Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.524exploits catalogados
37.962CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
ASP Photo Gallery 1.0 - Multiple SQL Injections
CVE-2008-0256—webappsasp
Multiple SQL injection vulnerabilities in Matteo Binda ASP Photo Gallery 1.0 allow remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Zervit Web Server 0.02 - Remote Buffer Overflow (PoC)
CVE-2009-1353—doswindows
Buffer overflow in the http_parse_hex function in libz/misc.c in Zervit Webserver 0.02 allows remote attackers to cause
23RIESGO
abrir ↗
Referência✓ VexDay Proof
5 star review - Cross-Site Scripting / SQL Injection
CVE-2008-3780—webappsphp
SQL injection vulnerability in recommend.php in Five Star Review Script allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Referência✓ VexDay Proof
AJ Auction Pro Platinum - 'seller_id' SQL Injection
CVE-2008-6003—webappsphp
SQL injection vulnerability in sellers_othersitem.php in AJ Auction Pro Platinum 2 allows remote attackers to execute ar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Microsoft Works 7 - 'WkImgSrv.dll' ActiveX Denial of Service (PoC)
CVE-2008-1898—doswindows
A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and
50RIESGO
abrir ↗
Referência✓ VexDay Proof
phpAuction - 'profile.php' SQL Injection (1)
CVE-2008-6663—webappsphp
SQL injection vulnerability in profile.php in PHPAuctions.info PHPAuctions (aka PHPAuctionSystem) allows remote attacker
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Flyspeck CMS 6.8 - Local/Remote File Inclusion / Change Add Admin
CVE-2009-1770—webappsphp
Directory traversal vulnerability in includes/database/examples/addressbook.php in Flyspeck CMS 6.8 allows remote attack
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Agares phpAutoVideo 2.21 - 'articlecat' SQL Injection (1)
CVE-2008-0262—webappsphp
SQL injection vulnerability in includes/articleblock.php in Agares PhpAutoVideo 2.21 allows remote attackers to execute
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Bux.to Clone Script - Insecure Cookie Handling
CVE-2008-6162—webappsphp
Bux.to Clone script allows remote attackers to bypass authentication and gain administrative access by setting the logge
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ImageAlbum 2.0.0b2 - 'id' SQL Injection
CVE-2008-0288—webappsphp
Multiple SQL injection vulnerabilities in ImageAlbum 2.0.0b2 allow remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Evilsentinel 1.0.9 - Multiple Vulnerabilities Disable
CVE-2008-0351—webappsphp
admin/config.php in Evilsentinel 1.0.9 and earlier allows remote attackers to bypass the CAPTCHA test by omitting the es
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CA BrightStor ARCserve - 'tapeeng.exe' Remote Buffer Overflow
CVE-2006-6917—remotewindows
Multiple buffer overflows in Computer Associates (CA) BrightStor ARCserve Backup R11.5 Server before SP2 allows remote a
28RIESGO
abrir ↗
Referência✓ VexDay Proof
Rigter Portal System (RPS) 6.2 - Blind SQL Injection
CVE-2007-1293—webappsphp
SQL injection vulnerability in Rigter Portal System (RPS) 6.2, when magic_quotes_gpc is disabled, allows remote attacker
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Quote&Ordering System 1.0 - 'ordernum' Multiple Vulnerabilities
CVE-2006-6911—webappsasp
SQL injection vulnerability in search.asp in Digitizing Quote And Ordering System 1.0 allows remote authenticated users
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Formbankserver 1.9 - 'Name' Remote Denial of Service
CVE-2006-6910—doswindows
formbankcgi.exe in Fersch Formbankserver 1.9, when the PATH_INFO begins with Abfrage, allows remote attackers to cause a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP-RESIDENCE 0.7.2 - 'Search' SQL Injection
CVE-2008-0353—webappsphp
SQL injection vulnerability in visualizza_tabelle.php in php-residence 0.7.2 and 1.0 allows remote attackers to execute
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Fuzzylime CMS 3.01 - 'commrss.php' Remote Code Execution
CVE-2008-6833—webappsphp
Directory traversal vulnerability in commsrss.php in fuzzylime (cms) before 3.01b allows remote attackers to include and
23RIESGO
abrir ↗
Referência✓ VexDay Proof
HispaH textlinksads - 'index.php' SQL Injection
CVE-2008-6154—webappsphp
SQL injection vulnerability in index.php in Hispah Text Links Ads 1.1 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHPEcho CMS 2.0 - 'id' SQL Injection
CVE-2008-0355—webappsphp
SQL injection vulnerability in index.php in the forum module in PHPEcho CMS, probably 2.0-rc3 and earlier, allows remote
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Digital Data Communications - 'RtspVaPgCtrl' Class Remote Buffer Overflow
CVE-2008-0380—remotewindows
Buffer overflow in the Digital Data Communications RtspVaPgCtrl ActiveX control (RtspVapgDecoder.dll 1.1.0.29) allows re
28RIESGO
abrir ↗
Referência✓ VexDay Proof
Connectix Boards 0.7 - 'p_skin' Multiple Vulnerabilities
CVE-2007-1255—webappsphp
Unrestricted file upload vulnerability in admin.bbcode.php in Connectix Boards 0.7 and earlier allows remote authenticat
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WordPress Plugin Enigma 2 Bridge - 'boarddir' Remote File Inclusion
CVE-2006-6863CRITICALwebappsphp
PHP remote file inclusion vulnerability in the Enigma2 plugin (Enigma2.php) in Enigma WordPress Bridge allows remote att
53RIESGO
abrir ↗
Referência✓ VexDay Proof
alitalk 1.9.1.1 - Multiple Vulnerabilities
CVE-2008-0391—webappsphp
inc/elementz.php in aliTalk 1.9.1.1 does not properly verify authentication, which allows remote attackers to add an arb
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Microsoft Visual Basic Enterprise 6 SP6 - '.dsr' File Handling Buffer Overflow
CVE-2008-0392—localwindows
Multiple buffer overflows in Microsoft Visual Basic Enterprise Edition 6.0 SP6 allow user-assisted remote attackers to e
35RIESGO
abrir ↗
Referência✓ VexDay Proof
Shadowed Portal Module Character Roster - 'mod_root' Remote File Inclusion
CVE-2006-6850—webappsphp
PHP remote file inclusion vulnerability in include.php in the Roster Module (character_roster) in Shadowed Portal 5.7 al
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SaveWeb Portal 3.4 - 'SITE_Path' Remote File Inclusion
CVE-2006-4012—webappsphp
Multiple PHP remote file inclusion vulnerabilities in circeOS SaveWeb Portal 3.4 allow remote attackers to execute arbit
23RIESGO
abrir ↗
Referência✓ VexDay Proof
XMB 1.9.6 - 'mq=off' 'u2uid' SQL Injection
CVE-2006-3994—webappsphp
SQL injection vulnerability in the u2u_send_recp function in u2u.inc.php in XMB (aka extreme message board) 1.9.6 Alpha
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Yourownbux 4.0 - 'cookie' SQL Injection
CVE-2008-4492—webappsphp
SQL injection vulnerability in referrals.php in YourOwnBux 4.0 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Lycos FileUploader Control - ActiveX Remote Buffer Overflow
CVE-2008-0443—remotewindows
Heap-based buffer overflow in the FileUploader.FUploadCtl.1 ActiveX control in FileUploader.dll 2.0.0.2 in Lycos FileUpl
28RIESGO
abrir ↗
Referência✓ VexDay Proof
Comodo AntiVirus 2.0 - 'ExecuteStr()' Remote Command Execution
CVE-2008-0470—remotewindows
A certain ActiveX control in Comodo AntiVirus 2.0 allows remote attackers to execute arbitrary commands via the ExecuteS
35RIESGO
abrir ↗
← anteriorpágina 639 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.