Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.107exploits catalogados
36.322CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
ITLPoll 2.7 Stable2 - Blind SQL Injection
CVE-2009-0295webappsphp
SQL injection vulnerability in index.php in Information Technology Light Poll Information (ITLPoll) 2.7 Stable 2, when m
23RISCO
abrir
ReferênciaVexDay Proof
Download Accelerator Plus DAP 8.x - '.m3u' Local Buffer Overflow
CVE-2008-3182localwindows
Stack-based buffer overflow in DAP.exe in Download Accelerator Plus (DAP) 7.0.1.3, 8.6.6.3, and other 8.x versions allow
23RISCO
abrir
ReferênciaVexDay Proof
Pluck CMS 4.5.1 (Windows) - 'blogpost' Local File Inclusion
CVE-2008-3194webappsphp
Multiple directory traversal vulnerabilities in data/inc/themes/predefined_variables.php in pluck 4.5.1 allow remote att
23RISCO
abrir
ReferênciaVexDay Proof
Groone's GLink ORGanizer 2.1 - 'cat' Blind SQL Injection
CVE-2009-0299webappsphp
SQL injection vulnerability in index.php in Groone GLinks 2.1 allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
ReferênciaVexDay Proof
AuraCMS 2.2.2 - '/pages_data.php' Arbitrary Edit/Add/Delete
CVE-2008-3203webappsphp
js/pages/pages_data.php in AuraCMS 2.2 through 2.2.2 does not perform authentication, which allows remote attackers to a
23RISCO
abrir
ReferênciaVexDay Proof
Million Pixels 3 - 'id_cat' SQL Injection
CVE-2008-3204webappsphp
SQL injection vulnerability in tops_top.php in E-topbiz Million Pixels 3 allows remote attackers to execute arbitrary SQ
23RISCO
abrir
ReferênciaVexDay Proof
Pragyan CMS 2.6.2 - 'sourceFolder' Remote File Inclusion
CVE-2008-3207webappsphp
PHP remote file inclusion vulnerability in cms/modules/form.lib.php in Pragyan CMS 2.6.2, when register_globals is enabl
23RISCO
abrir
ReferênciaVexDay Proof
Amaya Web Editor 11.0 - XML / HTML Parser
CVE-2009-0323doswindows
Multiple stack-based buffer overflows in W3C Amaya Web Browser 10.0 and 11.0 allow remote attackers to execute arbitrary
50RISCO
abrir
ReferênciaVexDay Proof
Simple DNS Plus 5.0/4.1 - Remote Denial of Service
CVE-2008-3208doswindows
Simple DNS Plus 4.1, 5.0, and possibly other versions before 5.1.101 allows remote attackers to cause a denial of servic
23RISCO
abrir
ReferênciaVexDay Proof
PHPizabi 0.848b C1 HFP1 - Remote Code Execution
CVE-2008-3239webappsphp
Unrestricted file upload vulnerability in the writeLogEntry function in system/v_cron_proc.php in PHPizabi 0.848b C1 HFP
23RISCO
abrir
ReferênciaVexDay Proof
blogit! - SQL Injection / File Disclosure / Cross-Site Scripting
CVE-2009-0335webappsphp
Cross-site scripting (XSS) vulnerability in index.asp in Katy Whitton BlogIt! allows remote attackers to inject arbitrar
23RISCO
abrir
ReferênciaVexDay Proof
ProFTPd - 'mod_mysql' Authentication Bypass
CVE-2009-0542remotemultiple
SQL injection vulnerability in ProFTPD Server 1.3.1 through 1.3.2rc2 allows remote attackers to execute arbitrary SQL co
45RISCO
abrir
ReferênciaVexDay Proof
PPMate PPMedia Class - ActiveX Control Buffer Overflow (PoC)
CVE-2008-3242doswindows
Heap-based buffer overflow in the PPMedia Class ActiveX control in PPMPlayer.dll in PPMate 2.3.1.93 allows remote attack
28RISCO
abrir
ReferênciaVexDay Proof
Arctic Issue Tracker 2.0.0 - 'filter' SQL Injection (1)
CVE-2008-3250webappsphp
SQL injection vulnerability in index.php in Arctic Issue Tracker 2.0.0 allows remote attackers to execute arbitrary SQL
23RISCO
abrir
ReferênciaVexDay Proof
preCMS 1 - 'index.php' SQL Injection
CVE-2008-3254webappsphp
SQL injection vulnerability in index.php in preCMS 1 allows remote attackers to execute arbitrary SQL commands via the i
23RISCO
abrir
ReferênciaVexDay Proof
MW6 Datamatrix - ActiveX 'Datamatrix.dll' Insecure Method
CVE-2008-4925remotewindows
Multiple insecure method vulnerabilities in MW6 Technologies DataMatrix ActiveX control (DATAMATRIXLib.MW6DataMatrix, Da
23RISCO
abrir
ReferênciaVexDay Proof
Simple PHP NewsLetter 1.5 - Local File Inclusion
CVE-2009-0340webappsphp
Multiple directory traversal vulnerabilities in Simple PHP Newsletter 1.5 allow remote attackers to read arbitrary files
23RISCO
abrir
ReferênciaVexDay Proof
HRS Multi - 'key' Blind SQL Injection
CVE-2008-3266webappsasp
SQL injection vulnerability in picture_pic_bv.asp in SoftAcid Hotel Reservation System (HRS) Multi allows remote attacke
23RISCO
abrir
ReferênciaVexDay Proof
WinRemotePC Full+Lite 2008 r.2server - Denial of Service
CVE-2008-3269doswindows
WRPCServer.exe in WinSoftMagic WinRemotePC (WRPC) Lite 2008 and Full 2008 allows remote attackers to cause a denial of s
28RISCO
abrir
ReferênciaVexDay Proof
PHP TopTree BBS 2.0.1a - 'right_file' Remote File Inclusion
CVE-2007-2544webappsphp
PHP remote file inclusion vulnerability in templates/default/tpl_message.php in PHP TopTree BBS 2.0.1a and earlier allow
23RISCO
abrir
ReferênciaVexDay Proof
OpenSSL 0.9.8c-1 < 0.9.8g-9 (Debian and Derivatives) - Predictable PRNG Brute Force SSH
CVE-2008-3280remotelinux
It was found that various OpenID Providers (OPs) had TLS Server Certificates that used weak keys, as a result of the Deb
23RISCO
abrir
ReferênciaVexDay Proof
Aprox CMS Engine 5.1.0.4 - 'index.php' SQL Injection
CVE-2008-3291webappsphp
SQL injection vulnerability in index.php in AproxEngine (aka Aprox CMS Engine) 5.1.0.4 allows remote attackers to execut
23RISCO
abrir
ReferênciaVexDay Proof
EZWebAlbum - Insecure Cookie Handling
CVE-2008-3292webappsphp
constants.inc in EZWebAlbum 1.0 allows remote attackers to bypass authentication and gain administrator privileges by se
23RISCO
abrir
ReferênciaVexDay Proof
Persism CMS 0.9.2 - system[path] Remote File Inclusion
CVE-2007-2545webappsphp
Multiple PHP remote file inclusion vulnerabilities in Persism CMS 0.9.2 and earlier allow remote attackers to execute ar
35RISCO
abrir
ReferênciaVexDay Proof
DeluxeBB 1.07 - Remote Create Admin
CVE-2006-3304webappsphp
SQL injection vulnerability in cp.php in DeluxeBB 1.07 and earlier allows remote attackers to execute arbitrary SQL comm
23RISCO
abrir
ReferênciaVexDay Proof
bilboblog 2.1 - Multiple Vulnerabilities
CVE-2008-3302webappsphp
SQL injection vulnerability in admin/delete.php in BilboBlog 0.2.1, when magic_quotes_gpc is disabled, allows remote aut
23RISCO
abrir
ReferênciaVexDay Proof
bilboblog 2.1 - Multiple Vulnerabilities
CVE-2008-3304webappsphp
BilboBlog 0.2.1 allows remote attackers to obtain sensitive information via (1) an enable_cache=false query string to fo
23RISCO
abrir
ReferênciaVexDay Proof
Pre Survey Poll - 'catid' SQL Injection
CVE-2008-3310webappsasp
SQL injection vulnerability in default.asp in Pre Survey Poll allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
ReferênciaVexDay Proof
feedDemon 2.7 - OPML Outline Tag Buffer Overflow
CVE-2009-0546localwindows
Stack-based buffer overflow in NewsGator FeedDemon 2.7 and earlier allows user-assisted remote attackers to execute arbi
50RISCO
abrir
ReferênciaVexDay Proof
Maian Search 1.1 - Insecure Cookie Handling
CVE-2008-3317webappsphp
admin/index.php in Maian Search 1.1 and earlier allows remote attackers to bypass authentication and gain administrative
23RISCO
abrir
anteriorpágina 94 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.