Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
yourplace 1.0.2 - Multiple Vulnerabilities / Remote Code Execution
CVE-2008-6770webappsphp
YourPlace 1.0.2 and earlier stores sensitive information under the web root with insufficient access control, which allo
23RIESGO
abrir
ReferênciaVexDay Proof
ASPThai.Net Forum 8.5 - Remote Database Disclosure
CVE-2008-6872webappsasp
ASPThai.NET ASPThai Forums 8.5 stores sensitive information under the web root with insufficient access control, which a
23RIESGO
abrir
ReferênciaVexDay Proof
Power Editor 2.0 - Remote File Disclosure / Edit
CVE-2008-2115webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in editor.php in ScriptsEZ.net Power Editor 2.0 allow remote attacke
23RIESGO
abrir
ReferênciaVexDay Proof
Simple Website Software 0.99 - 'common.php' File Inclusion
CVE-2006-5636webappsphp
PHP remote file inclusion vulnerability in common.php in Simple Website Software (SWS) 0.99 and earlier allows remote at
23RIESGO
abrir
ReferênciaVexDay Proof
Elecard MPEG Player 5.5 - '.m3u' Stack Buffer Overflow (PoC)
CVE-2009-0491doswindows
Stack-based buffer overflow in Elecard MPEG Player 5.5 build 15884.081218 allows remote attackers to execute arbitrary c
23RIESGO
abrir
ReferênciaVexDay Proof
ViPlay3 < 3.00 - '.vpl' Local Stack Overflow (PoC)
CVE-2009-1660doswindows
Stack-based buffer overflow in URUWorks ViPlay3 3.0 and earlier allows remote attackers to cause a denial of service (cr
23RIESGO
abrir
ReferênciaVexDay Proof
Exhibit Engine 1.5 RC 4 - 'photo_comment.php' File Inclusion
CVE-2006-5292webappsphp
PHP remote file inclusion vulnerability in photo_comment.php in Exhibit Engine 1.5 RC 4 and earlier allows remote attack
23RIESGO
abrir
ReferênciaVexDay Proof
PHP 5.2.3 - PHP_ntuser ntuser_getuserlist() Local Buffer Overflow (PoC)
CVE-2007-4507doswindows
Multiple buffer overflows in the php_ntuser component for PHP 5.2.3 allow context-dependent attackers to cause a denial
23RIESGO
abrir
ReferênciaVexDay Proof
Mambo Component SMF Forum 1.3.1.3 - Remote File Inclusion
CVE-2006-3773webappsphp
PHP remote file inclusion vulnerability in smf.php in the SMF-Forum 1.3.1.3 Bridge Component (com_smf) For Joomla! and M
23RIESGO
abrir
ReferênciaVexDay Proof
Myspace Clone Script - 'index.php' Remote File Inclusion
CVE-2007-6057webappsphp
PHP remote file inclusion vulnerability in index.php in datecomm Social Networking Script (aka Myspace Clone Script) all
23RIESGO
abrir
ReferênciaVexDay Proof
TUTOS 1.3 - 'cmd.php' Remote Command Execution
CVE-2008-0148webappsphp
TUTOS 1.3 does not restrict access to php/admin/cmd.php, which allows remote attackers to execute arbitrary shell comman
23RIESGO
abrir
ReferênciaVexDay Proof
asg-sentry 7.0.0 - Multiple Vulnerabilities
CVE-2008-1320dosmultiple
Multiple buffer overflows in ASG-Sentry Network Manager 7.0.0 and earlier allow remote attackers to execute arbitrary co
28RIESGO
abrir
ReferênciaVexDay Proof
Gateway Weblaunch - ActiveX Control Insecure Method
CVE-2008-0221remotewindows
Directory traversal vulnerability in the WebLaunch.WeblaunchCtl.1 (aka CWebLaunchCtl) ActiveX control in weblaunch.ocx 1
23RIESGO
abrir
ReferênciaVexDay Proof
Chilkat Socket ActiveX 2.3.1.1 - Arbitrary File Creation
CVE-2008-6959remotewindows
Insecure method vulnerability in the Chilkat Socket ActiveX control (ChilkatSocket.ChilkatSocket.1) in ChilkatSocket.dll
23RIESGO
abrir
ReferênciaVexDay Proof
DoSePa 1.0.4 - 'textview.php' Information Disclosure
CVE-2006-6028webappsphp
Directory traversal vulnerability in textview.php in Anton Vlasov DoSePa 1.0.4 allows remote attackers to read arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
AS-GasTracker 1.0.0 - Insecure Cookie Handling
CVE-2008-2269webappsphp
AustinSmoke GasTracker (AS-GasTracker) 1.0.0 allows remote attackers to bypass authentication and gain privileges by set
23RIESGO
abrir
ReferênciaVexDay Proof
WordPress Plugin dmsguestbook 1.7.0 - Multiple Vulnerabilities
CVE-2008-0616webappsphp
SQL injection vulnerability in the administration panel in the DMSGuestbook 1.7.0 plugin for WordPress allows remote aut
23RIESGO
abrir
ReferênciaVexDay Proof
MikroTik RouterOS 3.13 - SNMP write (Set request)
CVE-2008-6976remotehardware
MikroTik RouterOS 3.x through 3.13 and 2.x through 2.9.51 allows remote attackers to modify Network Management System (N
23RIESGO
abrir
ReferênciaVexDay Proof
RSSonate - 'xml2rss.php' Remote File Inclusion
CVE-2006-5518webappsphp
Multiple PHP remote file inclusion vulnerabilities in Christopher Fowler (Rhode Island) RSSonate allow remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
ActiveKB 1.5 - Insecure Cookie Handling/Arbitrary Admin Access
CVE-2008-2338webappsphp
Interspire ActiveKB 1.5 and earlier allows remote attackers to gain privileges by setting the auth cookie to true when a
23RIESGO
abrir
ReferênciaVexDay Proof
SyndeoCMS 2.6.0 - Local File Inclusion / Cross-Site Scripting
CVE-2008-5272webappsphp
Multiple directory traversal vulnerabilities in Fred Stuurman SyndeoCMS 2.6.0 allow remote authenticated users to read a
23RIESGO
abrir
ReferênciaVexDay Proof
XOOPS 2.3.1 - Multiple Local File Inclusions
CVE-2008-6884webappsphp
Multiple directory traversal vulnerabilities in XOOPS 2.3.1, when register_globals is enabled, allow remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
MW6 Barcode - ActiveX 'Barcode.dll' Remote Heap Overflow (PoC)
CVE-2009-0298doswindows
Heap-based buffer overflow in MW6 Technologies Barcode ActiveX control (Barcode.MW6Barcode.1, Barcode.dll) 3.0.0.1 allow
23RIESGO
abrir
ReferênciaVexDay Proof
Firefly Media Server 0.2.4 - Remote Denial of Service
CVE-2007-5824doslinux
webserver.c in mt-dappd in Firefly Media Server 0.2.4 and earlier allows remote attackers to cause a denial of service (
23RIESGO
abrir
ReferênciaVexDay Proof
MP3 TrackMaker 1.5 - '.mp3' Local Heap Overflow (PoC)
CVE-2009-0175doswindows
Heap-based buffer overflow in Heathco Software MP3 TrackMaker 1.5 allows remote attackers to cause a denial of service (
23RIESGO
abrir
ReferênciaVexDay Proof
TLS - Renegotiation
CVE-2009-3555CRITICALremotemultiple
The TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS
70RIESGO
abrir
ReferênciaVexDay Proof
PHP 5.2.3 Win32std - 'win_shell_execute' Safe Mode / disable_functions Bypass
CVE-2007-4010localwindows
The win32std extension in PHP 5.2.3 does not follow safe_mode and disable_functions restrictions, which allows remote at
23RIESGO
abrir
ReferênciaVexDay Proof
WordPress Plugin fGallery 2.4.1 - 'fimrss.php' SQL Injection
CVE-2008-0491webappsphp
SQL injection vulnerability in fim_rss.php in the fGallery 2.4.1 plugin for WordPress allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
Apollo 37zz - '.m3u' Local Heap Overflow (PoC)
CVE-2009-1351doswindows
Heap-based buffer overflow in Apollo 37zz allows remote attackers to cause a denial of service (application crash) and p
23RIESGO
abrir
ReferênciaVexDay Proof
DigiMode Maya 1.0.2 - '.m3u' / '.m3l' Buffer Overflow (PoC)
CVE-2009-1817doswindows
Multiple buffer overflows in DigiMode Maya 1.0.2 allow remote attackers to execute arbitrary code via a long string in a
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.