Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.524exploits catalogados
37.962CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
IrfanView 3.99 - '.ani' Local Buffer Overflow (1)
CVE-2007-1867—localwindows
Buffer overflow in IrfanView 3.99 allows remote attackers to execute arbitrary code via a crafted animated cursor (ANI)
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Lama Software 14.12.2007 - Multiple Remote File Inclusions
CVE-2008-0423—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Lama Software allow remote attackers to execute arbitrary PHP code
35RIESGO
abrir ↗
Referência✓ VexDay Proof
BolinOS 4.6.1 - Local File Inclusion / Cross-Site Scripting
CVE-2008-1555—webappsphp
Directory traversal vulnerability in system/_b/contentFiles/gbincluder.php in BolinOS 4.6.1 allows remote attackers to i
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ACGVannu 1.3 - 'index2.php' Remote User Pass Change
CVE-2007-0697—webappsphp
index2.php in ACGVannu 1.3 and earlier allows remote attackers to change the password or profile of a user via a modifie
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CoD2: DreamStats 4.2 - 'index.php' Remote File Inclusion
CVE-2007-0757—webappsphp
PHP remote file inclusion vulnerability in index.php in Miguel Nunes Call of Duty 2 (CoD2) DreamStats System 4.2 and ear
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Simple Machines Forum (SMF) 1.1.4 - SQL Injection
CVE-2008-6741—webappsphp
SQL injection vulnerability in Load.php in Simple Machines Forum (SMF) 1.1.4 and earlier allows remote attackers to exec
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Chicken of the VNC 2.0 - 'NULL-pointer' Remote Denial of Service
CVE-2007-0756—dososx
Chicken of the VNC (cotv) 2.0 allows remote attackers to cause a denial of service (application crash) via a large compu
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Smart Publisher 1.0.1 - 'filedata' Remote Code Execution
CVE-2008-0503—webappsphp
Eval injection vulnerability in admin/op/disp.php in Netwerk Smart Publisher 1.0.1 allows remote attackers to execute ar
28RIESGO
abrir ↗
Referência✓ VexDay Proof
JAF CMS 4.0 RC2 - Multiple Remote File Inclusions
CVE-2008-1609—webappsphp
Multiple PHP remote file inclusion vulnerabilities in just another flat file (JAF) CMS 4.0 RC2 allow remote attackers to
35RIESGO
abrir ↗
Referência✓ VexDay Proof
Flip 2.01 final - 'previewtheme.php?inc_path' Remote File Inclusion
CVE-2007-0785—webappsphp
PHP remote file inclusion vulnerability in previewtheme.php in Flipsource Flip 2.01-final 1.0 and earlier allows remote
35RIESGO
abrir ↗
Referência✓ VexDay Proof
A Better Member-Based ASP Photo Gallery - 'entry' SQL Injection
CVE-2009-0531—webappsphp
SQL injection vulnerability in gallery/view.asp in A Better Member-Based ASP Photo Gallery before 1.2 allows remote atta
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Star Articles 6.0 - Blind SQL Injection (1)
CVE-2008-7075—webappsphp
Multiple SQL injection vulnerabilities in Kalptaru Infotech Ltd. Star Articles 6.0 allow remote attackers to inject arbi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
e107 0.617 - Cross-Site Scripting Remote Cookie Disclosure
CVE-2005-2327—webappsphp
Cross-site scripting (XSS) vulnerability in e107 0.617 and earlier allows remote attackers to inject arbitrary web scrip
23RIESGO
abrir ↗
Referência✓ VexDay Proof
yourplace 1.0.2 - Multiple Vulnerabilities / Remote Code Execution
CVE-2008-6771—webappsphp
YourPlace 1.0.2 and earlier allows remote attackers to obtain sensitive system information via a direct request via a di
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Web Wiz Guestbook 8.21 - Database Disclosure
CVE-2003-1571—webappsasp
Web Wiz Guestbook 6.0 stores sensitive information under the web root with insufficient access control, which allows rem
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SmartFTP Client 2.0.1002 - Remote Heap Overflow Denial of Service
CVE-2007-0790—doswindows
Heap-based buffer overflow in SmartFTP 2.0.1002 allows remote FTP servers to execute arbitrary code via a large banner.
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP 'Perl' Extension - 'Safe_mode' Bypass
CVE-2007-4596—localwindows
The perl extension in PHP does not follow safe_mode restrictions, which allows context-dependent attackers to execute ar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Charrays CMS 0.9.3 - Multiple Remote File Inclusions
CVE-2007-6179—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Charray's CMS 0.9.3 allow remote attackers to execute arbitrary PH
23RIESGO
abrir ↗
Referência✓ VexDay Proof
RedDot CMS 7.5 - 'LngId' SQL Injection
CVE-2008-1613—webappsasp
SQL injection vulnerability in ioRD.asp in RedDot CMS 7.5 Build 7.5.0.48, and possibly other versions including 6.5 and
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Maian Links 3.1 - Insecure Cookie Handling
CVE-2008-3319—webappsphp
admin/index.php in Maian Links 3.1 and earlier allows remote attackers to bypass authentication and gain administrative
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Woltlab Burning Board Lite 1.0.2pl3e - 'pms.php' SQL Injection
CVE-2007-0812—webappsphp
SQL injection vulnerability in pms.php in Woltlab Burning Board (wBB) Lite 1.0.2pl3e and earlier allows remote authentic
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mini File Host 1.x - Arbitrary '.PHP' File Upload
CVE-2008-6785—webappsphp
Unrestricted file upload vulnerability in Mini File Host 1.5 allows remote attackers to execute arbitrary code by upload
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Geeklog 2 - 'BaseView.php' Remote File Inclusion
CVE-2007-0810—webappsphp
PHP remote file inclusion vulnerability in MVCnPHP/BaseView.php in GeekLog 2 and earlier allows remote attackers to exec
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CA BrightStor ARCserve 11.5.2.0 - 'catirpc.dll' RPC Server Denial of Service
CVE-2007-0816—doswindows
The RPC Server service (catirpc.exe) in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 SP2 and earlie
28RIESGO
abrir ↗
Referência✓ VexDay Proof
WordPress Plugin Wp-FileManager 1.2 - Arbitrary File Upload
CVE-2008-0222—webappsphp
Unrestricted file upload vulnerability in ajaxfilemanager.php in the Wp-FileManager 1.2 plugin for WordPress allows remo
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Titan FTP Server 6.03 - 'USER/PASS' Remote Heap Overflow (PoC)
CVE-2008-0702—doswindows
Multiple heap-based buffer overflows in Titan FTP Server 6.03 and 6.0.5.549 allow remote attackers to cause a denial of
38RIESGO
abrir ↗
Referência✓ VexDay Proof
LightRO CMS 1.0 - 'inhalt.php' Remote File Inclusion
CVE-2007-0824—webappsphp
PHP remote file inclusion vulnerability in inhalt.php in LightRO CMS 1.0 allows remote attackers to execute arbitrary PH
23RIESGO
abrir ↗
Referência✓ VexDay Proof
chipmunk topsites - Authentication Bypass / Cross-Site Scripting
CVE-2008-7072—webappsphp
Cross-site scripting (XSS) vulnerability in index.php in Chipmunk Topsites allows remote attackers to inject arbitrary w
23RIESGO
abrir ↗
Referência✓ VexDay Proof
LoveCMS 1.6.2 Final (Download Manager 1.0) - Arbitrary File Upload
CVE-2008-7062—webappsphp
Unrestricted file upload vulnerability in admin/index.php in Download Manager module 1.0 for LoveCMS 1.6.2 Final allows
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Kisisel Site 2007 - 'tr' SQL Injection
CVE-2007-0826—webappsphp
SQL injection vulnerability in forum.asp in Kisisel Site 2007 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗
← anteriorpágina 651 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.