Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
Scout Portal Toolkit 1.4.0 - 'ParentId' SQL Injection
CVE-2005-4195webappsphp
Multiple SQL injection vulnerabilities in Scout Portal Toolkit (SPT) 1.3.1 and earlier allow remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
BareNuked CMS 1.1.0 - Arbitrary Add Admin
CVE-2008-3133webappsphp
SQL injection vulnerability in admin/index.php in BareNuked CMS 1.1.0, when magic_quotes_gpc is disabled, allows remote
23RIESGO
abrir
ReferênciaVexDay Proof
AShop Deluxe 4.x - 'catalogue.php' SQL Injection
CVE-2008-3136webappsphp
SQL injection vulnerability in catalogue.php in AShop Deluxe 4.x allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
ReferênciaVexDay Proof
Barracuda Web Application Firewall - Authentication Bypass
CVE-2014-2595remotehardware
Barracuda Web Application Firewall (WAF) 7.8.1.013 allows remote attackers to bypass authentication by leveraging a perm
28RIESGO
abrir
ReferênciaVexDay Proof
RunCMS 1.5.2 - 'debug_show.php' SQL Injection
CVE-2007-2538webappsphp
SQL injection vulnerability in class/debug/debug_show.php in RunCms 1.5.2 and earlier allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
MiniBB keyword_replacer 1.0 - 'pathToFiles' File Inclusion
CVE-2006-7156webappsphp
PHP remote file inclusion vulnerability in addon_keywords.php in Keyword Replacer (keyword_replacer) 1.0 and earlier, a
23RIESGO
abrir
ReferênciaVexDay Proof
QuickTicket 1.5 - 'qti_usr.php' SQL Injection
CVE-2007-3539webappsphp
Multiple SQL injection vulnerabilities in QuickTicket 1.2 build:20070621 and QuickTalk Forum 1.3 allow remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
Fully Modded phpBB 2021.4.40 - Multiple File Inclusions
CVE-2006-5526webappsphp
Multiple PHP remote file inclusion vulnerabilities in Teake Nutma Foing, as modified in Fully Modded phpBB (phpbbfm) 202
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Visual 6 - 'VDT70.dll NotSafe' Remote Stack Overflow
CVE-2007-4254remotewindows
Stack-based buffer overflow in a certain ActiveX control in VDT70.DLL in Microsoft Visual Database Tools Database Design
28RIESGO
abrir
ReferênciaVexDay Proof
BoonEx Ray 3.5 - 'sIncPath' Remote File Inclusion
CVE-2008-3166webappsphp
PHP remote file inclusion vulnerability in modules/global/inc/content.inc.php in BoonEx Ray 3.5, when register_globals i
23RIESGO
abrir
ReferênciaVexDay Proof
Boonex Dolphin 6.1.2 - Multiple Remote File Inclusions
CVE-2008-3167webappsphp
Multiple PHP remote file inclusion vulnerabilities in BoonEx Dolphin 6.1.2, when register_globals is enabled, allow remo
23RIESGO
abrir
ReferênciaVexDay Proof
AllMyLinks 0.5.0 - 'index.php' Remote File Inclusion
CVE-2007-0171webappsphp
PHP remote file inclusion vulnerability in index.php in AllMyLinks 0.5.0 and earlier allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
BaoFeng2 - 'mps.dll' ActiveX Multiple Remote Buffer Overflows (PoC)
CVE-2007-4816doswindows
Multiple buffer overflows in the BaoFeng2 storm ActiveX control in Mps.dll allow remote attackers to have an unknown imp
23RIESGO
abrir
ReferênciaVexDay Proof
dBpowerAMP Audio Player 2 - '.m3u' Remote Buffer Overflow
CVE-2008-0661remotewindows
Buffer overflow in dBpowerAMP Audio Player Release 2 allows remote attackers to execute arbitrary code via a .M3U file w
23RIESGO
abrir
ReferênciaVexDay Proof
CMS Made Simple 1.2.4 Module FileManager - Arbitrary File Upload
CVE-2008-2267webappsphp
Incomplete blacklist vulnerability in javaUpload.php in Postlet in the FileManager module in CMS Made Simple 1.2.4 and e
23RIESGO
abrir
ReferênciaVexDay Proof
mxCamArchive 2.2 - Bypass Configuration Download
CVE-2008-6956webappsphp
Static code injection vulnerability in admin/admin.php in mxCamArchive 2.2 allows remote authenticated administrators to
23RIESGO
abrir
ReferênciaVexDay Proof
Omegaboard 1.0beta4 - 'functions.php' Remote File Inclusion
CVE-2007-0683webappsphp
PHP remote file inclusion vulnerability in includes/functions.php in Omegaboard 1.0beta4 and earlier allows remote attac
23RIESGO
abrir
ReferênciaVexDay Proof
Htaccess Passwort Generator 1.1 - 'ht_pfad' Remote File Inclusion
CVE-2007-1013webappsphp
PHP remote file inclusion vulnerability in generate.php in VirtualSystem Htaccess Passwort Generator 1.1 allows remote a
23RIESGO
abrir
ReferênciaVexDay Proof
IrayoBlog 0.2.4 - '/inc/irayofuncs.php' Remote File Inclusion
CVE-2006-5849webappsphp
PHP remote file inclusion vulnerability in inc/irayofuncs.php in IrayoBlog alpha-0.2.4 allows remote attackers to execut
23RIESGO
abrir
ReferênciaVexDay Proof
Nessus Vulnerability Scanner 3.0.6 - ActiveX Command Execution
CVE-2007-4061remotewindows
Directory traversal vulnerability in a certain ActiveX control in Nessus Vulnerability Scanner 3.0.6 allows remote attac
28RIESGO
abrir
ReferênciaVexDay Proof
Scripteen Free Image Hosting Script 1.2 - 'cookie' Pass Grabber
CVE-2008-3211webappsphp
Scripteen Free Image Hosting Script 1.2 and 1.2.1 allows remote attackers to bypass authentication and gain administrati
23RIESGO
abrir
ReferênciaVexDay Proof
Debian OpenSSH - (Authenticated) Remote SELinux Privilege Escalation
CVE-2008-3234remotelinux
sshd in OpenSSH 4 on Debian GNU/Linux, and the 20070303 OpenSSH snapshot, allows remote authenticated users to obtain ac
23RIESGO
abrir
ReferênciaVexDay Proof
Achievo 1.3.2 - 'FCKeditor' Arbitrary File Upload
CVE-2008-2742webappsphp
Unrestricted file upload in the mcpuk file editor (atk/attributes/fck/editor/filemanager/browser/mcpuk/connectors/php/co
23RIESGO
abrir
ReferênciaVexDay Proof
Electronics Workbench - '.ewb' Local Stack Overflow (PoC)
CVE-2008-5383doswindows
Stack-based buffer overflow in National Instruments Electronics Workbench allows user-assisted attackers to cause a deni
23RIESGO
abrir
ReferênciaVexDay Proof
Bea Weblogic Apache Connector - Code Execution / Denial of Service
CVE-2008-3257remotewindows
Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10
60RIESGO
abrir
ReferênciaVexDay Proof
Web Content System 2.7.1 - Remote File Inclusion
CVE-2007-1771webappsphp
PHP remote file inclusion vulnerability in manage/javascript/formjavascript.php in Ay System Solutions Web Content Syste
23RIESGO
abrir
ReferênciaVexDay Proof
Adobe JRun 4 - 'logfile' (Authenticated) Directory Traversal
CVE-2009-1873remotewindows
Directory traversal vulnerability in logging/logviewer.jsp in the Management Console in Adobe JRun Application Server 4
23RIESGO
abrir
ReferênciaVexDay Proof
Lms 1.8.9 - Vala Remote File Inclusion
CVE-2007-1643webappsphp
Multiple PHP remote file inclusion vulnerabilities in LAN Management System (LMS) 1.8.9 Vala and earlier allow remote at
28RIESGO
abrir
ReferênciaVexDay Proof
Focus/SIS 1.0/2.2 - Remote File Inclusion
CVE-2007-4806webappsphp
PHP remote file inclusion vulnerability in modules/Discipline/CategoryBreakdownTime.php in Focus/SIS 1.0 allows remote a
23RIESGO
abrir
ReferênciaVexDay Proof
EZWebAlbum - Remote File Disclosure
CVE-2008-3293webappsphp
Directory traversal vulnerability in download.php in EZWebAlbum allows remote attackers to read arbitrary files via the
23RIESGO
abrir
anteriorpágina 135 / 188siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.