Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.524exploits catalogados
37.962CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
MyPHP CMS 0.3.1 - 'pid' SQL Injection
CVE-2008-3497—webappsphp
SQL injection vulnerability in pages.php in MyPHP CMS 0.3.1 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
polypager 1.0rc2 - SQL Injection / Cross-Site Scripting
CVE-2008-3505—webappsphp
Cross-site scripting (XSS) vulnerability in PolyPager 1.0 rc2 and earlier allows remote attackers to inject arbitrary we
23RIESGO
abrir ↗
Referência✓ VexDay Proof
minimal Gallery 0.8 - Remote File Disclosure
CVE-2008-0260—webappsphp
minimal Gallery 0.8 allows remote attackers to obtain configuration information via a direct request to php_info.php, wh
23RIESGO
abrir ↗
Referência✓ VexDay Proof
eDContainer 2.22 - Local File Inclusion
CVE-2008-5818—webappsphp
Directory traversal vulnerability in index.php in eDreamers eDContainer 2.22, when magic_quotes_gpc is disabled, allows
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ashNews 0.83 - 'pathtoashnews' Remote File Inclusion
CVE-2003-1292—webappsphp
PHP remote file include vulnerability in Derek Ashauer ashNews 0.83 allows remote attackers to include and execute arbit
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SazCart 1.5 - 'cart.php' Remote File Inclusion
CVE-2006-5727—webappsphp
PHP remote file inclusion vulnerability in admin/controls/cart.php in sazcart 1.5 allows remote attackers to execute arb
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Alt-N MDaemon IMAP server 9.6.4 - 'FETCH' Remote Buffer Overflow
CVE-2008-1358—remotewindows
Stack-based buffer overflow in the IMAP server in Alt-N Technologies MDaemon 9.6.4 allows remote authenticated users to
50RIESGO
abrir ↗
Referência✓ VexDay Proof
LiteNews 0.1 - Insecure Cookie Handling
CVE-2008-3508—webappsphp
LiteNews 0.1 (aka 01), and possibly 1.2 and earlier, allows remote attackers to bypass authentication and gain administr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PixelPost 1.7 - Blind SQL Injection
CVE-2008-0358—webappsphp
SQL injection vulnerability in index.php in Pixelpost 1.7 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗
Referência✓ VexDay Proof
eXV2 Module Viso 2.0.4.3 - 'kid' SQL Injection
CVE-2008-1404—webappsphp
SQL injection vulnerability in index.php in the Viso (Industry Book) 2.04 and 2.03 module for eXV2 allows remote attacke
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Apple Safari - RSS 'feed://' Buffer Overflow via libxml2 (PoC)
CVE-2008-3529—doswindows
Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-de
28RIESGO
abrir ↗
Referência✓ VexDay Proof
Eznet 3.5.0 - Remote Stack Overflow / Denial of Service
CVE-2003-1339—remotewindows
Stack-based buffer overflow in eZnet.exe, as used in eZ (a) eZphotoshare, (b) eZmeeting, (c) eZnetwork, and (d) eZshare
35RIESGO
abrir ↗
Referência✓ VexDay Proof
WordPress Plugin WP-Forum 1.7.4 - SQL Injection
CVE-2008-0388—webappsphp
SQL injection vulnerability in the WP-Forum 1.7.4 plugin for WordPress allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Wsn (Multiple Products) - Local File Inclusion / Code Execution
CVE-2008-3555—webappsphp
Directory traversal vulnerability in index.php in (1) WSN Forum 4.1.43 and earlier, (2) Gallery 4.1.30 and earlier, (3)
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Easy-Clanpage 2.2 - 'id' SQL Injection
CVE-2008-1425—webappsphp
SQL injection vulnerability in index.php in the gallery module in Easy-Clanpage 2.2 allows remote attackers to execute a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
KAPhotoservice - 'album.asp' SQL Injection
CVE-2008-1426—webappsasp
SQL injection vulnerability in album.asp in KAPhotoservice allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗
Referência✓ VexDay Proof
k-links directory - SQL Injection / Cross-Site Scripting
CVE-2008-3580—webappsphp
Multiple SQL injection vulnerabilities in Qsoft K-Links allow remote attackers to execute arbitrary SQL commands via (1)
23RIESGO
abrir ↗
Referência✓ VexDay Proof
k-links directory - SQL Injection / Cross-Site Scripting
CVE-2008-3581—webappsphp
Cross-site scripting (XSS) vulnerability in index.php in Qsoft K-Links allows remote attackers to inject arbitrary web s
23RIESGO
abrir ↗
Referência✓ VexDay Proof
IntelliTamper 2.07 - 'imgsrc' Remote Buffer Overflow
CVE-2008-3583—remotewindows
Buffer overflow in the HTML parser in IntelliTamper 2.07 allows remote attackers to execute arbitrary code via a long UR
23RIESGO
abrir ↗
Referência✓ VexDay Proof
GreenCart PHP Shopping Cart - 'id' SQL Injection
CVE-2008-3585—webappsphp
Multiple SQL injection vulnerabilities in PozScripts GreenCart PHP Shopping Cart allow remote attackers to execute arbit
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Symphony 1.7.01 (non-patched) - Remote Code Execution
CVE-2008-3592—webappsphp
Unrestricted file upload vulnerability in the File Manager in the admin panel in Twentyone Degrees Symphony 1.7.01 and e
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP iCalendar 2.24 - 'cookie_language' Local File Inclusion / Arbitrary File Upload
CVE-2008-5968—webappsphp
Directory traversal vulnerability in print.php in PHP iCalendar 2.24 and earlier allows remote attackers to include and
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Simple Forum 3.2 - File Disclosure / Cross-Site Scripting
CVE-2008-0542—webappsphp
Directory traversal vulnerability in thumbnail.php in Gerd Tentler Simple Forum 3.2 allows remote attackers to read arbi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Bubbling Library 1.32 - Multiple Local File Inclusions
CVE-2008-0545—webappsphp
Multiple directory traversal vulnerabilities in Bubbling Library 1.32 allow remote attackers to include and execute arbi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
XNova 0.8 sp1 - 'xnova_root_path' Remote File Inclusion
CVE-2008-6023—webappsphp
PHP remote file inclusion vulnerability in includes/todofleetcontrol.php in a newer version of Xnova, possibly 0.8 sp1,
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Ventrilo 3.0.2 - Null Pointer Remote Denial of Service
CVE-2008-3680—dosmultiple
The decryption function in Flagship Industries Ventrilo 3.0.2 and earlier allows remote attackers to cause a denial of s
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Download Accelerator Plus DAP 8.6 - 'AniGIF.ocx' Buffer Overflow (PoC)
CVE-2008-3702—doswindows
Multiple stack-based buffer overflows in the Animation GIF ActiveX control in JComSoft AniGIF.ocx 1.12 and 2.47, as used
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Microsoft Visual Studio - 'Msmask32.ocx' ActiveX Remote Buffer Overflow (PoC)
CVE-2008-3704—doswindows
Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions befo
50RIESGO
abrir ↗
Referência✓ VexDay Proof
Ipswitch WS_FTP Home/Professional FTP Client - Remote Format String (PoC)
CVE-2008-3734—doswindows
Format string vulnerability in Ipswitch WS_FTP Home 2007.0.0.2 and WS_FTP Professional 2007.1.0.0 allows remote FTP serv
28RIESGO
abrir ↗
Referência✓ VexDay Proof
Active PHP BookMarks 1.1.02 - SQL Injection
CVE-2008-3748—webappsphp
SQL injection vulnerability in view_group.php in Active PHP Bookmarks (APB) 1.1.02 and 1.2.06 allows remote attackers to
23RIESGO
abrir ↗
← anteriorpágina 637 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.