Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
Booby 1.0.1 - Multiple Remote File Inclusions
CVE-2008-2645webappsphp
Multiple PHP remote file inclusion vulnerabilities in Brim (formerly Booby) 1.0.1 allow remote attackers to execute arbi
35RIESGO
abrir
ReferênciaVexDay Proof
Socketmail 2.2.8 - 'fnc-readmail3.php' Remote File Inclusion
CVE-2007-5627webappsphp
PHP remote file inclusion vulnerability in content/fnc-readmail3.php in SocketMail 2.2.8 allows remote attackers to exec
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Internet Explorer 7 - Memory Corruption (MS09-002)
CVE-2009-0075remotewindows
Microsoft Internet Explorer 7 does not properly handle errors during attempted access to deleted objects, which allows r
60RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component AgoraGroup 0.3.5.3 - Blind SQL Injection
CVE-2009-1848webappsphp
SQL injection vulnerability in the JoomlaMe AgoraGroups (aka AG or com_agoragroup) component 0.3.5.3 for Joomla! allows
23RIESGO
abrir
ReferênciaVexDay Proof
Wordsmith 1.1b - 'config.inc.php?_path' Remote File Inclusion
CVE-2007-5102webappsphp
PHP remote file inclusion vulnerability in config.inc.php in Wordsmith 1.0 RC1, when register_globals is enabled, allows
35RIESGO
abrir
ReferênciaVexDay Proof
Sige 0.1 - 'sige_init.php' Remote File Inclusion
CVE-2007-5781webappsphp
PHP remote file inclusion vulnerability in inc/sige_init.php in Sige 0.1 allows remote attackers to execute arbitrary PH
35RIESGO
abrir
ReferênciaVexDay Proof
PlaySms 0.9.3 - Multiple Local/Remote File Inclusions
CVE-2009-0103webappsphp
Multiple PHP remote file inclusion vulnerabilities in playSMS 0.9.3 allow remote attackers to execute arbitrary PHP code
28RIESGO
abrir
ReferênciaVexDay Proof
ezpack 4.2b2 - Cross-Site Scripting / SQL Injection
CVE-2009-0104webappsphp
SQL injection vulnerability in index.php in EZpack 4.2b2 allows remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir
ReferênciaVexDay Proof
Mambo Component com_lurm_constructor 0.6b - Remote File Inclusion
CVE-2006-4372webappsphp
PHP remote file inclusion vulnerability in admin.lurm_constructor.php in the Lurm Constructor component (com_lurm_constr
23RIESGO
abrir
ReferênciaVexDay Proof
pSlash 0.7 - 'lvc_include_dir' Remote File Inclusion
CVE-2006-4373webappsphp
PHP remote file inclusion vulnerability in modules/visitors2/include/config.inc.php in pSlash 0.70 allows remote attacke
23RIESGO
abrir
ReferênciaVexDay Proof
PeopleAggregator 1.2pre6-release-53 - Multiple Remote File Inclusions
CVE-2007-5631webappsphp
Multiple PHP remote file inclusion vulnerabilities in PeopleAggregator 1.2pre6, when register_globals is enabled, allow
35RIESGO
abrir
ReferênciaVexDay Proof
RiotPix 0.61 - Authentication Bypass
CVE-2009-0109webappsphp
SQL injection vulnerability in index.php in RiotPix 0.61 and earlier allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir
ReferênciaVexDay Proof
Goople 1.8.2 - 'FrontPage.php' Blind SQL Injection
CVE-2009-0111webappsphp
SQL injection vulnerability in frontpage.php in Goople CMS 1.8.2 and earlier allows remote attackers to execute arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
Apple QuickTime 7.2/7.3 (OSX/Windows) - RSTP Response Universal
CVE-2002-0252remotemultiple
Buffer overflow in Apple QuickTime Player 5.01 and 5.02 allows remote web servers to execute arbitrary code via a respon
28RIESGO
abrir
ReferênciaVexDay Proof
PHP Project Management 0.8.10 - Multiple Local/Remote File Inclusions
CVE-2007-5642webappsphp
Multiple directory traversal vulnerabilities in PHP Project Management 0.8.10 and earlier allow remote attackers to incl
23RIESGO
abrir
ReferênciaVexDay Proof
AAA EasyGrid ActiveX 3.51 - Remote File Overwrite
CVE-2009-0134remotewindows
Insecure method vulnerability in the EasyGrid.SGCtrl.32 ActiveX control in EasyGrid.ocx 1.0.0.1 in AAA EasyGrid ActiveX
23RIESGO
abrir
ReferênciaVexDay Proof
VUPlayer 2.49 - '.asx' HREF Local Buffer Overflow (PoC)
CVE-2009-0174doswindows
Stack-based buffer overflow in VUPlayer 2.49 allows remote attackers to execute arbitrary code via a long .asf URI in th
28RIESGO
abrir
ReferênciaVexDay Proof
VUPlayer 2.49 - '.asx' 'HREF' Universal Buffer Overflow
CVE-2009-0174localwindows
Stack-based buffer overflow in VUPlayer 2.49 allows remote attackers to execute arbitrary code via a long .asf URI in th
28RIESGO
abrir
ReferênciaVexDay Proof
VUPlayer 2.49 - '.asx' HREF Local Buffer Overflow (2)
CVE-2009-0174localwindows
Stack-based buffer overflow in VUPlayer 2.49 allows remote attackers to execute arbitrary code via a long .asf URI in th
28RIESGO
abrir
ReferênciaVexDay Proof
Free Download Manager 2.5/3.0 - Authorisation Stack Buffer Overflow (PoC)
CVE-2009-0183doswindows
Stack-based buffer overflow in Remote Control Server in Free Download Manager (FDM) 2.5 Build 758 and 3.0 Build 844 allo
50RIESGO
abrir
ReferênciaVexDay Proof
Ultra Shareware Office Control - ActiveX Control Remote Buffer Overflow
CVE-2008-3878remotewindows
Stack-based buffer overflow in the Ultra.OfficeControl ActiveX control in OfficeCtrl.ocx 2.0.2008.801 in Ultra Shareware
50RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component mp3 allopass 1.0 - Remote File Inclusion
CVE-2007-5412webappsphp
Multiple PHP remote file inclusion vulnerabilities in the Quoc-Huy MP3 Allopass (com_mp3_allopass) 1.0 component for Joo
35RIESGO
abrir
ReferênciaVexDay Proof
Realtek Sound Manager (rtlrack.exe 1.15.0.0) - Playlist Buffer Overflow
CVE-2008-5664localwindows
Stack-based buffer overflow in Realtek Media Player (aka Realtek Sound Manager, RtlRack, or rtlrack.exe) 1.15.0.0 allows
50RIESGO
abrir
ReferênciaVexDay Proof
vicFTP 5.0 - 'LIST' Remote Denial of Service
CVE-2008-6829doswindows
VicFTPS 5.0 allows remote attackers to cause a denial of service (crash) via a LIST command that starts with a "/\/" (fo
50RIESGO
abrir
ReferênciaVexDay Proof
scWiki 1.0 Beta 2 - 'common.php?pathdot' Remote File Inclusion
CVE-2007-5843webappsphp
PHP remote file inclusion vulnerability in includes/common.php in scWiki 1.0 Beta 2 allows remote attackers to execute a
35RIESGO
abrir
ReferênciaVexDay Proof
Rankem - File Disclosure / Cross-Site Scripting / Cookie
CVE-2009-0249webappsphp
Katy Whitton RankEm stores sensitive information under the web root with insufficient access control, which allows remot
23RIESGO
abrir
ReferênciaVexDay Proof
Xerox Phaser 8400 - Remote Reboot (Denial of Service)
CVE-2008-3571doshardware
The Xerox Phaser 8400 allows remote attackers to cause a denial of service (reboot) via an empty UDP packet to port 1900
35RIESGO
abrir
ReferênciaVexDay Proof
phosheezy 2.0 - Remote Command Execution
CVE-2009-0251webappsphp
Static code injection vulnerability in admin.php in Ryneezy phoSheezy 0.2 allows remote authenticated administrators to
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Windows Wordpad - '.doc' File Local Denial of Service (PoC)
CVE-2009-0259doswindows
The Word processor in OpenOffice.org 1.1.2 through 1.1.5 allows remote attackers to cause a denial of service (crash) an
23RIESGO
abrir
ReferênciaVexDay Proof
Luxbum 0.5.5/stable - Authentication Bypass
CVE-2009-1913webappsphp
SQL injection vulnerability in manager.php in LuxBum 0.5.5, when magic_quotes_gpc is disabled and dotclear authenticatio
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.