Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
WordPress Plugin BackUpWordPress 0.4.2b - Remote File Inclusion
CVE-2007-5800webappsphp
Multiple PHP remote file inclusion vulnerabilities in the BackUpWordPress 0.4.2b and earlier plugin for WordPress allow
35RIESGO
abrir
ReferênciaVexDay Proof
Booking Centre 2.01 - 'HotelID' SQL Injection
CVE-2008-6809webappsphp
SQL injection vulnerability in hotel_habitaciones.php in Venalsur Booking Centre Booking System for Hotels Group 2.01 al
23RIESGO
abrir
ReferênciaVexDay Proof
Booking Centre 2.01 - Authentication Bypass
CVE-2008-6810webappsphp
Multiple SQL injection vulnerabilities in admin/checklogin.php in Venalsur Booking Centre Booking System for Hotels Grou
23RIESGO
abrir
ReferênciaVexDay Proof
PHPwebnews 0.2 MySQL Edition - 'det' SQL Injection
CVE-2008-6812webappsphp
SQL injection vulnerability in bukutamu.php in phpWebNews 0.2 MySQL Edition allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
Vortex Portal 1.0.42 - Remote File Inclusion
CVE-2007-5842webappsphp
Multiple PHP remote file inclusion vulnerabilities in Vortex Portal 1.0.42 allow remote attackers to execute arbitrary P
35RIESGO
abrir
ReferênciaVexDay Proof
PHPwebnews 0.2 MySQL Edition - 'id_kat' SQL Injection
CVE-2008-6813webappsphp
SQL injection vulnerability in index.php in phpWebNews 0.2 MySQL Edition allows remote attackers to execute arbitrary SQ
23RIESGO
abrir
ReferênciaVexDay Proof
MaxCMS 2.0 - '/inc/ajax.asp' SQL Injection
CVE-2009-1764webappsasp
SQL injection vulnerability in inc/ajax.asp in MaxCMS 2.0 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
ReferênciaVexDay Proof
Mambo Component SimpleBoard 1.0.1 - Arbitrary File Upload
CVE-2008-6814webappsphp
Unrestricted file upload vulnerability in image_upload.php in the SimpleBoard (com_simpleboard) component 1.0.1 and earl
23RIESGO
abrir
ReferênciaVexDay Proof
A-Link WL54AP3 / WL54AP2 - Cross-Site Request Forgery / Cross-Site Scripting
CVE-2008-6824remotehardware
The management interface on the A-LINK WL54AP3 and WL54AP2 access points has a blank default password for the admin acco
23RIESGO
abrir
ReferênciaVexDay Proof
Ubuntu 6.06 - DHCPd Remote Denial of Service
CVE-2007-5365dosmultiple
Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some othe
45RIESGO
abrir
ReferênciaVexDay Proof
LightOpenCMS 0.1 - 'id' SQL Injection
CVE-2009-1766webappsphp
SQL injection vulnerability in index.php in LightOpenCMS 0.1 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component AlphaUserPoints - SQL Injection
CVE-2009-3342webappsphp
SQL injection vulnerability in frontend/assets/ajax/checkusername.php in the AlphaUserPoints (com_alphauserpoints) compo
23RIESGO
abrir
ReferênciaVexDay Proof
DFD Cart 1.1 - Multiple Remote File Inclusions
CVE-2007-5098webappsphp
Multiple PHP remote file inclusion vulnerabilities in DFD Cart 1.1.4 and earlier, when register_globals is enabled, allo
35RIESGO
abrir
ReferênciaVexDay Proof
FeedMon 2.7.0.0 - outline Tag Buffer Overflow (PoC)
CVE-2009-0546doswindows
Stack-based buffer overflow in NewsGator FeedDemon 2.7 and earlier allows user-assisted remote attackers to execute arbi
50RIESGO
abrir
ReferênciaVexDay Proof
Real Player - 'rmoc3260.dll' ActiveX Control Remote Code Execution
CVE-2008-1309remotewindows
The RealAudioObjects.RealAudio ActiveX control in rmoc3260.dll in RealNetworks RealPlayer Enterprise, RealPlayer 10, Rea
50RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component DBQuery 1.4.1.1 - Remote File Inclusion
CVE-2008-6841webappsphp
PHP remote file inclusion vulnerability in the Green Mountain Information Technology and Consulting Database Query (com_
23RIESGO
abrir
ReferênciaVexDay Proof
LS Simple Guestbook 1.0 - Remote Code Execution
CVE-2007-2093webappsphp
Direct static code injection vulnerability in index.php in Limesoft Guestbook (LS Simple Guestbook) 1.0 allows remote at
35RIESGO
abrir
ReferênciaVexDay Proof
Microsoft SQL Server - Distributed Management Objects 'sqldmo.dll' Buffer Overflow (PoC)
CVE-2007-4814doswindows
Buffer overflow in the SQLServer ActiveX control in the Distributed Management Objects OLE DLL (sqldmo.dll) 2000.085.200
35RIESGO
abrir
ReferênciaVexDay Proof
WebDesktop 0.1 - Remote File Inclusion
CVE-2007-5388webappsphp
Multiple PHP remote file inclusion vulnerabilities in WebDesktop 0.1 allow remote attackers to execute arbitrary PHP cod
35RIESGO
abrir
ReferênciaVexDay Proof
CuteNews 1.1.1 - 'html.php' Remote Code Execution
CVE-2008-4557webappsphp
plugins/wacko/highlight/html.php in Strawberry in CuteNews.ru 1.1.1 (aka Strawberry) allows remote attackers to execute
35RIESGO
abrir
ReferênciaVexDay Proof
Pluck CMS 4.6.1 - 'module_pages_site.php' Local File Inclusion
CVE-2008-6842webappsphp
Directory traversal vulnerability in data/modules/blog/module_pages_site.php in Pluck 4.6.1 allows remote attackers to i
23RIESGO
abrir
ReferênciaVexDay Proof
PicoFlat CMS 0.4.14 - 'index.php' Remote File Inclusion
CVE-2007-5390webappsphp
PHP remote file inclusion vulnerability in index.php in PicoFlat CMS 0.4.14 and earlier allows remote attackers to execu
23RIESGO
abrir
ReferênciaVexDay Proof
phpGreetCards - Cross-Site Scripting / Arbitrary File Upload
CVE-2008-6848webappsphp
Cross-site scripting (XSS) vulnerability in index.php in phpGreetCards 3.7 allows remote attackers to inject arbitrary w
23RIESGO
abrir
ReferênciaVexDay Proof
PHPSlash 0.8.1.1 - Remote Code Execution
CVE-2009-0517webappsphp
Eval injection vulnerability in index.php in phpSlash 0.8.1.1 and earlier allows remote attackers to execute arbitrary P
35RIESGO
abrir
ReferênciaVexDay Proof
VIDEOSCRIPT.us - Authentication Bypass
CVE-2009-1804webappsphp
Multiple SQL injection vulnerabilities in admin/index.php in VideoScript.us YouTube Video Script allow remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
phpGreetCards - Cross-Site Scripting / Arbitrary File Upload
CVE-2008-6849webappsphp
Unrestricted file upload vulnerability in index.php in phpGreetCards 3.7 allows remote attackers to execute arbitrary PH
23RIESGO
abrir
ReferênciaVexDay Proof
PHPLD 3.3 - Blind SQL Injection
CVE-2008-6851webappsphp
SQL injection vulnerability in page.php in PHP Link Directory (phpLD) 3.3, when register_globals is enabled and magic_qu
23RIESGO
abrir
ReferênciaVexDay Proof
CMS NetCat 3.0/3.12 - Blind SQL Injection
CVE-2008-6853webappsphp
SQL injection vulnerability in modules/poll/index.php in AIST NetCat 3.0 and 3.12 allows remote attackers to execute arb
23RIESGO
abrir
ReferênciaVexDay Proof
Absolute News Feed 1.0 - Remote Insecure Cookie Handling
CVE-2008-6855webappsphp
Xigla Software Absolute News Feed 1.0 and possibly 1.5 allows remote attackers to bypass authentication and gain adminis
23RIESGO
abrir
ReferênciaVexDay Proof
Absolute News Manager 5.1 - Insecure Cookie Handling
CVE-2008-6856webappsphp
Xigla Software Absolute News Manager.NET 5.1 allows remote attackers to bypass authentication and gain administrative ac
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.