Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.954exploits catalogados
36.205CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
WebCMS Portal Edition - 'id' Blind SQL Injection
CVE-2008-4185webappsphp
SQL injection vulnerability in index.php in webCMS Portal Edition allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir
ReferênciaVexDay Proof
Harlandscripts Pro Traffic One - 'mypage.php' SQL Injection
CVE-2008-6213webappsphp
SQL injection vulnerability in mypage.php in Harlandscripts Pro Traffic One allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
Simple Document Management System 1.1.4 - Authentication Bypass
CVE-2008-6220webappsphp
SQL injection vulnerability in login.php in Simple Document Management System (SDMS) 1.1.5 and 1.1.4, and possibly earli
23RIESGO
abrir
ReferênciaVexDay Proof
glFusion 1.1.2 - 'COM_applyFilter()/cookies' Blind SQL Injection
CVE-2009-1282webappsphp
SQL injection vulnerability in private/system/lib-session.php in glFusion 1.1.2 and earlier allows remote attackers to e
23RIESGO
abrir
ReferênciaVexDay Proof
Sitellite CMS 4.2.12 - '559668.php' Remote File Inclusion
CVE-2007-3228webappsphp
PHP remote file inclusion vulnerability in saf/lib/PEAR/PhpDocumentor/Documentation/tests/bug-559668.php in Sitellite CM
35RIESGO
abrir
ReferênciaVexDay Proof
Attachmax Dolphin 2.1.0 - Multiple Vulnerabilities
CVE-2008-4206webappsphp
PHP remote file inclusion vulnerability in config.php in Attachmax Dolphin 2.1.0 and earlier, when register_globals is e
23RIESGO
abrir
ReferênciaVexDay Proof
Attachmax Dolphin 2.1.0 - Multiple Vulnerabilities
CVE-2008-4207webappsphp
Attachmax Dolphin 2.1.0 and earlier does not properly protect info.php in the main folder, which allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
CJ Ultra Plus 1.0.4 - Cookie SQL Injection
CVE-2008-4241webappsphp
SQL injection vulnerability in CJ Ultra Plus 1.0.4 and earlier allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
SNMPc 7.0.18 - Remote Denial of Service (Metasploit)
CVE-2007-3098doswindows
The SNMPc Server (crserv.exe) process in Castle Rock Computing SNMPc before 7.0.19 allows remote attackers to cause a de
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Windows Server - Code Execution (PoC) (MS08-067)
CVE-2008-4250CRITICALbajo ataquedoswindows
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Windows Server - Code Execution (MS08-067)
CVE-2008-4250CRITICALbajo ataqueremotewindows
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Windows Server - Universal Code Execution (MS08-067)
CVE-2008-4250CRITICALbajo ataqueremotewindows
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RIESGO
abrir
ReferênciaVexDay Proof
smcFanControl 2.1.2 (OSX) - Multiple Buffer Overflow Vulnerabilities (PoC)
CVE-2008-6252dososx
Stack-based buffer overflow in the smc program in smcFanControl 2.1.2 allows local users to execute arbitrary code and g
23RIESGO
abrir
ReferênciaVexDay Proof
OpenASP 3.0 - Blind SQL Injection
CVE-2008-6257webappsasp
SQL injection vulnerability in default.asp in Openasp 3.0 and earlier allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
ReferênciaVexDay Proof
Cyberfolio 7.12.2 - 'theme' Local File Inclusion
CVE-2008-6265webappsphp
Directory traversal vulnerability in portfolio/css.php in Cyberfolio 7.12.2 and earlier allows remote attackers to inclu
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Windows Server 2000/2003 - Code Execution (MS08-067)
CVE-2008-4250CRITICALbajo ataqueremotewindows
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Windows Explorer - '.zip' Denial of Service
CVE-2008-4323doswindows
Windows Explorer in Microsoft Windows XP SP3 allows user-assisted attackers to cause a denial of service (application cr
23RIESGO
abrir
ReferênciaVexDay Proof
PHPOCS 0.1-beta3 - 'act' Local File Inclusion
CVE-2008-4331webappsphp
Directory traversal vulnerability in library/pagefunctions.inc.php in phpOCS 0.1 beta3 and earlier allows remote attacke
23RIESGO
abrir
ReferênciaVexDay Proof
PHP infoBoard 7 - Plus Insecure Cookie Handling
CVE-2008-4334webappsphp
PHP infoBoard V.7 Plus allows remote attackers to bypass authentication and gain administrative access by setting the in
23RIESGO
abrir
ReferênciaVexDay Proof
VUPlayer 2.44 - '.m3u' UNC Name Buffer Overflow
CVE-2006-6251localwindows
Stack-based buffer overflow in VUPlayer 2.44 and earlier allows remote attackers to execute arbitrary code via a long st
50RIESGO
abrir
ReferênciaVexDay Proof
Atomic Photo Album 1.1.0pre4 - Blind SQL Injection
CVE-2008-4335webappsphp
SQL injection vulnerability in album.php in Atomic Photo Album (APA) 1.1.0pre4 allows remote attackers to execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
Acc Real Estate 4.0 - Insecure Cookie Handling
CVE-2008-6293webappsphp
admin/Index.php in Acc Real Estate 4.0 allows remote attackers to bypass authentication and gain administrative access b
23RIESGO
abrir
ReferênciaVexDay Proof
Atomic Photo Album 1.1.0pre4 - Cross-Site Scripting / SQL Injection
CVE-2008-4335webappsphp
SQL injection vulnerability in album.php in Atomic Photo Album (APA) 1.1.0pre4 allows remote attackers to execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
Atomic Photo Album 1.1.0pre4 - Cross-Site Scripting / SQL Injection
CVE-2008-4336webappsphp
Cross-site scripting (XSS) vulnerability in album.php in Atomic Photo Album (APA) 1.1.0pre4 allows remote attackers to i
23RIESGO
abrir
ReferênciaVexDay Proof
MyBlog 0.9.8 - Insecure Cookie Handling
CVE-2008-4341webappsphp
add.php in MyBlog 0.9.8 and earlier allows remote attackers to bypass authentication and gain administrative access by s
23RIESGO
abrir
ReferênciaVexDay Proof
TFTP Server for Windows 1.4 - ST Remote BSS Overflow
CVE-2008-2161remotewindows
Buffer overflow in TFTP Server SP 1.4 and 1.5 on Windows, and possibly other versions, allows remote attackers to execut
50RIESGO
abrir
ReferênciaVexDay Proof
pNews 2.03 - 'newsid' SQL Injection
CVE-2008-4347webappsphp
SQL injection vulnerability in newskom.php in Powie pNews 2.03 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
Talkback 2.3.6 - Multiple Local File Inclusion / PHPInfo Disclosure Vulnerabilities
CVE-2008-4346webappsphp
Directory traversal vulnerability in TalkBack 2.3.6 and 2.3.6.4 allows remote attackers to include and execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
Apple Mac OSX - 'mount_smbfs' Local Stack Buffer Overflow
CVE-2007-3876localosx
Stack-based buffer overflow in SMB in Apple Mac OS X 10.4.11 allows local users to execute arbitrary code via (1) a long
23RIESGO
abrir
ReferênciaVexDay Proof
WM Downloader - '.m3u' Local Stack Overflow (PoC)
CVE-2009-1327doswindows
Stack-based buffer overflow in Mini-stream WM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.