Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.524exploits catalogados
37.962CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
ReVou Twitter Clone - Admin Password Change
CVE-2008-6752—webappsphp
adminlogin/password.php in the Twitter Clone (TClone) plugin for ReVou Micro Blogging does not verify the original passw
23RIESGO
abrir ↗
Referência✓ VexDay Proof
webid 0.5.4 - Multiple Vulnerabilities
CVE-2008-7117—webappsphp
eledicss.php in WeBid auction script 0.5.4 allows remote attackers to modify arbitrary cascading style sheets (CSS) file
23RIESGO
abrir ↗
Referência✓ VexDay Proof
EnjoySAP ActiveX kweditcontrol.kwedit.1 - Remote Stack Overflow (PoC)
CVE-2007-3607—doswindows
Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to cause a denia
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Wallpaper Complete Website 1.0.09 - SQL Injection
CVE-2006-6214—webappsphp
SQL injection vulnerability in wallpaper.php in Wallpaper Website (Wallpaper Complete Website) 1.0.09 allows remote atta
23RIESGO
abrir ↗
Referência✓ VexDay Proof
e107 Plugin BLOG Engine 2.2 - 'rid' Blind SQL Injection
CVE-2008-2455—webappsphp
SQL injection vulnerability in comment.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows remote attackers to exe
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MapLab MS4W 2.2.1 - Remote File Inclusion
CVE-2007-1843—webappsphp
PHP remote file inclusion vulnerability in gmapfactory/params.php in MapLab 2.2.1, when register_globals is enabled, all
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MySpace Content Zone 3.x - Arbitrary File Upload
CVE-2007-6668—webappsphp
admin/uploadgames.php in MySpace Content Zone (MCZ) 3.x does not require administrative privileges, which allows remote
23RIESGO
abrir ↗
Referência✓ VexDay Proof
mxCamArchive 2.2 - Bypass Configuration Download
CVE-2008-6955—webappsphp
mxCamArchive 2.2 stores sensitive information under the web root with insufficient access control, which allows remote a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP 4.4.6 - 'cpdf_open()' Local Source Code Disclosure
CVE-2007-1412—localmultiple
The cpdf_open function in the ClibPDF (cpdf) extension in PHP 4.4.6 allows context-dependent attackers to obtain sensiti
23RIESGO
abrir ↗
Referência✓ VexDay Proof
k-rate - SQL Injection / Cross-Site Scripting
CVE-2008-7099—webappsphp
Unspecified vulnerability in the Manage Templates feature in Qsoft K-Rate Premium allows remote attackers to execute arb
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Microsoft Visual Basic 6.0 Project - Description Stack Overflow (PoC)
CVE-2007-2884—doswindows
Multiple stack-based buffer overflows in Microsoft Visual Basic 6 allow user-assisted remote attackers to cause a denial
35RIESGO
abrir ↗
Referência✓ VexDay Proof
WebSVN 2.0 - Cross-Site Scripting / File Handling / Code Execution
CVE-2008-5919—webappsphp
Directory traversal vulnerability in rss.php in WebSVN 2.0 and earlier, when magic_quotes_gpc is disabled, allows remote
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Envolution 1.1.0 - 'PNSVlang' Remote Code Execution
CVE-2006-6445—webappsphp
Directory traversal vulnerability in error.php in Envolution 1.1.0 and earlier allows remote attackers to include and ex
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Samsung DVR SHR2040 - HTTPd Remote Denial of Service Denial of Service (PoC)
CVE-2008-4380—doshardware
The web interface in Samsung DVR SHR2040 allows remote attackers to cause a denial of service (crash) via a malformed HT
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Flexcustomer 0.0.6 - Admin Authentication Bypass / Possible PHP Code Writing
CVE-2008-6761—webappsphp
Static code injection vulnerability in admin/install.php in Flexcustomer 0.0.6 might allow remote attackers to inject ar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WeBid 0.5.4 - 'item.php' SQL Injection
CVE-2008-7119—webappsphp
SQL injection vulnerability in item.php in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Google Chrome - 'ChromeHTML://' Remote Parameter Injection
CVE-2008-5749—remotewindows
Argument injection vulnerability in Google Chrome 1.0.154.36 on Windows XP SP3 allows remote attackers to execute arbitr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mambo Component com_flyspray < 1.0.1 - Remote File Disclosure
CVE-2006-6203—webappsphp
Directory traversal vulnerability in startdown.php in the Flyspray ME 1.0.1 (com_flyspray) component for Mambo allows re
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Vantage Linguistics AnswerWorks 4 - API ActiveX Control Buffer Overflow
CVE-2007-6387—remotewindows
Multiple stack-based buffer overflows in the awApi4.AnswerWorks.1 ActiveX control in awApi4.dll 4.0.0.42, as used by Van
35RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP 4.4.6 - 'snmpget()' Object id Local Buffer Overflow
CVE-2007-1413—localwindows
Buffer overflow in the snmpget function in the snmp extension in PHP 5.2.3 and earlier, including PHP 4.4.6 and probably
28RIESGO
abrir ↗
Referência✓ VexDay Proof
E-GADS! 2.2.6 - 'common.php?locale' Remote File Inclusion
CVE-2007-2521—webappsphp
PHP remote file inclusion vulnerability in common.php in E-GADS! before 2.2.7 allows remote attackers to execute arbitra
23RIESGO
abrir ↗
Referência✓ VexDay Proof
acFTP FTP Server 1.4 - 'USER' Remote Buffer Overflow (PoC)
CVE-2006-2242—doswindows
acFTP 1.4 allows remote attackers to cause a denial of service (application crash) via a long string with "{" (brace) ch
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CPCommerce 1.1.0 - 'id_category' SQL Injection
CVE-2007-2890—webappsphp
SQL injection vulnerability in category.php in cpCommerce 1.1.0 and earlier allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SimpCMS 04.10.2007 - 'site' Remote File Inclusion
CVE-2007-2009—webappsphp
PHP remote file inclusion vulnerability in index.php in SimpCMS Light 04.10.2007 and earlier allows remote attackers to
23RIESGO
abrir ↗
Referência✓ VexDay Proof
BlazeVideo HDTV Player 2.1 - '.PLF' Local Buffer Overflow
CVE-2006-6199—localwindows
Stack-based buffer overflow in BlazeVideo BlazeDVD Standard and Professional 5.0, and possibly earlier, allows remote at
50RIESGO
abrir ↗
Referência✓ VexDay Proof
maGAZIn 2.0 - 'PHPThumb.php?src' Remote File Disclosure
CVE-2007-2643—webappsphp
Directory traversal vulnerability in phpThumb.php in PinkCrow Designs Gallery or maGAZIn 2.0 allows remote attackers to
23RIESGO
abrir ↗
Referência✓ VexDay Proof
LaserNet CMS 1.5 - SQL Injection
CVE-2008-1913—webappsphp
SQL injection vulnerability in index.php in Lasernet CMS 1.5 and 1.11, when magic_quotes_gpc is disabled, allows remote
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Siemens C450IP/C475IP - Remote Denial of Service
CVE-2008-7065—doshardware
Siemens C450 IP and C475 IP VoIP devices allow remote attackers to cause a denial of service (disconnected calls and dev
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ItCMS 1.9 - 'boxpop.php' Remote Code Execution
CVE-2008-2192—webappsphp
Static code injection vulnerability in box/minichat/boxpop.php in IT!CMS (aka itcms) 1.9 allows remote attackers to inje
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Page Manager CMS 2006-02-04 - Arbitrary File Upload
CVE-2008-7167—webappsphp
Unrestricted file upload vulnerability in upload.php in Page Manager 2006-02-04 allows remote attackers to execute arbit
23RIESGO
abrir ↗
← anteriorpágina 655 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.