Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
Vote-Pro 4.0 - 'poll_frame.php?poll_id' Remote Code Execution
CVE-2007-0504webappsphp
Eval injection vulnerability in poll_frame.php in Vote! Pro 4.0, and possibly other scripts, allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
EDraw Office Viewer Component 5.2 - ActiveX Remote Buffer Overflow (PoC)
CVE-2007-4821doswindows
Buffer overflow in a certain ActiveX control in officeviewer.ocx 5.2.218.1 in EDraw Office Viewer Component 5.2 allows r
23RIESGO
abrir
ReferênciaVexDay Proof
Acidcat CMS 3.4.1 - Multiple Vulnerabilities
CVE-2008-1990webappsphp
Multiple SQL injection vulnerabilities in Acidcat CMS 3.4.1 allow remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
ReferênciaVexDay Proof
moziloCMS 1.11 - Local File Inclusion / Full Path Disclosure / Cross-Site Scripting
CVE-2009-1368webappsphp
Directory traversal vulnerability in index.php in moziloCMS 1.11 allows remote attackers to read arbitrary files via a .
23RIESGO
abrir
ReferênciaVexDay Proof
WonderWare SuiteLink 2.0 - Remote Denial of Service (Metasploit)
CVE-2008-2005doswindows
The SuiteLink Service (aka slssvc.exe) in WonderWare SuiteLink before 2.0 Patch 01, as used in WonderWare InTouch 8.0, a
28RIESGO
abrir
ReferênciaVexDay Proof
MiniBB 2.2 - Cross-Site Scripting / SQL Injection / Full Path Disclosure
CVE-2008-2024webappsphp
Cross-site scripting (XSS) vulnerability in index.php in miniBB 2.2, and possibly earlier, when register_globals is enab
23RIESGO
abrir
ReferênciaVexDay Proof
MiniBB 2.2 - Cross-Site Scripting / SQL Injection / Full Path Disclosure
CVE-2008-2029webappsphp
Multiple SQL injection vulnerabilities in (1) setup_mysql.php and (2) setup_options.php in miniBB 2.2 and possibly earli
23RIESGO
abrir
ReferênciaVexDay Proof
Mambo Component MGM 0.95r2 - Remote File Inclusion
CVE-2006-3980webappsphp
PHP remote file inclusion vulnerability in administrator/components/com_mgm/help.mgm.php in Mambo Gallery Manager (MGM)
23RIESGO
abrir
ReferênciaVexDay Proof
Dream4 Koobi Pro 6.25 Poll - 'poll_id' SQL Injection
CVE-2008-2036webappsphp
SQL injection vulnerability in index.php in dream4 Koobi Pro 6.25 allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir
ReferênciaVexDay Proof
Job Script 2.0 - Arbitrary Change Admin Password
CVE-2009-1610webappsphp
admin/changepassword.php in Job Script Job Board Software 2.0 allows remote attackers to change the administrator passwo
23RIESGO
abrir
ReferênciaVexDay Proof
VImpX ActiveX (VImpX.ocx 4.7.3.0) - Remote Buffer Overflow
CVE-2007-2667remotewindows
Buffer overflow in the DB Software Laboratory VImpX ActiveX control in VImpX.ocx 4.7.3 allows remote attackers to execut
23RIESGO
abrir
ReferênciaVexDay Proof
Ruby 1.8.6/1.9 (WEBick HTTPd 1.3.1) - Directory Traversal
CVE-2008-1145remotemultiple
Directory traversal vulnerability in WEBrick in Ruby 1.8 before 1.8.5-p115 and 1.8.6-p114, and 1.9 through 1.9.0-1, when
28RIESGO
abrir
ReferênciaVexDay Proof
Angelo-Emlak 1.0 - Multiple SQL Injections
CVE-2008-2047webappsasp
Multiple SQL injection vulnerabilities in Angelo-Emlak 1.0 allow remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
ReferênciaVexDay Proof
WebPortal CMS 0.8b - Multiple Local/Remote File Inclusions
CVE-2009-1445webappsphp
Multiple directory traversal vulnerabilities in WebPortal CMS 0.8-beta allow remote attackers to (1) read arbitrary file
23RIESGO
abrir
ReferênciaVexDay Proof
QuickTime 7.4.1 - 'QTPlugin.ocx' Multiple Stack Overflow Vulnerabilities
CVE-2008-0778doswindows
Multiple stack-based buffer overflows in an ActiveX control in QTPlugin.ocx for Apple QuickTime 7.4.1 and earlier allow
23RIESGO
abrir
ReferênciaVexDay Proof
ActualAnalyzer Lite (free) 2.78 - Local File Inclusion
CVE-2008-2076webappsphp
Directory traversal vulnerability in admin.php in ActualScripts ActualAnalyzer Lite 2.78 allows remote attackers to incl
23RIESGO
abrir
ReferênciaVexDay Proof
Siteman 2.x - Code Execution / Local File Inclusion / Cross-Site Scripting
CVE-2008-2081webappsphp
Directory traversal vulnerability in index.php in Siteman 2.0.x2 allows remote authenticated administrators to include a
23RIESGO
abrir
ReferênciaVexDay Proof
Advanced Webhost Billing System (AWBS) 2.4.0 - 'cart2.php' Remote File Inclusion
CVE-2007-2272webappsphp
PHP remote file inclusion vulnerability in docs/front-end-demo/cart2.php in Advanced Webhost Billing System (AWBS) 2.4.0
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft FoxServer - 'vfp6r.dll 6.0.8862.0' ActiveX Command Execution
CVE-2008-0236remotewindows
An ActiveX control for Microsoft Visual FoxPro (vfp6r.dll 6.0.8862.0) allows remote attackers to execute arbitrary comma
28RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component Community Builder 1.0.1 - Blind SQL Injection
CVE-2008-2093webappsphp
SQL injection vulnerability in the Profiler (com_comprofiler) component in Community Builder for Mambo and Joomla! allow
23RIESGO
abrir
ReferênciaVexDay Proof
eZip Wizard 3.0 - Local Stack Buffer Overflow (PoC) (SEH)
CVE-2009-1058doswindows
Stack-based buffer overflow in ZipGenius might allow remote attackers to execute arbitrary code via a crafted .zip file
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component FlippingBook 1.0.4 - SQL Injection
CVE-2008-2095webappsphp
SQL injection vulnerability in index.php in the FlippingBook (com_flippingbook) 1.0.4 component for Joomla! allows remot
23RIESGO
abrir
ReferênciaVexDay Proof
BackLinkSpider 1.1 - 'cat_id' SQL Injection
CVE-2008-2096webappsphp
SQL injection vulnerability in BackLinkSpider allows remote attackers to execute arbitrary SQL commands via the cat_id p
23RIESGO
abrir
ReferênciaVexDay Proof
CUPS 1.3.7 - Cross-Site Request Forgery (Add RSS Subscription) Remote Crash
CVE-2008-5183doslinux
cupsd in CUPS 1.3.9 and earlier allows local users, and possibly remote attackers, to cause a denial of service (daemon
23RIESGO
abrir
ReferênciaVexDay Proof
WorkSimple 1.2.1 - Remote File Inclusion / Sensitive Data Disclosure
CVE-2008-5765webappsphp
WorkSimple 1.2.1 stores sensitive information under the web root with insufficient access control, which allows remote a
23RIESGO
abrir
ReferênciaVexDay Proof
yourplace 1.0.2 - Multiple Vulnerabilities / Remote Code Execution
CVE-2008-6770webappsphp
YourPlace 1.0.2 and earlier stores sensitive information under the web root with insufficient access control, which allo
23RIESGO
abrir
ReferênciaVexDay Proof
ASPThai.Net Forum 8.5 - Remote Database Disclosure
CVE-2008-6872webappsasp
ASPThai.NET ASPThai Forums 8.5 stores sensitive information under the web root with insufficient access control, which a
23RIESGO
abrir
ReferênciaVexDay Proof
Simple Website Software 0.99 - 'common.php' File Inclusion
CVE-2006-5636webappsphp
PHP remote file inclusion vulnerability in common.php in Simple Website Software (SWS) 0.99 and earlier allows remote at
23RIESGO
abrir
ReferênciaVexDay Proof
Power Editor 2.0 - Remote File Disclosure / Edit
CVE-2008-2115webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in editor.php in ScriptsEZ.net Power Editor 2.0 allow remote attacke
23RIESGO
abrir
ReferênciaVexDay Proof
Elecard MPEG Player 5.5 - '.m3u' Stack Buffer Overflow (PoC)
CVE-2009-0491doswindows
Stack-based buffer overflow in Elecard MPEG Player 5.5 build 15884.081218 allows remote attackers to execute arbitrary c
23RIESGO
abrir
anteriorpágina 124 / 188siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.