Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
Easy News Content Management - Database Disclosure
CVE-2008-6493webappsasp
Easy Content Management Publishing stores sensitive information under the web root with insufficient access control, whi
23RIESGO
abrir
ReferênciaVexDay Proof
NVR SP2 2.0 'nvUtility.dll 1.0.14.0' - 'SaveXMLFile()' Insecure Method
CVE-2007-4583remotewindows
Multiple absolute path traversal vulnerabilities in the nvUtility.Utility.1 ActiveX control in nvUtility.dll 1.0.14.0 in
23RIESGO
abrir
ReferênciaVexDay Proof
ASP User Engine .NET - Remote Database Disclosure
CVE-2008-6494webappsphp
ASP User Engine.NET stores sensitive information under the web root with insufficient access control, which allows remot
23RIESGO
abrir
ReferênciaVexDay Proof
WebFileExplorer 3.1 - 'db.mdb' Database Disclosure
CVE-2009-1495webappsphp
Web File Explorer 3.1 stores sensitive information under the web root with insufficient access control, which allows rem
23RIESGO
abrir
ReferênciaVexDay Proof
TorrentTrader Classic 1.09 - Multiple Vulnerabilities
CVE-2009-2160webappsphp
TorrentTrader Classic 1.09 allows remote attackers to (1) obtain configuration information via a direct request to phpin
23RIESGO
abrir
ReferênciaVexDay Proof
XAMPP 1.6.8 - Cross-Site Request Forgery (Change Administrative Password)
CVE-2008-6499remotewindows
security/xamppsecurity.php in XAMPP 1.6.8 performs an extract operation on the SERVER superglobal array, which allows re
23RIESGO
abrir
ReferênciaVexDay Proof
Pro Chat Rooms 3.0.2 - Cross-Site Scripting / Cross-Site Request Forgery
CVE-2008-6502webappsphp
Directory traversal vulnerability in Pro Chat Rooms 3.0.2 allows remote authenticated users to select an arbitrary local
23RIESGO
abrir
ReferênciaVexDay Proof
Openfire Server 3.6.0a - Authentication Bypass / SQL Injection / Cross-Site Scripting
CVE-2008-6508webappsjsp
Directory traversal vulnerability in the AuthCheck filter in the Admin Console in Openfire 3.6.0a and earlier allows rem
60RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Windows - GDI Image Parsing Stack Overflow (MS08-021)
CVE-2008-1087localwindows
Stack-based buffer overflow in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 200
35RIESGO
abrir
ReferênciaVexDay Proof
iDB 0.2.5pa SVN 243 - 'skin' Local File Inclusion
CVE-2009-1498webappsphp
Directory traversal vulnerability in inc/profilemain.php in Game Maker 2k Internet Discussion Boards (iDB) 0.2.5 Pre-Alp
23RIESGO
abrir
ReferênciaVexDay Proof
Kjtechforce mailman b1 - 'dest' Blind SQL Injection
CVE-2009-2164webappsphp
Multiple SQL injection vulnerabilities in Kjtechforce mailman beta1, when magic_quotes_gpc is disabled, allow remote att
23RIESGO
abrir
ReferênciaVexDay Proof
Openfire Server 3.6.0a - Authentication Bypass / SQL Injection / Cross-Site Scripting
CVE-2008-6511webappsjsp
Open redirect vulnerability in login.jsp in Openfire 3.6.0a and earlier allows remote attackers to redirect users to arb
23RIESGO
abrir
ReferênciaVexDay Proof
Andy's PHP KnowledgeBase 0.92.9 - Arbitrary File Upload
CVE-2008-6513webappsphp
Unrestricted file upload vulnerability in saa.php in Andy's PHP Knowledgebase (aphpkb) 0.92.9 allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
VidiScript (Avatar) - Arbitrary File Upload
CVE-2008-6518webappsphp
Unrestricted file upload vulnerability in the profile feature in VidiScript allows registered remote authenticated users
23RIESGO
abrir
ReferênciaVexDay Proof
Focus/SIS 1.0/2.2 - Remote File Inclusion
CVE-2007-4807webappsphp
Multiple PHP remote file inclusion vulnerabilities in Focus/SIS 2.2 allow remote attackers to execute arbitrary PHP code
23RIESGO
abrir
ReferênciaVexDay Proof
Xitami Web Server 2.5c2 - LRWP Processing Format String (PoC)
CVE-2008-6519doswindows
Format string vulnerability in Xitami Web Server 2.2a through 2.5c2, and possibly other versions, allows remote attacker
23RIESGO
abrir
ReferênciaVexDay Proof
OpenInvoice 0.9 - Arbitrary Change User Password
CVE-2008-6523webappsphp
auth.php in openInvoice 0.90 beta and earlier allows remote attackers to bypass authentication and gain privileges by se
23RIESGO
abrir
ReferênciaVexDay Proof
BosClassifieds - 'cat_id' SQL Injection
CVE-2008-6526webappsphp
SQL injection vulnerability in index.php in BosDev BosClassifieds allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir
ReferênciaVexDay Proof
GO4I.NET ASP Forum 1.0 - SQL Injection
CVE-2008-6527webappsphp
SQL injection vulnerability in forum.asp in GO4I.NET ASP Forum 1.0 allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
ReferênciaVexDay Proof
TmaxSoft JEUS - Alternate Data Streams File Disclosure
CVE-2008-6528remotewindows
NTFS TmaxSoft JEUS 5 before Fix 26 allows remote attackers to read the source code for scripts by appending ::$DATA to t
23RIESGO
abrir
ReferênciaVexDay Proof
PayPal eStore - Admin Password Change
CVE-2008-6535webappsphp
admin/settings.php in PayPal eStores allows remote attackers to bypass intended access restrictions and change the admin
23RIESGO
abrir
ReferênciaVexDay Proof
Destar 0.2.2-5 - Arbitrary Add Admin
CVE-2008-6539webappsphp
Static code injection vulnerability in user/settings/ in DeStar 0.2.2-5 allows remote authenticated users to add arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
Ajax File Browser 3b - 'settings.inc.php?approot' Remote File Inclusion
CVE-2007-4921webappsphp
PHP remote file inclusion vulnerability in _includes/settings.inc.php in Ajax File Browser 3 Beta allows remote attacker
35RIESGO
abrir
ReferênciaVexDay Proof
KwsPHP Module jeuxflash 1.0 - 'id' SQL Injection
CVE-2007-4922webappsphp
SQL injection vulnerability in play.php in the jeuxflash 1.0 module for KwsPHP allows remote authenticated users to exec
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component Joomlaradio 5.0 - Remote File Inclusion
CVE-2007-4923webappsphp
PHP remote file inclusion vulnerability in admin.joomlaradiov5.php in the Joomla Radio 5 (com_joomlaradiov5) component f
35RIESGO
abrir
ReferênciaVexDay Proof
Roundcube Webmail 0.2-3 Beta - Code Execution
CVE-2008-5619webappsphp
html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail)
35RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Windows - '.chm' Denial of Service (HTML Compiled)
CVE-2009-0119doswindows
Buffer overflow in Microsoft Windows XP SP3 allows remote attackers to cause a denial of service (memory corruption and
35RIESGO
abrir
ReferênciaVexDay Proof
MyioSoft Ajax Portal 3.0 - 'page' SQL Injection
CVE-2009-1509webappsphp
SQL injection vulnerability in ajaxp_backend.php in MyioSoft AjaxPortal 3.0 allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
SimpCMS - 'keyword' SQL Injection
CVE-2007-4953webappsphp
SQL injection vulnerability in index.php in SimpCMS allows remote attackers to execute arbitrary SQL commands via the ke
23RIESGO
abrir
ReferênciaVexDay Proof
KwsPHP 1.0 Member_Space Module - SQL Injection
CVE-2007-4956webappsphp
Multiple SQL injection vulnerabilities in KwsPHP 1.0 allow remote attackers to execute arbitrary SQL commands via (1) th
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.