Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.524exploits catalogados
37.962CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
Ventrilo 3.0.2 - Null Pointer Remote Denial of Service
CVE-2008-3680—dosmultiple
The decryption function in Flagship Industries Ventrilo 3.0.2 and earlier allows remote attackers to cause a denial of s
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Company WebSite Builder PRO 1.9.8 - 'INCLUDE_PATH' Remote File Inclusion
CVE-2007-1513—webappsphp
PHP remote file inclusion vulnerability in comanda.php in GraFX Company WebSite Builder (CWB) PRO 1.9.8, when register_g
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CJG EXPLORER PRO 3.2 - 'g_pcltar_lib_dir' Remote File Inclusion
CVE-2007-2660—webappsphp
PHP remote file inclusion vulnerability in pcltrace.lib.php in the PclTar module in Vincent Blavet PhpConcept Library, a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
XNova 0.8 sp1 - 'xnova_root_path' Remote File Inclusion
CVE-2008-6023—webappsphp
PHP remote file inclusion vulnerability in includes/todofleetcontrol.php in a newer version of Xnova, possibly 0.8 sp1,
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Bubbling Library 1.32 - Multiple Local File Inclusions
CVE-2008-0545—webappsphp
Multiple directory traversal vulnerabilities in Bubbling Library 1.32 allow remote attackers to include and execute arbi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Megabbs Forum 2.2 - SQL Injection / Cross-Site Scripting
CVE-2008-2022—webappsasp
Mulatiple cross-site scripting (XSS) vulnerabilities in PD9 Software MegaBBS 2.2 allow remote attackers to inject arbitr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component JooBB 0.5.9 - Blind SQL Injection
CVE-2008-2651—webappsphp
SQL injection vulnerability in the Joomla! Bulletin Board (aka Joo!BB or com_joobb) component 0.5.9 for Joomla! allows r
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Simple Forum 3.2 - File Disclosure / Cross-Site Scripting
CVE-2008-0542—webappsphp
Directory traversal vulnerability in thumbnail.php in Gerd Tentler Simple Forum 3.2 allows remote attackers to read arbi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP iCalendar 2.24 - 'cookie_language' Local File Inclusion / Arbitrary File Upload
CVE-2008-5968—webappsphp
Directory traversal vulnerability in print.php in PHP iCalendar 2.24 and earlier allows remote attackers to include and
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Symphony 1.7.01 (non-patched) - Remote Code Execution
CVE-2008-3592—webappsphp
Unrestricted file upload vulnerability in the File Manager in the admin panel in Twentyone Degrees Symphony 1.7.01 and e
23RIESGO
abrir ↗
Referência✓ VexDay Proof
GreenCart PHP Shopping Cart - 'id' SQL Injection
CVE-2008-3585—webappsphp
Multiple SQL injection vulnerabilities in PozScripts GreenCart PHP Shopping Cart allow remote attackers to execute arbit
23RIESGO
abrir ↗
Referência✓ VexDay Proof
IntelliTamper 2.07 - 'imgsrc' Remote Buffer Overflow
CVE-2008-3583—remotewindows
Buffer overflow in the HTML parser in IntelliTamper 2.07 allows remote attackers to execute arbitrary code via a long UR
23RIESGO
abrir ↗
Referência✓ VexDay Proof
AJA Portal 1.2 (Windows) - Local File Inclusion
CVE-2009-0457—webappsphp
Multiple directory traversal vulnerabilities in AJA Portal 1.2 allow remote attackers to include and execute arbitrary l
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Telephone Directory 2008 - SQL Injection / Cross-Site Scripting
CVE-2008-2678—webappsphp
Multiple SQL injection vulnerabilities in Telephone Directory 2008, when magic_quotes_gpc is disabled, allow remote atta
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Euphonics Audio Player 1.0 (Windows XP SP3) - '.pls' Local Buffer Overflow
CVE-2009-0476—localwindows
Stack-based buffer overflow in MultiMedia Soft AdjMmsEng.dll 7.11.1.0 and 7.11.2.7, as distributed in multiple MultiMedi
50RIESGO
abrir ↗
Referência✓ VexDay Proof
k-links directory - SQL Injection / Cross-Site Scripting
CVE-2008-3581—webappsphp
Cross-site scripting (XSS) vulnerability in index.php in Qsoft K-Links allows remote attackers to inject arbitrary web s
23RIESGO
abrir ↗
Referência✓ VexDay Proof
k-links directory - SQL Injection / Cross-Site Scripting
CVE-2008-3580—webappsphp
Multiple SQL injection vulnerabilities in Qsoft K-Links allow remote attackers to execute arbitrary SQL commands via (1)
23RIESGO
abrir ↗
Referência✓ VexDay Proof
KAPhotoservice - 'album.asp' SQL Injection
CVE-2008-1426—webappsasp
SQL injection vulnerability in album.asp in KAPhotoservice allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Easy-Clanpage 2.2 - 'id' SQL Injection
CVE-2008-1425—webappsphp
SQL injection vulnerability in index.php in the gallery module in Easy-Clanpage 2.2 allows remote attackers to execute a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
4Site CMS 2.6 - Multiple SQL Injections
CVE-2009-0646—webappsphp
Multiple SQL injection vulnerabilities in 4Site CMS 2.6 and earlier allow remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Wsn (Multiple Products) - Local File Inclusion / Code Execution
CVE-2008-3555—webappsphp
Directory traversal vulnerability in index.php in (1) WSN Forum 4.1.43 and earlier, (2) Gallery 4.1.30 and earlier, (3)
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ACGVclick 0.2.0 - 'path' Remote File Inclusion
CVE-2007-0577—webappsphp
PHP remote file inclusion vulnerability in function.inc.php in ACGVclick 0.2.0 and earlier allows remote attackers to ex
23RIESGO
abrir ↗
Referência✓ VexDay Proof
phpBB MOD Forum picture and META tags 1.7 - Remote File Inclusion
CVE-2007-1818—webappsphp
PHP remote file inclusion vulnerability in MOD_forum_fields_parse.php in the Forum picture and META tags 1.7 module for
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WordPress Plugin WP-Forum 1.7.4 - SQL Injection
CVE-2008-0388—webappsphp
SQL injection vulnerability in the WP-Forum 1.7.4 plugin for WordPress allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Referência✓ VexDay Proof
YAAP 1.5 - '__autoload()' Remote File Inclusion
CVE-2007-2664—webappsphp
PHP remote file inclusion vulnerability in includes/common.php in Yaap 1.5 and earlier allows remote attackers to execut
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Scallywag - 'template.php?path' Remote File Inclusion
CVE-2007-2900—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Scallywag 2005-04-25 allow remote attackers to execute arbitrary P
23RIESGO
abrir ↗
Referência✓ VexDay Proof
phpBB Mod OpenID 0.2.0 - 'BBStore.php' Remote File Inclusion
CVE-2007-5173—webappsphp
PHP remote file inclusion vulnerability in includes/openid/Auth/OpenID/BBStore.php in phpBB Openid 0.2.0 allows remote a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Flat PHP Board 1.2 - Multiple Vulnerabilities
CVE-2007-6397—webappsphp
Multiple directory traversal vulnerabilities in index.php in Flat PHP Board 1.2 and earlier allow remote attackers to (1
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Cyberfolio 7.12 - 'rep' Remote File Inclusion
CVE-2008-2228—webappsphp
PHP remote file inclusion vulnerability in portfolio/commentaires/derniers_commentaires.php in Cyberfolio 7.12, when reg
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Eznet 3.5.0 - Remote Stack Overflow / Denial of Service
CVE-2003-1339—remotewindows
Stack-based buffer overflow in eZnet.exe, as used in eZ (a) eZphotoshare, (b) eZmeeting, (c) eZnetwork, and (d) eZshare
35RIESGO
abrir ↗
← anteriorpágina 654 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.