Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.524exploits catalogados
37.962CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
webSPELL 4.01.02 - 'topic' SQL Injection
CVE-2007-1163—webappsphp
SQL injection vulnerability in printview.php in webSPELL 4.01.02 and earlier allows remote attackers to execute arbitrar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Irokez Blog 0.7.1 - Multiple Remote File Inclusions
CVE-2006-6771—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Irokez CMS 0.7.1 and earlier, when register_globals is enabled, al
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Http explorer Web Server 1.02 - Directory Traversal
CVE-2006-6758—remotewindows
Directory traversal vulnerability in Http explorer 1.02 allows remote attackers to read arbitrary files via a .. (dot do
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SunByte e-Flower - 'id' SQL Injection
CVE-2008-5969—webappsphp
SQL injection vulnerability in popupproduct.php in Sunbyte e-Flower allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Real Estate Scripts 2008 - 'cat' SQL Injection
CVE-2008-4570—webappsphp
SQL injection vulnerability in index.php in Real Estate Classifieds allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗
Referência✓ VexDay Proof
RealPlayer 10.5 - ActiveX Control Denial of Service
CVE-2006-6759—doswindows
A certain ActiveX control in rpau3260.dll in RealNetworks RealPlayer 10.5 allows remote attackers to cause a denial of s
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Ixprim CMS 1.2 - Blind SQL Injection
CVE-2006-6756—webappsphp
The code function in install.fct.php in Ixprim 1.2 produces a guessable value of the confidential IXP_CODE in mainfile.p
23RIESGO
abrir ↗
Referência✓ VexDay Proof
LokiCMS 0.3.4 - 'index.php' Arbitrary Check File
CVE-2008-5965—webappsphp
Directory traversal vulnerability in index.php in LokiCMS 0.3.4 and earlier, when magic_quotes_gpc is disabled, allows r
23RIESGO
abrir ↗
Referência✓ VexDay Proof
sma-db 0.3.12 - Remote File Inclusion / Cross-Site Scripting
CVE-2009-1451—webappsphp
Cross-site scripting (XSS) vulnerability in startpage.php in SMA-DB 0.3.12 allows remote attackers to inject arbitrary w
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Ez Ringtone Manager - Multiple Remote File Disclosure Vulnerabilities
CVE-2008-6112—webappsphp
Multiple directory traversal vulnerabilities in Ez Ringtone Manager allow remote attackers to read arbitrary files via a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Valdersoft Shopping Cart 3.0 - Remote Command Execution
CVE-2006-0099—webappsphp
PHP remote file include vulnerability in (1) include/templates/categories/default.php and (2) certain other include/temp
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Apple Mac OSX xnu 1228.3.13 - 'macfsstat' Local Kernel Memory Leak/Denial of Service
CVE-2009-1237—dososx
Multiple memory leaks in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and earlier allow local users to cause a den
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Active Test 2.1 - 'QuizID' Blind SQL Injection
CVE-2008-5958—webappsasp
Multiple SQL injection vulnerabilities in Active Test 2.1 allow remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Microsoft Windows - 'NetrWkstaUserEnum()' Remote Denial of Service
CVE-2006-6723—doswindows
The Workstation service in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to cause a denial of service (m
35RIESGO
abrir ↗
Referência✓ VexDay Proof
open NewsLetter 2.5 - Multiple Vulnerabilities (2)
CVE-2006-6786—webappsphp
Open Newsletter 2.5 and earlier allows remote authenticated administrators to execute arbitrary PHP code by inserting th
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHPFootball 1.6 - Remote Database Disclosure
CVE-2007-0638—webappsphp
show.php in Vlad Alexa Mancini PHPFootball 1.6 allows remote attackers to obtain sensitive information (database content
23RIESGO
abrir ↗
Referência✓ VexDay Proof
BolinTech DreamFTP Server 1.0.2 - 'PORT' Remote Denial of Service
CVE-2006-6724—doswindows
BolinTech Dream FTP Server 1.02 allows remote authenticated users, including anonymous users, to cause a denial of servi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
XLAtunes 0.1 - 'album' SQL Injection
CVE-2007-1026—webappsphp
SQL injection vulnerability in view.php in XLAtunes 0.1 and earlier allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Newxooper-PHP 0.9.1 - 'mapage.php' Remote File Inclusion
CVE-2006-6711—webappsphp
PHP remote file inclusion vulnerability in compteur/mapage.php in Newxooper 0.9.1 allows remote attackers to execute arb
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PowerClan 1.14a - 'footer.inc.php' Remote File Inclusion
CVE-2006-6715—webappsphp
PHP remote file inclusion vulnerability in footer.inc.php in PowerClan 1.14a and earlier, when register_globals is enabl
23RIESGO
abrir ↗
Referência✓ VexDay Proof
XOOPS Module cjay content 3 - Remote File Inclusion
CVE-2007-3220—webappsphp
PHP remote file inclusion vulnerability in admin/editor2/spaw_control.class.php in the Cjay Content 3 module for XOOPS a
35RIESGO
abrir ↗
Referência✓ VexDay Proof
Jupiter CMS 1.1.5 - Arbitrary File Upload
CVE-2007-0972—webappsphp
Unrestricted file upload vulnerability in modules/emoticons.php in Jupiter CMS 1.1.5 allows remote attackers to upload a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
XOOPS Module XT-Conteudo - 'spaw_root' Remote File Inclusion
CVE-2007-3221—webappsphp
PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the XT-Conteudo module for XOOPS allows
35RIESGO
abrir ↗
Referência✓ VexDay Proof
Yahoo! Messenger 8.1.0.421 - CYFT Object Arbitrary File Download
CVE-2007-5017—remotewindows
Absolute path traversal vulnerability in a certain ActiveX control in the CYFT object in ft60.dll in Yahoo! Messenger 8.
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PgmReloaded 0.8.5 - Multiple Remote File Inclusions
CVE-2006-6710—webappsphp
Multiple PHP remote file inclusion vulnerabilities in PgmReloaded 0.8.5 and earlier allow remote attackers to execute ar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
E-Uploader Pro 1.0 - Image Upload / Code Execution
CVE-2006-6694—webappsphp
Directory traversal vulnerability in include/config.php in E-Uploader Pro 1.0 and earlier allows remote attackers to exe
23RIESGO
abrir ↗
Referência✓ VexDay Proof
the net guys aspired2blog - SQL Injection / File Disclosure
CVE-2008-5931—webappsasp
The Net Guys ASPired2Blog stores sensitive information under the web root with insufficient access control, which allows
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joovili 3.0.6 - 'joovili.images.php' Remote File Disclosure
CVE-2007-6621—webappsphp
Directory traversal vulnerability in joovili.images.php in Joovili 3.0.0 through 3.0.6 allows remote attackers to read a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
VerliAdmin 0.3 - 'index.php' Remote File Inclusion
CVE-2006-6666—webappsphp
PHP remote file inclusion vulnerability in index.php in VerliAdmin 0.3 and earlier allows remote authenticated users to
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ASP-DEV Internal E-Mail System - Authentication Bypass
CVE-2008-5926—webappsasp
Multiple SQL injection vulnerabilities in login.asp in ASP-DEv Internal E-Mail System allow remote attackers to execute
23RIESGO
abrir ↗
← anteriorpágina 653 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.