Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.524exploits catalogados
37.962CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
eZip Wizard 3.0 - Local Stack Buffer Overflow (PoC) (SEH)
CVE-2009-1057—doswindows
MicroSmarts Enterprise ZipItFast! 3.0 allows remote attackers to execute arbitrary code via a crafted .zip file that tri
23RIESGO
abrir ↗
Referência✓ VexDay Proof
AGENCY4NET WEBFTP 1 - 'download2.php' File Disclosure
CVE-2008-0091—webappsphp
Directory traversal vulnerability in download2.php in AGENCY4NET WEBFTP 1 allows remote attackers to read and delete arb
23RIESGO
abrir ↗
Referência✓ VexDay Proof
BbZL.php 0.92 - Insecure Cookie Handling
CVE-2008-4708—webappsphp
BbZL.PhP 0.92 allows remote attackers to bypass authentication and gain administrative access by setting the phorum_admi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHPAddressBook 2.11 - 'view.php' SQL Injection
CVE-2008-1847—webappsphp
SQL injection vulnerability in view.php in CoronaMatrix phpAddressBook 2.11 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Alstrasoft SendIt Pro - Arbitrary File Upload
CVE-2008-6932—webappsphp
Unrestricted file upload vulnerability in submit_file.php in AlstraSoft SendIt Pro allows remote attackers to execute ar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
sCssBoard (Multiple Versions) - 'pwnpack' Remote s
CVE-2008-5576—webappsphp
admin/forums.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allows remote attackers to bypass authentication and gain adminis
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Coppermine Photo Gallery 1.3.x - Blind SQL Injection
CVE-2007-1107—webappsphp
SQL injection vulnerability in thumbnails.php in Coppermine Photo Gallery (CPG) 1.3.x allows remote authenticated users
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Wysi Wiki Wyg 1.0 - Local File Inclusion / Cross-Site Scripting / PHPInfo
CVE-2008-3205—webappsphp
Directory traversal vulnerability in index.php in Easy-Script Wysi Wiki Wyg 1.0 allows remote attackers to read arbitrar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
asp-project 1.0 - Insecure Cookie Method
CVE-2009-0280—webappsasp
Asp Project Management 1.0 allows remote attackers to bypass authentication and gain administrative access by setting th
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WordPress Plugin E-Commerce 3.4 - Arbitrary File Upload
CVE-2008-6811—webappsphp
Unrestricted file upload vulnerability in image_processing.php in the e-Commerce Plugin 3.4 and earlier for Wordpress al
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP Multiple Newsletters 2.7 - Local File Inclusion / Cross-Site Scripting
CVE-2008-5566—webappsphp
Cross-site scripting (XSS) vulnerability in index.php in Triangle Solutions PHP Multiple Newsletters 2.7 allows remote a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHPStore Car Dealers - Arbitrary File Upload
CVE-2008-6929—webappsphp
Unrestricted file upload vulnerability in PHPStore Auto Classifieds allows remote authenticated users to execute arbitra
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CzarNews 1.14 - 'tpath' Remote File Inclusion
CVE-2006-3685—webappsphp
PHP remote file inclusion vulnerability in CzarNews 1.12 through 1.14 allows remote attackers to execute arbitrary PHP c
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Velocity Web-Server 1.0 - Directory Traversal
CVE-2008-7084—remotewindows
Directory traversal vulnerability in the web server 1.0 in Velocity Security Management System allows remote attackers t
23RIESGO
abrir ↗
Referência✓ VexDay Proof
phpBB Module NoMoKeTos Rules 0.0.1 - Remote File Inclusion
CVE-2007-1106—webappsphp
PHP remote file inclusion vulnerability in includes/functions_nomoketos_rules.php in the NoMoKeTos Rules 0.0.1 module fo
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Quantum Game Library 0.7.2c - Remote File Inclusion
CVE-2008-1069—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Quantum Game Library 0.7.2c allow remote attackers to execute arbi
28RIESGO
abrir ↗
Referência✓ VexDay Proof
phpQuiz 0.1.2 - SQL Injection / Code Execution
CVE-2006-4979—webappsphp
Direct static code injection vulnerability in cfgphpquiz/install.php in Walter Beschmout PhpQuiz 1.2 and earlier allows
23RIESGO
abrir ↗
Referência✓ VexDay Proof
HydraIrc 0.3.164 - Remote Denial of Service
CVE-2008-3578—doswindows
HydraIRC 0.3.164 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and applicat
23RIESGO
abrir ↗
Referência✓ VexDay Proof
netForo! 0.1 - 'down.php?file_to_download' Remote File Disclosure
CVE-2007-1392—webappsphp
Directory traversal vulnerability in down.php in netForo! 0.1g allows remote attackers to read arbitrary files via a ..
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP-Nuke 8.0 Final - HTTP Referers SQL Injection
CVE-2007-1061—webappsphp
SQL injection vulnerability in index.php in Francisco Burzi PHP-Nuke 8.0 Final and earlier, when the "HTTP Referers" blo
35RIESGO
abrir ↗
Referência✓ VexDay Proof
phpsyncml 0.1.2 - Remote File Inclusion
CVE-2007-4978—webappsphp
Multiple PHP remote file inclusion vulnerabilities in phpSyncML 0.1.2 and earlier allow remote attackers to execute arbi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
mutiple timesheets 5.0 - Multiple Vulnerabilities
CVE-2008-1415—webappsphp
Directory traversal vulnerability in index.php in Multiple Time Sheets (MTS) 5.0 and earlier allows remote attackers to
23RIESGO
abrir ↗
Referência✓ VexDay Proof
phpinv 0.8.0 - Local File Inclusion / Cross-Site Scripting
CVE-2008-2694—webappsphp
Cross-site scripting (XSS) vulnerability in search.php in phpInv 0.8.0 allows remote attackers to inject arbitrary web s
23RIESGO
abrir ↗
Referência✓ VexDay Proof
rdesktop 1.5.0 - 'iso_recv_msg()' Integer Underflow (PoC)
CVE-2008-1801—doslinux
Integer underflow in the iso_recv_msg function (iso.c) in rdesktop 1.5.0 allows remote attackers to cause a denial of se
28RIESGO
abrir ↗
Referência✓ VexDay Proof
ASPReferral 5.3 - 'AccountID' Blind SQL Injection
CVE-2008-6889—webappsasp
SQL injection vulnerability in Merchantsadd.asp in ASPReferral 5.3 allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗
Referência✓ VexDay Proof
webSPELL 4.01.02 - 'showonly' Blind SQL Injection
CVE-2007-1019—webappsphp
SQL injection vulnerability in news.php in webSPELL 4.01.02, when register_globals is enabled, allows remote attackers t
23RIESGO
abrir ↗
Referência✓ VexDay Proof
AyeView 2.20 - Invalid Bitmap Header Parsing Crash
CVE-2008-5937—doswindows
AyeView 2.20 allows user-assisted attackers to cause a denial of service (memory consumption or application crash) via a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Prozilla Top 100 1.2 - Arbitrary Delete Stats
CVE-2008-1785—webappsphp
delete.php in Prozilla Top 100 1.2 allows remote authenticated users to delete statistics and accounts of arbitrary user
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component Restaurante - Arbitrary File Upload
CVE-2007-4817—webappsphp
Unrestricted file upload vulnerability in the Restaurante (com_restaurante) component for Joomla! allows remote attacker
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Jupiter CMS 1.1.5 - '/index.php' Local/Remote File Inclusion
CVE-2007-0987—webappsphp
Directory traversal vulnerability in index.php in Jupiter CMS 1.1.5 allows remote attackers to include and execute arbit
23RIESGO
abrir ↗
← anteriorpágina 640 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.