Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
The Net Guys ASPired2Protect - Database Disclosure
CVE-2008-6355webappsasp
The Net Guys ASPired2Protect stores sensitive information under the web root with insufficient access control, which all
23RIESGO
abrir
ReferênciaVexDay Proof
evCal Events Calendar - Database Disclosure
CVE-2008-6356webappsasp
evCal Events Calendar stores sensitive information under the web root with insufficient access control, which allows rem
23RIESGO
abrir
ReferênciaVexDay Proof
MyCal Personal Events Calendar - Database Disclosure
CVE-2008-6357webappsasp
MyCal Personal Events Calendar stores sensitive information under the web root with insufficient access control, which a
23RIESGO
abrir
ReferênciaVexDay Proof
Social Groupie - 'id' SQL Injection
CVE-2008-6358webappsphp
SQL injection vulnerability in group_index.php in Social Groupie allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
ReferênciaVexDay Proof
DesignWorks Professional 4.3.1 - '.CCT' File Local Stack Buffer Overflow (PoC)
CVE-2008-6363doswindows
Stack-based buffer overflow in DesignWorks Professional 4.3.1 and 5.0.7 allows remote attackers to execute arbitrary cod
23RIESGO
abrir
ReferênciaVexDay Proof
my-colex 1.4.2 - Authentication Bypass / SQL Injection / Cross-Site Scripting
CVE-2009-1809webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in myColex 1.4.2 allow remote attackers to inject arbitrary web scri
23RIESGO
abrir
ReferênciaVexDay Proof
CHILKAT ASP String - 'CkString.dll 1.1 SaveToFile()' Insecure Method
CVE-2007-4252remotewindows
Absolute path traversal vulnerability in a certain ActiveX control in CkString.dll 1.1 and earlier in CHILKAT ASP String
23RIESGO
abrir
ReferênciaVexDay Proof
Banner Exchange Java - Authentication Bypass
CVE-2008-6364webappsasp
SQL injection vulnerability in logon_process.jsp in Ad Server Solutions Banner Exchange Solution Java allows remote atta
23RIESGO
abrir
ReferênciaVexDay Proof
Ad Management Java - Authentication Bypass
CVE-2008-6365webappsasp
SQL injection vulnerability in logon.jsp in Ad Server Solutions Ad Management Software Java allows remote attackers to e
23RIESGO
abrir
ReferênciaVexDay Proof
Affiliate Software Java 4.0 - Authentication Bypass
CVE-2008-6366webappsasp
SQL injection vulnerability in logon.jsp in Ad Server Solutions Affiliate Software Java 4.0 allows remote attackers to e
23RIESGO
abrir
ReferênciaVexDay Proof
Ocean12 Contact Manager Pro - SQL Injection / Cross-Site Scripting / File Disclosure
CVE-2008-6369webappsphp
SQL injection vulnerability in default.asp in Ocean12 Contact Manager Pro 1.02 allows remote attackers to execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
Codefixer MailingListPro - Database Disclosure
CVE-2008-6374webappsasp
CodefixerSoftware MailingListPro Free Edition stores sensitive information under the web root with insufficient access c
23RIESGO
abrir
ReferênciaVexDay Proof
Multi SEO phpBB 1.1.0 - Remote File Inclusion
CVE-2008-6377webappsphp
PHP remote file inclusion vulnerability in include/global.php in Multi SEO phpBB 1.1.0 allows remote attackers to execut
23RIESGO
abrir
ReferênciaVexDay Proof
Calendar MX Professional 2.0.0 - Blind SQL Injection
CVE-2008-6378webappsasp
SQL injection vulnerability in calendar_Eventupdate.asp in Calendar Mx Professional 2.0.0 allows remote attackers to exe
23RIESGO
abrir
ReferênciaVexDay Proof
2DayBiz Custom T-shirt Design - SQL Injection / Cross-Site Scripting
CVE-2009-1820webappsphp
Cross-site scripting (XSS) vulnerability in product.php in 2daybiz Custom T-shirt Design Script allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
Active Web Helpdesk 2 - 'categoryId' Blind SQL Injection
CVE-2008-6380webappsphp
SQL injection vulnerability in default.aspx in Active Web Helpdesk 2.0 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
Quick Tree View .NET 3.1 - Database Disclosure
CVE-2008-6387webappsphp
Quick Tree View .NET 3.1 stores sensitive information under the web root with insufficient access control, which allows
23RIESGO
abrir
ReferênciaVexDay Proof
Feindt Computerservice News 2.0 - 'newsadmin.php?action' Remote File Inclusion
CVE-2007-2708webappsphp
PHP remote file inclusion vulnerability in newsadmin.php in Feindt Computerservice News (News-Script) 2.0 allows remote
35RIESGO
abrir
ReferênciaVexDay Proof
LimeSurvey (phpsurveyor) 1.49rc2 - Remote File Inclusion
CVE-2007-3632webappsphp
Multiple PHP remote file inclusion vulnerabilities in LimeSurvey (aka PHPSurveyor) 1.49RC2 allow remote attackers to exe
35RIESGO
abrir
ReferênciaVexDay Proof
HotScripts Clone - 'cid' SQL Injection
CVE-2008-6405webappsphp
SQL injection vulnerability in showcategory.php in Hotscripts Clone allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft DXMedia SDK 6 - 'SourceUrl' ActiveX Remote Code Execution
CVE-2007-4336remotewindows
Buffer overflow in the Live Picture Corporation DXSurface.LivePicture.FlashPix.1 (DirectTransform FlashPix) ActiveX cont
35RIESGO
abrir
ReferênciaVexDay Proof
Ol BookMarks Manager 0.7.5 - Local File Inclusion / Remote File Inclusion / SQL Injection
CVE-2008-6408webappsphp
PHP remote file inclusion vulnerability in frame.php in ol'bookmarks manager 0.7.5 allows remote attackers to execute ar
23RIESGO
abrir
ReferênciaVexDay Proof
Ol BookMarks Manager 0.7.5 - Local File Inclusion / Remote File Inclusion / SQL Injection
CVE-2008-6409webappsphp
SQL injection vulnerability in index.php in ol'bookmarks manager 0.7.5 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
AJ Auction Pro Platinum Skin - 'item_id' SQL Injection
CVE-2008-6414webappsphp
SQL injection vulnerability in detail.php in AJ Auction Pro Platinum Skin 2 allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
Social Site Generator 2.0 - 'sgc_id' SQL Injection
CVE-2008-6419webappsphp
Multiple SQL injection vulnerabilities in Social Site Generator (SSG) 2.0 allow remote attackers to execute arbitrary SQ
23RIESGO
abrir
ReferênciaVexDay Proof
Social Site Generator 2.0 - Multiple Remote File Disclosure Vulnerabilities
CVE-2008-6420webappsphp
Social Site Generator (SSG) 2.0 allows remote attackers to read arbitrary files via the file parameter to (1) filedload.
23RIESGO
abrir
ReferênciaVexDay Proof
SOTEeSKLEP 3.5RC9 - 'file' Remote File Disclosure
CVE-2007-4369webappsphp
Directory traversal vulnerability in go/_files in SOTEeSKLEP before 4.0 allows remote attackers to read arbitrary files
23RIESGO
abrir
ReferênciaVexDay Proof
HiveMaker Directory 1.0.2 - 'cid' SQL Injection
CVE-2008-6427webappsphp
SQL injection vulnerability in index.php in Hivemaker Professional 1.0.2 and earlier, when magic_quotes_gpc is disabled,
23RIESGO
abrir
ReferênciaVexDay Proof
HiveMaker Professional 1.0.2 - 'cid' SQL Injection
CVE-2008-6427webappsphp
SQL injection vulnerability in index.php in Hivemaker Professional 1.0.2 and earlier, when magic_quotes_gpc is disabled,
23RIESGO
abrir
ReferênciaVexDay Proof
CoolPlayer Portable 2.19.1 - '.m3u' Local Buffer Overflow (2)
CVE-2009-1437localwindows
Stack-based buffer overflow in PortableApps CoolPlayer Portable (aka CoolPlayer+ Portable) 2.19.6 and earlier allows rem
28RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.