Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
Pluck CMS 4.5.2 - Multiple Local File Inclusions
CVE-2008-3851webappsphp
Multiple directory traversal vulnerabilities in Pluck CMS 4.5.2 on Windows allow remote attackers to include and execute
23RIESGO
abrir
ReferênciaVexDay Proof
Keller Web Admin CMS 0.94 Pro - Local File Inclusion (1)
CVE-2008-6734webappsphp
Directory traversal vulnerability in Public/index.php in Keller Web Admin CMS 0.94 Pro allows remote attackers to includ
23RIESGO
abrir
ReferênciaVexDay Proof
Mambo Component MMP 1.2 - Remote File Inclusion
CVE-2006-4203webappsphp
PHP remote file inclusion vulnerability in help.mmp.php in the MMP Component (com_mmp) 1.2 and earlier for Mambo allows
23RIESGO
abrir
ReferênciaVexDay Proof
AEP SmartGate 4.3b - 'GET' Arbitrary File Download
CVE-2006-5596remotewindows
Directory traversal vulnerability in the SSL server in AEP Smartgate 4.3b allows remote attackers to download arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
Max.Blog 1.0.6 - Arbitrary Delete Post
CVE-2009-0383webappsphp
delete.php in Max.Blog 1.0.6 does not properly restrict access, which allows remote attackers to delete arbitrary blog p
23RIESGO
abrir
ReferênciaVexDay Proof
eNdonesia 8.4 - '/mod.php/friend.php/admin.php' Multiple Vulnerabilities
CVE-2006-6872webappsphp
Directory traversal vulnerability in mod.php in eNdonesia 8.4 allows remote attackers to read arbitrary files via a .. (
23RIESGO
abrir
ReferênciaVexDay Proof
Open Azimyt CMS 0.22 - 'lang' Local File Inclusion
CVE-2008-2820webappsphp
Directory traversal vulnerability in lang/lang-system.php in Open Azimyt CMS 0.22 minimal and 0.21 stable allows remote
23RIESGO
abrir
ReferênciaVexDay Proof
RoseOnlineCMS 3 beta2 - 'op' Local File Inclusion
CVE-2007-1636webappsphp
Directory traversal vulnerability in index.php in RoseOnlineCMS 3 B1 allows remote attackers to include arbitrary files
23RIESGO
abrir
ReferênciaVexDay Proof
Sepcity Classified - 'ID' SQL Injection
CVE-2008-6157webappsasp
SepCity Classified Ads stores the admin password in cleartext in data/classifieds.mdb, which allows context-dependent at
23RIESGO
abrir
ReferênciaVexDay Proof
Sendcard 3.4.1 - Local File Inclusion / Remote Code Execution
CVE-2007-3082webappsphp
Directory traversal vulnerability in sendcard.php in Sendcard 3.4.1 and earlier allows remote attackers to include and e
23RIESGO
abrir
ReferênciaVexDay Proof
db Software Laboratory VImpX - 'VImpX.ocx' Multiple Vulnerabilities
CVE-2008-4750remotewindows
Stack-based buffer overflow in the VImpX.VImpAX ActiveX control (VImpX.ocx) 4.8.8.0 in DB Software Laboratory VImp X, po
23RIESGO
abrir
ReferênciaVexDay Proof
Grestul 1.2 - Remote Add Administrator Account
CVE-2009-2040webappsphp
admin/options.php in Grestul 1.2 does not properly restrict access, which allows remote attackers to bypass authenticati
23RIESGO
abrir
ReferênciaVexDay Proof
FTP Voyager 14.0.0.3 - 'CWD' Remote Stack Overflow (PoC)
CVE-2007-1079doswindows
Stack-based buffer overflow in Rhino Software, Inc. FTP Voyager 14.0.0.3 and earlier allows remote servers to cause a de
23RIESGO
abrir
ReferênciaVexDay Proof
AssetMan 2.4a - 'download_pdf.php' Remote File Disclosure
CVE-2007-1427webappsphp
Directory traversal vulnerability in download_pdf.php in AssetMan 2.4a and earlier allows remote attackers to read arbit
23RIESGO
abrir
ReferênciaVexDay Proof
PH Pexplorer 0.24 - 'explorer_load_lang.php' Local File Inclusion
CVE-2006-5510webappsphp
Directory traversal vulnerability in explorer_load_lang.php in PH Pexplorer 0.24 allows remote attackers to include arbi
23RIESGO
abrir
ReferênciaVexDay Proof
PHPOF 20040226 - 'DB_adodb.class.php' Remote File Inclusion
CVE-2007-4763webappsphp
PHP remote file inclusion vulnerability in dbmodules/DB_adodb.class.php in PHP Object Framework (PHPOF) 20040226 and ear
23RIESGO
abrir
ReferênciaVexDay Proof
Irola My-Time 3.5 - SQL Injection
CVE-2007-6217webappsphp
Multiple SQL injection vulnerabilities in login.asp in Irola My-Time (aka Timesheet) 3.5 allow remote attackers to execu
23RIESGO
abrir
ReferênciaVexDay Proof
RunCMS 1.6 - Multiple Vulnerabilities
CVE-2007-6548webappsphp
Multiple direct static code injection vulnerabilities in RunCMS before 1.6.1 allow remote authenticated administrators t
23RIESGO
abrir
ReferênciaVexDay Proof
HIS-Webshop - 'his-webshop.pl t' Remote File Disclosure
CVE-2008-1541webappscgi
Directory traversal vulnerability in cgi-bin/his-webshop.pl in HIS Webshop 2.50 allows remote attackers to read arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
TinyButStrong 3.4.0 - 'script' Local File Disclosure
CVE-2009-1653webappsphp
Directory traversal vulnerability in examples/tbs_us_examples_0view.php in TinyButStrong 3.4.0 allows remote attackers t
23RIESGO
abrir
ReferênciaVexDay Proof
MyForum 1.3 - 'lecture.php' SQL Injection
CVE-2008-4760webappsphp
SQL injection vulnerability in lecture.php in Graphiks MyForum 1.3, when register_globals is enabled, allows remote atta
23RIESGO
abrir
ReferênciaVexDay Proof
Quick.Cart 2.2 - Local/Remote File Inclusion / Remote Code Execution
CVE-2007-3138webappsphp
Directory traversal vulnerability in index.php in Open Solution Quick.Cart 2.2 and earlier allows remote attackers to in
23RIESGO
abrir
ReferênciaVexDay Proof
bubbling library 1.32 - 'uri' Remote File Disclosure
CVE-2008-0521webappsphp
Multiple directory traversal vulnerabilities in Bubbling Library 1.32 allow remote attackers to read arbitrary files via
23RIESGO
abrir
ReferênciaVexDay Proof
Kasseler CMS 1.3.0 - Local File Inclusion / Cross-Site Scripting
CVE-2008-3087webappsphp
Directory traversal vulnerability in Kasseler CMS 1.3.0 allows remote attackers to read arbitrary files via a .. (dot do
23RIESGO
abrir
ReferênciaVexDay Proof
freeSSHd 1.2.1 - (Authenticated) SFTP 'realpath' Remote Buffer Overflow (PoC)
CVE-2008-4762doswindows
Stack-based buffer overflow in freeSSHd 1.2.1 allows remote authenticated users to cause a denial of service (service cr
28RIESGO
abrir
ReferênciaVexDay Proof
PHPmyGallery Gold 1.51 - 'index.php' Directory Traversal
CVE-2008-5598webappsphp
Directory traversal vulnerability in index.php in PHPmyGallery 1.51 gold allows remote attackers to list arbitrary direc
23RIESGO
abrir
ReferênciaVexDay Proof
Pre Classified Listings - Insecure Cookie Handling
CVE-2008-6231webappsphp
Pre Classified Listing PHP allows remote attackers to bypass authentication and gain administrative access by setting th
23RIESGO
abrir
ReferênciaVexDay Proof
FREEsimplePHPGuestbook - 'Guestbook.php' Remote Code Execution
CVE-2008-6934webappsphp
Static code injection vulnerability in Sanus|artificium (aka Sanusart) Free simple guestbook PHP script, when downloaded
23RIESGO
abrir
ReferênciaVexDay Proof
CyberBrau 0.9.4 - '/forum/track.php' Remote File Inclusion
CVE-2006-5400webappsphp
PHP remote file inclusion vulnerability in forum/track.php in CyberBrau 0.9.4, when register_globals is enabled, allows
23RIESGO
abrir
ReferênciaVexDay Proof
MyCMS 0.9.8 - Remote Command Execution (1)
CVE-2007-3587webappsphp
MyCMS 0.9.8 and earlier allows remote attackers to gain privileges via the admin cookie parameter, as demonstrated by a
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.