Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
PixelPost 1.7.1 - 'language_full' Local File Inclusion
CVE-2008-3365webappsphp
Directory traversal vulnerability in index.php in Pixelpost 1.7.1 on Windows, when register_globals is enabled, allows r
23RIESGO
abrir
ReferênciaVexDay Proof
XOOPS myAds Module - 'lid' SQL Injection
CVE-2006-3341webappsphp
SQL injection vulnerability in annonces-p-f.php in MyAds module 2.04jp for Xoops allows remote attackers to execute arbi
23RIESGO
abrir
ReferênciaVexDay Proof
Censura 1.15.04 - 'censura.php?vendorid' SQL Injection
CVE-2007-2673webappsphp
SQL injection vulnerability in includes/funcs_vendors.php in Censura 1.15.04, and other versions before 1.16.04, allows
23RIESGO
abrir
ReferênciaVexDay Proof
Pre Classifieds Listings 1.0 - SQL Injection
CVE-2007-2675webappsphp
SQL injection vulnerability in search.php in Pre Classifieds Listings 1.0 allows remote attackers to execute arbitrary S
23RIESGO
abrir
ReferênciaVexDay Proof
TalkBack 2.3.5 - 'Language' Local File Inclusion
CVE-2008-3371webappsphp
Directory traversal vulnerability in install/help.php in TalkBack 2.3.5, and other versions before 2.3.6.2, allows remot
23RIESGO
abrir
ReferênciaVexDay Proof
Gregarius 0.5.4 - SQL Injection
CVE-2008-3374webappsphp
SQL injection vulnerability in ajax.php in Gregarius 0.5.4 and earlier allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
Open Translation Engine (OTE) 0.7.8 - 'header.php?ote_home' Remote File Inclusion
CVE-2007-2676webappsphp
PHP remote file inclusion vulnerability in skins/header.php in Open Translation Engine (OTE) 0.7.8 allows remote attacke
35RIESGO
abrir
ReferênciaVexDay Proof
Microsoft SQL Server - 'sp_replwritetovarbin()' Heap Overflow
CVE-2008-5416localwindows
Heap-based buffer overflow in Microsoft SQL Server 2000 SP4, 8.00.2050, 8.00.2039, and earlier; SQL Server 2000 Desktop
60RIESGO
abrir
ReferênciaVexDay Proof
PHPTest 0.6.3 - SQL Injection
CVE-2008-3377webappsphp
SQL injection vulnerability in picture.php in phpTest 0.6.3 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir
ReferênciaVexDay Proof
linksnet newsfeed 1.0 - Remote File Inclusion
CVE-2007-2707webappsphp
PHP remote file inclusion vulnerability in linksnet_linkslog_rss.php in Linksnet Newsfeed 1.0 allows remote attackers to
35RIESGO
abrir
ReferênciaVexDay Proof
SAP MaxDB 7.6.03.07 - Remote Command Execution
CVE-2008-0244remotemultiple
SAP MaxDB 7.6.03 build 007 and earlier allows remote attackers to execute arbitrary commands via "&&" and other shell me
60RIESGO
abrir
ReferênciaVexDay Proof
WEBalbum 2.4b - 'id' Blind SQL Injection
CVE-2009-0446webappsphp
SQL injection vulnerability in photo.php in WEBalbum 2.4b allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
ReferênciaVexDay Proof
MojoAuto - Blind SQL Injection
CVE-2008-3383webappscgi
SQL injection vulnerability in mojoAuto.cgi in MojoAuto allows remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir
ReferênciaVexDay Proof
Alstrasoft Video Share Enterprise 4.5.1 - 'UID' SQL Injection
CVE-2008-3386webappsphp
SQL injection vulnerability in album.php in AlstraSoft Video Share Enterprise 4.51 allows remote attackers to execute ar
23RIESGO
abrir
ReferênciaVexDay Proof
XRms 1.99.2 - Remote File Inclusion / Cross-Site Scripting / Information Gathering
CVE-2008-3400webappsphp
XRMS CRM 1.99.2 allows remote attackers to obtain configuration information via a direct request to tests/info.php, whic
23RIESGO
abrir
ReferênciaVexDay Proof
XRms 1.99.2 - Remote File Inclusion / Cross-Site Scripting / Information Gathering
CVE-2008-3398webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in XRMS CRM 1.99.2 allow remote attackers to inject arbitrary web sc
23RIESGO
abrir
ReferênciaVexDay Proof
Alstrasoft Live Support 1.21 - Admin Credential Retrieve
CVE-2007-2775webappsphp
AlstraSoft Live Support 1.21 sends a redirect to the web browser but does not exit when administrative credentials are m
23RIESGO
abrir
ReferênciaVexDay Proof
Euphonics Audio Player 1.0 (Windows XP SP3) - '.pls' Local Buffer Overflow
CVE-2009-0476localwindows
Stack-based buffer overflow in MultiMedia Soft AdjMmsEng.dll 7.11.1.0 and 7.11.2.7, as distributed in multiple MultiMedi
50RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Windows Message Queuing Service - RPC Buffer Overflow (MS07-065) (1)
CVE-2007-3039remotewindows
Stack-based buffer overflow in the Microsoft Message Queuing (MSMQ) service in Microsoft Windows 2000 Server SP4, Window
50RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Windows Message Queuing Service - RPC Buffer Overflow (MS07-065) (2)
CVE-2007-3039remotewindows
Stack-based buffer overflow in the Microsoft Message Queuing (MSMQ) service in Microsoft Windows 2000 Server SP4, Window
50RIESGO
abrir
ReferênciaVexDay Proof
MojoPersonals - Blind SQL Injection
CVE-2008-3403webappscgi
SQL injection vulnerability in mojoClassified.cgi in MojoPersonals allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
ReferênciaVexDay Proof
phpLinkat 0.1 - Insecure Cookie Handling / SQL Injection
CVE-2008-3406webappsphp
SQL injection vulnerability in showcat.php in phpLinkat 0.1 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir
ReferênciaVexDay Proof
CoolPlayer 2.18 - '.m3u' File Local Buffer Overflow
CVE-2008-3408localwindows
Stack-based buffer overflow in CoolPlayer 2.18, and possibly other versions, allows user-assisted remote attackers to ex
23RIESGO
abrir
ReferênciaVexDay Proof
EPShop < 3.0 - 'pid' SQL Injection
CVE-2008-3412webappsphp
SQL injection vulnerability in Comsenz EPShop (aka ECShop) before 3.0 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
ReferênciaVexDay Proof
Alstrasoft Template Seller Pro 3.25 - Remote Code Execution
CVE-2007-2777webappsphp
Unrestricted file upload vulnerability in admin/addsptemplate.php in AlstraSoft Template Seller Pro 3.25 and earlier all
23RIESGO
abrir
ReferênciaVexDay Proof
Libstats 1.0.3 - 'template_csv.php' Remote File Inclusion
CVE-2007-2779webappsphp
PHP remote file inclusion vulnerability in template_csv.php in Libstats 1.0.3 and earlier allows remote attackers to exe
23RIESGO
abrir
ReferênciaVexDay Proof
Squid < 3.1 5 - HTTP Version Number Parsing Denial of Service
CVE-2009-0478dosmultiple
Squid 2.7 to 2.7.STABLE5, 3.0 to 3.0.STABLE12, and 3.1 to 3.1.0.4 allows remote attackers to cause a denial of service v
45RIESGO
abrir
ReferênciaVexDay Proof
Audacity 1.2.6 - '.gro' Local Buffer Overflow (PoC)
CVE-2009-0490doswindows
Stack-based buffer overflow in the String_parse::get_nonspace_quoted function in lib-src/allegro/strparse.cpp in Audacit
28RIESGO
abrir
ReferênciaVexDay Proof
IceBB 1.0-RC9.2 - Blind SQL Injection / Session Hijacking
CVE-2008-3416webappsphp
SQL injection vulnerability in modules/members.php in IceBB before 1.0-rc9.3 allows remote attackers to execute arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
FipsCMS Light 2.1 - 'r' SQL Injection
CVE-2008-3417webappsasp
SQL injection vulnerability in home/index.asp in fipsCMS light 2.1 and earlier allows remote attackers to execute arbitr
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.