
SQL injection vulnerability in mojoAuto.cgi in MojoAuto allows remote attackers to execute arbitrary SQL commands via th
23RISCO
abrir
ReferênciaVexDay Proof
Alstrasoft Video Share Enterprise 4.5.1 - 'UID' SQL Injection
CVE-2008-3386webappsphp
SQL injection vulnerability in album.php in AlstraSoft Video Share Enterprise 4.51 allows remote attackers to execute ar
23RISCO
abrir
ReferênciaVexDay Proof
Woltlab Burning Board Lite 1.0.2pl3e - 'pms.php' SQL Injection
CVE-2007-0812webappsphp
SQL injection vulnerability in pms.php in Woltlab Burning Board (wBB) Lite 1.0.2pl3e and earlier allows remote authentic
23RISCO
abrir
ReferênciaVexDay Proof
Drake CMS 0.4.11 - Blind SQL Injection
CVE-2008-6475webappsphp
SQL injection vulnerability in the guestbook component (components/guestbook/guestbook.php) in Drake CMS 0.4.11 and earl
23RISCO
abrir
ReferênciaVexDay Proof
PHPFootball 1.6 - SQL Injection
CVE-2008-3387webappsphp
SQL injection vulnerability in show.php in PHPFootball 1.6 allows remote attackers to execute arbitrary SQL commands via
23RISCO
abrir
ReferênciaVexDay Proof
XRms 1.99.2 - Remote File Inclusion / Cross-Site Scripting / Information Gathering
CVE-2008-3400webappsphp
XRMS CRM 1.99.2 allows remote attackers to obtain configuration information via a direct request to tests/info.php, whic
23RISCO
abrir
ReferênciaVexDay Proof
MojoPersonals - Blind SQL Injection
CVE-2008-3403webappscgi
SQL injection vulnerability in mojoClassified.cgi in MojoPersonals allows remote attackers to execute arbitrary SQL comm
23RISCO
abrir
ReferênciaVexDay Proof
IceBB 1.0-RC9.2 - Blind SQL Injection / Session Hijacking
CVE-2008-3416webappsphp
SQL injection vulnerability in modules/members.php in IceBB before 1.0-rc9.3 allows remote attackers to execute arbitrar
23RISCO
abrir
ReferênciaVexDay Proof
FipsCMS Light 2.1 - 'r' SQL Injection
CVE-2008-3417webappsasp
SQL injection vulnerability in home/index.asp in fipsCMS light 2.1 and earlier allows remote attackers to execute arbitr
23RISCO
abrir
ReferênciaVexDay Proof
Youtuber Clone - SQL Injection
CVE-2008-3419webappsphp
SQL injection vulnerability in ugroups.php in Youtuber Clone allows remote attackers to execute arbitrary SQL commands v
23RISCO
abrir
ReferênciaVexDay Proof
Mobius 1.4.4.1 - SQL Injection
CVE-2008-3420webappsphp
Multiple SQL injection vulnerabilities in Mobius for Mimsy XG 1 1.4.4.1 and earlier allow remote attackers to execute ar
23RISCO
abrir
ReferênciaVexDay Proof
phpMyRealty 2.0.0 - 'location' SQL Injection
CVE-2008-3445webappsphp
SQL injection vulnerability in index.php in phpMyRealty (PMR) 2.0.0 allows remote attackers to execute arbitrary SQL com
23RISCO
abrir
ReferênciaVexDay Proof
otscms 2.1.5 - SQL Injection / Cross-Site Scripting
CVE-2007-0847webappsphp
SQL injection vulnerability in mod/PM/reply.php in Open Tibia Server CMS (OTSCMS) 2.1.5 and earlier allows remote attack
23RISCO
abrir
ReferênciaVexDay Proof
LetterIt 2 - 'Language' Local File Inclusion
CVE-2008-3446webappsphp
Directory traversal vulnerability in inc/wysiwyg.php in LetterIt 2 allows remote attackers to include and execute arbitr
23RISCO
abrir
ReferênciaVexDay Proof
Scripts24 iPost 1.0.1 - 'id' SQL Injection
CVE-2008-3491webappsphp
SQL injection vulnerability in go.php in Scripts24 iPost 1.0.1 and iTGP 1.0.4 allows remote attackers to execute arbitra
23RISCO
abrir
ReferênciaVexDay Proof
Scripts24 iTGP 1.0.4 - 'id' SQL Injection
CVE-2008-3491webappsphp
SQL injection vulnerability in go.php in Scripts24 iPost 1.0.1 and iTGP 1.0.4 allows remote attackers to execute arbitra
23RISCO
abrir
ReferênciaVexDay Proof
SoftComplex PHP Image Gallery - 'ctg' SQL Injection
CVE-2008-6485webappsphp
SQL injection vulnerability in index.php in SoftComplex PHP Image Gallery allows remote attackers to execute arbitrary S
23RISCO
abrir
ReferênciaVexDay Proof
DigiAffiliate 1.4 - Authentication Bypass
CVE-2008-6487webappsasp
Multiple SQL injection vulnerabilities in login.asp in Digiappz DigiAffiliate 1.4 and earlier allow remote attackers to
23RISCO
abrir
ReferênciaVexDay Proof
OpenX 2.6.3 - 'MAX_type' Local File Inclusion
CVE-2009-0291webappsphp
Directory traversal vulnerability in fc.php in OpenX 2.6.3 allows remote attackers to include and execute arbitrary file
23RISCO
abrir
ReferênciaVexDay Proof
RealVNC Windows Client 4.1.2 - Remote Denial of Service Crash (PoC)
CVE-2008-3493doswindows
vncviewer.exe in RealVNC Windows Client 4.1.2.0 allows remote VNC servers to cause a denial of service (application cras
23RISCO
abrir
ReferênciaVexDay Proof
MyPHP CMS 0.3.1 - 'pid' SQL Injection
CVE-2008-3497webappsphp
SQL injection vulnerability in pages.php in MyPHP CMS 0.3.1 allows remote attackers to execute arbitrary SQL commands vi
23RISCO
abrir
ReferênciaVexDay Proof
polypager 1.0rc2 - SQL Injection / Cross-Site Scripting
CVE-2008-3505webappsphp
Cross-site scripting (XSS) vulnerability in PolyPager 1.0 rc2 and earlier allows remote attackers to inject arbitrary we
23RISCO
abrir
ReferênciaVexDay Proof
LiteNews 0.1 - 'id' SQL Injection
CVE-2008-3507webappsphp
SQL injection vulnerability in index.php in LiteNews 0.1 (aka 01), and possibly 1.2 and earlier, allows remote attackers
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component MyAlbum 1.0 - 'album' SQL Injection
CVE-2008-6489webappsphp
SQL injection vulnerability in MyAlbum component (com_myalbum) 1.0 for Joomla! allows remote attackers to execute arbitr
23RISCO
abrir
ReferênciaVexDay Proof
Apple Safari - RSS 'feed://' Buffer Overflow via libxml2 (PoC)
CVE-2008-3529doswindows
Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-de
28RISCO
abrir
ReferênciaVexDay Proof
Discuz! 6.0.1 - 'searchid' SQL Injection
CVE-2008-3554webappsphp
SQL injection vulnerability in index.php in Discuz! 6.0.1 allows remote attackers to execute arbitrary SQL commands via
23RISCO
abrir
ReferênciaVexDay Proof
Cisco WebEx Meeting Manager UCF - 'atucfobj.dll' ActiveX Remote Buffer Overflow
CVE-2008-3558remotewindows
Stack-based buffer overflow in the WebexUCFObject ActiveX control in atucfobj.dll in Cisco WebEx Meeting Manager before
50RISCO
abrir
ReferênciaVexDay Proof
ABG Blocking Script 1.0a - 'abg_path' Remote File Inclusion
CVE-2008-3570webappsphp
PHP remote file inclusion vulnerability in index.php in Africa Be Gone (ABG) 1.0a allows remote attackers to execute arb
23RISCO
abrir
ReferênciaVexDay Proof
k-links directory - SQL Injection / Cross-Site Scripting
CVE-2008-3580webappsphp
Multiple SQL injection vulnerabilities in Qsoft K-Links allow remote attackers to execute arbitrary SQL commands via (1)
23RISCO
abrir

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.