Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.589exploits catalogados
34.508CVEs con explotación pública
24.695probados en laboratorio
21.554 exploits
ReferênciaVexDay Proof
RiotPix 0.61 - 'forumid' Blind SQL Injection
CVE-2009-0110webappsphp
SQL injection vulnerability in read.php in RiotPix 0.61 and earlier allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
ReferênciaVexDay Proof
Goople 1.8.2 - 'FrontPage.php' Blind SQL Injection
CVE-2009-0111webappsphp
SQL injection vulnerability in frontpage.php in Goople CMS 1.8.2 and earlier allows remote attackers to execute arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft HTML Workshop 4.74 - Universal Buffer Overflow
CVE-2009-0133localwindows
Buffer overflow in Microsoft HTML Help Workshop 4.74 and earlier allows context-dependent attackers to execute arbitrary
50RIESGO
abrir
ReferênciaVexDay Proof
VUPlayer 2.49 - '.asx' HREF Local Buffer Overflow (PoC)
CVE-2009-0174doswindows
Stack-based buffer overflow in VUPlayer 2.49 allows remote attackers to execute arbitrary code via a long .asf URI in th
28RIESGO
abrir
ReferênciaVexDay Proof
VUPlayer 2.49 - '.asx' 'HREF' Universal Buffer Overflow
CVE-2009-0174localwindows
Stack-based buffer overflow in VUPlayer 2.49 allows remote attackers to execute arbitrary code via a long .asf URI in th
28RIESGO
abrir
ReferênciaVexDay Proof
VUPlayer 2.49 - '.asx' HREF Local Buffer Overflow (1)
CVE-2009-0174localwindows
Stack-based buffer overflow in VUPlayer 2.49 allows remote attackers to execute arbitrary code via a long .asf URI in th
28RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component com_pccookbook - 'recipe_id' Blind SQL Injection
CVE-2009-0329webappsphp
SQL injection vulnerability in the PcCookBook (com_pccookbook) component for Joomla! allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
blogit! - SQL Injection / File Disclosure / Cross-Site Scripting
CVE-2009-0334webappsphp
SQL injection vulnerability in index.asp in Katy Whitton BlogIt! allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
Referência
CVE-2011-5139
SQL injection vulnerability in page.php in Pre Studio Business Cards Designer allows remote attackers to execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
blogit! - SQL Injection / File Disclosure / Cross-Site Scripting
CVE-2009-0336webappsphp
Katy Whitton BlogIt! stores sensitive information under the web root with insufficient access control, which allows remo
23RIESGO
abrir
Referência
CVE-2011-5139
SQL injection vulnerability in page.php in Pre Studio Business Cards Designer allows remote attackers to execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
blogit! - SQL Injection / File Disclosure / Cross-Site Scripting
CVE-2009-0337webappsphp
SQL injection vulnerability in index.asp in Katy Whitton BlogIt! allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Internet Explorer 7 - Clickjacking
CVE-2009-0369remotewindows
Microsoft Internet Explorer 7 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick acti
28RIESGO
abrir
ReferênciaVexDay Proof
SiteXS CMS 0.1.1 - Local File Inclusion
CVE-2009-0371webappsphp
Directory traversal vulnerability in post.php in SiteXS CMS 0.1.1 and earlier allows remote attackers to include and exe
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component beamospetition 1.0.12 - SQL Injection / Cross-Site Scripting
CVE-2009-0377webappsphp
SQL injection vulnerability in the beamospetition (com_beamospetition) 1.0.12 component for Joomla! allows remote attack
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component com_pcchess - Blind SQL Injection
CVE-2009-0379webappsphp
SQL injection vulnerability in the Prince Clan Chess Club (com_pcchess) component for Joomla! allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
Mambo Component SOBI2 RC 2.8.2 - SQL Injection
CVE-2009-0380webappsphp
SQL injection vulnerability in the Sigsiu Online Business Index 2 (SOBI2, com_sobi2) RC 2.8.2 component for Joomla! and
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component Com BazaarBuilder Shopping Cart 5.0 - SQL Injection
CVE-2009-0381webappsphp
SQL injection vulnerability in the BazaarBuilder Ecommerce Shopping Cart (com_prod) 5.0 component for Joomla! allows rem
23RIESGO
abrir
Referência
CVE-2011-5161
Unrestricted file upload vulnerability in the patient photograph functionality in OpenEMR 4 allows remote attackers to e
23RIESGO
abrir
ReferênciaVexDay Proof
OwnRS Blog 1.2 - 'autor.php' SQL Injection
CVE-2009-0384webappsphp
SQL injection vulnerability in autor.php in OwnRS CMS 1.2 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
ReferênciaVexDay Proof
TightVNC - Authentication Failure Integer Overflow (PoC)
CVE-2009-0388doswindows
Multiple integer signedness errors in (1) UltraVNC 1.0.2 and 1.0.5 and (2) TightVnc 1.3.9 allow remote VNC servers to ca
28RIESGO
abrir
ReferênciaVexDay Proof
PLE CMS 1.0 Beta 4.2 - Blind SQL Injection
CVE-2009-0394webappsphp
SQL injection vulnerability in login.php in Pre Lecture Exercises (PLEs) CMS 1.0 beta 4.2 allows remote attackers to exe
23RIESGO
abrir
Referência
CVE-2011-5165
Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted rem
50RIESGO
abrir
ReferênciaVexDay Proof
Netartmedia Car Portal 1.0 - Authentication Bypass
CVE-2009-0395webappsphp
SQL injection vulnerability in the login feature in NetArt Media Car Portal 1.0 allows remote attackers to execute arbit
23RIESGO
abrir
Referência
CVE-2011-5165
Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted rem
50RIESGO
abrir
ReferênciaVexDay Proof
SmartSiteCMS 1.0 - Blind SQL Injection
CVE-2009-0405webappsphp
SQL injection vulnerability in articles.php in smartSite CMS 1.0 allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
ReferênciaVexDay Proof
Community CMS 0.4 - 'id' Blind SQL Injection
CVE-2009-0406webappsphp
SQL injection vulnerability in index.php in Community CMS 0.4 and earlier allows remote attackers to execute arbitrary S
23RIESGO
abrir
ReferênciaVexDay Proof
PHP-CMS 1 - 'Username' Blind SQL Injection
CVE-2009-0407webappsphp
SQL injection vulnerability in admin/login.php in PHP-CMS Project 1 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
ReferênciaVexDay Proof
phpList 2.10.8 - Local File Inclusion
CVE-2009-0422webappsphp
Dynamic variable evaluation vulnerability in lists/admin.php in phpList 2.10.8 and earlier, when register_globals is dis
23RIESGO
abrir
ReferênciaVexDay Proof
Blue Eye CMS 1.0.0 - 'clanek' Blind SQL Injection
CVE-2009-0425webappsphp
SQL injection vulnerability in index.php in Blue Eye CMS 1.0.0 and earlier allows remote attackers to execute arbitrary
23RIESGO
abrir
anteriorpágina 222 / 719siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.