Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
Pie Cart Pro - 'Inc_Dir' Remote File Inclusion
CVE-2006-4969webappsphp
Multiple PHP remote file inclusion vulnerabilities in WAHM E-Commerce Pie Cart Pro allow remote attackers to execute arb
23RIESGO
abrir
ReferênciaVexDay Proof
JSBoard 2.0.10 - 'login.php?table' Local File Inclusion
CVE-2007-1842webappsphp
Directory traversal vulnerability in login.php in JSBoard before 2.0.12 allows remote attackers to include and execute a
23RIESGO
abrir
ReferênciaVexDay Proof
XOOPS Module XFsection - 'modify.php' Remote File Inclusion
CVE-2007-3222webappsphp
PHP remote file inclusion vulnerability in modify.php in the XFsection 1.07 module for XOOPS allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
MicroTik RouterOS 3.2 - SNMPd snmp-set Denial of Service
CVE-2008-0680doshardware
SNMPd in MikroTik RouterOS 3.2 and earlier allows remote attackers to cause a denial of service (daemon crash) via a cra
23RIESGO
abrir
ReferênciaVexDay Proof
Blogator-script 0.95 - 'id_art' SQL Injection
CVE-2008-1763webappsphp
SQL injection vulnerability in _blogadata/include/sond_result.php in Blogator-script 0.95 allows remote attackers to exe
23RIESGO
abrir
ReferênciaVexDay Proof
Adobe Album Starter 3.2 - Unchecked Local Buffer Overflow
CVE-2008-1765localwindows
Buffer overflow in Adobe Photoshop Album Starter Edition 3.2, and possibly After Effects CS3, allows user-assisted remot
28RIESGO
abrir
ReferênciaVexDay Proof
Apache 2.2.14 mod_isapi - Dangling Pointer Remote SYSTEM
CVE-2010-0425remotewindows
modules/arch/win32/mod_isapi.c in mod_isapi in the Apache HTTP Server 2.0.37 through 2.0.63, 2.2.0 through 2.2.14, and 2
60RIESGO
abrir
ReferênciaVexDay Proof
TeamCalPro 3.1.000 - Multiple Local/Remote File Inclusions
CVE-2007-6554webappsphp
Multiple directory traversal vulnerabilities in TeamCal Pro 3.1.000 and earlier allow remote attackers to include and ex
23RIESGO
abrir
ReferênciaVexDay Proof
Dragoon 0.1 - 'root' Remote File Inclusion
CVE-2008-1773webappsphp
PHP remote file inclusion vulnerability in includes/header.inc.php in Dragoon 0.1 allows remote attackers to execute arb
28RIESGO
abrir
ReferênciaVexDay Proof
V3 Chat Live Support 3.0.4 - Insecure Cookie Handling
CVE-2008-5783webappsphp
admin/index.php in V3 Chat Live Support 3.0.4 allows remote attackers to bypass authentication and gain administrative a
23RIESGO
abrir
ReferênciaVexDay Proof
ChartDirector 4.1 - 'viewsource.php' File Disclosure
CVE-2008-1782webappsphp
phpdemo/viewsource.php in Advanced Software Engineering ChartDirector 4.1 allows remote attackers to read sensitive file
23RIESGO
abrir
ReferênciaVexDay Proof
Ourgame GLWorld 2.x - 'hgs_startNotify()' ActiveX Buffer Overflow
CVE-2008-0647remotewindows
Multiple stack-based buffer overflows in the HanGamePluginCn18.HanGamePluginCn18.1 ActiveX control in HanGamePluginCn18.
23RIESGO
abrir
ReferênciaVexDay Proof
DS-IPN.NET Digital Sales IPN - Database Disclosure
CVE-2009-0328webappsasp
ROBS-PROJECTS Digital Sales IPN (aka DS-IPN.NET or DS-IPN Paypal Shop) stores sensitive information under the web root w
23RIESGO
abrir
ReferênciaVexDay Proof
Faq Administrator 2.1 - 'faq_reply.php' Remote File Inclusion
CVE-2006-5637webappsphp
PHP remote file inclusion vulnerability in faq_reply.php in Faq Administrator 2.1b allows remote attackers to execute ar
23RIESGO
abrir
ReferênciaVexDay Proof
Prozilla Top 100 1.2 - Arbitrary Delete Stats
CVE-2008-1785webappsphp
delete.php in Prozilla Top 100 1.2 allows remote authenticated users to delete statistics and accounts of arbitrary user
23RIESGO
abrir
ReferênciaVexDay Proof
Entertainment Directory 1.1 - SQL Injection
CVE-2008-1788webappsphp
SQL injection vulnerability in directory.php in Prozilla Entertainers 1.1 and earlier allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component Restaurante - Arbitrary File Upload
CVE-2007-4817webappsphp
Unrestricted file upload vulnerability in the Restaurante (com_restaurante) component for Joomla! allows remote attacker
23RIESGO
abrir
ReferênciaVexDay Proof
JBC Explorer 7.20 RC 1 - Remote Code Execution
CVE-2007-5913webappsphp
dirsys/modules/auth.php in JBC Explorer 7.20 RC1 and earlier does not require authentication, which allows remote attack
23RIESGO
abrir
ReferênciaVexDay Proof
Dragoon 0.1 - 'lng' Local File Inclusion
CVE-2008-1798webappsphp
Directory traversal vulnerability in forum/kietu/libs/calendrier.php in Dragoon 0.1 allows remote attackers to include a
23RIESGO
abrir
ReferênciaVexDay Proof
PPStream - 'PowerPlayer.dll 2.0.1.3829' ActiveX Remote Overflow
CVE-2007-4748remotewindows
Buffer overflow in the PowerPlayer.dll ActiveX control in PPStream 2.0.1.3829 allows remote attackers to execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
rdesktop 1.5.0 - 'iso_recv_msg()' Integer Underflow (PoC)
CVE-2008-1801doslinux
Integer underflow in the iso_recv_msg function (iso.c) in rdesktop 1.5.0 allows remote attackers to cause a denial of se
28RIESGO
abrir
ReferênciaVexDay Proof
μTorrent (uTorrent) / BitTorrent WebIU HTTP 1.7.7/6.0.1 - Range header Denial of Service
CVE-2008-0071doswindows
The Web UI interface in (1) BitTorrent before 6.0.3 build 8642 and (2) uTorrent before 1.8beta build 10524 allows remote
23RIESGO
abrir
ReferênciaVexDay Proof
32bit FTP (09.04.24) - 'CWD Response' Remote Buffer Overflow
CVE-2009-1611remotewindows_x86
Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a
23RIESGO
abrir
ReferênciaVexDay Proof
WordPress Core 2.1.2 - 'xmlrpc' SQL Injection
CVE-2007-1897webappsphp
SQL injection vulnerability in xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated
23RIESGO
abrir
ReferênciaVexDay Proof
WengoPhone 2.x - SIP Phone Remote Denial of Service
CVE-2007-4366doswindows
WengoPhone 2.1 allows remote attackers to cause a denial of service (device crash) via a SIP INVITE message without a Co
23RIESGO
abrir
ReferênciaVexDay Proof
Service Provider Management System v1.0 - SQL Injection
CVE-2023-34581webappsphp
Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/
23RIESGO
abrir
ReferênciaVexDay Proof
PHPAddressBook 2.11 - 'view.php' SQL Injection
CVE-2008-1847webappsphp
SQL injection vulnerability in view.php in CoronaMatrix phpAddressBook 2.11 allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
RealPlayer 10 - '.ra' Remote Denial of Service
CVE-2007-2497doswindows
RealNetworks RealPlayer 10 Gold allows remote attackers to cause a denial of service (memory consumption) via a certain
23RIESGO
abrir
ReferênciaVexDay Proof
PHP Multiple Newsletters 2.7 - Local File Inclusion / Cross-Site Scripting
CVE-2008-5566webappsphp
Cross-site scripting (XSS) vulnerability in index.php in Triangle Solutions PHP Multiple Newsletters 2.7 allows remote a
23RIESGO
abrir
ReferênciaVexDay Proof
WordPress Plugin E-Commerce 3.4 - Arbitrary File Upload
CVE-2008-6811webappsphp
Unrestricted file upload vulnerability in image_processing.php in the e-Commerce Plugin 3.4 and earlier for Wordpress al
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.