Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.647exploits catalogados
38.070CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
PostNuke Module pnEncyclopedia 0.2.0 - SQL Injection
CVE-2008-2191—webappsphp
SQL injection vulnerability in the pnEncyclopedia module 0.2.0 and earlier for PostNuke allows remote attackers to execu
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Wikiwig 4.1 - 'wk_lang.php' Remote File Inclusion
CVE-2006-2888—webappsphp
PHP remote file inclusion vulnerability in _wk/wk_lang.php in Wikiwig 4.1 and earlier allows remote attackers to execute
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Arcadwy Arcade Script - 'Username' Static Cross-Site Scripting
CVE-2009-1228—webappsphp
Cross-site scripting (XSS) vulnerability in register.php in Arcadwy Arcade Script CMS allows remote attackers to inject
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Cain & Abel 4.9.23 - '.rdp' Buffer Overflow (PoC)
CVE-2008-5405—doswindows
Stack-based buffer overflow in the RDP protocol password decoder in Cain & Abel 4.9.23 and 4.9.24, and possibly earlier,
50RIESGO
abrir ↗
Referência✓ VexDay Proof
PHPRaider 1.0.7 - 'PHPbb3.functions.php' Remote File Inclusion
CVE-2008-2481—webappsphp
PHP remote file inclusion vulnerability in authentication/phpbb3/phpbb3.functions.php in phpRaider 1.0.7 and 1.0.7a, whe
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Redaxo 3.2 - 'INCLUDE_PATH' Remote File Inclusion
CVE-2006-2845—webappsphp
PHP remote file inclusion vulnerability in Redaxo 3.0 up to 3.2 allows remote attackers to execute arbitrary PHP code vi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Redaxo 3.2 - 'INCLUDE_PATH' Remote File Inclusion
CVE-2006-2844—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Redaxo 3.0 allow remote attackers to execute arbitrary PHP code vi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Bloginator 1a - Cookie Bypass / SQL Injection
CVE-2009-1049—webappsphp
SQL injection vulnerability in articleCall.php in Bloginator 1A allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Bandwebsite 1.5 - SQL Injection / Cross-Site Scripting
CVE-2008-5338—webappsphp
Cross-site scripting (XSS) vulnerability in info.php in Bandwebsite (aka Bandsite portal system) 1.5 allows remote attac
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Bandwebsite 1.5 - SQL Injection / Cross-Site Scripting
CVE-2008-5337—webappsphp
SQL injection vulnerability in lyrics.php in Bandwebsite (aka Bandsite portal system) 1.5 allows remote attackers to exe
23RIESGO
abrir ↗
Referência✓ VexDay Proof
AssoCIateD CMS 1.1.3 - 'ROOT_PATH' Remote File Inclusion
CVE-2006-2841—webappsphp
Multiple PHP remote file inclusion vulnerabilities in AssoCIateD (aka ACID) CMS 1.1.3 allow remote attackers to execute
23RIESGO
abrir ↗
Referência✓ VexDay Proof
cf shopkart 5.2.2 - SQL Injection / File Disclosure
CVE-2008-6321—webappsasp
CF Shopkart 5.2.2 stores cfshopkart52.mdb under the web root with insufficient access control, which allows remote attac
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WebStudio CMS - Blind SQL Injection
CVE-2008-5336—webappsphp
SQL injection vulnerability in index.php in WebStudio CMS allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Wysi Wiki Wyg 1.0 - Local File Inclusion / Cross-Site Scripting / PHPInfo
CVE-2008-5322—webappsphp
Wysi Wiki Wyg 1.0 allows remote attackers to obtain system information via an invalid categup parameter to index.php, wh
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CaLogic Calendars 1.2.2 - 'langsel' SQL Injection
CVE-2008-2444—webappsphp
SQL injection vulnerability in userreg.php in CaLogic Calendars 1.2.2 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Pre Shopping Mall 1.1 - 'search.php' SQL Injection
CVE-2008-2114—webappsphp
SQL injection vulnerability in emall/search.php in Pre Shopping Mall 1.1 allows remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗
Referência✓ VexDay Proof
VideoLAN VLC Media Player 0.9.8a - Web UI 'input' Remote Denial of Service
CVE-2009-1045—doswindows
requests/status.xml in VLC 0.9.8a allows remote attackers to cause a denial of service (stack consumption and crash) via
23RIESGO
abrir ↗
Referência✓ VexDay Proof
BackLinkSpider 1.1 - 'cat_id' SQL Injection
CVE-2008-2096—webappsphp
SQL injection vulnerability in BackLinkSpider allows remote attackers to execute arbitrary SQL commands via the cat_id p
23RIESGO
abrir ↗
Referência✓ VexDay Proof
e107 < 0.7.13 - 'usersettings.php' Blind SQL Injection
CVE-2008-5320—webappsphp
SQL injection vulnerability in usersettings.php in e107 0.7.13 and earlier allows remote authenticated users to execute
23RIESGO
abrir ↗
Referência✓ VexDay Proof
gxine 0.5.6 - HTTP Plugin Remote Buffer Overflow (PoC)
CVE-2006-2802—doslinux
Buffer overflow in the HTTP Plugin (xineplug_inp_http.so) for xine-lib 1.1.1 allows remote attackers to cause a denial o
28RIESGO
abrir ↗
Referência✓ VexDay Proof
ClamAV < 0.94.2 - JPEG Parsing Recursive Stack Overflow (PoC)
CVE-2008-5314—dosmultiple
Stack consumption vulnerability in libclamav/special.c in ClamAV before 0.94.2 allows remote attackers to cause a denial
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Clean CMS 1.5 - Blind SQL Injection
CVE-2008-5289—webappsphp
SQL injection vulnerability in full_txt.php in Werner Hilversum Clean CMS 1.5 allows remote attackers to execute arbitra
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ASPPortal Free Version - 'Topic_Id' SQL Injection
CVE-2008-5268—webappsasp
SQL injection vulnerability in content/forums/reply.asp in ASPPortal allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗
Referência✓ VexDay Proof
TNT Forum 0.9.4 - Local File Inclusion
CVE-2008-5265—webappsphp
Directory traversal vulnerability in index.php in TNT Forum 0.9.4, when magic_quotes_gpc is disabled, allows remote atta
23RIESGO
abrir ↗
Referência✓ VexDay Proof
HP Software Update - 'Hpufunction.dll 4.0.0.1' Insecure Method
CVE-2008-2390—remotewindows
Hpufunction.dll 4.0.0.1 in HP Software Update exposes the unsafe (1) ExecuteAsync and (2) Execute methods, which allows
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CCLeague Pro 1.2 - Insecure Cookie Authentication
CVE-2008-5125—webappsphp
admin.php in CCleague Pro 1.2 allows remote attackers to bypass authentication by setting the type cookie value to admin
23RIESGO
abrir ↗
Referência✓ VexDay Proof
metajour 2.1 - 'system_path' Remote File Inclusion
CVE-2006-2768—webappsphp
PHP remote file inclusion vulnerability in METAjour 2.1, when register_globals is enabled, allows remote attackers to ex
23RIESGO
abrir ↗
Referência✓ VexDay Proof
AspWebCalendar 4.5 - 'eventid' SQL Injection
CVE-2004-1552—webappsasp
SQL injection vulnerability in aspWebCalendar allows remote attackers to execute arbitrary SQL statements via (1) the us
23RIESGO
abrir ↗
Referência✓ VexDay Proof
4Images 1.7.7 - Filter Bypass HTML Injection / Cross-Site Scripting
CVE-2009-2131—webappsphp
Cross-site scripting (XSS) vulnerability in 4images 1.7.7 and earlier allows remote authenticated users to inject arbitr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
TOWeLS 0.1 - 'scripture.php' Remote File Inclusion
CVE-2007-5628—webappsphp
PHP remote file inclusion vulnerability in src/scripture.php in The Online Web Library Site (TOWels) 0.1 allows remote a
28RIESGO
abrir ↗
← anteriorpágina 657 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.