Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
VWar 1.5.0 R15 - 'mvcw.php' Remote File Inclusion
CVE-2007-4605webappsphp
PHP remote file inclusion vulnerability in convert/mvcw.php in Virtual War (VWar) 1.5.0 R15 and earlier allows remote at
23RIESGO
abrir
ReferênciaVexDay Proof
PHPMyRing 4.2.0 - 'view_com.php' SQL Injection
CVE-2006-4114webappsphp
SQL injection vulnerability in view_com.php in Nicolas Grandjean PHPMyRing 4.2.0 and earlier allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
phpBB Ajax Shoutbox 0.0.5 - Remote File Inclusion
CVE-2006-5312webappsphp
PHP remote file inclusion vulnerability in shoutbox.php in the Ajax Shoutbox 0.0.5 and earlier module for phpBB allows r
23RIESGO
abrir
ReferênciaVexDay Proof
Uebimiau Web-Mail 2.7.10/2.7.2 - Remote File Disclosure
CVE-2008-0210webappsphp
Uebimiau Webmail 2.7.10 and 2.7.2 does not protect authentication state variables from being set through HTTP requests,
23RIESGO
abrir
ReferênciaVexDay Proof
zFeeder 1.6 - 'admin.php' Admin Bypass
CVE-2009-0807webappsphp
zFeeder 1.6 allows remote attackers to gain administrative access via a direct request to admin.php.
23RIESGO
abrir
ReferênciaVexDay Proof
Ad Manager Pro 2.6 - 'ipath' Remote File Inclusion
CVE-2006-3192webappsphp
PHP remote file inclusion vulnerability in Ad Manager Pro 2.6 allows remote attackers to execute arbitrary PHP code via
23RIESGO
abrir
ReferênciaVexDay Proof
LulieBlog 1.0.1 - Remote Authentication Bypass
CVE-2008-0329webappsphp
LulieBlog 1.0.1 and 1.0.2 does not restrict access to (1) article_suppr.php, (2) comment_accepter.php, and (3) comment_r
23RIESGO
abrir
ReferênciaVexDay Proof
DesktopOnNet 3 Beta - Multiple Remote File Inclusions
CVE-2008-2649webappsphp
Multiple PHP remote file inclusion vulnerabilities in DesktopOnNet 3 Beta allow remote attackers to execute arbitrary PH
23RIESGO
abrir
ReferênciaVexDay Proof
Avlc Forum - 'vlc_forum.php' SQL Injection
CVE-2008-3200webappsphp
SQL injection vulnerability in vlc_forum.php in Avlc Forum as of 20080715 allows remote attackers to execute arbitrary S
23RIESGO
abrir
ReferênciaVexDay Proof
AuraCMS 2.2.2 - '/pages_data.php' Arbitrary Edit/Add/Delete
CVE-2008-3203webappsphp
js/pages/pages_data.php in AuraCMS 2.2 through 2.2.2 does not perform authentication, which allows remote attackers to a
23RIESGO
abrir
ReferênciaVexDay Proof
Million Pixels 3 - 'id_cat' SQL Injection
CVE-2008-3204webappsphp
SQL injection vulnerability in tops_top.php in E-topbiz Million Pixels 3 allows remote attackers to execute arbitrary SQ
23RIESGO
abrir
ReferênciaVexDay Proof
HRS Multi - 'key' Blind SQL Injection
CVE-2008-3266webappsasp
SQL injection vulnerability in picture_pic_bv.asp in SoftAcid Hotel Reservation System (HRS) Multi allows remote attacke
23RIESGO
abrir
ReferênciaVexDay Proof
Voodoo chat 1.0RC1b - 'users.dat' Password Disclosure
CVE-2006-6890webappsphp
Voodoo chat 1.0RC1b stores sensitive information under the web root with insufficient access control, which allows remot
23RIESGO
abrir
ReferênciaVexDay Proof
Prozilla Cheat Script 2.0 - 'id' SQL Injection
CVE-2008-1863webappsphp
SQL injection vulnerability in view_reviews.php in Prozilla Cheat Script (aka Cheats) 2.0 allows remote attackers to exe
23RIESGO
abrir
ReferênciaVexDay Proof
Ultrastats 0.2.142 - 'players-detail.php' Blind SQL Injection
CVE-2008-3241webappsphp
SQL injection vulnerability in players-detail.php in UltraStats 0.2.136, 0.2.140, and 0.2.142 allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
OpenSSL 0.9.8c-1 < 0.9.8g-9 (Debian and Derivatives) - Predictable PRNG Brute Force SSH
CVE-2008-3280remotelinux
It was found that various OpenID Providers (OPs) had TLS Server Certificates that used weak keys, as a result of the Deb
23RIESGO
abrir
ReferênciaVexDay Proof
ASP Portal - Multiple SQL Injections
CVE-2008-5605webappsasp
Multiple SQL injection vulnerabilities in ASP Portal allow remote attackers to execute arbitrary SQL commands via the (1
23RIESGO
abrir
ReferênciaVexDay Proof
Pligg 9.9.5b - Arbitrary File Upload / SQL Injection
CVE-2008-5739webappsphp
SQL injection vulnerability in evb/check_url.php in Pligg CMS 9.9.5 Beta allows remote attackers to execute arbitrary SQ
23RIESGO
abrir
ReferênciaVexDay Proof
k-rate - SQL Injection / Cross-Site Scripting
CVE-2008-7097webappsphp
Multiple SQL injection vulnerabilities in Qsoft K-Rate Premium allow remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
2DayBiz Template Monster Clone - 'edituser.php' Change Pass
CVE-2009-1767webappsphp
admin/edituser.php in 2daybiz Template Monster Clone does not require administrative authentication, which allows remote
23RIESGO
abrir
ReferênciaVexDay Proof
NukeSentinel 2.5.05 - 'nsbypass.php' Blind SQL Injection
CVE-2007-1171webappsphp
SQL injection vulnerability in includes/nsbypass.php in NukeSentinel 2.5.05, 2.5.11, and other versions before 2.5.12 al
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component PU Arcade 2.1.3 - SQL Injection
CVE-2007-6663webappsphp
SQL injection vulnerability in (1) Puarcade.php and (2) PUarcade.html.php in Pragmatic Utopia PU Arcade (com_puarcade) 2
23RIESGO
abrir
ReferênciaVexDay Proof
Alstrasoft Forum Pay Per Post Exchange 2.0 - SQL Injection
CVE-2008-0440webappsphp
AlstraSoft Forum Pay Per Post Exchange 2.0 stores passwords in cleartext, which makes it easier for attackers to access
23RIESGO
abrir
ReferênciaVexDay Proof
DeluxeBB 1.2 - Multiple Vulnerabilities
CVE-2008-2195webappsphp
Static code injection vulnerability in admincp.php in DeluxeBB 1.2 and earlier allows remote authenticated administrator
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component iDoBlog b24 - SQL Injection
CVE-2008-2627webappsphp
SQL injection vulnerability in the IDoBlog (com_idoblog) component b24 and earlier and 1.0, a component for Joomla!, all
23RIESGO
abrir
ReferênciaVexDay Proof
Post Affiliate Pro 2.0 - 'md' Local File Inclusion
CVE-2008-4602webappsphp
Directory traversal vulnerability in index.php in Post Affiliate Pro 2.0 allows remote authenticated users to read and p
23RIESGO
abrir
ReferênciaVexDay Proof
PHPcounter 1.3.2 - 'defs.php' Local File Inclusion
CVE-2008-5989webappsphp
Directory traversal vulnerability in defs.php in PHPcounter 1.3.2 and earlier, when magic_quotes_gpc is disabled, allows
23RIESGO
abrir
ReferênciaVexDay Proof
PHPmyGallery 1.0beta2 - Local/Remote File Inclusion
CVE-2008-6315webappsphp
PHP remote file inclusion vulnerability in _conf/core/common-tpl-vars.php in PHPmyGallery 1.0 beta2 allows remote attack
23RIESGO
abrir
ReferênciaVexDay Proof
PHPmyGallery 1.5beta - '/common-tpl-vars.php' Local/Remote File Inclusion
CVE-2008-6318webappsphp
PHP remote file inclusion vulnerability in _conf/_php-core/common-tpl-vars.php in PHPmyGallery 1.5 beta allows remote at
23RIESGO
abrir
ReferênciaVexDay Proof
CMSbright - 'id_rub_page' SQL Injection
CVE-2008-6991webappsphp
SQL injection vulnerability in public/page.php in Websens CMSbright allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
anteriorpágina 160 / 188siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.