Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.524exploits catalogados
37.962CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
GEPI 1.4.0 - '/gestion/savebackup.php' Remote File Inclusion
CVE-2006-5669—webappsphp
PHP remote file inclusion vulnerability in gestion/savebackup.php in Gepi 1.4.0 and earlier, and possibly other versions
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Dragoon 0.1 - 'root' Remote File Inclusion
CVE-2008-1773—webappsphp
PHP remote file inclusion vulnerability in includes/header.inc.php in Dragoon 0.1 allows remote attackers to execute arb
28RIESGO
abrir ↗
Referência✓ VexDay Proof
EternalMart Guestbook 1.10 - '/admin/auth.php' Remote File Inclusion
CVE-2003-1314—webappsphp
PHP remote file inclusion vulnerability in admin/auth.php in EternalMart Guestbook (EMGB) 1.1 allows remote attackers to
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Affiliate Directory - 'id' SQL Injection
CVE-2008-3719—webappsphp
SQL injection vulnerability in directory.php in SFS Affiliate Directory allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Entertainment Directory 1.1 - SQL Injection
CVE-2008-1788—webappsphp
SQL injection vulnerability in directory.php in Prozilla Entertainers 1.1 and earlier allows remote attackers to execute
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mozilla Firefox 3.0.x - XML Parser Memory Corruption / Denial of Service (PoC)
CVE-2009-1232—doswindows
Mozilla Firefox 3.0.8 and earlier 3.0.x versions allows remote attackers to cause a denial of service (memory corruption
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Prozilla Cheat Script 2.0 - 'id' SQL Injection
CVE-2008-1863—webappsphp
SQL injection vulnerability in view_reviews.php in Prozilla Cheat Script (aka Cheats) 2.0 allows remote attackers to exe
23RIESGO
abrir ↗
Referência✓ VexDay Proof
LokiCMS 0.3.3 - Remote Command Execution
CVE-2008-1860—webappsphp
Static code injection vulnerability in admin.php in LokiCMS 0.3.3 and earlier allows remote attackers to inject arbitrar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
isiAJAX 1 - 'praises.php?id' SQL Injection
CVE-2009-0881—webappsphp
SQL injection vulnerability in ejemplo/paises.php in isiAJAX 1 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Cain & Abel 4.9.24 - '.rdp' Local Stack Overflow
CVE-2008-5405—localwindows
Stack-based buffer overflow in the RDP protocol password decoder in Cain & Abel 4.9.23 and 4.9.24, and possibly earlier,
50RIESGO
abrir ↗
Referência✓ VexDay Proof
Pro Chat Rooms 3.0.2 - Cross-Site Scripting / Cross-Site Request Forgery
CVE-2008-6502—webappsphp
Directory traversal vulnerability in Pro Chat Rooms 3.0.2 allows remote authenticated users to select an arbitrary local
23RIESGO
abrir ↗
Referência✓ VexDay Proof
phpProfiles 2.1 Beta - Multiple Remote File Inclusions
CVE-2006-5634—webappsphp
Multiple PHP remote file inclusion vulnerabilities in phpProfiles 2.1 Beta allow remote attackers to execute arbitrary P
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Blog PixelMotion - 'categorie' SQL Injection
CVE-2008-1867—webappsphp
SQL injection vulnerability in Blog Pixel Motion (aka Blog PixelMotion) allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ASP User Engine .NET - Remote Database Disclosure
CVE-2008-6494—webappsphp
ASP User Engine.NET stores sensitive information under the web root with insufficient access control, which allows remot
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Links Directory 1.1 - 'cat_id' SQL Injection
CVE-2008-1871—webappsphp
SQL injection vulnerability in links.php in Scriptsagent.com Links Directory 1.1 allows remote authenticated users to ex
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Kusaba 1.0.4 - Remote Code Execution (1)
CVE-2008-5663—webappsphp
Multiple unrestricted file upload vulnerabilities in Kusaba 1.0.4 and earlier allow remote authenticated users to execut
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Comdev News Publisher 4.1.2 - SQL Injection
CVE-2008-1872—webappsphp
SQL injection vulnerability in home.news.php in Comdev News Publisher 4.1.2 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
mp3SDS 3.0 - '/Core/core.inc.php' Remote File Inclusion
CVE-2006-5613—webappsphp
PHP remote file inclusion in Core/core.inc.php in MP3 Streaming DownSampler (mp3SDS) 3.0, when register_globals is enabl
23RIESGO
abrir ↗
Referência✓ VexDay Proof
XPOZE Pro 3.05 - 'reed' SQL Injection
CVE-2008-1874—webappsphp
SQL injection vulnerability in account/user/mail.html in Xpoze Pro 3.05 and earlier allows remote authenticated users to
23RIESGO
abrir ↗
Referência✓ VexDay Proof
GestArt Beta 1 - 'aide.php?aide' Remote File Inclusion
CVE-2006-5612—webappsphp
PHP remote file inclusion vulnerability in aide.php3 (aka aide.php) in GestArt beta 1, when register_globals is enabled,
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CDNetworks Nefficient Download - 'NeffyLauncher.dll' Code Execution
CVE-2008-1886—remotewindows
The NeffyLauncher 1.0.5 ActiveX control (NeffyLauncher.dll) in CDNetworks Nefficient Download uses weak cryptography for
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP-Fusion 6.01.14 - Blind SQL Injection
CVE-2008-1918—webappsphp
SQL injection vulnerability in submit.php in PHP-Fusion 6.01.14 and 6.00.307, when magic_quotes_gpc is disabled and the
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Realtek Sound Manager (rtlrack.exe 1.15.0.0) - Playlist Buffer Overflow
CVE-2008-5664—localwindows
Stack-based buffer overflow in Realtek Media Player (aka Realtek Sound Manager, RtlRack, or rtlrack.exe) 1.15.0.0 allows
50RIESGO
abrir ↗
Referência✓ VexDay Proof
GDL 4.x - 'node' SQL Injection
CVE-2009-0965—webappsphp
SQL injection vulnerability in functions/browse.php in Ganesha Digital Library (GDL) 4.0 and 4.2 allows remote attackers
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Classifieds Caffe - 'cat_id' SQL Injection
CVE-2008-1936—webappsphp
SQL injection vulnerability in index.php in Classifieds Caffe allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗
Referência✓ VexDay Proof
TR News 2.1 - 'nb' SQL Injection
CVE-2008-1957—webappsphp
SQL injection vulnerability in news.php in Tr Script News 2.1 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗
Referência✓ VexDay Proof
TR News 2.1 - 'nb' SQL Injection
CVE-2008-1958—webappsphp
Unrestricted file upload vulnerability in the ajout_cat mode in admin/main.php in Tr Script News 2.1 allows remote authe
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Aterr 0.9.1 - PHP5 Local File Inclusion
CVE-2008-1962—webappsphp
Multiple directory traversal vulnerabilities in Aterr 0.9.1 allow remote attackers to include and execute arbitrary loca
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Grape Statistics 0.2a - 'location' Remote File Inclusion
CVE-2008-1963—webappsphp
PHP remote file inclusion vulnerability in includes/functions.php in Quate Grape Web Statistics 0.2a allows remote attac
35RIESGO
abrir ↗
Referência✓ VexDay Proof
Xine-Lib 1.1.12 - NSF demuxer Stack Overflow (PoC)
CVE-2008-1878—doslinux
Stack-based buffer overflow in the demux_nsf_send_chunk function in src/demuxers/demux_nsf.c in xine-lib 1.1.12 and earl
28RIESGO
abrir ↗
← anteriorpágina 648 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.