Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
PHPMyRealty 1.0.9 - Multiple SQL Injections
CVE-2008-3861webappsphp
Multiple SQL injection vulnerabilities in phpMyRealty (PMR) 1.0.9 and earlier allow remote attackers to execute arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
SFS Ez Forum - SQL Injection
CVE-2008-4754webappsphp
SQL injection vulnerability in forum.php in Scripts for Sites (SFS) Ez Forum allows remote attackers to execute arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
Ext 1.0 - 'feed-proxy.php?feed' Remote File Disclosure
CVE-2007-2285webappsphp
Directory traversal vulnerability in examples/layout/feed-proxy.php in Jack Slocum Ext 1.0 alpha1 (Ext JS) allows remote
28RIESGO
abrir
ReferênciaVexDay Proof
K&S Shopsysteme - Arbitrary File Upload
CVE-2008-6768webappsphp
Unrestricted file upload vulnerability in admin/editor/images.php in K&S Shopsoftware allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
SyndeoCMS 2.5.01 - 'cmsdir' Remote File Inclusion
CVE-2007-5840webappsphp
PHP remote file inclusion vulnerability in starnet/themes/c-sky/main.inc.php in Fred Stuurman SyndeoCMS 2.5.01 allows re
23RIESGO
abrir
ReferênciaVexDay Proof
Spice Classifieds - 'cat_path' SQL Injection
CVE-2008-4039webappsphp
SQL injection vulnerability in index.php in Spice Classifieds allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
Trawler Web CMS 1.8.1 - Multiple Remote File Inclusions
CVE-2006-5495webappsphp
Multiple PHP remote file inclusion vulnerabilities in Trawler Web CMS 1.8.1 and earlier allow remote attackers to execut
23RIESGO
abrir
ReferênciaVexDay Proof
ID Automation Linear Barcode - ActiveX Denial of Service
CVE-2007-2658doswindows
Unspecified vulnerability in the ID Automation Linear Barcode 1.6.0.5 ActiveX control in IDAutomationLinear6.dll allows
23RIESGO
abrir
ReferênciaVexDay Proof
Musoo 0.21 - Remote File Inclusion
CVE-2007-3297webappsphp
Multiple PHP remote file inclusion vulnerabilities in Musoo 0.21 allow remote attackers to execute arbitrary PHP code vi
23RIESGO
abrir
ReferênciaVexDay Proof
PA168 Chipset IP Phones - Weak Session Management
CVE-2007-0528remotehardware
The admin web console implemented by the Centrality Communications (aka Aredfox) PA168 chipset and firmware 1.54 and ear
23RIESGO
abrir
ReferênciaVexDay Proof
NEPT Image Uploader 1.0 - Arbitrary File Upload
CVE-2008-6822webappsphp
Unrestricted file upload vulnerability in uploadp.php in New Earth Programming Team (NEPT) imgupload (aka Image Uploader
23RIESGO
abrir
ReferênciaVexDay Proof
SpeedStream 5200 - Authentication Bypass Configuration Download
CVE-2008-6916remotehardware
Siemens SpeedStream 5200 with NetPort Software 1.1 allows remote attackers to bypass authentication via an invalid Host
23RIESGO
abrir
ReferênciaVexDay Proof
Remote Display Dev kit 1.2.1.0 - 'RControl.dll' Denial of Service
CVE-2007-2623doswindows
Multiple buffer overflows in RControl.dll in Remote Display Dev kit 1.2.1.0 allow remote attackers to cause a denial of
23RIESGO
abrir
ReferênciaVexDay Proof
PHP recommend 1.3 - Authentication Bypass / Remote File Inclusion / Code Injection
CVE-2009-1781webappsphp
Static code injection vulnerability in admin.php in Frax.dk Php Recommend 1.3 and earlier allows remote attackers to inj
23RIESGO
abrir
ReferênciaVexDay Proof
Interact 2.4.1 - 'help.php' Local File Inclusion
CVE-2008-3384webappsphp
Multiple directory traversal vulnerabilities in help/help.php in Interact Learning Community Environment Interact 2.4.1
23RIESGO
abrir
ReferênciaVexDay Proof
OTSCMS 2.1.3 - Multiple Remote File Inclusions
CVE-2006-5546webappsphp
PHP remote file inclusion vulnerability in OTSCMS/OTSCMS.php in Open Tibia Server Content Management System (OTSCMS) 1.3
23RIESGO
abrir
ReferênciaVexDay Proof
phpRealty 0.3 - 'INC' Remote File Inclusion
CVE-2008-4134webappsphp
PHP remote file inclusion vulnerability in manager/static/view.php in phpRealty 0.03 and earlier, and possibly other ver
23RIESGO
abrir
ReferênciaVexDay Proof
PHPPeanuts 1.3 Beta - 'Inspect.php' Remote File Inclusion
CVE-2006-5948webappsphp
PHP remote file inclusion vulnerability in pntUnit/Inspect.php in phpPeanuts 1.1 and earlier allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
Natterchat 1.1 - Remote Authentication Bypass
CVE-2008-7047webappsphp
NatterChat 1.1 allows remote attackers to bypass authentication and gain administrator privileges to read or delete room
23RIESGO
abrir
ReferênciaVexDay Proof
MDForum 2.0.1 - 'PNSVlang' Remote Code Execution
CVE-2006-6869webappsphp
Directory traversal vulnerability in includes/search/search_mdforum.php in MAXdev MDForum 2.0.1 and earlier, when magic_
23RIESGO
abrir
ReferênciaVexDay Proof
pragmaMX Module Landkarten 2.1 (Windows) - Local File Inclusion
CVE-2007-1539webappsphp
Directory traversal vulnerability in inc/map.func.php in pragmaMX Landkarten 2.1 module allows remote attackers to inclu
23RIESGO
abrir
ReferênciaVexDay Proof
phpAddressBook 2.11 - Multiple Local File Inclusions
CVE-2008-1492webappsphp
Multiple directory traversal vulnerabilities in CoronaMatrix phpAddressBook 2.11 allow remote attackers to include and e
23RIESGO
abrir
ReferênciaVexDay Proof
CandyPress eCommerce suite 4.1.1.26 - Multiple Vulnerabilities
CVE-2008-0546webappsasp
Multiple SQL injection vulnerabilities in CandyPress (CP) 4.1.1.26, and earlier 4.1.x versions, allow remote attackers t
23RIESGO
abrir
ReferênciaVexDay Proof
ACG-ScriptShop - 'cid' SQL Injection
CVE-2008-4144webappsphp
SQL injection vulnerability in index.php in ACG-ScriptShop E-Gold Script Shop allows remote attackers to execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! 1.5.x - 'Token' Remote Admin Change Password
CVE-2008-3681webappsphp
components/com_user/models/reset.php in Joomla! 1.5 through 1.5.5 does not properly validate reset tokens, which allows
23RIESGO
abrir
ReferênciaVexDay Proof
Anthologia 0.5.2 - 'index.php?ads_file' Remote File Inclusion
CVE-2007-2094webappsphp
PHP remote file inclusion vulnerability in index.php in Anthologia 0.5.2 allows remote attackers to execute arbitrary PH
23RIESGO
abrir
ReferênciaVexDay Proof
wbstreet 1.0 - SQL Injection / File Disclosure
CVE-2008-5956webappsphp
Wbstreet (aka PHPSTREET Webboard) 1.0 stores sensitive information under the web root with insufficient access control,
23RIESGO
abrir
ReferênciaVexDay Proof
PHP-Generics 1.0.0 Beta - Multiple Remote File Inclusions
CVE-2007-2346webappsphp
Multiple PHP remote file inclusion vulnerabilities in PHP-Generics 1.0 beta allow remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
Glossword 1.8.1 - 'custom_vars.php' Remote File Inclusion
CVE-2007-2743webappsphp
PHP remote file inclusion vulnerability in custom_vars.php in GlossWord 1.8.1 allows remote attackers to execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
CounterPath X-Lite 3.x - SIP phone Remote Denial of Service
CVE-2007-4382doswindows
CounterPath X-Lite 3.0 34025, and possibly eyeBeam, allows remote attackers to cause a denial of service (device crash)
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.