Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
isweb CMS 3.0 - SQL Injection / Cross-Site Scripting
CVE-2008-5934webappsphp
SQL injection vulnerability in index.php in CMS ISWEB 3.0 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
ReferênciaVexDay Proof
mini-pub 0.3 - Local Directory Traversal / File Disclosure
CVE-2008-5936webappsphp
front-end/edit.php in mini-pub 0.3 and earlier allows remote attackers to read files and obtain PHP source code via a fi
23RIESGO
abrir
ReferênciaVexDay Proof
WebAlbum 2.02pl - COOKIE[skin2] Remote Code Execution
CVE-2006-1480webappsphp
Directory traversal vulnerability in start.php in WebAlbum 2.02 allows remote attackers to include arbitrary files and e
23RIESGO
abrir
ReferênciaVexDay Proof
PHP Ticket 0.71 - 'search.php' SQL Injection
CVE-2006-1481webappsphp
SQL injection vulnerability in search.php in PHP Ticket 0.71 allows remote authenticated users to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Office Products - Array Index Bounds Error (PoC)
CVE-2006-1540doswindows
MSO.DLL in Microsoft Office 2000, Office XP (2002), and Office 2003 allows user-assisted attackers to cause a denial of
28RIESGO
abrir
ReferênciaVexDay Proof
Python 2.4.2 - 'realpath()' Local Stack Overflow
CVE-2006-1542locallinux
Stack-based buffer overflow in Python 2.4.2 and earlier, running on Linux 2.6.12.5 under gcc 4.0.3 with libc 2.3.5, allo
23RIESGO
abrir
ReferênciaVexDay Proof
BMForum 5.6 - 'tagname' SQL Injection
CVE-2008-6091webappsphp
SQL injection vulnerability in plugins.php in BMForum 5.6, when magic_quotes_gpc is disabled, allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
phpscripts Ranking Script - Insecure Cookie Handling
CVE-2008-6092webappsphp
phpscripts Ranking Script allows remote attackers to bypass authentication and gain administrative access by sending an
23RIESGO
abrir
ReferênciaVexDay Proof
Noname CMS 1.0 - Multiple SQL Injections
CVE-2008-6093webappsphp
SQL injection vulnerability in index.php in Noname CMS 1.0, when magic_quotes_gpc is disabled, allows remote attackers t
23RIESGO
abrir
ReferênciaVexDay Proof
Discussion Forums 2k 3.3 - Multiple SQL Injections
CVE-2008-6100webappsphp
Multiple SQL injection vulnerabilities in Discussion Forums 2k 3.3, when magic_quotes_gpc is disabled, allow remote atta
23RIESGO
abrir
ReferênciaVexDay Proof
Goople CMS 1.7 - Insecure Cookie Handling
CVE-2008-6118webappsphp
win/content/upload.php in Goople CMS 1.7 allows remote attackers to bypass authentication and gain administrative access
23RIESGO
abrir
ReferênciaVexDay Proof
Full PHP Emlak Script - 'arsaprint.php' SQL Injection
CVE-2008-6133webappsphp
SQL injection vulnerability in arsaprint.php in Full PHP Emlak Script allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
ReferênciaVexDay Proof
Flexphpic 0.0.x - Authentication Bypass
CVE-2008-6142webappsphp
Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPic 0.0.4 and FlexPHPic Pro 0.0.3, and other 0.0.
23RIESGO
abrir
ReferênciaVexDay Proof
OwenPoll 1.0 - Insecure Cookie Handling
CVE-2008-6143webappsphp
OwenPoll 1.0 allows remote attackers to bypass authentication and obtain administrative access via a modified account na
23RIESGO
abrir
ReferênciaVexDay Proof
DeluxeBB 1.2 - Blind SQL Injection
CVE-2008-6146webappsphp
SQL injection vulnerability in pm.php in DeluxeBB 1.2 and earlier, when magic_quotes_gpc is disabled, allows remote atta
23RIESGO
abrir
ReferênciaVexDay Proof
ForumApp 3.3 - Remote Database Disclosure
CVE-2008-6147webappsasp
ForumApp 3.3 stores sensitive information under the web root with insufficient access control, which allows remote attac
23RIESGO
abrir
ReferênciaVexDay Proof
Sepcity Shopping Mall - SQL Injection
CVE-2008-6151webappsasp
SQL injection vulnerability in shpdetails.asp in SepCity Shopping Mall allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
Sepcity Lawyer Portal - SQL Injection
CVE-2008-6152webappsasp
SQL injection vulnerability in deptdisplay.asp in SepCity Faculty Portal allows remote attackers to execute arbitrary SQ
23RIESGO
abrir
ReferênciaVexDay Proof
Pixel8 Web Photo Album 3.0 - SQL Injection
CVE-2008-6153webappsasp
SQL injection vulnerability in Photo.asp in Jay Patel Pixel8 Web Photo Album 3.0 allows remote attackers to execute arbi
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component Kbase 1.0 - SQL Injection
CVE-2008-6166webappsphp
SQL injection vulnerability in the KBase (com_kbase) 1.2 component for Joomla! allows remote attackers to execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component RWCards 3.0.11 - Local File Inclusion
CVE-2008-6172webappsphp
Directory traversal vulnerability in captcha/captcha_image.php in the RWCards (com_rwcards) 3.0.11 component for Joomla!
43RIESGO
abrir
ReferênciaVexDay Proof
SilverSHielD 1.0.2.34 - Denial of Service
CVE-2008-6175doswindows
SilverSHielD 1.0.2.34 allows remote attackers to cause a denial of service (application crash) via a crafted argument to
23RIESGO
abrir
ReferênciaVexDay Proof
TopList 1.3.8 - 'phpBB Hack' Remote File Inclusion (1)
CVE-2006-2151webappsphp
PHP remote file inclusion vulnerability in toplist.php in phpBB TopList 1.3.8 and earlier, when register_globals is enab
28RIESGO
abrir
ReferênciaVexDay Proof
TopList 1.3.8 - 'phpBB Hack' Remote File Inclusion (2)
CVE-2006-2151webappsphp
PHP remote file inclusion vulnerability in toplist.php in phpBB TopList 1.3.8 and earlier, when register_globals is enab
28RIESGO
abrir
ReferênciaVexDay Proof
Advanced Guestbook 2.4.0 - 'phpBB' File Inclusion
CVE-2006-2152webappsphp
PHP remote file inclusion vulnerability in admin/addentry.php in phpBB Advanced Guestbook 2.4.0 and earlier, when regist
23RIESGO
abrir
ReferênciaVexDay Proof
X7 Chat 2.0 - 'help_file' Remote Command Execution
CVE-2006-2156webappsphp
Directory traversal vulnerability in help/index.php in X7 Chat 2.0 and earlier allows remote attackers to include arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
Fast Click 1.1.3/2.3.8 - 'show.php' Remote File Inclusion
CVE-2006-2175webappsphp
PHP remote file inclusion vulnerability in FtrainSoft Fast Click 2.3.8 and earlier allows remote attackers to execute ar
23RIESGO
abrir
ReferênciaVexDay Proof
SaturnCMS - Blind SQL Injection
CVE-2008-6263webappsphp
SQL injection vulnerability in lib/user/t_user.php in SaturnCMS allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
ReferênciaVexDay Proof
WEBBDOMAIN WebShop 1.02 - SQL Injection / Cross-Site Scripting
CVE-2008-6268webappsphp
SQL injection vulnerability in detail.php in WEBBDOMAIN Multi Languages WebShop Online 1.02 allows remote attackers to e
23RIESGO
abrir
ReferênciaVexDay Proof
Active NewsLetter 4.3 - Authentication Bypass
CVE-2008-6286webappsasp
Multiple SQL injection vulnerabilities in SubscriberStart.asp in Active Newsletter 4.3 allow remote attackers to execute
23RIESGO
abrir
anteriorpágina 129 / 188siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.