Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.524exploits catalogados
37.962CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
Gforge 4.6 rc1 - 'skill_edit' SQL Injection
CVE-2008-6188—webappsphp
SQL injection vulnerability in people/editprofile.php in Gforge 4.6 rc1 and earlier allows remote attackers to execute a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MyDesing Sayac 2.0 - Authentication Bypass
CVE-2009-0447—webappsasp
Multiple SQL injection vulnerabilities in default.asp in MyDesign Sayac 2.0 allow remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Discuz! 6.0.1 - 'searchid' SQL Injection
CVE-2008-3554—webappsphp
SQL injection vulnerability in index.php in Discuz! 6.0.1 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗
Referência✓ VexDay Proof
LoCal Calendar 1.1 - 'lcUser.php' Remote File Inclusion
CVE-2006-5426—webappsphp
PHP remote file inclusion vulnerability in lib/lcUser.php in LoCal Calendar System 1.1 remote attackers to execute arbit
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Xfire 1.6.4 - Remote Denial of Service
CVE-2006-5391—doswindows
Xfire 1.64 and earlier allows remote attackers to cause a denial of service (client application crash) via a long string
23RIESGO
abrir ↗
Referência✓ VexDay Proof
phpBB PlusXL 2.0_272 - 'constants.php' Remote File Inclusion
CVE-2006-5387—webappsphp
PHP remote file inclusion vulnerability in mods/iai/includes/constants.php in the PlusXL 20_272 and earlier phpBB module
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Drake CMS 0.4.11 - Blind SQL Injection
CVE-2008-6475—webappsphp
SQL injection vulnerability in the guestbook component (components/guestbook/guestbook.php) in Drake CMS 0.4.11 and earl
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Adobe Photoshop CS2 / CS3 - '.bmp' Local Buffer Overflow
CVE-2007-2244—localwindows
Multiple buffer overflows in Adobe Photoshop CS2 and CS3, Illustrator CS3, and GoLive 9 allow user-assisted remote attac
35RIESGO
abrir ↗
Referência✓ VexDay Proof
Goople CMS 1.7 - Insecure Cookie Handling
CVE-2008-6118—webappsphp
win/content/upload.php in Goople CMS 1.7 allows remote attackers to bypass authentication and gain administrative access
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Adult Banner Exchange Website - 'targetid' SQL Injection
CVE-2008-6101—webappsphp
SQL injection vulnerability in click.php in Adult Banner Exchange Website allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗
Referência✓ VexDay Proof
LiteNews 0.1 - 'id' SQL Injection
CVE-2008-3507—webappsphp
SQL injection vulnerability in index.php in LiteNews 0.1 (aka 01), and possibly 1.2 and earlier, allows remote attackers
23RIESGO
abrir ↗
Referência✓ VexDay Proof
6rbScript 3.3 - 'singerid' SQL Injection
CVE-2008-6454—webappsphp
SQL injection vulnerability in section.php in 6rbScript 3.3 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
6rbScript 3.3 - 'section.php' Local File Inclusion
CVE-2008-6453—webappsphp
Directory traversal vulnerability in section.php in 6rbScript 3.3, when magic_quotes_gpc is disabled, allows remote atta
23RIESGO
abrir ↗
Referência✓ VexDay Proof
phpBB Prillian French Mod 0.8.0 - Remote File Inclusion
CVE-2006-5309—webappsphp
PHP remote file inclusion vulnerability in language/lang_french/lang_prillian_faq.php in the Prillian French 0.8.0 and e
23RIESGO
abrir ↗
Referência✓ VexDay Proof
e107 Plugin BLOG Engine 2.2 - 'uid' Blind SQL Injection
CVE-2008-6438—webappsphp
SQL injection vulnerability in macgurublog_menu/macgurublog.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows re
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PUMA 1.0 RC 2 - 'config.php' Remote File Inclusion
CVE-2006-4713—webappsphp
PHP remote file inclusion vulnerability in config.php in PSYWERKS PUMA 1.0 RC2 allows remote attackers to execute arbitr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Microsoft Windows Vista - Access Violation from Limited Account (Blue Screen of Death)
CVE-2008-4510—doswindows
Microsoft Windows Vista Home and Ultimate Edition SP1 and earlier allows local users to cause a denial of service (page
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Redaction System 1.0 - 'lang_prefix' Remote File Inclusion
CVE-2006-5302—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Redaction System 1.0000 allow remote attackers to execute arbitrar
28RIESGO
abrir ↗
Referência✓ VexDay Proof
Zeeways PHOTOVIDEOTUBE 1.1 - Authentication Bypass
CVE-2008-5042—webappsphp
Zeeways PhotoVideoTube 1.1 and earlier allows remote attackers to bypass authentication and perform administrative tasks
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mercury/32 Mail Server 4.01 - 'Pegasus' IMAP Buffer Overflow (3)
CVE-2004-2513—remotewindows
Buffer overflow in the IMAP service of Mercury (Pegasus) Mail 4.01 allows remote attackers to execute arbitrary code via
23RIESGO
abrir ↗
Referência✓ VexDay Proof
HiveMaker Directory 1.0.2 - 'cid' SQL Injection
CVE-2008-6427—webappsphp
SQL injection vulnerability in index.php in Hivemaker Professional 1.0.2 and earlier, when magic_quotes_gpc is disabled,
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PassWiki 0.9.16 RC3 - 'site_id' Local File Inclusion
CVE-2008-6423—webappsphp
Directory traversal vulnerability in passwiki.php in PassWiki 0.9.16 RC3 and earlier allows remote attackers to read arb
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Segue CMS 1.5.8 - 'themesdir' Remote File Inclusion
CVE-2006-5497—webappsphp
PHP remote file inclusion vulnerability in themes/program/themesettings.inc.php in Segue CMS 1.5.8 and earlier, when reg
23RIESGO
abrir ↗
Referência✓ VexDay Proof
BlazeVideo HDTV Player 3.5 - '.PLF' Playlist File Local Overflow
CVE-2009-0450—localwindows
Stack-based buffer overflow in BlazeVideo HDTV Player 3.5 and earlier allows remote attackers to execute arbitrary code
28RIESGO
abrir ↗
Referência✓ VexDay Proof
a-ConMan 3.2b - 'common.inc.php' Remote File Inclusion
CVE-2006-6078—webappsphp
PHP remote file inclusion vulnerability in common.inc.php in a-ConMan 3.2 beta allows remote attackers to execute arbitr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Macromedia Flash 8 (Flash8b.ocx) Internet Explorer 7 - Denial of Service
CVE-2006-6827—doswindows
Flash8b.ocx in Macromedia Flash 8 allows remote attackers to cause a denial of service (Internet Explorer 7 crash) via a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WSN Links 2.22/2.23 - 'vote.php' SQL Injection
CVE-2008-6031—webappsphp
SQL injection vulnerability in vote.php in WSN Links 2.22 and 2.23 allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗
Referência✓ VexDay Proof
QMail Mailing List Manager 1.2 - Database Disclosure
CVE-2008-5606—webappsasp
Gazatem QMail Mailing List Manager 1.2 stores sensitive information under the web root with insufficient access control,
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Scripts24 iPost 1.0.1 - 'id' SQL Injection
CVE-2008-3491—webappsphp
SQL injection vulnerability in go.php in Scripts24 iPost 1.0.1 and iTGP 1.0.4 allows remote attackers to execute arbitra
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Advanced Webhost Billing System (AWBS) 2.4.0 - 'cart2.php' Remote File Inclusion
CVE-2007-2272—webappsphp
PHP remote file inclusion vulnerability in docs/front-end-demo/cart2.php in Advanced Webhost Billing System (AWBS) 2.4.0
23RIESGO
abrir ↗
← anteriorpágina 647 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.