Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
eFront 3.5.1 / build 2710 - Arbitrary File Upload
CVE-2008-7026webappsphp
Unrestricted file upload vulnerability in filesystem3.class.php in eFront 3.5.1 build 2710 and earlier allows remote att
23RIESGO
abrir
ReferênciaVexDay Proof
XOOPS Module My_eGallery 3.04 - 'gid' SQL Injection
CVE-2008-7038webappsphp
SQL injection vulnerability in the My_eGallery module for PHP-Nuke allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
ReferênciaVexDay Proof
EZContents CMS 2.0.3 - Multiple Local File Inclusions
CVE-2008-7055webappsphp
module.php in ezContents 2.0.3 allows remote attackers to bypass the directory traversal protection mechanism to include
23RIESGO
abrir
ReferênciaVexDay Proof
BandSite CMS 1.1.4 - Download Backup / Cross-Site Scripting / Cross-Site Request Forgery
CVE-2008-7056webappsphp
BandSite CMS 1.1.4 does not perform access control for adminpanel/phpmydump.php, which allows remote attackers to obtain
23RIESGO
abrir
ReferênciaVexDay Proof
BandSite CMS 1.1.4 - Download Backup / Cross-Site Scripting / Cross-Site Request Forgery
CVE-2008-7057webappsphp
Cross-site scripting (XSS) vulnerability in merchandise.php in BandSite CMS 1.1.4 allows remote attackers to inject arbi
23RIESGO
abrir
ReferênciaVexDay Proof
k-rate - SQL Injection / Cross-Site Scripting
CVE-2008-7098webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in Qsoft K-Rate Premium allow remote attackers to inject arbitrary w
23RIESGO
abrir
ReferênciaVexDay Proof
k-rate - SQL Injection / Cross-Site Scripting
CVE-2008-7099webappsphp
Unspecified vulnerability in the Manage Templates feature in Qsoft K-Rate Premium allows remote attackers to execute arb
23RIESGO
abrir
ReferênciaVexDay Proof
WeBid 0.5.4 - 'item.php' SQL Injection
CVE-2008-7119webappsphp
SQL injection vulnerability in item.php in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
ReferênciaVexDay Proof
VideoLAN VLC Media Player < 0.9.6 - '.rt' Local Stack Buffer Overflow
CVE-2008-5036localwindows
Stack-based buffer overflow in VideoLAN VLC media player 0.9.x before 0.9.6 might allow user-assisted attackers to execu
50RIESGO
abrir
ReferênciaVexDay Proof
Artmedic CMS 3.4 - 'index.php' Local File Inclusion
CVE-2007-5489webappsphp
Directory traversal vulnerability in index.php in Artmedic CMS 3.4 and earlier allows remote attackers to include and ex
23RIESGO
abrir
ReferênciaVexDay Proof
zKup CMS 2.0 < 2.3 - Arbitrary File Upload
CVE-2008-7124webappsphp
zKup CMS 2.0 through 2.3 does not require administrative authentication for admin/configuration/modifier.php, which allo
23RIESGO
abrir
ReferênciaVexDay Proof
zKup CMS 2.0 < 2.3 - Remote Add Admin
CVE-2008-7124webappsphp
zKup CMS 2.0 through 2.3 does not require administrative authentication for admin/configuration/modifier.php, which allo
23RIESGO
abrir
ReferênciaVexDay Proof
Soulseek 157 NS - Remote Buffer Overflow (SEH)
CVE-2009-1830remotewindows
Stack-based buffer overflow in Soulseek 156 and 157 NS allows remote attackers to execute arbitrary code via a long sear
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component jabode - 'id' SQL Injection
CVE-2008-7169webappsphp
SQL injection vulnerability in Jabode horoscope extension (com_jabode) for Joomla! allows remote attackers to execute ar
23RIESGO
abrir
ReferênciaVexDay Proof
Winamp 5.551 - MAKI Parsing Integer Overflow (PoC)
CVE-2009-1831doswindows
The Nullsoft Modern Skins Support module (gen_ff.dll) in Nullsoft Winamp before 5.552 allows remote attackers to execute
50RIESGO
abrir
ReferênciaVexDay Proof
Cisco Phone 7940 - Remote Denial of Service
CVE-2007-5583doshardware
Cisco IP Phone 7940 with firmware P0S3-08-7-00 allows remote attackers to cause a denial of service ("486 Busy" response
23RIESGO
abrir
ReferênciaVexDay Proof
Chilkat Crypt - ActiveX Arbitrary File Creation/Execution
CVE-2008-5002remotewindows
Insecure method vulnerability in the ChilkatCrypt2.ChilkatCrypt2.1 ActiveX control (ChilkatCrypt2.dll 4.3.2.1) in Chilka
50RIESGO
abrir
ReferênciaVexDay Proof
Lightweight news portal (LNP) 1.0b - Multiple Vulnerabilities
CVE-2008-7172webappsphp
Lightweight news portal (LNP) 1.0b does not properly restrict access to administrator functionality, which allows remote
23RIESGO
abrir
ReferênciaVexDay Proof
Facil-CMS 0.1RC - Multiple Local File Inclusions
CVE-2008-7176webappsphp
Multiple directory traversal vulnerabilities in Facil CMS 0.1RC allow remote attackers to read arbitrary files via a ..
23RIESGO
abrir
ReferênciaVexDay Proof
Winamp 5.551 - MAKI Parsing Integer Overflow
CVE-2009-1831localwindows
The Nullsoft Modern Skins Support module (gen_ff.dll) in Nullsoft Winamp before 5.552 allows remote attackers to execute
50RIESGO
abrir
ReferênciaVexDay Proof
OTManager CMS 2.4 - Insecure Cookie Handling
CVE-2008-7179webappsphp
OTManager CMS 2.4 allows remote attackers to bypass authentication and gain administrator privileges by setting the ADMI
23RIESGO
abrir
ReferênciaVexDay Proof
Half-Life CSTRIKE Server 1.6 - 'no-steam' Denial of Service
CVE-2008-7203dosmultiple
Valve Software Half-Life Counter-Strike 1.6 allows remote attackers to cause a denial of service (crash) via multiple cr
23RIESGO
abrir
ReferênciaVexDay Proof
OneCMS 2.4 - SQL Injection / Upload
CVE-2008-7209webappsphp
Unrestricted file upload vulnerability in the add2 action in a_upload.php in OneCMS 2.4, and possibly earlier, allows re
23RIESGO
abrir
ReferênciaVexDay Proof
Mozilla Firefox 3.0.6 - BODY onload Remote Crash
CVE-2009-0071dosmultiple
Mozilla Firefox 3.0.5 and earlier 3.0.x versions, when designMode is enabled, allows remote attackers to cause a denial
23RIESGO
abrir
ReferênciaVexDay Proof
Discloser 0.0.4 - 'fileloc' Remote File Inclusion
CVE-2006-4207webappsphp
Multiple PHP remote file inclusion vulnerabilities in Bob Jewell Discloser 0.0.4 and earlier allow remote attackers to e
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Internet Explorer 7 - Memory Corruption (PoC) (MS09-002)
CVE-2009-0075doswindows
Microsoft Internet Explorer 7 does not properly handle errors during attempted access to deleted objects, which allows r
60RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Internet Explorer 7 (Windows 2003 SP2) - Memory Corruption (MS09-002)
CVE-2009-0075remotewindows
Microsoft Internet Explorer 7 does not properly handle errors during attempted access to deleted objects, which allows r
60RIESGO
abrir
ReferênciaVexDay Proof
phpBB All Topics Mod 1.5.0 - 'start' SQL Injection
CVE-2006-4367webappsphp
SQL injection vulnerability in alltopics.php in the All Topics Hack 1.5.0 and earlier for phpBB 2.0.21 allows remote att
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Internet Explorer 7 (Windows XP SP2) - Memory Corruption (MS09-002)
CVE-2009-0075remotewindows
Microsoft Internet Explorer 7 does not properly handle errors during attempted access to deleted objects, which allows r
60RIESGO
abrir
ReferênciaVexDay Proof
Foxit Reader 9.7.1 - Remote Command Execution (Javascript API)
CVE-2020-14425localwindows
Foxit Reader before 10.0 allows Remote Command Execution via the app.opencPDFWebPage JavsScript API. An attacker can exe
35RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.