Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.039exploits catalogados
36.284CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
Mosaic Commerce - 'cid' SQL Injection
CVE-2008-4599webappsphp
SQL injection vulnerability in category.php in Mosaic Commerce allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
CafeEngine - Multiple SQL Injections
CVE-2008-4604webappsphp
SQL injection vulnerability in index.php in Easy CafeEngine 1.1 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
ReferênciaVexDay Proof
Dart Communications PowerTCP FTP module - Remote Buffer Overflow
CVE-2008-4652remotewindows
Buffer overflow in the ActiveX control (DartFtp.dll) in Dart Communications PowerTCP FTP for ActiveX 2.0.2 0 allows remo
28RIESGO
abrir
ReferênciaVexDay Proof
PowerTCP FTP Module - Multiple Techniques (SEH HeapSpray)
CVE-2008-4652remotewindows
Buffer overflow in the ActiveX control (DartFtp.dll) in Dart Communications PowerTCP FTP for ActiveX 2.0.2 0 allows remo
28RIESGO
abrir
ReferênciaVexDay Proof
Ultimate WebBoard 3.00 - 'Category' SQL Injection
CVE-2008-4666webappsphp
SQL injection vulnerability in webboard.php in Ultimate Webboard 3.00 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
ReferênciaVexDay Proof
Acidcat CMS 3.4.1 - Multiple Vulnerabilities
CVE-2008-1992webappsphp
Acidcat CMS 3.4.1 does not properly restrict access to (1) default_mail_aspemail.asp, (2) default_mail_cdosys.asp or (3)
23RIESGO
abrir
ReferênciaVexDay Proof
RPG.Board 0.0.8Beta2 - 'showtopic' SQL Injection
CVE-2008-4736webappsphp
SQL injection vulnerability in index.php in RPG.Board 0.8 Beta2 and earlier allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
Aardvark Topsites PHP 4.2.2 - 'path' Remote File Inclusion
CVE-2006-7026webappsphp
PHP remote file inclusion vulnerability in sources/join.php in Aardvark Topsites PHP 4.2.2 and earlier, when register_gl
23RIESGO
abrir
ReferênciaVexDay Proof
EZ Publish < 3.9.5/3.10.1/4.0.1 - Privilege Escalation
CVE-2008-6844webappsphp
The registration view (/user/register) in eZ Publish 3.5.6 and earlier, and possibly other versions before 3.9.5, 3.10.1
23RIESGO
abrir
ReferênciaVexDay Proof
QuickTalk forum 1.3 - 'lang' Local File Inclusion
CVE-2007-3505webappsphp
Multiple directory traversal vulnerabilities in QuickTalk forum 1.3 allow remote attackers to include and execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
Pluck CMS 4.5.2 - Multiple Local File Inclusions
CVE-2008-3851webappsphp
Multiple directory traversal vulnerabilities in Pluck CMS 4.5.2 on Windows allow remote attackers to include and execute
23RIESGO
abrir
ReferênciaVexDay Proof
Mambo Component MMP 1.2 - Remote File Inclusion
CVE-2006-4203webappsphp
PHP remote file inclusion vulnerability in help.mmp.php in the MMP Component (com_mmp) 1.2 and earlier for Mambo allows
23RIESGO
abrir
ReferênciaVexDay Proof
Keller Web Admin CMS 0.94 Pro - Local File Inclusion (1)
CVE-2008-6734webappsphp
Directory traversal vulnerability in Public/index.php in Keller Web Admin CMS 0.94 Pro allows remote attackers to includ
23RIESGO
abrir
ReferênciaVexDay Proof
Max.Blog 1.0.6 - Arbitrary Delete Post
CVE-2009-0383webappsphp
delete.php in Max.Blog 1.0.6 does not properly restrict access, which allows remote attackers to delete arbitrary blog p
23RIESGO
abrir
ReferênciaVexDay Proof
AEP SmartGate 4.3b - 'GET' Arbitrary File Download
CVE-2006-5596remotewindows
Directory traversal vulnerability in the SSL server in AEP Smartgate 4.3b allows remote attackers to download arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
EasyNews PRO News Publishing 4.0 - Password Disclosure
CVE-2006-6866webappsphp
STphp EasyNews PRO 4.0 stores sensitive information under the web root with insufficient access control, which allows re
23RIESGO
abrir
ReferênciaVexDay Proof
CMScout 2.05 - 'bit' Local File Inclusion
CVE-2008-3415webappsphp
Directory traversal vulnerability in common.php in CMScout 2.05, when .htaccess is not supported, allows remote attacker
23RIESGO
abrir
ReferênciaVexDay Proof
openEngine 2.0 beta2 - Remote File Inclusion
CVE-2008-4719webappsphp
PHP remote file inclusion vulnerability in cms/classes/openengine/filepool.php in openEngine 2.0 beta2, when register_gl
23RIESGO
abrir
ReferênciaVexDay Proof
Motorola Timbuktu Pro 8.6.5/8.7 - Directory Traversal / Log Injection
CVE-2008-1118remotewindows
Timbuktu Pro 8.6.5 for Windows, and possibly 8.7 for Mac OS X, does not perform input validation before logging informat
23RIESGO
abrir
ReferênciaVexDay Proof
db Software Laboratory VImpX - 'VImpX.ocx' Multiple Vulnerabilities
CVE-2008-4750remotewindows
Stack-based buffer overflow in the VImpX.VImpAX ActiveX control (VImpX.ocx) 4.8.8.0 in DB Software Laboratory VImp X, po
23RIESGO
abrir
ReferênciaVexDay Proof
Grestul 1.2 - Remote Add Administrator Account
CVE-2009-2040webappsphp
admin/options.php in Grestul 1.2 does not properly restrict access, which allows remote attackers to bypass authenticati
23RIESGO
abrir
ReferênciaVexDay Proof
Sendcard 3.4.1 - Local File Inclusion / Remote Code Execution
CVE-2007-3082webappsphp
Directory traversal vulnerability in sendcard.php in Sendcard 3.4.1 and earlier allows remote attackers to include and e
23RIESGO
abrir
ReferênciaVexDay Proof
TinyButStrong 3.4.0 - 'script' Local File Disclosure
CVE-2009-1653webappsphp
Directory traversal vulnerability in examples/tbs_us_examples_0view.php in TinyButStrong 3.4.0 allows remote attackers t
23RIESGO
abrir
ReferênciaVexDay Proof
HIS-Webshop - 'his-webshop.pl t' Remote File Disclosure
CVE-2008-1541webappscgi
Directory traversal vulnerability in cgi-bin/his-webshop.pl in HIS Webshop 2.50 allows remote attackers to read arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
PH Pexplorer 0.24 - 'explorer_load_lang.php' Local File Inclusion
CVE-2006-5510webappsphp
Directory traversal vulnerability in explorer_load_lang.php in PH Pexplorer 0.24 allows remote attackers to include arbi
23RIESGO
abrir
ReferênciaVexDay Proof
MyForum 1.3 - 'lecture.php' SQL Injection
CVE-2008-4760webappsphp
SQL injection vulnerability in lecture.php in Graphiks MyForum 1.3, when register_globals is enabled, allows remote atta
23RIESGO
abrir
ReferênciaVexDay Proof
PHPOF 20040226 - 'DB_adodb.class.php' Remote File Inclusion
CVE-2007-4763webappsphp
PHP remote file inclusion vulnerability in dbmodules/DB_adodb.class.php in PHP Object Framework (PHPOF) 20040226 and ear
23RIESGO
abrir
ReferênciaVexDay Proof
FTP Voyager 14.0.0.3 - 'CWD' Remote Stack Overflow (PoC)
CVE-2007-1079doswindows
Stack-based buffer overflow in Rhino Software, Inc. FTP Voyager 14.0.0.3 and earlier allows remote servers to cause a de
23RIESGO
abrir
ReferênciaVexDay Proof
AssetMan 2.4a - 'download_pdf.php' Remote File Disclosure
CVE-2007-1427webappsphp
Directory traversal vulnerability in download_pdf.php in AssetMan 2.4a and earlier allows remote attackers to read arbit
23RIESGO
abrir
ReferênciaVexDay Proof
Irola My-Time 3.5 - SQL Injection
CVE-2007-6217webappsphp
Multiple SQL injection vulnerabilities in login.asp in Irola My-Time (aka Timesheet) 3.5 allow remote attackers to execu
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.