Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.524exploits catalogados
37.962CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
Post Comments 3.0 - Insecure Cookie Handling
CVE-2008-4721—webappsphp
PHP Jabbers Post Comment 3.0 allows remote attackers to bypass authentication and gain administrative access by setting
23RIESGO
abrir ↗
Referência✓ VexDay Proof
The Gemini Portal 4.7 - 'lang' Remote File Inclusion
CVE-2008-4720—webappsphp
Multiple PHP remote file inclusion vulnerabilities in The Gemini Portal 4.7 allow remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joovili 3.0 - Multiple SQL Injections
CVE-2008-4711—webappsphp
SQL injection vulnerability in Joovili 3.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to ex
23RIESGO
abrir ↗
Referência✓ VexDay Proof
LokiCMS 0.3.4 - 'admin.php' Create Local File Inclusion
CVE-2008-4662—webappsphp
Directory traversal vulnerability in admin.php in LokiCMS 0.3.4, when magic_quotes_gpc is disabled, allows remote attack
23RIESGO
abrir ↗
Referência✓ VexDay Proof
My PHP Dating - 'id' SQL Injection
CVE-2008-4705—webappsphp
SQL injection vulnerability in success_story.php in php Online Dating Software MyPHPDating allows remote attackers to ex
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CodeAvalanche RateMySite - Database Disclosure
CVE-2008-5896—webappsasp
CodeAvalanche RateMySite stores sensitive information under the web root with insufficient access control, which allows
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mini-stream RM-MP3 Converter 3.0.0.7 - '.m3u' Local Stack Overflow (PoC)
CVE-2009-1328—doswindows
Stack-based buffer overflow in Mini-stream RM-MP3 Converter 3.0.0.7 allows remote attackers to execute arbitrary code vi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHPMyphorum 1.5a - '/mep/frame.php' Remote File Inclusion
CVE-2007-0361—webappsphp
PHP remote file inclusion vulnerability in mep/frame.php in PHPMyphorum 1.5a allows remote attackers to execute arbitrar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Net-Side.net CMS - 'index.php?cms' Remote File Inclusion
CVE-2007-1707—webappsphp
PHP remote file inclusion vulnerability in index.php in Net Side Content Management System (Net-Side.net CMS) allows rem
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Fuzzylime CMS 3.01 - 'admindir' Remote File Inclusion
CVE-2008-1405—webappsphp
PHP remote file inclusion vulnerability in code/display.php in fuzzylime (cms) 3.01 allows remote attackers to execute a
35RIESGO
abrir ↗
Referência✓ VexDay Proof
EHCP 0.22.8 - Multiple Remote File Inclusions
CVE-2007-6178—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Easy Hosting Control Panel for Ubuntu (EHCP) 0.22.8 and earlier al
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Affiliate Market 0.1 Beta - 'Language' Local File Inclusion
CVE-2008-0794—webappsphp
Directory traversal vulnerability in user/header.php in Affiliate Market 0.1 BETA allows remote attackers to include and
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Clever Copy 3.0 - 'results.php' SQL Injection
CVE-2008-2909—webappsphp
SQL injection vulnerability in results.php in Clever Copy 3.0 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Contenido 4.8.4 - Remote File Inclusion / Cross-Site Scripting
CVE-2008-2911—webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Contenido 4.8.4 allow remote attackers to inject arb
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mantis Bug Tracker 1.1.3 - Remote Code Execution
CVE-2008-4687—webappsphp
manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort param
50RIESGO
abrir ↗
Referência✓ VexDay Proof
Wireshark 1.0.x - '.ncf' Packet Capture Local Denial of Service
CVE-2008-4682—dosmultiple
wtap.c in Wireshark 0.99.7 through 1.0.3 allows remote attackers to cause a denial of service (application abort) via a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHPWebGallery 1.7.2 - Session Hijacking / Code Execution
CVE-2008-4645—webappsphp
plugins/event_tracer/event_list.php in PhpWebGallery 1.7.2 and earlier allows remote authenticated administrators to exe
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WebAlbum 2.02pl - COOKIE[skin2] Remote Code Execution
CVE-2006-1480—webappsphp
Directory traversal vulnerability in start.php in WebAlbum 2.02 allows remote attackers to include arbitrary files and e
23RIESGO
abrir ↗
Referência✓ VexDay Proof
mystats - 'hits.php' Multiple Vulnerabilities
CVE-2008-4643—webappsphp
SQL injection vulnerability in hits.php in myWebland myStats allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗
Referência✓ VexDay Proof
iWare Pro 5.0.4 - 'chat_panel.php' Remote Code Execution
CVE-2006-5837—webappsphp
Static code injection vulnerability in chat_panel.php in the SimpleChat 1.0.0 module for iWare Professional CMS allows r
23RIESGO
abrir ↗
Referência✓ VexDay Proof
AstroSPACES 1.1.1 - 'id' SQL Injection
CVE-2008-4642—webappsphp
SQL injection vulnerability in profile.php in AstroSPACES 1.1.1 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗
Referência✓ VexDay Proof
TorrentFlux 2.2 - 'downloaddetails.php' Local File Disclosure
CVE-2006-6598—webappsphp
Directory traversal vulnerability in viewnfo.php in (1) TorrentFlux before 2.2 and (2) torrentflux-b4rt before 2.1-b4rt-
23RIESGO
abrir ↗
Referência✓ VexDay Proof
NewsCMSLite - 'newsCMS.mdb' Remote Password Disclosure
CVE-2007-0091—webappsasp
newsCMSlite stores sensitive information under the web root with insufficient access control, which allows remote attack
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Pakupaku CMS 0.4 - Arbitrary File Upload / Local File Inclusion
CVE-2007-4640—webappsphp
Unrestricted file upload vulnerability in index.php in Pakupaku CMS 0.4 and earlier allows remote attackers to upload an
23RIESGO
abrir ↗
Referência✓ VexDay Proof
RoomPHPlanning 1.5 - Multiple SQL Injections
CVE-2008-6634—webappsphp
SQL injection vulnerability in RoomPHPlanning 1.5 allows remote attackers to execute arbitrary SQL commands via the idro
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP Photo Gallery 1.0 - 'photo_id' SQL Injection
CVE-2008-1711—webappsphp
Terong PHP Photo Gallery (aka Advanced Web Photo Gallery) 1.0 stores passwords in cleartext in a MySQL database, which a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Hedgehog-CMS 1.21 - 'header.php' Local File Inclusion
CVE-2008-2898—webappsphp
Directory traversal vulnerability in includes/header.php in Hedgehog-CMS 1.21 allows remote attackers to include and exe
23RIESGO
abrir ↗
Referência✓ VexDay Proof
YourFreeWorld Shopping Cart - Blind SQL Injection
CVE-2008-4886—webappsphp
SQL injection vulnerability in index.php in YourFreeWorld Shopping Cart Script allows remote attackers to execute arbitr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
AllMyGuests 0.4.1 - 'AMG_id' SQL Injection
CVE-2008-1961—webappsphp
SQL injection vulnerability in index.php in Voice Of Web AllMyGuests 0.4.1 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WEBBDOMAIN Post Card 1.02 - 'catid' SQL Injection
CVE-2008-6622—webappsphp
SQL injection vulnerability in choosecard.php in WEBBDOMAIN Post Card (aka Web Postcards) 1.02, 1.01, and earlier allows
23RIESGO
abrir ↗
← anteriorpágina 644 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.