Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
Hummingbird Deployment Wizard 2008 - Registry Values Creation/Change
CVE-2008-4728remotewindows
Multiple insecure method vulnerabilities in the DeployRun.DeploymentSetup.1 (DeployRun.dll) ActiveX control 10.0.0.44 in
35RIESGO
abrir
ReferênciaVexDay Proof
Hummingbird 13.0 - ActiveX Remote Buffer Overflow (PoC)
CVE-2008-4729doswindows
Stack-based buffer overflow in Hummingbird.XWebHostCtrl.1 ActiveX control (hclxweb.dll) in Hummingbird Xweb ActiveX Cont
23RIESGO
abrir
ReferênciaVexDay Proof
WordPress Plugin WP Comment Remix 1.4.3 - SQL Injection
CVE-2008-4732webappsphp
SQL injection vulnerability in ajax_comments.php in the WP Comment Remix plugin before 1.4.4 for WordPress allows remote
23RIESGO
abrir
ReferênciaVexDay Proof
1st News - SQL Injection
CVE-2008-4890webappsphp
SQL injection vulnerability in products.php in 1st News 4 Professional (PR 1) allows remote attackers to execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
YourFreeWorld Downline Builder - 'tr.php' SQL Injection
CVE-2008-4895webappsphp
SQL injection vulnerability in tr.php in YourFreeWorld Downline Builder allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
ZeusCart 2.0 - 'category_list.php' SQL Injection
CVE-2008-5216webappsphp
SQL injection vulnerability in category_list.php in AJ Square ZeusCart 2.0 and earlier allows remote attackers to execut
23RIESGO
abrir
ReferênciaVexDay Proof
FREEze Greetings 1.0 - Remote Password Retrieve
CVE-2008-5218webappsphp
ScriptsEz FREEze Greetings 1.0 stores pwd.txt under the web root with insufficient access control, which allows remote a
23RIESGO
abrir
ReferênciaVexDay Proof
wPortfolio 0.3 - Admin Password Changing
CVE-2008-5221webappsphp
The account_save action in admin/userinfo.php in wPortfolio 0.3 and earlier does not require authentication and does not
23RIESGO
abrir
ReferênciaVexDay Proof
AirvaeCommerce 3.0 - 'pid' SQL Injection
CVE-2008-5223webappsphp
SQL injection vulnerability in index.php in Airvae Commerce 3.0 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
ReferênciaVexDay Proof
TNT Forum 0.9.4 - Local File Inclusion
CVE-2008-5265webappsphp
Directory traversal vulnerability in index.php in TNT Forum 0.9.4, when magic_quotes_gpc is disabled, allows remote atta
23RIESGO
abrir
ReferênciaVexDay Proof
Clean CMS 1.5 - Blind SQL Injection
CVE-2008-5289webappsphp
SQL injection vulnerability in full_txt.php in Werner Hilversum Clean CMS 1.5 allows remote attackers to execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
BitDefender - Module pdf.xmd Infinite Loop Denial of Service (PoC)
CVE-2008-5409doswindows
Unspecified vulnerability in the pdf.xmd module in (1) BitDefender Free Edition 10 and Antivirus Standard 10, (2) BullGu
28RIESGO
abrir
ReferênciaVexDay Proof
yahoo answers - 'id' SQL Injection
CVE-2008-5490webappsphp
SQL injection vulnerability in index.php in PHPStore Yahoo Answers allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
ReferênciaVexDay Proof
SlimCMS 1.0.0 - 'edit.php' SQL Injection
CVE-2008-5491webappsphp
SQL injection vulnerability in edit.php in SlimCMS 1.0.0 and earlier allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir
ReferênciaVexDay Proof
VeryPDF PDFView - OCX ActiveX OpenPDF Heap Overflow (PoC)
CVE-2008-5492doswindows
Heap-based buffer overflow in the PDFVIEW.PdfviewCtrl.1 ActiveX control in pdfview.ocx 2.0.0.1 in VeryDOC PDF Viewer OCX
50RIESGO
abrir
ReferênciaVexDay Proof
Merlix Teamworx Server - File Disclosure/Bypass
CVE-2008-5600webappsphp
Merlix Teamworx Server stores sensitive information under the web root with insufficient access control, which allows re
23RIESGO
abrir
ReferênciaVexDay Proof
A-Blog 2.0 - Multiple Remote File Inclusions
CVE-2006-5135webappsphp
Multiple PHP remote file inclusion vulnerabilities in A-Blog 2 allow remote attackers to execute arbitrary PHP code via
23RIESGO
abrir
ReferênciaVexDay Proof
User Engine Lite ASP - 'users.mdb' Database Disclosure
CVE-2008-5601webappsphp
User Engine Lite ASP stores sensitive information under the web root with insufficient access control, which allows remo
23RIESGO
abrir
ReferênciaVexDay Proof
Natterchat 1.12 - Database Disclosure
CVE-2008-5602webappsasp
Natterchat 1.12 stores sensitive information under the web root with insufficient access control, which allows remote at
23RIESGO
abrir
ReferênciaVexDay Proof
ASPTicker 1.0 - Remote Database Disclosure
CVE-2008-5603webappsasp
ASPTicker 1.0 stores sensitive information under the web root with insufficient access control, which allows remote atta
23RIESGO
abrir
ReferênciaVexDay Proof
BulletProof FTP Client 2009 - '.bps' Local Buffer Overflow (SEH)
CVE-2008-5754localwindows
Stack-based buffer overflow in BulletProof FTP Client allows user-assisted attackers to execute arbitrary code via a .bp
23RIESGO
abrir
ReferênciaVexDay Proof
IntelliTamper 2.07/2.08 - '.map' Local Overwrite (SEH)
CVE-2008-5755localwindows
Stack-based buffer overflow in IntelliTamper 2.07 and 2.08 allows remote attackers to execute arbitrary code via a MAP f
23RIESGO
abrir
ReferênciaVexDay Proof
ASPired2Quote - Remote Database Disclosure
CVE-2008-5885webappsasp
The Net Guys ASPired2Quote stores sensitive information under the web root with insufficient access control, which allow
23RIESGO
abrir
ReferênciaVexDay Proof
Discussion Web 4 - Remote Database Disclosure
CVE-2008-5886webappsasp
TAKempis Discussion Web 4.0 stores sensitive information under the web root with insufficient access control, which allo
23RIESGO
abrir
ReferênciaVexDay Proof
Mambo Component com_registration_detailed 4.1 - Remote File Inclusion
CVE-2006-5254webappsphp
PHP remote file inclusion vulnerability in registration_detailed.inc.php in Mark Van Bellen Detailed User Registration (
23RIESGO
abrir
ReferênciaVexDay Proof
Click&Rank - SQL Injection / Cross-Site Scripting
CVE-2008-5888webappsasp
Multiple SQL injection vulnerabilities in Click&Rank allow remote attackers to execute arbitrary SQL commands via the id
23RIESGO
abrir
ReferênciaVexDay Proof
4Images 1.7.x - 'search.php' SQL Injection
CVE-2006-5236webappsphp
SQL injection vulnerability in search.php in 4images 1.7.x allows remote authenticated users to execute arbitrary SQL co
23RIESGO
abrir
ReferênciaVexDay Proof
CodeAvalanche Directory - Database Disclosure
CVE-2008-5898webappsasp
CodeAvalanche Directory stores sensitive information under the web root with insufficient access control, which allows r
23RIESGO
abrir
ReferênciaVexDay Proof
CodeAvalanche FreeForAll - Database Disclosure
CVE-2008-5899webappsasp
CodeAvalanche FreeForAll stores sensitive information under the web root with insufficient access control, which allows
23RIESGO
abrir
ReferênciaVexDay Proof
Claroline 1.8.0 rc1 - 'import.lib.php' Remote File Inclusion
CVE-2006-5256webappsphp
PHP remote file inclusion vulnerability in claroline/inc/lib/import.lib.php in Claroline 1.8.0 and earlier allows remote
23RIESGO
abrir
anteriorpágina 178 / 188siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.