Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.524exploits catalogados
37.962CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
EZContents CMS 2.0.0 - Multiple SQL Injections
CVE-2008-2135—webappsphp
Multiple SQL injection vulnerabilities in VisualShapers ezContents 2.0.0 allow remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SunShop Shopping Cart 4.1.4 - 'id' SQL Injection
CVE-2008-3768—webappsphp
Multiple SQL injection vulnerabilities in class.ajax.php in Turnkey Web Tools SunShop Shopping Cart before 4.1.5 allow r
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP-Nuke Platinum 7.6.b.5 - 'dynamic_titles.php' SQL Injection
CVE-2008-1539—webappsphp
SQL injection vulnerability in includes/dynamic_titles.php in PHP-Nuke Platinum 7.6.b.5 allows remote attackers to execu
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Quick Poll Script - 'id' SQL Injection
CVE-2008-3765—webappsphp
SQL injection vulnerability in code.php in Quick Poll Script allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP Live Helper 2.0.1 - Multiple Vulnerabilities
CVE-2008-3762—webappsphp
SQL injection vulnerability in onlinestatus_html.php in Turnkey PHP Live Helper 2.0.1 and earlier allows remote attacker
23RIESGO
abrir ↗
Referência✓ VexDay Proof
VMware Workstation 6.5.1 - 'hcmon.sys 6.0.0.45731' Local Denial of Service
CVE-2008-3761—doswindows
hcmon.sys in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMware ACE 2.5.1 and earlier, and VM
23RIESGO
abrir ↗
Referência✓ VexDay Proof
YourFreeWorld Viral Marketing - SQL Injection
CVE-2008-3756—webappsphp
SQL injection vulnerability in tr.php in YourFreeWorld Viral Marketing Script allows remote attackers to execute arbitra
23RIESGO
abrir ↗
Referência✓ VexDay Proof
My PHP Indexer 1.0 - 'index.php' Local File Download
CVE-2008-6183—webappsphp
Multiple directory traversal vulnerabilities in index.php in My PHP Indexer 1.0 allow remote attackers to read arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
RunCMS 1.6 - Multiple Vulnerabilities
CVE-2007-6545—webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in RunCMS before 1.6.1 allow remote attackers to inject arbitrary we
23RIESGO
abrir ↗
Referência✓ VexDay Proof
2532/Gigs 1.2.2 Stable - Multiple Vulnerabilities
CVE-2008-6902—webappsphp
Unrestricted file upload vulnerability in upload_flyer.php in 2532designs 2532|Gigs 1.2.2 Stable allows remote attackers
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Active PHP BookMarks 1.1.02 - SQL Injection
CVE-2008-3748—webappsphp
SQL injection vulnerability in view_group.php in Active PHP Bookmarks (APB) 1.1.02 and 1.2.06 allows remote attackers to
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Ipswitch WS_FTP Home/Professional FTP Client - Remote Format String (PoC)
CVE-2008-3734—doswindows
Format string vulnerability in Ipswitch WS_FTP Home 2007.0.0.2 and WS_FTP Professional 2007.1.0.0 allows remote FTP serv
28RIESGO
abrir ↗
Referência✓ VexDay Proof
Microsoft Visual Studio - 'Msmask32.ocx' ActiveX Remote Buffer Overflow (PoC)
CVE-2008-3704—doswindows
Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions befo
50RIESGO
abrir ↗
Referência✓ VexDay Proof
Download Accelerator Plus DAP 8.6 - 'AniGIF.ocx' Buffer Overflow (PoC)
CVE-2008-3702—doswindows
Multiple stack-based buffer overflows in the Animation GIF ActiveX control in JComSoft AniGIF.ocx 1.12 and 2.47, as used
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Ventrilo 3.0.2 - Null Pointer Remote Denial of Service
CVE-2008-3680—dosmultiple
The decryption function in Flagship Industries Ventrilo 3.0.2 and earlier allows remote attackers to cause a denial of s
23RIESGO
abrir ↗
Referência✓ VexDay Proof
XNova 0.8 sp1 - 'xnova_root_path' Remote File Inclusion
CVE-2008-6023—webappsphp
PHP remote file inclusion vulnerability in includes/todofleetcontrol.php in a newer version of Xnova, possibly 0.8 sp1,
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Ksemail - Local File Inclusion
CVE-2008-1751—webappsphp
Multiple directory traversal vulnerabilities in index.php in Ksemail allow remote attackers to read arbitrary local file
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MyPHPsite - Local File Inclusion
CVE-2008-6018—webappsphp
Directory traversal vulnerability in index.php in MyPHPSite, when magic_quotes_gpc is disabled, allows remote attackers
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Bubbling Library 1.32 - Multiple Local File Inclusions
CVE-2008-0545—webappsphp
Multiple directory traversal vulnerabilities in Bubbling Library 1.32 allow remote attackers to include and execute arbi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Simple Forum 3.2 - File Disclosure / Cross-Site Scripting
CVE-2008-0542—webappsphp
Directory traversal vulnerability in thumbnail.php in Gerd Tentler Simple Forum 3.2 allows remote attackers to read arbi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
zeeproperty 1.0 - Arbitrary File Upload / Cross-Site Scripting
CVE-2008-6914—webappsphp
Unrestricted file upload vulnerability in viewprofile.php in Zeeways ZEEPROPERTY 1.0 allows remote authenticated users t
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP iCalendar 2.24 - 'cookie_language' Local File Inclusion / Arbitrary File Upload
CVE-2008-5968—webappsphp
Directory traversal vulnerability in print.php in PHP iCalendar 2.24 and earlier allows remote attackers to include and
23RIESGO
abrir ↗
Referência✓ VexDay Proof
OneCMS 2.5 - 'install_mod.php' Local File Inclusion
CVE-2008-2482—webappsphp
Directory traversal vulnerability in install_mod.php in insanevisions OneCMS 2.5 allows remote attackers to include and
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SineCMS 2.3.5 - Local File Inclusion / Remote Code Execution
CVE-2008-7163—webappsphp
Directory traversal vulnerability in mods/Integrated/index.php in SineCMS 2.3.5 and earlier, when register_globals is en
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Panda Security ActiveScan 2.0 (Update) - Remote Buffer Overflow
CVE-2008-3156—remotewindows
The ActiveScan ActiveX Control (as2guiie.dll) in Panda ActiveScan before 1.02.00 allows remote attackers to download and
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Symphony 1.7.01 (non-patched) - Remote Code Execution
CVE-2008-3592—webappsphp
Unrestricted file upload vulnerability in the File Manager in the admin panel in Twentyone Degrees Symphony 1.7.01 and e
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Jinzora 2.1 - 'media.php' Remote File Inclusion
CVE-2006-7130—webappsphp
PHP remote file inclusion vulnerability in backend/primitives/cache/media.php in Jinzora 2.1 and earlier allows remote a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
GreenCart PHP Shopping Cart - 'id' SQL Injection
CVE-2008-3585—webappsphp
Multiple SQL injection vulnerabilities in PozScripts GreenCart PHP Shopping Cart allow remote attackers to execute arbit
23RIESGO
abrir ↗
Referência✓ VexDay Proof
IntelliTamper 2.07 - 'imgsrc' Remote Buffer Overflow
CVE-2008-3583—remotewindows
Buffer overflow in the HTML parser in IntelliTamper 2.07 allows remote attackers to execute arbitrary code via a long UR
23RIESGO
abrir ↗
Referência✓ VexDay Proof
cPanel 11.x - Cross-Site Scripting / Local File Inclusion
CVE-2008-6926—webappsphp
Directory traversal vulnerability in autoinstall4imagesgalleryupgrade.php in the Fantastico De Luxe Module for cPanel al
23RIESGO
abrir ↗
← anteriorpágina 646 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.