Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.524exploits catalogados
37.962CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
Hedgehog-CMS 1.21 - 'header.php' Local File Inclusion
CVE-2008-2898—webappsphp
Directory traversal vulnerability in includes/header.php in Hedgehog-CMS 1.21 allows remote attackers to include and exe
23RIESGO
abrir ↗
Referência✓ VexDay Proof
RoomPHPlanning 1.5 - Multiple SQL Injections
CVE-2008-6634—webappsphp
SQL injection vulnerability in RoomPHPlanning 1.5 allows remote attackers to execute arbitrary SQL commands via the idro
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHPX 3.5.16 - 'news_id' SQL Injection
CVE-2008-5000—webappsphp
SQL injection vulnerability in admin/includes/news.inc.php in PHPX 3.5.16, when magic_quotes_gpc is disabled, allows rem
23RIESGO
abrir ↗
Referência✓ VexDay Proof
OWL Intranet Engine 0.82 - 'xrms_file_root' Code Execution
CVE-2006-1149—webappsphp
PHP remote file inclusion vulnerability in lib/OWL_API.php in OWL Intranet Engine 0.82, when register_globals is enabled
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MW6 Barcode - ActiveX 'Barcode.dll' Remote Heap Overflow (PoC)
CVE-2009-0298—doswindows
Heap-based buffer overflow in MW6 Technologies Barcode ActiveX control (Barcode.MW6Barcode.1, Barcode.dll) 3.0.0.1 allow
23RIESGO
abrir ↗
Referência✓ VexDay Proof
rdesktop 1.5.0 - 'process_redirect_pdu()' BSS Overflow (PoC)
CVE-2008-1802—doslinux
Buffer overflow in the process_redirect_pdu (rdp.c) function in rdesktop 1.5.0 allows remote attackers to execute arbitr
28RIESGO
abrir ↗
Referência✓ VexDay Proof
Feedback and Rating Script 1.0 - 'detail.php' SQL Injection
CVE-2008-2277—webappsphp
SQL injection vulnerability in detail.php in Feedback and Rating Script 1.0 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
VideoLAN VLC Media Player < 0.9.6 - '.rt' Local Stack Buffer Overflow
CVE-2008-5036—localwindows
Stack-based buffer overflow in VideoLAN VLC media player 0.9.x before 0.9.6 might allow user-assisted attackers to execu
50RIESGO
abrir ↗
Referência✓ VexDay Proof
MyForum 1.3 - Insecure Cookie Handling
CVE-2008-5040—webappsphp
Graphiks MyForum 1.3 allows remote attackers to bypass authentication and gain administrative access by setting the (1)
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component beamospetition 1.0.12 - SQL Injection / Cross-Site Scripting
CVE-2009-0378—webappsphp
Cross-site scripting (XSS) vulnerability in index.php in the beamospetition (com_beamospetition) 1.0.12 component for Jo
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Snaps! Gallery 1.4.4 - Remote User Pass Change
CVE-2007-2715—webappsphp
Admin/users.php in Snaps! Gallery 1.4.4 allows remote attackers to change arbitrary usernames and passwords via the (1)
28RIESGO
abrir ↗
Referência✓ VexDay Proof
VideoLAN VLC Media Player 0.8.6e - Subtitle Parsing Local Buffer Overflow
CVE-2008-1881—localwindows
Stack-based buffer overflow in the ParseSSA function (modules/demux/subtitle.c) in VLC 0.8.6e allows remote attackers to
28RIESGO
abrir ↗
Referência✓ VexDay Proof
Anti-Keylogger Elite 3.3.0 - 'AKEProtect.sys' Local Privilege Escalation
CVE-2008-5049—localwindows
Buffer overflow in AKEProtect.sys 3.3.3.0 in ISecSoft Anti-Keylogger Elite 3.3.0 and earlier, and possibly other version
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component JooBlog 0.1.1 - 'PostID' SQL Injection
CVE-2008-5051—webappsphp
SQL injection vulnerability in the JooBlog (com_jb2) component 0.1.1 for Joomla! allows remote attackers to execute arbi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
DevelopItEasy Membership System 1.3 - Authentication Bypass
CVE-2008-5054—webappsphp
Multiple SQL injection vulnerabilities in Develop It Easy Membership System 1.3 allow remote attackers to execute arbitr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ASP.NET w3wp - COM Components Remote Crash
CVE-2006-1364—doswindows
Microsoft w3wp (aka w3wp.exe) does not properly handle when the AspCompat directive is not used when referencing COM com
35RIESGO
abrir ↗
Referência✓ VexDay Proof
Microsoft Works 7 - 'WkImgSrv.dll' ActiveX Remote Buffer Overflow
CVE-2008-1898—remotewindows
A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and
50RIESGO
abrir ↗
Referência✓ VexDay Proof
Blue Eye CMS 1.0.0 - 'clanek' Blind SQL Injection
CVE-2009-0425—webappsphp
SQL injection vulnerability in index.php in Blue Eye CMS 1.0.0 and earlier allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WholeHogSoftware Ware Support - Authentication Bypass
CVE-2009-0458—webappsphp
Multiple SQL injection vulnerabilities in admin/login_submit.php in Whole Hog Ware Support 1.x allow remote attackers to
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Agares ThemeSiteScript 1.0 - 'loadadminpage' Remote File Inclusion
CVE-2008-5066—webappsphp
PHP remote file inclusion vulnerability in upload/admin/frontpage_right.php in Agares Media ThemeSiteScript 1.0 allows r
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Virtual Guestbook 2.1 - Remote Database Disclosure
CVE-2009-0498—webappsasp
Virtual GuestBook (vgbook) 2.1 stores sensitive information under the web root with insufficient access control, which a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Simplog 0.9.2 - 's' Remote Command Execution
CVE-2006-1777—webappsphp
Directory traversal vulnerability in doc/index.php in Jeremy Ashcraft Simplog 0.9.2 and earlier allows remote attackers
23RIESGO
abrir ↗
Referência✓ VexDay Proof
XOOPS Module resmanager 1.21 - Blind SQL Injection
CVE-2007-2735—webappsphp
SQL injection vulnerability in edit_day.php in the ResManager 1.2.1 and earlier module for Xoops allows remote attackers
23RIESGO
abrir ↗
Referência✓ VexDay Proof
5th Avenue Shopping Cart - 'category_id' SQL Injection
CVE-2008-1921—webappsphp
SQL injection vulnerability in store_pages/category_list.php in 5th Avenue Shopping Cart 1.2 trial edition allows remote
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Crazy Goomba 1.2.1 - 'id' SQL Injection
CVE-2008-1934—webappsphp
SQL injection vulnerability in commentaires.php in Crazy Goomba 1.2.1 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHPFootball 1.6 - SQL Injection
CVE-2008-3387—webappsphp
SQL injection vulnerability in show.php in PHPFootball 1.6 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Deterministic Network Enhancer - 'dne2000.sys' Kernel Ring0 SYSTEM
CVE-2008-5121—localwindows
dne2000.sys in Citrix Deterministic Network Enhancer (DNE) 2.21.7.233 through 3.21.7.17464, as used in (1) Cisco VPN Cli
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MyServer 0.8.11 - '204 No Content' error Remote Denial of Service
CVE-2008-5160—doswindows
Unspecified vulnerability in MyServer 0.8.11 allows remote attackers to cause a denial of service (daemon crash) via mul
23RIESGO
abrir ↗
Referência✓ VexDay Proof
StatIt 4 - 'statitpath' Remote File Inclusion
CVE-2006-2253—webappsphp
PHP remote file inclusion vulnerability in visible_count_inc.php in Statit 4 (060207) allows remote attackers to execute
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SoftComplex PHP Image Gallery - 'ctg' SQL Injection
CVE-2008-6485—webappsphp
SQL injection vulnerability in index.php in SoftComplex PHP Image Gallery allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗
← anteriorpágina 641 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.