Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
X.Org xorg-x11-xfs 1.0.2-3.1 - Local Race Condition
CVE-2007-3103locallinux
The init.d script for the X.Org X11 xfs font server on various Linux distributions might allow local users to change the
23RIESGO
abrir
ReferênciaVexDay Proof
Kravchuk letter script 1.0 - 'scdir' Remote File Inclusion
CVE-2007-3118webappsphp
Multiple PHP remote file inclusion vulnerabilities in Kravchuk letter (K-letter) 1.0 allow remote attackers to execute a
23RIESGO
abrir
ReferênciaVexDay Proof
phpsmartcom 0.2 - Local File Inclusion / SQL Injection
CVE-2008-4352webappsphp
SQL injection vulnerability in inc/pages/viewprofile.php in phpSmartCom 0.2 allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
Kartli Alisveris Sistemi 1.0 - SQL Injection
CVE-2007-3119webappsasp
SQL injection vulnerability in news.asp in Kartli Alisveris Sistemi (aka Free-PayPal-Shopping-Cart) 1.0 allows remote at
23RIESGO
abrir
ReferênciaVexDay Proof
ABC Advertise 1.0 - Admin Password Disclosure
CVE-2009-1550webappsphp
Zakkis Technology ABC Advertise 1.0 does not properly restrict access to admin.inc.php, which allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
cf shopkart 5.2.2 - SQL Injection / File Disclosure
CVE-2008-6320webappsasp
SQL injection vulnerability in index.cfm in CF Shopkart 5.2.2 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
iBoutique 4.0 - 'cat' SQL Injection
CVE-2008-4354webappsphp
SQL injection vulnerability in the products module in NetArt Media iBoutique 4.0 allows remote attackers to execute arbi
23RIESGO
abrir
ReferênciaVexDay Proof
CFMBLOG - 'categorynbr' Blind SQL Injection
CVE-2008-6322webappsasp
SQL injection vulnerability in index.cfm in CFMSource CFMBlog allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
pForum 1.30 - 'showprofil.php' SQL Injection
CVE-2008-4355webappsphp
SQL injection vulnerability in showprofil.php in Powie PSCRIPT Forum (aka PHP Forum or pForum) 1.30 and earlier allows r
23RIESGO
abrir
ReferênciaVexDay Proof
DESlock+ < 3.2.7 - 'probe read' Local Kernel Denial of Service (PoC)
CVE-2008-4363doswindows
DLMFENC.sys 1.0.0.28 in DESlock+ 3.2.7 allows local users to cause a denial of service (system crash) or potentially exe
23RIESGO
abrir
ReferênciaVexDay Proof
ParsaWeb CMS - 'Search' SQL Injection
CVE-2008-4364webappsasp
SQL injection vulnerability in default.aspx in ParsaGostar ParsaWeb CMS allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
AvailScript Photo Album - 'pics.php' Multiple Vulnerabilities
CVE-2008-4370webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in Availscript Photo Album allow remote attackers to inject arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
Xserver 0.1 Alpha - 'POST' Remote Buffer Overflow (PoC)
CVE-2007-3957doslinux
Buffer overflow in Nipun Jain xserver 0.1 alpha allows remote attackers to cause a denial of service via a POST request
23RIESGO
abrir
ReferênciaVexDay Proof
AvailScript Article Script - 'articles.php' Multiple Vulnerabilities
CVE-2008-4372webappsphp
Cross-site scripting (XSS) vulnerability in articles.php in AvailScript Article Script allows remote attackers to inject
23RIESGO
abrir
ReferênciaVexDay Proof
JBlog 1.0 - Create / Delete Admin Authentication Bypass
CVE-2007-3973webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in JBlog 1.0 allow remote attackers to inject arbitrary web script o
23RIESGO
abrir
ReferênciaVexDay Proof
CF_Forum - Blind SQL Injection
CVE-2008-6324webappsasp
SQL injection vulnerability in forummessages.cfm in CF_Forum allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
ReferênciaVexDay Proof
bwired - 'index.php?newsID' SQL Injection
CVE-2007-3976webappsphp
SQL injection vulnerability in index.php in bwired allows remote attackers to execute arbitrary SQL commands via the new
23RIESGO
abrir
ReferênciaVexDay Proof
AvailScript Jobs Portal Script - 'jid' SQL Injection
CVE-2008-4373webappsphp
SQL injection vulnerability in job_seeker/applynow.php in AvailScript Job Portal Script allows remote attackers to execu
23RIESGO
abrir
ReferênciaVexDay Proof
Creator CMS 5.0 - 'sideid' SQL Injection
CVE-2008-4377webappsasp
SQL injection vulnerability in index.asp in Creative Mind Creator CMS 5.0 allows remote attackers to execute arbitrary S
23RIESGO
abrir
ReferênciaVexDay Proof
Mazens PHP Chat V3 (basepath) - Remote File Inclusion
CVE-2007-2939webappsphp
Multiple PHP remote file inclusion vulnerabilities in Mazen's PHP Chat 3.0.0 allow remote attackers to execute arbitrary
35RIESGO
abrir
ReferênciaVexDay Proof
PHP 5.2.3 - 'PHP_gd2.dll' imagepsloadfont Local Buffer Overflow (PoC)
CVE-2007-4033doswindows
Buffer overflow in the intT1_EnvGetCompletePath function in lib/t1lib/t1env.c in t1lib 5.1.1 allows context-dependent at
28RIESGO
abrir
ReferênciaVexDay Proof
VMware Inc 6.0.0 - 'vielib.dll 2.2.5.42958' Remode Code Execution
CVE-2007-4058remotewindows
Absolute path traversal vulnerability in a certain ActiveX control in vielib.dll 2.2.5.42958 in EMC VMware 6.0.0 allows
28RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component Volunteer 2.0 - SQL Injection
CVE-2008-6337webappsphp
SQL injection vulnerability in the Volunteer Management System (com_volunteer) module 2.0 for Joomla! allows remote atta
23RIESGO
abrir
ReferênciaVexDay Proof
pPIM 1.0 - Upload/Change Password
CVE-2008-4427webappsphp
changepassword.php in Phlatline's Personal Information Manager (pPIM) 1.0 and earlier does not require administrative au
23RIESGO
abrir
ReferênciaVexDay Proof
BlazeVideo HDTV Player 2.1 - '.PLF' Local Buffer Overflow
CVE-2006-6199localwindows
Stack-based buffer overflow in BlazeVideo BlazeDVD Standard and Professional 5.0, and possibly earlier, allows remote at
50RIESGO
abrir
ReferênciaVexDay Proof
RM Downloader 3.0.0.9 - '.RAM' Local Buffer Overflow
CVE-2009-1646localwindows
Stack-based buffer overflow in Mini-stream RM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a
23RIESGO
abrir
ReferênciaVexDay Proof
Shutter 0.1.1 - Multiple SQL Injections
CVE-2009-1650webappsphp
Multiple SQL injection vulnerabilities in photos.php in Shutter 0.1.1 allow remote attackers to execute arbitrary SQL co
23RIESGO
abrir
ReferênciaVexDay Proof
BBlog 0.7.6 - 'mod' SQL Injection
CVE-2008-4436webappsphp
SQL injection vulnerability in bblog_plugins/builtin.help.php in bBlog 0.7.6 allows remote attackers to execute arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Windows XP/2003 - IGMP v3 Denial of Service (MS06-007) (1)
CVE-2006-0021doswindows
Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote attackers to cause a denial of service (hang)
35RIESGO
abrir
ReferênciaVexDay Proof
WordPress Plugin mygallery 1.4b4 - Remote File Inclusion
CVE-2007-2426webappsphp
PHP remote file inclusion vulnerability in myfunctions/mygallerybrowser.php in the myGallery 1.4b4 and earlier plugin fo
35RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.