Exploração pública

Catálogo de exploits

Todo exploit público que catalogamos, num índice só. Busque por CVE, nome do exploit ou tecnologia — e veja, ao lado, o que a falha realmente vale: severidade, probabilidade de exploração e se já está sob ataque.

79.107exploits catalogados
36.322CVEs com exploração pública
24.695testados em laboratório
5.629 exploits
ReferênciaVexDay Proof
FreeWPS 2.11 - 'images.php' Remote Code Execution
CVE-2006-1363webappsphp
images.php in Justin White (aka YTZ) Free Web Publishing System (FreeWPS) 2.11 allows remote attackers to execute arbitr
23RISCO
abrir
ReferênciaVexDay Proof
MiniHTTPServer Web Forum & File Sharing Server 4.0 - Add User
CVE-2006-5597remotewindows
join.asp in MiniHTTP Web Forum & File Server PowerPack 4.0 allows remote attackers to add or modify arbitrary user accou
23RISCO
abrir
ReferênciaVexDay Proof
SH-News 3.0 - Insecure Cookie Handling
CVE-2008-6664webappsphp
action.php in SH-News 3.0 allows remote attackers to bypass authentication and gain administrator privileges by setting
23RISCO
abrir
ReferênciaVexDay Proof
ScarNews 1.2.1 - 'sn_admin_dir' Local File Inclusion
CVE-2007-1932webappsphp
Directory traversal vulnerability in scarnews.inc.php in ScarNews 1.2.1 allows remote attackers to include and execute a
23RISCO
abrir
ReferênciaVexDay Proof
My Little Forum 1.7 - 'user.php?id' SQL Injection
CVE-2007-2942webappsphp
SQL injection vulnerability in user.php in My Little Forum 1.7 and earlier allows remote attackers to execute arbitrary
23RISCO
abrir
ReferênciaVexDay Proof
Absolute Form Processor 4.0 - Insecure Cookie Handling
CVE-2008-6863webappsphp
Xigla Software Absolute Form Processor .NET 4.0 allows remote attackers to bypass authentication and gain administrative
23RISCO
abrir
ReferênciaVexDay Proof
DreamLog 0.5 - 'upload.php' Arbitrary File Upload
CVE-2007-3403webappsphp
Unrestricted file upload vulnerability in upload.php in dreamLog (aka dreamblog) 0.5 allows remote attackers to upload a
23RISCO
abrir
ReferênciaVexDay Proof
LinPHA 1.3.1 - 'new_images.php' Blind SQL Injection
CVE-2007-4053webappsphp
SQL injection vulnerability in include/img_view.class.php in LinPHA 1.3.1 and earlier allows remote attackers to execute
23RISCO
abrir
ReferênciaVexDay Proof
AssoCIateD CMS 1.1.3 - 'ROOT_PATH' Remote File Inclusion
CVE-2006-2841webappsphp
Multiple PHP remote file inclusion vulnerabilities in AssoCIateD (aka ACID) CMS 1.1.3 allow remote attackers to execute
23RISCO
abrir
ReferênciaVexDay Proof
Alstrasoft AskMe Pro 2.1 - Multiple SQL Injections
CVE-2008-2902webappsphp
SQL injection vulnerability in profile.php in AlstraSoft AskMe Pro 2.1 and earlier allows remote attackers to execute ar
23RISCO
abrir
ReferênciaVexDay Proof
Phaos 0.9.2 - 'basename()' Remote Command Execution
CVE-2006-4420webappsphp
Directory traversal vulnerability in include_lang.php in Phaos 0.9.2 allows remote attackers to include arbitrary local
23RISCO
abrir
ReferênciaVexDay Proof
PHP Crawler 0.8 - Remote File Inclusion
CVE-2008-4137webappsphp
PHP remote file inclusion vulnerability in footer.php in PHP-Crawler 0.8 allows remote attackers to execute arbitrary PH
23RISCO
abrir
ReferênciaVexDay Proof
NuralStorm Webmail 0.98b - 'process.php' Remote File Inclusion
CVE-2006-5386webappsphp
PHP remote file inclusion vulnerability in process.php in NuralStorm Webmail 0.98b and earlier, when register_globals is
23RISCO
abrir
ReferênciaVexDay Proof
Fuzzylime CMS 3.03 - 'track.php' Local File Inclusion
CVE-2008-5291webappsphp
Directory traversal vulnerability in code/track.php in FuzzyLime 3.03 allows remote attackers to include and execute arb
23RISCO
abrir
ReferênciaVexDay Proof
Ultimate HelpDesk - Cross-Site Scripting / Local File Disclosure
CVE-2006-6381webappsasp
Directory traversal vulnerability in getfile.asp in Ultimate HelpDesk allows remote attackers to read arbitrary files vi
23RISCO
abrir
ReferênciaVexDay Proof
ASP-Nuke Community 1.5 - Cookie Privilege Escalation
CVE-2006-7152webappsasp
default.asp in ASP-Nuke Community 1.5 and earlier allows remote attackers to gain privileges by setting certain pseudo c
23RISCO
abrir
ReferênciaVexDay Proof
Maran PHP Shop - 'admin.php' Insecure Cookie Handling
CVE-2008-6296webappsphp
admin.php in Maran PHP Shop allows remote attackers to bypass authentication and gain administrative access by setting t
23RISCO
abrir
ReferênciaVexDay Proof
McGallery 0.5b - 'download.php' Arbitrary File Download
CVE-2007-1478webappsphp
download.php in McGallery 0.5b allows remote attackers to read arbitrary files and obtain script source code via the fil
23RISCO
abrir
ReferênciaVexDay Proof
OpenForum 0.66 Beta - Remote Reset Admin Password
CVE-2008-7066webappsphp
OpenForum 0.66 Beta allows remote attackers to bypass authentication and reset passwords of other users via a direct req
23RISCO
abrir
ReferênciaVexDay Proof
pivot 1.40.4-7 - Multiple Vulnerabilities
CVE-2009-2134webappsphp
pivot/tb.php in Pivot 1.40.4 and 1.40.7 allows remote attackers to obtain sensitive information via an invalid url param
23RISCO
abrir
ReferênciaVexDay Proof
PBLang 4.67.16.a - Remote Code Execution
CVE-2007-3096webappsphp
Directory traversal vulnerability in login.php in PBLang (PBL) 4.67.16.a and earlier, when magic_quotes_gpc is disabled,
23RISCO
abrir
ReferênciaVexDay Proof
Evilsentinel 1.0.9 - Multiple Vulnerabilities Disable
CVE-2008-0350webappsphp
admin/index.php in Evilsentinel 1.0.9 and earlier sends a redirect to the web browser but does not exit, which allows re
23RISCO
abrir
ReferênciaVexDay Proof
freePHPgallery 0.6 - Cookie Local File Inclusion
CVE-2008-0818webappsphp
Multiple directory traversal vulnerabilities in freePHPgallery 0.6 allow remote attackers to include and execute arbitra
23RISCO
abrir
ReferênciaVexDay Proof
iScripts Socialware - 'id' SQL Injection
CVE-2008-1772webappsphp
iScripts SocialWare stores passwords in cleartext in a database, which allows context-dependent attackers to obtain sens
23RISCO
abrir
ReferênciaVexDay Proof
IndexScript 2.8 - 'cat_id' SQL Injection
CVE-2007-4069webappsphp
SQL injection vulnerability in show_cat.php in IndexScript 2.8 and earlier allows remote attackers to execute arbitrary
23RISCO
abrir
ReferênciaVexDay Proof
BtiTracker 1.4.7 / xbtit 2.0.542 - SQL Injection
CVE-2008-3784webappsphp
SQL injection vulnerability in scrape.php in BtiTracker 1.4.7 and earlier and xBtiTracker 2.0.542 and earlier allows rem
23RISCO
abrir
ReferênciaVexDay Proof
mini-pub 0.3 - File Disclosure / Code Execution
CVE-2008-5581webappsphp
PHP remote file inclusion vulnerability in mini-pub.php/front-end/img.php in mini-pub 0.3 allows remote attackers to exe
23RISCO
abrir
ReferênciaVexDay Proof
CFAGCMS 1 - Remote File Inclusion
CVE-2008-5922webappsphp
Multiple PHP remote file inclusion vulnerabilities in themes/default/index.php in Cant Find A Gaming CMS (CFAGCMS) 1 all
23RISCO
abrir
ReferênciaVexDay Proof
basebuilder 2.0.1 - 'main.inc.php' Remote File Inclusion
CVE-2008-6036webappsphp
PHP remote file inclusion vulnerability in main.inc.php in BaseBuilder 2.0.1 and earlier allows remote attackers to exec
23RISCO
abrir
ReferênciaVexDay Proof
PHPMyCart 1.3 - 'cat' SQL Injection
CVE-2008-2904webappsphp
SQL injection vulnerability in shop.php in Conkurent PHPMyCart allows remote attackers to execute arbitrary SQL commands
23RISCO
abrir
anteriorpágina 97 / 188próximo

Indexamos apenas o link público para a prova de conceito — nunca hospedamos nem redistribuímos código de exploração. Fontes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit e VulnCheck XDB. A existência de PoC pública não significa que a falha seja explorável no seu ambiente.