Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.107exploits catalogados
36.322CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
KML share 1.1 - 'region.php?layer' Remote File Disclosure
CVE-2007-6212webappsphp
Directory traversal vulnerability in region.php in KML share 1.1 allows remote attackers to read arbitrary files via a .
23RISCO
abrir
ReferênciaVexDay Proof
Absolute Banner Manager - Insecure Cookie Handling
CVE-2008-6858webappsphp
Absolute Banner Manager .NET 4.0 allows remote attackers to bypass authentication and gain administrative access by sett
23RISCO
abrir
ReferênciaVexDay Proof
Absolute Control Panel XE 1.5 - Insecure Cookie Handling
CVE-2008-6859webappsphp
Xigla Software Absolute Control Panel XE 1.5 allows remote attackers to bypass authentication and gain administrative ac
23RISCO
abrir
ReferênciaVexDay Proof
Absolute Live Support 5.1 - Insecure Cookie Handling
CVE-2008-6864webappsphp
Xigla Software Absolute Live Support .NET 5.1 allows remote attackers to bypass authentication and gain administrative a
23RISCO
abrir
ReferênciaVexDay Proof
merlix educate servert - Authentication Bypass / File Disclosure
CVE-2008-6870webappsasp
Merlix Educate Server allows remote attackers to bypass intended security restrictions and obtain sensitive information
23RISCO
abrir
ReferênciaVexDay Proof
merlix educate servert - Authentication Bypass / File Disclosure
CVE-2008-6871webappsasp
Merlix Educate Server stores db.mdb under the web root with insufficient access control, which allows remote attackers t
23RISCO
abrir
ReferênciaVexDay Proof
ExoPHPDesk 1.2 Final - Authentication Bypass
CVE-2008-6917webappsphp
SQL injection vulnerability in admin.php in Exocrew ExoPHPDesk 1.2 Final allows remote attackers to execute arbitrary SQ
23RISCO
abrir
ReferênciaVexDay Proof
ThePortal 2.2 - Arbitrary File Upload
CVE-2008-6918webappsphp
Unrestricted file upload vulnerability in admin/galeria.php in ThePortal2 2.2 allows remote attackers to execute arbitra
23RISCO
abrir
ReferênciaVexDay Proof
TaskDriver 1.3 - Remote Change Admin Password
CVE-2008-6919webappsphp
profileedit.php TaskDriver 1.3 and earlier allows remote attackers to bypass authentication and gain administrative acce
23RISCO
abrir
ReferênciaVexDay Proof
dotProject 2.0.4 - 'baseDir' Remote File Inclusion
CVE-2006-4234webappsphp
PHP remote file inclusion vulnerability in classes/query.class.php in dotProject 2.0.4 and earlier allows remote attacke
23RISCO
abrir
ReferênciaVexDay Proof
PHPAdBoard - PHP uploads Arbitrary File Upload
CVE-2008-6921webappsphp
Unrestricted file upload vulnerability in index.php in phpAdBoard 1.8 allows remote attackers to execute arbitrary code
23RISCO
abrir
ReferênciaVexDay Proof
Google Chrome 0.2.149.27 - Denial of Service
CVE-2008-6995doswindows
Integer underflow in net/base/escape.cc in chrome.dll in Google Chrome 0.2.149.27 allows remote attackers to cause a den
23RISCO
abrir
ReferênciaVexDay Proof
phpBB Garage 1.2.0 Beta3 - SQL Injection
CVE-2007-6223webappsphp
SQL injection vulnerability in garage.php in phpBB Garage 1.2.0 Beta3 allows remote attackers to execute arbitrary SQL c
23RISCO
abrir
ReferênciaVexDay Proof
Rayzz Script 2.0 - Local/Remote File Inclusion
CVE-2007-6229webappsphp
PHP remote file inclusion vulnerability in common/classes/class_HeaderHandler.lib.php in Rayzz Script 2.0 allows remote
23RISCO
abrir
ReferênciaVexDay Proof
RealPlayer 11 - '.au' Denial of Service
CVE-2007-6235doswindows
A certain ActiveX control in RealNetworks RealPlayer 11 allows remote attackers to cause a denial of service (applicatio
23RISCO
abrir
ReferênciaVexDay Proof
tellmatic 1.0.7 - Multiple Remote File Inclusions
CVE-2007-6231webappsphp
Multiple PHP remote file inclusion vulnerabilities in tellmatic 1.0.7 allow remote attackers to execute arbitrary PHP co
23RISCO
abrir
ReferênciaVexDay Proof
Snitz Forums 2000 - 'Active.asp' SQL Injection
CVE-2007-6240webappsasp
SQL injection vulnerability in active.asp in Snitz Forums 2000 3.4.06 allows remote attackers to execute arbitrary SQL c
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Component Kochsuite 0.9.4 - Remote File Inclusion
CVE-2006-4348webappsphp
PHP remote file inclusion vulnerability in config.kochsuite.php in the Kochsuite (com_kochsuite) 0.9.4 component for Mam
23RISCO
abrir
ReferênciaVexDay Proof
Empire CMS 3.7 - 'checklevel.php' Remote File Inclusion
CVE-2006-4354webappsphp
PHP remote file inclusion vulnerability in e/class/CheckLevel.php in Phome Empire CMS 3.7 and earlier allows remote atta
23RISCO
abrir
ReferênciaVexDay Proof
HP Compaq Notebooks - ActiveX Remote Code Execution
CVE-2007-6333remotewindows
The HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 i
23RISCO
abrir
ReferênciaVexDay Proof
XChat 2.6.7 (Windows) - Remote Denial of Service
CVE-2006-4455doswindows
Unspecified vulnerability in Xchat 2.6.7 and earlier allows remote attackers to cause a denial of service (crash) via un
23RISCO
abrir
ReferênciaVexDay Proof
Web3news 0.95 - 'PHPSECURITYADMIN_PATH' Remote File Inclusion
CVE-2006-4452webappsphp
PHP remote file inclusion vulnerability in security/include/_class.security.php in Web3news 0.95 and earlier, when regis
23RISCO
abrir
ReferênciaVexDay Proof
ClamAV 0.91.2 - libclamav MEW PE Buffer Overflow
CVE-2007-6335remotelinux
Integer overflow in libclamav in ClamAV before 0.92 allows remote attackers to execute arbitrary code via a crafted MEW
28RISCO
abrir
ReferênciaVexDay Proof
Joomla! / Mambo Component rsgallery 2.0b5 - 'catid' SQL Injection
CVE-2007-6362webappsphp
SQL injection vulnerability in index.php in the RSGallery (com_rsgallery) 2.0 beta 5 and earlier component for Mambo and
23RISCO
abrir
ReferênciaVexDay Proof
SineCMS 2.3.4 - Calendar SQL Injection
CVE-2007-6366webappsphp
Multiple SQL injection vulnerabilities in SineCMS 2.3.4 and earlier allow remote attackers to execute arbitrary SQL comm
23RISCO
abrir
ReferênciaVexDay Proof
BadBlue 2.72 - PassThru Remote Buffer Overflow
CVE-2007-6377remotewindows
Stack-based buffer overflow in the PassThru functionality in ext.dll in BadBlue 2.72b and earlier allows remote attacker
50RISCO
abrir
ReferênciaVexDay Proof
Linksys SPA941 - Remote Reboot (Denial of Service)
CVE-2007-2270doshardware
The Linksys SPA941 VoIP Phone allows remote attackers to cause a denial of service (device reboot) via a 0377 (0xff) cha
23RISCO
abrir
ReferênciaVexDay Proof
USP FOSS Distribution 1.01 - 'dnld' Remote File Disclosure
CVE-2007-2271webappsphp
Directory traversal vulnerability in Rajneel Lal TotaRam USP FOSS Distribution 1.01 allows remote attackers to read arbi
23RISCO
abrir
ReferênciaVexDay Proof
Joomla! Plugin tinybrowser 1.5.12 - Arbitrary File Upload / Execution
CVE-2011-4908webappsphp
TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php.
50RISCO
abrir
ReferênciaVexDay Proof
GrapAgenda 0.1 - 'page' Remote File Inclusion
CVE-2006-4610webappsphp
PHP remote file inclusion vulnerability in index.php in GrapAgenda 0.11 and earlier, when register_globals is enabled, a
23RISCO
abrir
anteriorpágina 84 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.