Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
Netartmedia Car Portal 1.0 - Authentication Bypass
CVE-2009-0395webappsphp
SQL injection vulnerability in the login feature in NetArt Media Car Portal 1.0 allows remote attackers to execute arbit
23RIESGO
abrir
ReferênciaVexDay Proof
SmartSiteCMS 1.0 - Blind SQL Injection
CVE-2009-0405webappsphp
SQL injection vulnerability in articles.php in smartSite CMS 1.0 allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
ReferênciaVexDay Proof
Community CMS 0.4 - 'id' Blind SQL Injection
CVE-2009-0406webappsphp
SQL injection vulnerability in index.php in Community CMS 0.4 and earlier allows remote attackers to execute arbitrary S
23RIESGO
abrir
ReferênciaVexDay Proof
Max.Blog 1.0.6 - 'offline_auth.php' Offline Authentication Bypass
CVE-2009-0409webappsphp
SQL injection vulnerability in offline_auth.php in Max.Blog 1.0.6 and earlier, when magic_quotes_gpc is disabled, allows
23RIESGO
abrir
ReferênciaVexDay Proof
Blue Eye CMS 1.0.0 - 'clanek' Blind SQL Injection
CVE-2009-0425webappsphp
SQL injection vulnerability in index.php in Blue Eye CMS 1.0.0 and earlier allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
DMXReady Classified Listings Manager 1.1 - SQL Injection
CVE-2009-0426webappsasp
SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Classified Listings Manager 1.1 and
23RIESGO
abrir
ReferênciaVexDay Proof
DMXReady Member Directory Manager 1.1 - SQL Injection
CVE-2009-0427webappsasp
SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Member Directory Manager 1.1 and ea
23RIESGO
abrir
ReferênciaVexDay Proof
PHPbbBook 1.3 - 'bbcode.php?l' Local File Inclusion
CVE-2009-0442webappsphp
Directory traversal vulnerability in bbcode.php in PHPbbBook 1.3 and 1.3h allows remote attackers to include and execute
23RIESGO
abrir
ReferênciaVexDay Proof
GOM Player 2.1.6.3499 - 'GomWeb3.dll 1.0.0.12' Remote Overflow
CVE-2007-5779remotewindows
Buffer overflow in the GomManager (GomWeb Control) ActiveX control in GomWeb3.dll 1.0.0.12 in Gretech Online Movie Playe
60RIESGO
abrir
ReferênciaVexDay Proof
Elecard AVC HD player - '.m3u' / '.xpl' Local Stack Overflow (PoC)
CVE-2009-0443doswindows
Stack-based buffer overflow in Elecard AVC HD PLAYER 5.5.90116 allows remote attackers to execute arbitrary code via an
23RIESGO
abrir
ReferênciaVexDay Proof
DreamPics Photo/Video Gallery - Blind SQL Injection
CVE-2009-0445webappsphp
SQL injection vulnerability in index.php in Dreampics Gallery Builder allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
ReferênciaVexDay Proof
MyDesing Sayac 2.0 - Authentication Bypass
CVE-2009-0447webappsasp
Multiple SQL injection vulnerabilities in default.asp in MyDesign Sayac 2.0 allow remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component com_school 1.4 - 'classid' SQL Injection
CVE-2009-2014webappsphp
SQL injection vulnerability in the ComSchool (com_school) component 1.4 for Joomla! allows remote attackers to execute a
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Windows - '.doc' Malformed Pointers Denial of Service
CVE-2007-1347doswindows
Microsoft Windows Explorer on Windows 2000 SP4 FR and XP SP2 FR, and possibly other versions and platforms, allows remot
35RIESGO
abrir
ReferênciaVexDay Proof
DM Guestbook 0.4.1 - Multiple Local File Inclusions
CVE-2007-5821webappsphp
Multiple directory traversal vulnerabilities in DM Guestbook 0.4.1 and earlier allow remote attackers to include and exe
23RIESGO
abrir
ReferênciaVexDay Proof
nuBoard 0.5 - 'site' Remote File Inclusion
CVE-2007-5841webappsphp
PHP remote file inclusion vulnerability in admin/index.php in nuBoard 0.5 allows remote attackers to execute arbitrary P
35RIESGO
abrir
ReferênciaVexDay Proof
BlazeVideo HDTV Player 3.5 - '.PLF' Playlist File Local Overflow
CVE-2009-0450localwindows
Stack-based buffer overflow in BlazeVideo HDTV Player 3.5 and earlier allows remote attackers to execute arbitrary code
28RIESGO
abrir
ReferênciaVexDay Proof
NCTAudioStudio2 - ActiveX DLL 2.6.1.148 'CreateFile()'/ Insecure Method
CVE-2007-3493remotewindows
A certain ActiveX control in NCTWavChunksEditor2.dll 2.6.1.148 in NCTAudioStudio (NCTAudioStudio2) 2.7, as used by Sienz
35RIESGO
abrir
ReferênciaVexDay Proof
Online Grades 3.2.4 - Authentication Bypass
CVE-2009-0452webappsphp
Multiple SQL injection vulnerabilities in parents/login.php in Online Grades 3.2.4, when magic_quotes_gpc is disabled, a
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component com_colorlab 1.0 - Remote File Inclusion
CVE-2007-5451webappsphp
PHP remote file inclusion vulnerability in admin.color.php in the com_colorlab (aka com_color) 1.0 component for Joomla!
35RIESGO
abrir
ReferênciaVexDay Proof
MyCars Automotive - Authentication Bypass
CVE-2009-2018webappsphp
SQL injection vulnerability in admin/index.php in Jared Eckersley MyCars, when magic_quotes_gpc is disabled, allows remo
23RIESGO
abrir
ReferênciaVexDay Proof
AJA Portal 1.2 (Windows) - Local File Inclusion
CVE-2009-0457webappsphp
Multiple directory traversal vulnerabilities in AJA Portal 1.2 allow remote attackers to include and execute arbitrary l
23RIESGO
abrir
ReferênciaVexDay Proof
WholeHogSoftware Ware Support - Authentication Bypass
CVE-2009-0458webappsphp
Multiple SQL injection vulnerabilities in admin/login_submit.php in Whole Hog Ware Support 1.x allow remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Visual Studio 6.0 - 'PDWizard.ocx' Remote Command Execution
CVE-2007-4891remotewindows
A certain ActiveX control in PDWizard.ocx 6.0.0.9782 and earlier in Microsoft Visual Studio 6.0 exposes dangerous (1) St
35RIESGO
abrir
ReferênciaVexDay Proof
WholeHogSoftware Password Protect - Authentication Bypass
CVE-2009-0459webappsphp
Multiple SQL injection vulnerabilities in admin/login_submit.php in Whole Hog Password Protect: Enhanced 1.x allow remot
23RIESGO
abrir
ReferênciaVexDay Proof
GuppY 4.6.3 - 'index.php?selskin' Remote File Inclusion
CVE-2007-5844webappsphp
Directory traversal vulnerability in inc/includes.inc in GuppY 4.6.3 allows remote attackers to include and execute arbi
23RIESGO
abrir
ReferênciaVexDay Proof
WorkSimple 1.2.1 - Remote File Inclusion / Sensitive Data Disclosure
CVE-2008-5764webappsphp
PHP remote file inclusion vulnerability in calendar.php in WorkSimple 1.2.1, when register_globals is enabled, allows re
35RIESGO
abrir
ReferênciaVexDay Proof
WholeHogSoftware Ware Support - Insecure Cookie Handling
CVE-2009-0460webappsphp
Whole Hog Ware Support 1.x allows remote attackers to bypass authentication and obtain administrative access via an inte
23RIESGO
abrir
ReferênciaVexDay Proof
GuppY 4.5.16 - Remote Command Execution
CVE-2007-5845webappsphp
Directory traversal vulnerability in error.php in GuppY 4.6.3, 4.5.16, and earlier allows remote attackers to include an
23RIESGO
abrir
ReferênciaVexDay Proof
WholeHogSoftware Password Protect - Insecure Cookie Handling
CVE-2009-0461webappsphp
Whole Hog Password Protect: Enhanced 1.x allows remote attackers to bypass authentication and obtain administrative acce
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.