Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
IrfanView 3.99 - '.ani' Local Buffer Overflow (1)
CVE-2007-1867localwindows
Buffer overflow in IrfanView 3.99 allows remote attackers to execute arbitrary code via a crafted animated cursor (ANI)
23RIESGO
abrir
ReferênciaVexDay Proof
Lama Software 14.12.2007 - Multiple Remote File Inclusions
CVE-2008-0423webappsphp
Multiple PHP remote file inclusion vulnerabilities in Lama Software allow remote attackers to execute arbitrary PHP code
35RIESGO
abrir
ReferênciaVexDay Proof
RunCMS 1.5.2 - 'debug_show.php' SQL Injection
CVE-2007-2539webappsphp
The show_files function in RunCms 1.5.2 and earlier allows remote attackers to obtain sensitive information (file existe
23RIESGO
abrir
ReferênciaVexDay Proof
Mini Web Calendar 1.2 - File Disclosure / Cross-Site Scripting
CVE-2008-5062webappsphp
Directory traversal vulnerability in php/cal_pdf.php in Mini Web Calendar (mwcal) 1.2 allows remote attackers to read ar
23RIESGO
abrir
ReferênciaVexDay Proof
JAF CMS 4.0 RC2 - Multiple Remote File Inclusions
CVE-2008-1609webappsphp
Multiple PHP remote file inclusion vulnerabilities in just another flat file (JAF) CMS 4.0 RC2 allow remote attackers to
35RIESGO
abrir
ReferênciaVexDay Proof
Smart Publisher 1.0.1 - 'filedata' Remote Code Execution
CVE-2008-0503webappsphp
Eval injection vulnerability in admin/op/disp.php in Netwerk Smart Publisher 1.0.1 allows remote attackers to execute ar
28RIESGO
abrir
ReferênciaVexDay Proof
Downline Goldmine Builder - SQL Injection
CVE-2008-4178webappsphp
SQL injection vulnerability in tr.php in DownlineGoldmine Special Category Addon, Downline Builder Pro, New Addon, and D
23RIESGO
abrir
ReferênciaVexDay Proof
Shadows Rising RPG 0.0.5b - Remote File Inclusion
CVE-2006-4329webappsphp
Multiple PHP remote file inclusion vulnerabilities in Shadows Rising RPG (Pre-Alpha) 0.0.5b and earlier allow remote att
23RIESGO
abrir
ReferênciaVexDay Proof
Autodesk DWF Viewer Control / LiveUpdate Module - Remote Code Execution
CVE-2008-4472remotewindows
The UpdateEngine class in the LiveUpdate ActiveX control (LiveUpdate16.DLL 17.2.56), as used in Revit Architecture 2009
23RIESGO
abrir
ReferênciaVexDay Proof
Quicksilver Forums 1.2.1 - Remote File Inclusion
CVE-2006-4824webappsphp
PHP remote file inclusion vulnerability in lib/activeutil.php in Quicksilver Forums (QSF) 1.2.1 and earlier allows remot
23RIESGO
abrir
ReferênciaVexDay Proof
SendStudio 2004.14 - 'ROOTDIR' Remote File Inclusion
CVE-2007-1060webappsphp
Multiple PHP remote file inclusion vulnerabilities in Interspire SendStudio 2004.14 and earlier, when register_globals a
23RIESGO
abrir
ReferênciaVexDay Proof
Imageview 5.3 - 'fileview.php?album' Local File Inclusion
CVE-2007-2425webappsphp
Directory traversal vulnerability in fileview.php in Imageview 5.3 allows remote attackers to read arbitrary files via a
23RIESGO
abrir
ReferênciaVexDay Proof
CGX 20050314 - 'pathCGX' Remote File Inclusion
CVE-2007-2611webappsphp
Multiple PHP remote file inclusion vulnerabilities in CGX 20050314 allow remote attackers to execute arbitrary PHP code
23RIESGO
abrir
ReferênciaVexDay Proof
RedDot CMS 7.5 - 'LngId' SQL Injection
CVE-2008-1613webappsasp
SQL injection vulnerability in ioRD.asp in RedDot CMS 7.5 Build 7.5.0.48, and possibly other versions including 6.5 and
23RIESGO
abrir
ReferênciaVexDay Proof
Web Wiz Guestbook 8.21 - Database Disclosure
CVE-2003-1571webappsasp
Web Wiz Guestbook 6.0 stores sensitive information under the web root with insufficient access control, which allows rem
23RIESGO
abrir
ReferênciaVexDay Proof
Neat weblog 0.2 - 'articleId' SQL Injection
CVE-2008-1639webappsphp
SQL injection vulnerability in index.php in Neat weblog 0.2 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir
ReferênciaVexDay Proof
Mambo Component nfnaddressbook 0.4 - Remote File Inclusion
CVE-2007-1596webappsphp
Multiple PHP remote file inclusion vulnerabilities in the NFN Address Book (com_nfn_addressbook) 0.4 component for Mambo
23RIESGO
abrir
ReferênciaVexDay Proof
Maian Links 3.1 - Insecure Cookie Handling
CVE-2008-3319webappsphp
admin/index.php in Maian Links 3.1 and earlier allows remote attackers to bypass authentication and gain administrative
23RIESGO
abrir
ReferênciaVexDay Proof
Dokuwiki 2009-02-14 - Local File Inclusion
CVE-2009-1960webappsphp
inc/init.php in DokuWiki 2009-02-14, rc2009-02-06, and rc2009-01-30, when register_globals is enabled, allows remote att
28RIESGO
abrir
ReferênciaVexDay Proof
phpMyPortal 3.0.0 RC3 - GLOBALS[CHEMINMODULES] Remote File Inclusion
CVE-2007-2594webappsphp
PHP remote file inclusion vulnerability in inc/articles.inc.php in phpMyPortal 3.0.0 RC3 allows remote attackers to exec
23RIESGO
abrir
ReferênciaVexDay Proof
PHP 'Perl' Extension - 'Safe_mode' Bypass
CVE-2007-4596localwindows
The perl extension in PHP does not follow safe_mode restrictions, which allows context-dependent attackers to execute ar
23RIESGO
abrir
ReferênciaVexDay Proof
Charrays CMS 0.9.3 - Multiple Remote File Inclusions
CVE-2007-6179webappsphp
Multiple PHP remote file inclusion vulnerabilities in Charray's CMS 0.9.3 allow remote attackers to execute arbitrary PH
23RIESGO
abrir
ReferênciaVexDay Proof
Woltlab Burning Board Addon JGS-Treffen 2.0.2 - SQL Injection
CVE-2008-1640webappsphp
SQL injection vulnerability in jgs_treffen.php in the JGS-XA JGS-Treffen 2.0.2 and earlier addon for Woltlab Burning Boa
23RIESGO
abrir
ReferênciaVexDay Proof
Oracle 10g - MDSYS.SDO_TOPO_DROP_FTBL SQL Injection (Metasploit)
CVE-2008-3979localmultiple
Unspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5 and 10.2.0.2 allows remote authent
50RIESGO
abrir
ReferênciaVexDay Proof
bugmall shopping cart 2.5 - SQL Injection / Cross-Site Scripting
CVE-2007-3446webappsphp
BugMall Shopping Cart 2.5 and earlier has a default username "demo" and password "demo," which allows remote attackers t
23RIESGO
abrir
ReferênciaVexDay Proof
WordPress Plugin Wp-FileManager 1.2 - Arbitrary File Upload
CVE-2008-0222webappsphp
Unrestricted file upload vulnerability in ajaxfilemanager.php in the Wp-FileManager 1.2 plugin for WordPress allows remo
23RIESGO
abrir
ReferênciaVexDay Proof
Titan FTP Server 6.03 - 'USER/PASS' Remote Heap Overflow (PoC)
CVE-2008-0702doswindows
Multiple heap-based buffer overflows in Titan FTP Server 6.03 and 6.0.5.549 allow remote attackers to cause a denial of
38RIESGO
abrir
ReferênciaVexDay Proof
Dokuwiki 2009-02-14 - Temporary/Remote File Inclusion
CVE-2009-1960webappsphp
inc/init.php in DokuWiki 2009-02-14, rc2009-02-06, and rc2009-01-30, when register_globals is enabled, allows remote att
28RIESGO
abrir
ReferênciaVexDay Proof
FaScript FaPhoto 1.0 - 'show.php' SQL Injection
CVE-2008-1714webappsphp
SQL injection vulnerability in show.php in FaScript FaPhoto 1.0, when magic_quotes_gpc is disabled, allows remote attack
23RIESGO
abrir
ReferênciaVexDay Proof
AuraCMS 2.x - '/user.php' Security Code Bypass / Arbitrary Add Administrator
CVE-2008-1715webappsphp
SQL injection vulnerability in content/user.php in AuraCMS 2.2.1 and earlier, when magic_quotes_gpc is disabled, allows
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.