Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
impleo music Collection 2.0 - SQL Injection / Cross-Site Scripting
CVE-2009-2154webappsphp
SQL injection vulnerability in admin/login.php in Impleo Music Collection 2.0, when magic_quotes_gpc is disabled, allows
23RIESGO
abrir
ReferênciaVexDay Proof
Kjtechforce mailman b1 - Delete Row 'code' SQL Injection
CVE-2009-2164webappsphp
Multiple SQL injection vulnerabilities in Kjtechforce mailman beta1, when magic_quotes_gpc is disabled, allow remote att
23RIESGO
abrir
ReferênciaVexDay Proof
Carom3D 5.06 - Unicode Buffer Overrun/Denial of Service
CVE-2009-2173doswindows
The LAN game feature in Carom3D 5.06 allows remote authenticated users to cause a denial of service (application hang) v
23RIESGO
abrir
ReferênciaVexDay Proof
Fuzzylime CMS 3.03a - Local Inclusion / Arbitrary File Corruption
CVE-2009-2176webappsphp
Multiple directory traversal vulnerabilities in fuzzylime (cms) 3.03a and earlier, when magic_quotes_gpc is disabled, al
23RIESGO
abrir
ReferênciaVexDay Proof
Fuzzylime CMS 3.03a - Local Inclusion / Arbitrary File Corruption
CVE-2009-2177webappsphp
code/display.php in fuzzylime (cms) 3.03a and earlier, when magic_quotes_gpc is disabled, allows remote attackers to con
23RIESGO
abrir
ReferênciaVexDay Proof
phpDatingClub 3.7 - SQL Injection / Cross-Site Scripting Injection
CVE-2009-2179webappsphp
SQL injection vulnerability in search.php in phpDatingClub 3.7 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
pc4 Uploader 10.0 - Remote File Disclosure
CVE-2009-2180webappsphp
Multiple directory traversal vulnerabilities in upfiles/index.php in Pc4 Uploader 10.0 and earlier allow remote attacker
23RIESGO
abrir
ReferênciaVexDay Proof
Campsite 3.3.0 RC1 - Multiple Remote File Inclusions
CVE-2009-2183webappsphp
Directory traversal vulnerability in admin-files/ad.php in Campsite 3.3.0 RC1 allows remote attackers to read and possib
23RIESGO
abrir
ReferênciaVexDay Proof
RS-CMS 2.1 - 'key' SQL Injection
CVE-2009-2209webappsphp
SQL injection vulnerability in rscms_mod_newsview.php in RS-CMS 2.1 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
ReferênciaVexDay Proof
Adobe Acrobat 9 - ActiveX Remote Denial of Service
CVE-2008-4071doswindows
A certain ActiveX control in Adobe Acrobat 9, when used with Microsoft Windows Vista and Internet Explorer 7, allows rem
28RIESGO
abrir
ReferênciaVexDay Proof
WordPress Plugin User Photo Component - Arbitrary File Upload
CVE-2013-1916webappsphp
In WordPress Plugin User Photo 0.9.4, when a photo is uploaded, it is only partially validated and it is possible to upl
28RIESGO
abrir
ReferênciaVexDay Proof
LoveCMS 1.6.2 Final - Remote Code Execution
CVE-2008-3509webappsphp
LoveCMS 1.6.2 does not require administrative authentication for (1) addblock.php, (2) blocks.php, and (3) themes.php in
23RIESGO
abrir
ReferênciaVexDay Proof
Solaris 9 PortBind - XDR-DECODE 'taddr2uaddr()' Remote Denial of Service
CVE-2008-4619dossolaris
The RPC subsystem in Sun Solaris 9 allows remote attackers to cause a denial of service (daemon crash) via a crafted req
28RIESGO
abrir
ReferênciaVexDay Proof
Online Fantasy Football League (OFFL) 0.2.6 - Remote File Inclusion
CVE-2007-4809webappsphp
Multiple PHP remote file inclusion vulnerabilities in Online Fantasy Football League (OFFL) 0.2.6 allow remote attackers
35RIESGO
abrir
ReferênciaVexDay Proof
WordPress MU < 1.3.2 - 'active_plugins' Code Execution
CVE-2008-5695webappsphp
wp-admin/options.php in WordPress MU before 1.3.2, and WordPress 2.3.2 and earlier, does not properly validate requests
28RIESGO
abrir
ReferênciaVexDay Proof
xeCMS 1.0.0 RC2 - Insecure Cookie Handling
CVE-2008-6714webappsphp
admin.php in xeCMS 1.0.0 RC2 and earlier allows remote attackers to bypass authentication and access the admin panel by
28RIESGO
abrir
ReferênciaVexDay Proof
Citadel SMTP 7.10 - Remote Overflow
CVE-2008-0394remotewindows
Buffer overflow in Citadel SMTP server 7.10 and earlier allows remote attackers to execute arbitrary code via a long RCP
28RIESGO
abrir
ReferênciaVexDay Proof
MySpace Uploader - 'MySpaceUploader.ocx 1.0.0.4' Remote Buffer Overflow
CVE-2008-0659remotewindows
Stack-based buffer overflow in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.5.70 and earlier, as used i
35RIESGO
abrir
ReferênciaVexDay Proof
Hannon Hill Cascade Server - (Authenticated) Command Execution
CVE-2009-1088webappscgi
Hannon Hill Cascade Server 5.7 and other versions allows remote authenticated users to execute arbitrary programs or Jav
28RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Word 2007 - Multiple Vulnerabilities
CVE-2007-1911doswindows
Multiple unspecified vulnerabilities in Microsoft Word 2007 allow remote attackers to cause a denial of service (CPU con
28RIESGO
abrir
ReferênciaVexDay Proof
EDraw Office Viewer Component - Denial of Service
CVE-2007-3169doswindows
Buffer overflow in a certain ActiveX control in the EDraw Office Viewer Component (edrawofficeviewer.ocx) 4.0.5.20, and
28RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component Ynews 1.0.0 - 'id' SQL Injection
CVE-2008-0653webappsphp
SQL injection vulnerability in index.php in the Ynews (com_ynews) 1.0.0 component for Joomla! allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
AspWebCalendar 2008 - Arbitrary File Upload
CVE-2008-2832webappsasp
Unrestricted file upload vulnerability in calendar_admin.asp in Full Revolution aspWebCalendar 2008 allows remote attack
28RIESGO
abrir
ReferênciaVexDay Proof
EgyPlus 7ml 1.0.1 - Authentication Bypass
CVE-2009-2168CRITICALwebappsphp
cpanel/login.php in EgyPlus 7ammel (aka 7ml) 1.0.1 and earlier sends a redirect to the web browser but does not exit whe
53RIESGO
abrir
ReferênciaVexDay Proof
Pixaria Gallery 1.x - 'class.Smarty.php' Remote File Inclusion
CVE-2007-2457webappsphp
PHP remote file inclusion vulnerability in resources/includes/class.Smarty.php in Pixaria Gallery before 1.4.3 allows re
28RIESGO
abrir
ReferênciaVexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
CVE-2007-6494webappsasp
Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to obtain login access via a request to hosting/a
28RIESGO
abrir
ReferênciaVexDay Proof
Backup Exec System Recovery Manager 7.0.1 - Arbitrary File Upload
CVE-2008-0457remotewindows
Unrestricted file upload vulnerability in the FileUpload class running on the Symantec LiveState Apache Tomcat server, a
28RIESGO
abrir
ReferênciaVexDay Proof
Apple QuickTime 7.5.5 / iTunes 8.0 - Remote Off-by-One Crash
CVE-2008-4116dosmultiple
Buffer overflow in Apple QuickTime 7.5.5 and iTunes 8.0 allows remote attackers to cause a denial of service (browser cr
28RIESGO
abrir
ReferênciaVexDay Proof
MailBee WebMail Pro 4.1 - Remote File Disclosure
CVE-2008-0333webappsasp
Directory traversal vulnerability in download_view_attachment.aspx in AfterLogic MailBee WebMail Pro 4.1 for ASP.NET all
28RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component ProDesk 1.0/1.2 - Local File Inclusion
CVE-2008-6222webappsphp
Directory traversal vulnerability in the Pro Desk Support Center (com_pro_desk) component 1.0 and 1.2 for Joomla! allows
43RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.