Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
Rayzz Script 2.0 - Local/Remote File Inclusion
CVE-2007-6229webappsphp
PHP remote file inclusion vulnerability in common/classes/class_HeaderHandler.lib.php in Rayzz Script 2.0 allows remote
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component OnlineFlashQuiz 1.0.2 - Remote File Inclusion
CVE-2008-1682webappsphp
PHP remote file inclusion vulnerability in quiz/common/db_config.inc.php in the Online FlashQuiz (com_onlineflashquiz) 1
28RIESGO
abrir
ReferênciaVexDay Proof
VMware - COM API ActiveX Remote Buffer Overflow (PoC)
CVE-2008-3892doswindows
Buffer overflow in a certain ActiveX control in the COM API in VMware Workstation 5.5.x before 5.5.8 build 108000, VMwar
28RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component Recly!Competitions 1.0.0 - Multiple Remote File Inclusions
CVE-2008-5790webappsphp
Multiple PHP remote file inclusion vulnerabilities in the Recly!Competitions (com_competitions) component 1.0 for Joomla
35RIESGO
abrir
ReferênciaVexDay Proof
Surgemail 39e-1 - (Authenticated) IMAP Remote Buffer Overflow (Denial of Service) (PoC)
CVE-2008-7182doswindows
Buffer overflow in the IMAP service in NetWin Surgemail 3.9e, and possibly other versions before 3.9g2, allows remote au
28RIESGO
abrir
ReferênciaVexDay Proof
PollHelper - Remote Configuration File Disclosure
CVE-2009-0827webappsphp
PollHelper stores poll.inc under the web root with insufficient access control, which allows remote attackers to downloa
23RIESGO
abrir
ReferênciaVexDay Proof
PHP-Fusion Mod Members CV (job) 1.0 - SQL Injection
CVE-2009-0831webappsphp
SQL injection vulnerability in members.php in the Members CV (job) module 1.0 for PHP-Fusion, when magic_quotes_gpc is d
23RIESGO
abrir
ReferênciaVexDay Proof
PHP-Fusion Mod E-Cart 1.3 - 'items.php' SQL Injection
CVE-2009-0832webappsphp
SQL injection vulnerability in items.php in the E-Cart module 1.3 for PHP-Fusion allows remote attackers to execute arbi
23RIESGO
abrir
ReferênciaVexDay Proof
ftp Admin 0.1.0 - Local File Inclusion / Cross-Site Scripting / Authentication Bypass
CVE-2007-6232webappsphp
Cross-site scripting (XSS) vulnerability in index.php in FTP Admin 0.1.0 allows remote attackers to inject arbitrary web
23RIESGO
abrir
ReferênciaVexDay Proof
S-CMS 1.1 Stable - Insecure Cookie Handling / Mass Page Delete
CVE-2009-0863webappsphp
SQL injection vulnerability in admin/delete_page.php in S-Cms 1.1 Stable allows remote attackers to execute arbitrary SQ
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Windows Media Player - '.AIFF' Divide By Zero Exception Denial of Service (PoC)
CVE-2007-6236doswindows
Microsoft Windows Media Player (WMP) allows remote attackers to cause a denial of service (application crash) via a cert
28RIESGO
abrir
ReferênciaVexDay Proof
S-CMS 1.1 Stable - Insecure Cookie Handling / Mass Page Delete
CVE-2009-0864webappsphp
S-Cms 1.1 Stable allows remote attackers to bypass authentication and obtain administrative access via an OK value for t
23RIESGO
abrir
ReferênciaVexDay Proof
GeoVision LiveX 8200 - ActiveX 'LIVEX_~1.OCX' File Corruption
CVE-2009-0865remotewindows
Directory traversal vulnerability in the SnapShotToFile method in the GeoVision LiveX (aka LiveX_v8200) ActiveX control
23RIESGO
abrir
ReferênciaVexDay Proof
pHNews Alpha 1 - 'genbackup.php' Database Disclosure
CVE-2009-0866webappsphp
pHNews Alpha 1 stores sensitive information under the web root with insufficient access control, which allows remote att
23RIESGO
abrir
ReferênciaVexDay Proof
IBM Director 5.20.3su2 CIM Server - Remote Denial of Service
CVE-2009-0879doswindows
The CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows remote attackers to cause a denial of se
23RIESGO
abrir
ReferênciaVexDay Proof
Blue Eye CMS 1.0.0 - Remote Cookie SQL Injection
CVE-2009-0883webappsphp
SQL injection vulnerability in Blue Eye CMS 1.0.0 and earlier, when magic_quotes_gpc is disabled, allows remote attacker
23RIESGO
abrir
ReferênciaVexDay Proof
Media Commands - '.m3u' / '.m3l' / '.TXT' / '.LRC' Local Heap Overflow (PoC)
CVE-2009-0885doswindows
Multiple heap-based buffer overflows in Media Commands 1.0 allow remote attackers to execute arbitrary code or cause a d
23RIESGO
abrir
ReferênciaVexDay Proof
OneOrZero Helpdesk 1.6.5.7 - Local File Inclusion
CVE-2009-0886webappsphp
Directory traversal vulnerability in login.php in OneOrZero Helpdesk 1.6.5.7 and earlier allows remote attackers to read
23RIESGO
abrir
ReferênciaVexDay Proof
Apple iTunes 8.1.1 - 'ITMS' Multiple Protocol Handler Buffer Overflow (Metasploit)
CVE-2009-0950remoteosx
Stack-based buffer overflow in Apple iTunes before 8.2 allows remote attackers to execute arbitrary code or cause a deni
43RIESGO
abrir
ReferênciaVexDay Proof
Apple iTunes 8.1.1.10 (Windows) - 'itms/itcp' Remote Buffer Overflow
CVE-2009-0950remotewindows
Stack-based buffer overflow in Apple iTunes before 8.2 allows remote attackers to execute arbitrary code or cause a deni
43RIESGO
abrir
ReferênciaVexDay Proof
WordPress Plugin fMoblog 2.1 - 'id' SQL Injection
CVE-2009-0968webappsphp
SQL injection vulnerability in fmoblog.php in the fMoblog plugin 2.1 for WordPress allows remote attackers to execute ar
23RIESGO
abrir
ReferênciaVexDay Proof
Gretech GOM Encoder 1.0.0.11 - '.Subtitle' Buffer Overflow (PoC)
CVE-2009-1022doswindows
Heap-based buffer overflow in the Preview/ Set Segment function in Gretech GOMlab GOM Encoder 1.0.0.11 and earlier allow
23RIESGO
abrir
ReferênciaVexDay Proof
Beerwin's PHPLinkAdmin 1.0 - Remote File Inclusion / SQL Injection
CVE-2009-1024webappsphp
Multiple SQL injection vulnerabilities in Beerwin PHPLinkAdmin 1.0 allow remote attackers to execute arbitrary SQL comma
23RIESGO
abrir
ReferênciaVexDay Proof
Beerwin's PHPLinkAdmin 1.0 - Remote File Inclusion / SQL Injection
CVE-2009-1025webappsphp
PHP remote file inclusion vulnerability in linkadmin.php in Beerwin PHPLinkAdmin 1.0 allows remote attackers to execute
35RIESGO
abrir
ReferênciaVexDay Proof
Kim Websites 1.0 - Authentication Bypass
CVE-2009-1026webappsphp
Multiple SQL injection vulnerabilities in login.php in Kim Websites 1.0 allow remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
eZip Wizard 3.0 - Local Stack Buffer Overflow (PoC) (SEH)
CVE-2009-1028doswindows
Stack-based buffer overflow in ediSys eZip Wizard 3.0 allows remote attackers to execute arbitrary code via a crafted .z
50RIESGO
abrir
ReferênciaVexDay Proof
WordPress MU < 2.7 - 'HOST' HTTP Header Cross-Site Scripting
CVE-2009-1030webappsphp
Cross-site scripting (XSS) vulnerability in the choose_primary_blog function in wp-includes/wpmu-functions.php in WordPr
23RIESGO
abrir
ReferênciaVexDay Proof
YAP 1.1.1 - Blind SQL Injection / SQL Injection
CVE-2009-1038webappsphp
Multiple SQL injection vulnerabilities in YAP Blog 1.1.1 allow remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir
ReferênciaVexDay Proof
FreeBSD 7.0/7.1 - 'ktimer' Local Privilege Escalation
CVE-2009-1041localfreebsd
The ktimer feature (sys/kern/kern_time.c) in FreeBSD 7.0, 7.1, and 7.2 allows local users to overwrite arbitrary kernel
23RIESGO
abrir
ReferênciaVexDay Proof
MOG-WebShop - 'index.php?group' SQL Injection
CVE-2007-6466webappsphp
Multiple SQL injection vulnerabilities in index.php in FreeWebshop 2.2.1 allow remote attackers to execute arbitrary SQL
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.