Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
exV2 < 2.0.4.3 - 'extract()' Remote Command Execution
CVE-2006-7080webappsphp
Directory traversal vulnerability in the avatar upload feature in exV2 2.0.4.3 and earlier allows remote attackers to de
23RIESGO
abrir
ReferênciaVexDay Proof
Simple Machines Forum (SMF) 1.1.5 (Windows x86) - Admin Reset Password
CVE-2008-6971webappsphp
The password reset functionality in Simple Machines Forum (SMF) 1.0.x before 1.0.14, 1.1.x before 1.1.6, and 2.0 before
23RIESGO
abrir
ReferênciaVexDay Proof
Michelles L2J Dropcalc 4 - SQL Injection
CVE-2007-0687webappsphp
SQL injection vulnerability in i-search.php in Michelle's L2J Dropcalc 4 and earlier allows remote authenticated users t
23RIESGO
abrir
ReferênciaVexDay Proof
phpBB ezBoard Converter 0.2 - 'ezconvert_dir' Remote File Inclusion
CVE-2007-0761webappsphp
PHP remote file inclusion vulnerability in config.php in phpBB ezBoard converter (ezconvert) 0.2 allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
phpBB++ Build 100 - 'phpbb_root_path' Remote File Inclusion
CVE-2007-0762webappsphp
PHP remote file inclusion vulnerability in includes/functions.php in phpBB++ Build 100 allows remote attackers to execut
23RIESGO
abrir
ReferênciaVexDay Proof
Cisco IP Phone 7940 - Reboot (Denial of Service)
CVE-2006-0179doshardware
The Cisco IP Phone 7940 allows remote attackers to cause a denial of service (reboot) via a large amount of TCP SYN pack
28RIESGO
abrir
ReferênciaVexDay Proof
Ultimate HelpDesk - Cross-Site Scripting / Local File Disclosure
CVE-2006-6380webappsasp
Cross-site scripting (XSS) vulnerability in index.asp in Ultimate HelpDesk allows remote attackers to inject arbitrary w
23RIESGO
abrir
ReferênciaVexDay Proof
Linksys SPA941 - Remote Reboot (Denial of Service)
CVE-2007-2270doshardware
The Linksys SPA941 VoIP Phone allows remote attackers to cause a denial of service (device reboot) via a 0377 (0xff) cha
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Windows - GDI+ '.ICO' File Remote Denial of Service
CVE-2007-2237doswindows
Microsoft Windows Graphics Device Interface (GDI+, GdiPlus.dll) allows context-dependent attackers to cause a denial of
28RIESGO
abrir
ReferênciaVexDay Proof
USP FOSS Distribution 1.01 - 'dnld' Remote File Disclosure
CVE-2007-2271webappsphp
Directory traversal vulnerability in Rajneel Lal TotaRam USP FOSS Distribution 1.01 allows remote attackers to read arbi
23RIESGO
abrir
ReferênciaVexDay Proof
WebCalendar 1.2.4 - Remote Code Execution
CVE-2012-1495webappsphp
install/index.php in WebCalendar before 1.2.5 allows remote attackers to execute arbitrary code via the form_single_user
60RIESGO
abrir
ReferênciaVexDay Proof
TinyIdentD 2.2 - Remote Buffer Overflow
CVE-2007-2711remotewindows
Stack-based buffer overflow in TinyIdentD 2.2 and earlier allows remote attackers to execute arbitrary code via a long s
50RIESGO
abrir
ReferênciaVexDay Proof
NewzCrawler 1.8 - invalid string Remote Denial of Service
CVE-2007-2722doswindows
Unspecified vulnerability in NewzCrawler 1.8 allows remote attackers to cause a denial of service (application instabili
23RIESGO
abrir
ReferênciaVexDay Proof
Sun Board 1.00.00 alpha - Remote File Inclusion
CVE-2007-3370webappsphp
Multiple PHP remote file inclusion vulnerabilities in Sun Board 1.00.00 Alpha allow remote attackers to execute arbitrar
45RIESGO
abrir
ReferênciaVexDay Proof
FrontAccounting 1.12 build 31 - Remote File Inclusion
CVE-2007-4279webappsphp
PHP remote file inclusion vulnerability in config.php in FrontAccounting 1.12 Build 31 allows remote attackers to execut
45RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component Nice Talk 0.9.3 - 'tagid' SQL Injection
CVE-2007-4503webappsphp
SQL injection vulnerability in index.php in the Nice Talk component (com_nicetalk) 0.9.3 and earlier for Joomla! allows
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component NeoRecruit 1.4 - 'id' SQL Injection
CVE-2007-4506webappsphp
SQL injection vulnerability in index.php in the NeoRecruit component (com_neorecruit) 1.4 and earlier for Joomla! allows
23RIESGO
abrir
ReferênciaVexDay Proof
SunShop Shopping Cart 4.0 RC 6 - 'Search' Blind SQL Injection
CVE-2007-4597webappsphp
SQL injection vulnerability in index.php in TurnkeyWebTools SunShop Shopping Cart 4.0 RC 6 allows remote attackers to ex
23RIESGO
abrir
ReferênciaVexDay Proof
NuclearBB Alpha 2 - 'ROOT_PATH' Remote File Inclusion
CVE-2007-4906webappsphp
PHP remote file inclusion vulnerability in tasks/send_queued_emails.php in NuclearBB Alpha 2, when register_globals is e
35RIESGO
abrir
ReferênciaVexDay Proof
JetCast Server 2.0.0.4308 - Remote Denial of Service
CVE-2007-4911doswindows
JSMP3OGGWt.dll in JetCast Server 2.0.0.4308 allows remote attackers to cause a denial of service (daemon crash) via a lo
23RIESGO
abrir
ReferênciaVexDay Proof
KwsPHP 1.0 sondages Module - SQL Injection
CVE-2007-4979webappsphp
SQL injection vulnerability in index.php in the sondages module in KwsPHP 1.0 allows remote attackers to execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
MW6 Technologies QRCode ActiveX 3.0 - Remote File Overwrite
CVE-2007-4982remotewindows
Multiple absolute path traversal vulnerabilities in the MW6QRCode.QRCode.1 ActiveX control in MW6QRCode.dll in MW6 Techn
28RIESGO
abrir
ReferênciaVexDay Proof
PhFiTo 1.3.0 - 'SRC_PATH' Remote File Inclusion
CVE-2007-5157webappsphp
PHP remote file inclusion vulnerability in phfito-post.php in Alex Kocharin PHP Fidonet Tosser (PhFiTo) 1.3.0 in phpFido
23RIESGO
abrir
ReferênciaVexDay Proof
Winamp 5.12 - '.pls' Remote Buffer Overflow (Perl) (2)
CVE-2006-0476remotewindows
Buffer overflow in Nullsoft Winamp 5.12 allows remote attackers to execute arbitrary code via a playlist (pls) file with
60RIESGO
abrir
ReferênciaVexDay Proof
ProfileCMS 1.0 - Arbitrary File Upload
CVE-2007-5720webappsphp
Unrestricted file upload vulnerability in the profiles script in ProfileCMS 1.0 allows remote attackers to upload and ex
23RIESGO
abrir
ReferênciaVexDay Proof
jPORTAL 2.3.1 - 'articles.php' SQL Injection
CVE-2007-5973webappsphp
SQL injection vulnerability in articles.php in JPortal 2.3.1 and earlier allows remote attackers to execute arbitrary SQ
23RIESGO
abrir
ReferênciaVexDay Proof
WebPortal CMS 0.6-beta - Remote Password Change
CVE-2008-0142webappsphp
Multiple SQL injection vulnerabilities in WebPortal CMS 0.6-beta allow remote attackers to execute arbitrary SQL command
23RIESGO
abrir
ReferênciaVexDay Proof
SmallNuke 2.0.4 - Pass Recovery SQL Injection
CVE-2008-0147webappsphp
SQL injection vulnerability in index.php in SmallNuke 2.0.4 and earlier, when magic_quotes_gpc is disabled, allows remot
23RIESGO
abrir
ReferênciaVexDay Proof
TUTOS 1.3 - 'cmd.php' Remote Command Execution
CVE-2008-0149webappsphp
TUTOS 1.3 allows remote attackers to read system information via a direct request to php/admin/phpinfo.php, which calls
23RIESGO
abrir
ReferênciaVexDay Proof
Xforum 1.4 - 'topic' SQL Injection
CVE-2008-0279webappsphp
SQL injection vulnerability in liretopic.php in Xforum 1.4 and possibly others allows remote attackers to execute arbitr
23RIESGO
abrir
anteriorpágina 179 / 188siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.