Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
LimeSurvey 1.52 - 'language.php' Remote File Inclusion
CVE-2007-5573webappsphp
PHP remote file inclusion vulnerability in classes/core/language.php in LimeSurvey 1.5.2 and earlier allows remote attac
23RIESGO
abrir
ReferênciaVexDay Proof
shibby shop 2.2 - Multiple Vulnerabilities
CVE-2008-2872webappsphp
SQL injection vulnerability in default.asp in sHibby sHop 2.2 and earlier allows remote attackers to execute arbitrary S
23RIESGO
abrir
ReferênciaVexDay Proof
PhpCommander 3.0 - 'upload' Remote Code Execution
CVE-2006-4636webappsphp
Directory traversal vulnerability in SZEWO PhpCommander 3.0 and earlier allows remote attackers to include and execute a
23RIESGO
abrir
ReferênciaVexDay Proof
shibby shop 2.2 - Multiple Vulnerabilities
CVE-2008-2873webappsphp
sHibby sHop 2.2 and earlier stores sensitive information under the web root with insufficient access control, which allo
23RIESGO
abrir
ReferênciaVexDay Proof
Polaring 0.04.03 - 'general.php' Remote File Inclusion
CVE-2006-5078webappsphp
PHP remote file inclusion vulnerability in view/general.php in Kristian Niemi Polaring 00.04.03 and earlier allows remot
23RIESGO
abrir
ReferênciaVexDay Proof
paBugs 2.0 Beta 3 - 'class.mysql.php' Remote File Inclusion
CVE-2006-5079webappsphp
PHP remote file inclusion vulnerability in class.mysql.php in Matt Humphrey paBugs 2.0 Beta 3 and earlier allows remote
23RIESGO
abrir
ReferênciaVexDay Proof
Ninja Blog 4.8 - Remote Information Disclosure
CVE-2009-0325webappsphp
Directory traversal vulnerability in entries/index.php in Ninja Blog 4.8, when magic_quotes_gpc is disabled, allows remo
23RIESGO
abrir
ReferênciaVexDay Proof
phpYabs 0.1.2 - 'Azione' Remote File Inclusion
CVE-2009-0639webappsphp
PHP remote file inclusion vulnerability in moduli/libri/index.php in phpyabs 0.1.2 allows remote attackers to execute ar
23RIESGO
abrir
ReferênciaVexDay Proof
Enthrallweb eCoupons 1.0 - 'myprofile.asp' Remote Pass Change
CVE-2006-6820webappsasp
myprofile.asp in Enthrallweb eCoupons does not properly validate the MM_recordId parameter during profile updates, which
23RIESGO
abrir
ReferênciaVexDay Proof
MyPicGallery 1.0 - Arbitrary Add Admin
CVE-2008-2347webappsphp
MyPicGallery 1.0 allows remote attackers to bypass application authentication and gain administrative access by setting
23RIESGO
abrir
ReferênciaVexDay Proof
odars CMS 1.0.2 - Remote File Inclusion
CVE-2008-2885webappsphp
PHP remote file inclusion vulnerability in src/browser/resource/categories/resource_categories_view.php in Open Digital
23RIESGO
abrir
ReferênciaVexDay Proof
Vivvo Article Manager 3.2 - 'id' SQL Injection
CVE-2006-4715webappsphp
SQL injection vulnerability in pdf_version.php in SpoonLabs Vivvo Article Management CMS (aka phpWordPress) 3.2 and earl
23RIESGO
abrir
ReferênciaVexDay Proof
Stash 1.0.3 - Insecure Cookie Handling
CVE-2008-4081webappsphp
admin/login.php in Stash 1.0.3 allows remote attackers to bypass authentication and gain administrative access by settin
23RIESGO
abrir
ReferênciaVexDay Proof
Atomic Photo Album 1.1.0pre4 - Insecure Cookie Handling
CVE-2008-4714webappsphp
Atomic Photo Album 1.1.0 pre4 does not properly handle the apa_cookie_login and apa_cookie_password cookies, which proba
23RIESGO
abrir
ReferênciaVexDay Proof
SG Real Estate Portal 2.0 - Insecure Cookie Handling
CVE-2008-6009webappsphp
SG Real Estate Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by setting the
23RIESGO
abrir
ReferênciaVexDay Proof
Explay CMS 2.1 - Insecure Cookie Handling
CVE-2008-6411webappsphp
Explay CMS 2.1 and earlier allows remote attackers to bypass authentication and gain administrative access by setting th
23RIESGO
abrir
ReferênciaVexDay Proof
A+ PHP Scripts - Nms Insecure Cookie Handling
CVE-2008-6667webappsphp
A+ PHP Scripts News Management System (NMS) allows remote attackers to bypass authentication and gain administrator priv
23RIESGO
abrir
ReferênciaVexDay Proof
MyShoutPro 1.2 - Final Insecure Cookie Handling
CVE-2008-6738webappsphp
MyShoutPro 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin_acce
23RIESGO
abrir
ReferênciaVexDay Proof
Esqlanelapse Software Project 2.6.2 - Insecure Cookie Handling
CVE-2008-7019webappsphp
Esqlanelapse 2.6.1 and 2.6.2 allows remote attackers to bypass authentication and gain privileges via modified (1) enomb
23RIESGO
abrir
ReferênciaVexDay Proof
RPG.Board 0.0.8Beta2 - Insecure Cookie Handling
CVE-2008-7028webappsphp
RPG.Board 0.8 Beta2 and earlier allows remote attackers to bypass authentication and gain privileges by setting the keep
23RIESGO
abrir
ReferênciaVexDay Proof
FretsWeb 1.2 - 'name' Blind SQL Injection
CVE-2009-2113webappsphp
Multiple SQL injection vulnerabilities in FretsWeb 1.2 allow remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir
ReferênciaVexDay Proof
Light Weight Calendar 1.x - 'date' Remote Code Execution
CVE-2006-1252webappsphp
Eval injection vulnerability in cal.php in Light Weight Calendar (LWC) 1.0 allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
Yahoo! Messenger 8.1.0.421 - CYFT Object Arbitrary File Download
CVE-2007-5017remotewindows
Absolute path traversal vulnerability in a certain ActiveX control in the CYFT object in ft60.dll in Yahoo! Messenger 8.
23RIESGO
abrir
ReferênciaVexDay Proof
Online Fantasy Football League (OFFL) 0.2.6 - 'teams.php' SQL Injection
CVE-2008-2890webappsphp
Multiple SQL injection vulnerabilities in Online Fantasy Football League (OFFL) 0.2.6 and earlier allow remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
Calendar Script 1.1 - Insecure Cookie Handling
CVE-2008-5738webappsphp
Nodstrum MySQL Calendar 1.1 and 1.2 allows remote attackers to bypass authentication and gain administrative access by s
23RIESGO
abrir
ReferênciaVexDay Proof
PHPAuctionSystem - Insecure Cookie Handling
CVE-2009-0108webappsphp
PHPAuctions (aka PHPAuctionSystem) allows remote attackers to bypass authentication and gain administrative access via m
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component EXP Shop - 'catid' SQL Injection
CVE-2008-2892webappsphp
SQL injection vulnerability in the EXP Shop (com_expshop) component 1.0 for Joomla! allows remote attackers to execute a
23RIESGO
abrir
ReferênciaVexDay Proof
phpMyAgenda 3.1 - '/templates/header.php3' Local File Inclusion
CVE-2006-5263webappsphp
Directory traversal vulnerability in templates/header.php3 in phpMyAgenda 3.1 and earlier allows remote attackers to inc
23RIESGO
abrir
ReferênciaVexDay Proof
TorrentFlux 2.2 - 'maketorrent.php' Remote Command Execution
CVE-2006-6599webappsphp
maketorrent.php in TorrentFlux 2.2 allows remote authenticated users to execute arbitrary commands via shell metacharact
23RIESGO
abrir
ReferênciaVexDay Proof
project alumni 1.0.9 - 'index.php?act' Local File Inclusion
CVE-2007-6184webappsphp
Directory traversal vulnerability in index.php in Project Alumni 1.0.9 allows remote attackers to include and execute ar
23RIESGO
abrir
anteriorpágina 133 / 188siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.