Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
Absolute Podcast 1.0 - Remote Insecure Cookie Handling
CVE-2008-6857webappsphp
Absolute Podcast .NET 1.0 allows remote attackers to bypass authentication and gain administrative access by setting a c
23RIESGO
abrir
ReferênciaVexDay Proof
Absolute Poll Manager XE 4.1 - Insecure Cookie Handling
CVE-2008-6860webappsphp
Xigla Software Absolute Poll Manager XE 4.1 allows remote attackers to bypass authentication and gain administrative acc
23RIESGO
abrir
ReferênciaVexDay Proof
Absolute NewsLetter 6.1 - Insecure Cookie Handling
CVE-2008-6861webappsphp
Xigla Software Absolute Newsletter 6.0 and 6.1 allows remote attackers to bypass authentication and gain administrative
23RIESGO
abrir
ReferênciaVexDay Proof
Absolute Content Rotator 6.0 - Insecure Cookie Handling
CVE-2008-6862webappsphp
Absolute Content Rotator 6.0 allows remote attackers to bypass authentication and gain administrative access by setting
23RIESGO
abrir
ReferênciaVexDay Proof
phpBB Plus 1.53 - 'phpbb_root_path' Remote File Inclusion
CVE-2007-5009webappsphp
PHP remote file inclusion vulnerability in language/lang_german/lang_main_album.php in phpBB Plus 1.53, and 1.53a before
35RIESGO
abrir
ReferênciaVexDay Proof
my-colex 1.4.2 - Authentication Bypass / SQL Injection / Cross-Site Scripting
CVE-2009-1810webappsphp
Multiple SQL injection vulnerabilities in myColex 1.4.2 allow remote attackers to execute arbitrary SQL commands via (1)
23RIESGO
abrir
ReferênciaVexDay Proof
TikiWiki 1.9.8 - Remote PHP Injection
CVE-2007-5423webappsphp
tiki-graph_formula.php in TikiWiki 1.9.8 allows remote attackers to execute arbitrary code via PHP sequences in the f ar
60RIESGO
abrir
ReferênciaVexDay Proof
SasCam WebCam Server 2.6.5 - ActiveX Remote Buffer Overflow
CVE-2008-6898remotewindows
Buffer overflow in the XHTTP Module 4.1.0.0 in the ActiveX control for SaschArt SasCam Webcam Server 2.6.5 allows remote
50RIESGO
abrir
ReferênciaVexDay Proof
AvailScript Article Script - Arbitrary File Upload
CVE-2008-6900webappsphp
Unrestricted file upload vulnerability in "Add Pen/Author Name" feature in addpen.php in AvailScript Article Script allo
23RIESGO
abrir
ReferênciaVexDay Proof
2532/Gigs 1.2.2 Stable - Multiple Vulnerabilities
CVE-2008-6902webappsphp
Unrestricted file upload vulnerability in upload_flyer.php in 2532designs 2532|Gigs 1.2.2 Stable allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
BabbleBoard 1.1.6 - Cross-Site Request Forgery/Cookie Grabber
CVE-2008-6905webappsphp
Cross-site request forgery (CSRF) vulnerability in index.php in BabbleBoard 1.1.6 allows remote authenticated users to h
23RIESGO
abrir
ReferênciaVexDay Proof
cPanel 11.x - Cross-Site Scripting / Local File Inclusion
CVE-2008-6927webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in autoinstall4imagesgalleryupgrade.php in the Fantastico De Luxe Mo
23RIESGO
abrir
ReferênciaVexDay Proof
PHPStore Complete Classifieds Script - Arbitrary File Upload
CVE-2008-6928webappsphp
Unrestricted file upload vulnerability in PHPStore Complete Classifieds allows remote authenticated users to execute arb
23RIESGO
abrir
ReferênciaVexDay Proof
PHPStore PHP Job Search Script - Arbitrary File Upload
CVE-2008-6931webappsphp
Unrestricted file upload vulnerability in PHPStore Job Search (aka PHPCareers) allows remote authenticated users to exec
23RIESGO
abrir
ReferênciaVexDay Proof
eXtremail 2.1.1 - PLAIN Authentication Remote Stack Overflow
CVE-2007-5466remotelinux
Multiple buffer overflows in eXtremail 2.1.1 and earlier allow remote attackers to (1) have an unknown impact by sending
28RIESGO
abrir
ReferênciaVexDay Proof
eXtremail 2.1.1 - 'memmove()' Remote Denial of Service
CVE-2007-5467doslinux
Integer overflow in eXtremail 2.1.1 and earlier allows remote attackers to cause a denial of service, and possibly execu
28RIESGO
abrir
ReferênciaVexDay Proof
Alstrasoft SendIt Pro - Arbitrary File Upload
CVE-2008-6932webappsphp
Unrestricted file upload vulnerability in submit_file.php in AlstraSoft SendIt Pro allows remote attackers to execute ar
23RIESGO
abrir
ReferênciaVexDay Proof
Exodus 0.10 - URI Handler Arbitrary Parameter Injection (2)
CVE-2008-6935remotewindows
Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, over
23RIESGO
abrir
ReferênciaVexDay Proof
Pi3Web 2.0.3 - 'ISAPI' Remote Denial of Service
CVE-2008-6938doswindows
Pi3Web 2.0.3 before PL2, when installed on Windows as a desktop application and without using the Pi3Web/Conf/Intenet.pi
43RIESGO
abrir
ReferênciaVexDay Proof
ScriptsFeed (SF) Real Estate Classifieds Software - Arbitrary File Upload
CVE-2008-6942webappsphp
Unrestricted file upload vulnerability in ScriptsFeed Realtor Classifieds System (aka Real Estate Classifieds) allows re
23RIESGO
abrir
ReferênciaVexDay Proof
Collabtive 0.4.8 - Cross-Site Scripting / Authentication Bypass / Arbitrary File Upload
CVE-2008-6948webappsphp
Unrestricted file upload vulnerability in Collabtive 0.4.8 allows remote authenticated users to execute arbitrary code b
23RIESGO
abrir
ReferênciaVexDay Proof
Bankoi Webhost Panel 1.20 - Authentication Bypass
CVE-2008-6950webappsasp
Multiple SQL injection vulnerabilities in login.asp in Bankoi WebHosting Control Panel 1.20 allow remote attackers to ex
23RIESGO
abrir
ReferênciaVexDay Proof
ooVoo 1.7.1.35 - 'URL Protocol' Remote Unicode Buffer Overflow (PoC)
CVE-2008-6953doswindows
Buffer overflow in oovoo.exe in ooVoo 1.7.1.35, and possibly other versions before 1.7.1.59, allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
X7 Chat 2.0.5 - Authentication Bypass
CVE-2008-6964webappsphp
SQL injection vulnerability in the login page in X7 Chat 2.0.5 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
aspwebalbum 3.2 - Multiple Vulnerabilities
CVE-2008-6978webappsasp
Unrestricted file upload vulnerability in Full Revolution aspWebAlbum 3.2 allows remote attackers to execute arbitrary c
23RIESGO
abrir
ReferênciaVexDay Proof
aspwebalbum 3.2 - Arbitrary File Upload / SQL Injection / Cross-Site Scripting
CVE-2008-6978webappsphp
Unrestricted file upload vulnerability in Full Revolution aspWebAlbum 3.2 allows remote attackers to execute arbitrary c
23RIESGO
abrir
ReferênciaVexDay Proof
Google Chrome 0.2.149.27 - 'SaveAs' Remote Buffer Overflow
CVE-2008-6994remotewindows
Stack-based buffer overflow in the SaveAs feature (SaveFileAsWithFilter function) in win_util.cc in Google Chrome 0.2.14
28RIESGO
abrir
ReferênciaVexDay Proof
The Rat CMS Alpha 2 - Authentication Bypass
CVE-2008-7003webappsphp
Multiple SQL injection vulnerabilities in login.php in The Rat CMS Alpha 2 allow remote attackers to execute arbitrary S
23RIESGO
abrir
ReferênciaVexDay Proof
SkaLinks 1.5 - 'register.php' Arbitrary Add Editor
CVE-2008-7010webappsphp
Skalfa Software SkaLinks Exchange Script 1.5 allows remote attackers to add new administrators and gain privileges via a
23RIESGO
abrir
ReferênciaVexDay Proof
Chilkat IMAP ActiveX 7.9 - File Execution / Denial of Service
CVE-2008-7022remotewindows
Insecure method vulnerability in ChilkatMail_v7_9.dll in the Chilkat Software IMAP ActiveX control (ChilkatMail2.Chilkat
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.