Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
PowerPortal 2.0.13 - 'path' Local Directory Traversal
CVE-2008-4361webappsphp
Directory traversal vulnerability in PowerPortal 2.0.13 allows remote attackers to list and possibly read arbitrary file
23RIESGO
abrir
ReferênciaVexDay Proof
neuron news 1.0 - 'index.php?q' Local File Inclusion
CVE-2007-5050webappsphp
Directory traversal vulnerability in index.php in Neuron News 1.0 allows remote attackers to include and execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
LiteNews 0.1 - Insecure Cookie Handling
CVE-2008-3508webappsphp
LiteNews 0.1 (aka 01), and possibly 1.2 and earlier, allows remote attackers to bypass authentication and gain administr
23RIESGO
abrir
ReferênciaVexDay Proof
Mosaic Commerce - 'cid' SQL Injection
CVE-2008-4599webappsphp
SQL injection vulnerability in category.php in Mosaic Commerce allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
iGaming CMS 2.0 Alpha 1 - 'search.php' SQL Injection
CVE-2008-4603webappsphp
SQL injection vulnerability in search.php in iGaming CMS 2.0 Alpha 1 allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir
ReferênciaVexDay Proof
Mantis Bug Tracker 1.1.3 - Remote Code Execution
CVE-2008-4687webappsphp
manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort param
50RIESGO
abrir
ReferênciaVexDay Proof
Opera 9.60 - Persistent Cross-Site Scripting
CVE-2008-4696remotewindows
Cross-site scripting (XSS) vulnerability in Opera.dll in Opera before 9.61 allows remote attackers to inject arbitrary w
50RIESGO
abrir
ReferênciaVexDay Proof
Peachtree Accounting 2004 - 'PAWWeb11.ocx' ActiveX Insecure Method
CVE-2008-4699remotewindows
Insecure method vulnerability in the ActiveX control (PAWWeb11.ocx) in Peachtree Accounting 2004 allows remote attackers
28RIESGO
abrir
ReferênciaVexDay Proof
Pilot Group eTraining - 'news_read.php' SQL Injection
CVE-2008-4709webappsphp
SQL injection vulnerability in news_read.php in Pilot Group (PG) eTraining allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
Joovili 3.0 - Multiple SQL Injections
CVE-2008-4711webappsphp
SQL injection vulnerability in Joovili 3.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to ex
23RIESGO
abrir
ReferênciaVexDay Proof
212Cafe Board 0.07 - 'qID' SQL Injection
CVE-2008-4713webappsphp
SQL injection vulnerability in view.php in 212cafe Board 0.07 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
PHP-Lance 1.52 - 'catid' SQL Injection
CVE-2008-4716webappsphp
SQL injection vulnerability in show.php in BitmixSoft PHP-Lance 1.52 allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir
ReferênciaVexDay Proof
Post Comments 3.0 - Insecure Cookie Handling
CVE-2008-4721webappsphp
PHP Jabbers Post Comment 3.0 allows remote attackers to bypass authentication and gain administrative access by setting
23RIESGO
abrir
ReferênciaVexDay Proof
Opera 9.60 - Persistent Cross-Site Scripting
CVE-2008-4725remotewindows
Cross-site scripting (XSS) vulnerability in Opera.dll in Opera 9.52 allows remote attackers to inject arbitrary web scri
23RIESGO
abrir
ReferênciaVexDay Proof
Aardvark Topsites PHP 4.2.2 - 'path' Remote File Inclusion
CVE-2006-7026webappsphp
PHP remote file inclusion vulnerability in sources/join.php in Aardvark Topsites PHP 4.2.2 and earlier, when register_gl
23RIESGO
abrir
ReferênciaVexDay Proof
QuickTalk forum 1.3 - 'lang' Local File Inclusion
CVE-2007-3505webappsphp
Multiple directory traversal vulnerabilities in QuickTalk forum 1.3 allow remote attackers to include and execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
PlugSpace 0.1 - 'navi' Local File Inclusion
CVE-2008-4739webappsphp
Directory traversal vulnerability in index.php in PlugSpace 0.1, when magic_quotes_gpc is disabled, allows remote attack
23RIESGO
abrir
ReferênciaVexDay Proof
Somery 0.4.6 - 'skin_dir' Remote File Inclusion
CVE-2006-4669webappsphp
PHP remote file inclusion vulnerability in admin/system/include.php in Somery 0.4.6 and earlier, when register_globals i
23RIESGO
abrir
ReferênciaVexDay Proof
Acidcat CMS 3.4.1 - Multiple Vulnerabilities
CVE-2008-1992webappsphp
Acidcat CMS 3.4.1 does not properly restrict access to (1) default_mail_aspemail.asp, (2) default_mail_cdosys.asp or (3)
23RIESGO
abrir
ReferênciaVexDay Proof
RPG.Board 0.0.8Beta2 - 'showtopic' SQL Injection
CVE-2008-4736webappsphp
SQL injection vulnerability in index.php in RPG.Board 0.8 Beta2 and earlier allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
EZ Publish < 3.9.5/3.10.1/4.0.1 - Privilege Escalation
CVE-2008-6844webappsphp
The registration view (/user/register) in eZ Publish 3.5.6 and earlier, and possibly other versions before 3.9.5, 3.10.1
23RIESGO
abrir
ReferênciaVexDay Proof
eNdonesia 8.4 - '/mod.php/friend.php/admin.php' Multiple Vulnerabilities
CVE-2006-6872webappsphp
Directory traversal vulnerability in mod.php in eNdonesia 8.4 allows remote attackers to read arbitrary files via a .. (
23RIESGO
abrir
ReferênciaVexDay Proof
Open Azimyt CMS 0.22 - 'lang' Local File Inclusion
CVE-2008-2820webappsphp
Directory traversal vulnerability in lang/lang-system.php in Open Azimyt CMS 0.22 minimal and 0.21 stable allows remote
23RIESGO
abrir
ReferênciaVexDay Proof
RoseOnlineCMS 3 beta2 - 'op' Local File Inclusion
CVE-2007-1636webappsphp
Directory traversal vulnerability in index.php in RoseOnlineCMS 3 B1 allows remote attackers to include arbitrary files
23RIESGO
abrir
ReferênciaVexDay Proof
Sepcity Classified - 'ID' SQL Injection
CVE-2008-6157webappsasp
SepCity Classified Ads stores the admin password in cleartext in data/classifieds.mdb, which allows context-dependent at
23RIESGO
abrir
ReferênciaVexDay Proof
Eudora 7.1 - SMTP ResponseRemote Remote Buffer Overflow
CVE-2007-2770remotewindows
Stack-based buffer overflow in Eudora 7.1 allows user-assisted, remote SMTP servers to execute arbitrary code via a long
23RIESGO
abrir
ReferênciaVexDay Proof
OZJournals 2.1.1 - 'id' File Disclosure
CVE-2008-0435webappsphp
Directory traversal vulnerability in index.php in OZJournals 2.1.1 allows remote attackers to read portions of arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
Newswriter SW 1.42 - 'editfunc.inc.php' File Inclusion
CVE-2006-5102webappsphp
PHP remote file inclusion vulnerability in include/editfunc.inc.php in Sebastian Baumann and Philipp Wolfer Newswriter S
23RIESGO
abrir
ReferênciaVexDay Proof
MG-SOFT Net Inspector 6.5.0.828 - Multiple Vulnerabilities
CVE-2008-1400remotewindows
Directory traversal vulnerability in the Net Inspector HTTP Server (mghttpd) in MG-SOFT Net Inspector 6.5.0.828 and earl
23RIESGO
abrir
ReferênciaVexDay Proof
gelato CMS 0.95 - 'img' Remote File Disclosure
CVE-2008-3675webappsphp
Directory traversal vulnerability in classes/imgsize.php in Gelato 0.95 allows remote attackers to read arbitrary files
23RIESGO
abrir
anteriorpágina 136 / 188siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.