Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
Joomla! Component prayercenter 1.4.9 - 'id' SQL Injection
CVE-2008-6429webappsphp
SQL injection vulnerability in the PrayerCenter (com_prayercenter) component 1.4.9 and earlier for Joomla! allows remote
23RIESGO
abrir
ReferênciaVexDay Proof
Elkagroup Image Gallery 1.0 - Arbitrary File Upload
CVE-2009-1446webappsphp
Unrestricted file upload vulnerability in upload.php in Elkagroup Image Gallery 1.0 allows remote authenticated users to
23RIESGO
abrir
ReferênciaVexDay Proof
Avahi < 0.6.24 - mDNS Daemon Remote Denial of Service
CVE-2008-5081dosmultiple
The originates_from_local_legacy_unicast_socket function (avahi-core/server.c) in avahi-daemon in Avahi before 0.6.24 al
50RIESGO
abrir
ReferênciaVexDay Proof
Dayfox Blog 4 - 'postpost.php' Remote Code Execution
CVE-2007-1525webappsphp
Direct static code injection vulnerability in postpost.php in Dayfox Blog (dfblog) 4 allows remote attackers to execute
35RIESGO
abrir
ReferênciaVexDay Proof
MKPortal NoBoard Module (Beta) - Remote File Inclusion
CVE-2007-3813webappsphp
PHP remote file inclusion vulnerability in include/user.php in the NoBoard BETA module for MKPortal allows remote attack
35RIESGO
abrir
ReferênciaVexDay Proof
CoolPlayer Portable 2.19.1 - 'Skin' Local Buffer Overflow
CVE-2009-1449localwindows
Stack-based buffer overflow in PortableApps CoolPlayer Portable (aka CoolPlayer+ Portable) 2.19.1 allows remote attacker
23RIESGO
abrir
ReferênciaVexDay Proof
e107 Plugin BLOG Engine 2.2 - 'uid' SQL Injection
CVE-2008-6438webappsphp
SQL injection vulnerability in macgurublog_menu/macgurublog.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows re
23RIESGO
abrir
ReferênciaVexDay Proof
EDraw Office Viewer Component 5.1 - HttpDownloadFile() Insecure Method
CVE-2007-4420remotewindows
Absolute path traversal vulnerability in a certain ActiveX control in officeviewer.ocx 5.1.199.1 in EDraw Office Viewer
23RIESGO
abrir
ReferênciaVexDay Proof
Shop Script Pro 2.12 - SQL Injection
CVE-2009-2023webappsphp
SQL injection vulnerability in index.php in Shop-Script Pro 2.12, when magic_quotes_gpc is disabled, allows remote attac
23RIESGO
abrir
ReferênciaVexDay Proof
yogurt 0.3 - Cross-Site Scripting / SQL Injection
CVE-2009-2034webappsphp
SQL injection vulnerability in writemessage.php in Yogurt 0.3, when register_globals is enabled, allows remote authentic
23RIESGO
abrir
ReferênciaVexDay Proof
EasyMail - ActiveX 'emmailstore.dll 6.5.0.3' Remote Buffer Overflow
CVE-2008-6447remotewindows
Buffer overflow in emmailstore.dll 6.5.0.3 in the QuikSoft EasyMail MailStore ActiveX control allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
jPORTAL 2 - 'humor.php' SQL Injection
CVE-2008-6451webappsphp
SQL injection vulnerability in humor.php in jPORTAL 2 allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir
ReferênciaVexDay Proof
IBM Domino Web Access 7.0 Upload Module - 'inotes6.dll' Remote Buffer Overflow
CVE-2007-4474remotewindows
Multiple stack-based buffer overflows in the IBM Lotus Domino Web Access ActiveX control, as provided by inotes6.dll, in
50RIESGO
abrir
ReferênciaVexDay Proof
Oceandir 2.9 - 'show_vote.php' SQL Injection
CVE-2008-6452webappsphp
SQL injection vulnerability in show_vote.php in Oceandir 2.9 and earlier allows remote attackers to execute arbitrary SQ
23RIESGO
abrir
ReferênciaVexDay Proof
Diesel Job Site - 'job_id' Blind SQL Injection
CVE-2008-6467webappsphp
SQL injection vulnerability in jobs/jobseekers/job-info.php in Diesel Job Site allows remote attackers to execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
IBM Domino Web Access Upload Module - Overwrite (SEH)
CVE-2007-4474remotewindows
Multiple stack-based buffer overflows in the IBM Lotus Domino Web Access ActiveX control, as provided by inotes6.dll, in
50RIESGO
abrir
ReferênciaVexDay Proof
Diesel Pay Script - 'area' SQL Injection
CVE-2008-6468webappsphp
SQL injection vulnerability in index.php in Diesel Pay allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir
ReferênciaVexDay Proof
Plaincart 1.1.2 - 'p' SQL Injection
CVE-2008-6469webappsphp
SQL injection vulnerability in index.php in PlainCart 1.1.2 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component EventList 0.8 - 'did' SQL Injection
CVE-2007-4509webappsphp
SQL injection vulnerability in index.php in the EventList component (com_eventlist) 0.8 and earlier for Joomla! allows r
23RIESGO
abrir
ReferênciaVexDay Proof
easyLink 1.1.0 - 'detail.php' SQL Injection
CVE-2008-6471webappsphp
SQL injection vulnerability in detail.php in MountainGrafix easyLink 1.1.0 allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
fungamez rc1 - Authentication Bypass / Local File Inclusion
CVE-2009-1487webappsphp
SQL injection vulnerability in pages/login.php in FunGamez RC1 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
HP Virtual Rooms WebHPVCInstall Control - Remote Buffer Overflow
CVE-2008-0437remotewindows
Multiple buffer overflows in the WebHPVCInstall.HPVirtualRooms14 ActiveX control in HPVirtualRooms14.dll 1.0.0.100, as u
35RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component com_iJoomla_rss - Blind SQL Injection
CVE-2009-2099webappsphp
SQL injection vulnerability in the iJoomla RSS Feeder (com_ijoomla_rss) component for Joomla! allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
Blogator-script 0.95 - Change User Password
CVE-2008-6473webappsphp
_blogadata/include/init_pass2.php in Blogator-script 0.95 allows remote attackers to change the password for arbitrary u
23RIESGO
abrir
ReferênciaVexDay Proof
Mumbo Jumbo Media OP4 - Blind SQL Injection
CVE-2008-6477webappsphp
SQL injection vulnerability in Mumbo Jumbo Media OP4 allows remote attackers to execute arbitrary SQL commands via the i
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component versioning 1.0.2 - 'id' SQL Injection
CVE-2008-6481webappsphp
SQL injection vulnerability in the Versioning component (com_versioning) 1.0.2 in Joomla! and Mambo allows remote attack
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component Flash Tree Gallery 1.0 - Remote File Inclusion
CVE-2008-6482webappsphp
PHP remote file inclusion vulnerability in admin.treeg.php in the Flash Tree Gallery (com_treeg) component 1.0 for Jooml
28RIESGO
abrir
ReferênciaVexDay Proof
Mole Group Taxi Calc Dist Script - Authentication Bypass
CVE-2008-6484webappsphp
SQL injection vulnerability in login.php in Mole Group Taxi Map Script (aka Taxi Calc Dist Script) allows remote attacke
23RIESGO
abrir
ReferênciaVexDay Proof
SoftComplex PHP Image Gallery 1.0 - Authentication Bypass
CVE-2008-6488webappsphp
SQL injection vulnerability in index.php in SoftComplex PHP Image Gallery 1.0 allows remote attackers to execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
FLABER 1.1 RC1 - Remote Command Execution
CVE-2008-6490webappsphp
function/update_xml.php in FLABER 1.1 and earlier allows remote attackers to overwrite arbitrary files by specifying the
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.