Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
Flexphplink Pro - Arbitrary File Upload
CVE-2008-6731webappsphp
Unrestricted file upload vulnerability in submitlink.php in FlexPHPLink Pro 0.0.7 allows remote attackers to execute arb
23RIESGO
abrir
ReferênciaVexDay Proof
Keller Web Admin CMS 0.94 Pro - Local File Inclusion (2)
CVE-2008-6734webappsphp
Directory traversal vulnerability in Public/index.php in Keller Web Admin CMS 0.94 Pro allows remote attackers to includ
23RIESGO
abrir
ReferênciaVexDay Proof
MyShoutPro 1.2 - Final Insecure Cookie Handling
CVE-2008-6738webappsphp
MyShoutPro 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the admin_acce
23RIESGO
abrir
ReferênciaVexDay Proof
Simple Machines Forum (SMF) 1.1.4 - SQL Injection
CVE-2008-6741webappsphp
SQL injection vulnerability in Load.php in Simple Machines Forum (SMF) 1.1.4 and earlier allows remote attackers to exec
23RIESGO
abrir
ReferênciaVexDay Proof
RSMScript 1.21 - Cross-Site Scripting / Insecure Cookie Handling
CVE-2008-6743webappsphp
RSMScript 1.21 allows remote attackers to bypass authentication and gain administrative privileges by setting the verifi
23RIESGO
abrir
ReferênciaVexDay Proof
BlogPHP 2.0 - Privilege Escalation / SQL Injection
CVE-2008-6745webappsphp
index.php in BlogPHP 2.0 allows remote attackers to gain administrator privileges via a crafted email parameter in a reg
23RIESGO
abrir
ReferênciaVexDay Proof
Megacubo 5.0.7 - 'mega://' Remote 'eval()' Injection
CVE-2008-6748remotewindows
Eval injection vulnerability in Megacubo 5.0.7 allows remote attackers to inject and execute arbitrary PHP code via the
23RIESGO
abrir
ReferênciaVexDay Proof
yourplace 1.0.2 - Multiple Vulnerabilities / Remote Code Execution
CVE-2008-6771webappsphp
YourPlace 1.0.2 and earlier allows remote attackers to obtain sensitive system information via a direct request via a di
23RIESGO
abrir
ReferênciaVexDay Proof
SFS EZ Affiliate - 'cat_id' SQL Injection
CVE-2008-6780webappsphp
SQL injection vulnerability in directory.php in Scripts for Sites (SFS) SFS EZ Affiliate allows remote attackers to exec
23RIESGO
abrir
ReferênciaVexDay Proof
SFS EZ Gaming Directory - 'cat_id' SQL Injection
CVE-2008-6781webappsphp
SQL injection vulnerability in directory.php in Sites for Scripts (SFS) Gaming Directory allows remote attackers to exec
23RIESGO
abrir
ReferênciaVexDay Proof
SAPID CMF Build 87 - 'last_module' Remote Code Execution
CVE-2007-5056webappsphp
Eval injection vulnerability in adodb-perf-module.inc.php in ADOdb Lite 1.42 and earlier, as used in products including
28RIESGO
abrir
ReferênciaVexDay Proof
SFS EZ Gaming Directory - 'directory.php' SQL Injection
CVE-2008-6781webappsphp
SQL injection vulnerability in directory.php in Sites for Scripts (SFS) Gaming Directory allows remote attackers to exec
23RIESGO
abrir
ReferênciaVexDay Proof
SFS EZ Home Business Directory - 'cat_id' SQL Injection
CVE-2008-6783webappsphp
SQL injection vulnerability in directory.php in Sites for Scripts (SFS) EZ Home Business Directory allows remote attacke
23RIESGO
abrir
ReferênciaVexDay Proof
Mini File Host 1.x - Arbitrary '.PHP' File Upload
CVE-2008-6785webappsphp
Unrestricted file upload vulnerability in Mini File Host 1.5 allows remote attackers to execute arbitrary code by upload
23RIESGO
abrir
ReferênciaVexDay Proof
Bitweaver 2.6 - 'saveFeed()' Remote Code Execution
CVE-2009-1669webappsphp
The smarty_function_math function in libs/plugins/function.math.php in Smarty 2.6.22 allows context-dependent attackers
28RIESGO
abrir
ReferênciaVexDay Proof
Lizardware CMS 0.6.0 - Blind SQL Injection
CVE-2008-6787webappsphp
SQL injection vulnerability in administrator/index.php in Lizardware CMS 0.6.0 and earlier allows remote attackers to ex
23RIESGO
abrir
ReferênciaVexDay Proof
Xitami Web Server 2.5 - 'If-Modified-Since' Remote Buffer Overflow
CVE-2007-5067remotewindows
Multiple buffer overflows in iMatix Xitami Web Server 2.5c2 allow remote attackers to execute arbitrary code via a long
60RIESGO
abrir
ReferênciaVexDay Proof
MindDezign Photo Gallery 2.2 - SQL Injection
CVE-2008-6788webappsphp
SQL injection vulnerability in MindDezign Photo Gallery 2.2, when magic_quotes_gpc is disabled, allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
MindDezign Photo Gallery 2.2 - Arbitrary Add Admin
CVE-2008-6789webappsphp
SQL injection vulnerability in MindDezign Photo Gallery 2.2 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir
ReferênciaVexDay Proof
PumpKIN TFTP Server 2.7.2.0 - Denial of Service (Metasploit)
CVE-2008-6791doswindows
PumpKIN TFTP Server 2.7.2.0 allows remote attackers to cause a denial of service via a write request with a long mode fi
23RIESGO
abrir
ReferênciaVexDay Proof
Vibro-School-CMS - 'nID' SQL Injection
CVE-2008-6795webappsphp
SQL injection vulnerability in view_news.php in nicLOR Vibro-School-CMS allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
helplink 0.1.0 - 'show.php' Remote File Inclusion
CVE-2007-5099webappsphp
PHP remote file inclusion vulnerability in show.php in David Watters Helplink 0.1.0 allows remote attackers to execute a
35RIESGO
abrir
ReferênciaVexDay Proof
Pre Real Estate Listings - Authentication Bypass
CVE-2008-6796webappsphp
SQL injection vulnerability in manager/login.php in Pre Projects Pre Real Estate Listings allows remote attackers to exe
23RIESGO
abrir
ReferênciaVexDay Proof
Pre Real Estate Listings - Arbitrary File Upload
CVE-2008-6798webappsphp
Multiple SQL injection vulnerabilities in login.php in Pre Projects Pre Real Estate Listings allow remote attackers to e
23RIESGO
abrir
ReferênciaVexDay Proof
Softbiz Classifieds PLUS - 'id' SQL Injection
CVE-2007-5122webappsphp
SQL injection vulnerability in store_info.php in SoftBiz Classifieds PLUS allows remote attackers to execute arbitrary S
23RIESGO
abrir
ReferênciaVexDay Proof
Tribiq CMS 5.0.9a (Beta) - Insecure Cookie Handling
CVE-2008-6804webappsphp
Tribiq CMS 5.0.9a beta allows remote attackers to bypass authentication and gain administrative access by setting the CO
23RIESGO
abrir
ReferênciaVexDay Proof
7Shop 1.1 - Arbitrary File Upload
CVE-2008-6806webappsphp
Unrestricted file upload vulnerability in includes/imageupload.php in 7Shop 1.1 and earlier allows remote attackers to e
23RIESGO
abrir
ReferênciaVexDay Proof
jetAudio 7.x - ActiveX 'DownloadFromMusicStore()' Code Execution
CVE-2007-4983remotewindows
Directory traversal vulnerability in the JetAudio.Interface.1 ActiveX control in JetFlExt.dll in jetAudio 7.0.3 Basic an
35RIESGO
abrir
ReferênciaVexDay Proof
C6 Messenger - ActiveX Remote Download and Execute
CVE-2008-2551remotewindows
The DownloaderActiveX Control (DownloaderActiveX.ocx) in Icona SpA C6 Messenger 1.0.0.1 allows remote attackers to force
50RIESGO
abrir
ReferênciaVexDay Proof
SFS EZ Link Directory - 'cat_id' SQL Injection
CVE-2008-6808webappsphp
SQL injection vulnerability in links.php in Scripts for Sites (SFS) EZ Link Directory allows remote attackers to execute
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.