Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.689exploits catalogados
38.075CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
Service Provider Management System v1.0 - SQL Injection
CVE-2023-34581—webappsphp
Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHPmotion 2.0 - 'update_profile.php' Arbitrary File Upload
CVE-2008-3117—webappsphp
Unrestricted file upload vulnerability in update_profile.php in PHPmotion 2.0 and earlier allows remote authenticated us
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHPmotion 2.0 - 'update_profile.php' Arbitrary File Upload
CVE-2008-3118—webappsphp
SQL injection vulnerability in play.php in PHPmotion 2.0 and earlier allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗
Referência✓ VexDay Proof
TurboFTP Server 5.30 Build 572 - 'newline/LIST' Multiple Remote Denial of Service Vulnerabilities
CVE-2007-1080—doswindows
Multiple heap-based buffer overflows in TurboFTP 5.30 Build 572 allow remote servers to cause a denial of service via (1
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Scout Portal Toolkit 1.4.0 - 'ParentId' SQL Injection
CVE-2005-4195—webappsphp
Multiple SQL injection vulnerabilities in Scout Portal Toolkit (SPT) 1.3.1 and earlier allow remote attackers to execute
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Yourownbux 4.0 - 'cookie' SQL Injection
CVE-2008-4492—webappsphp
SQL injection vulnerability in referrals.php in YourOwnBux 4.0 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WengoPhone 2.x - SIP Phone Remote Denial of Service
CVE-2007-4366—doswindows
WengoPhone 2.1 allows remote attackers to cause a denial of service (device crash) via a SIP INVITE message without a Co
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SasCam WebCam Server 2.6.5 - ActiveX Remote Buffer Overflow
CVE-2008-6898—remotewindows
Buffer overflow in the XHTTP Module 4.1.0.0 in the ActiveX control for SaschArt SasCam Webcam Server 2.6.5 allows remote
50RIESGO
abrir ↗
Referência✓ VexDay Proof
Fuzzylime CMS 3.01 - Remote Command Execution
CVE-2008-3165—webappsphp
Directory traversal vulnerability in rss.php in fuzzylime (cms) 3.01a and earlier, when magic_quotes_gpc is disabled, al
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP TopTree BBS 2.0.1a - 'right_file' Remote File Inclusion
CVE-2007-2544—webappsphp
PHP remote file inclusion vulnerability in templates/default/tpl_message.php in PHP TopTree BBS 2.0.1a and earlier allow
23RIESGO
abrir ↗
Referência✓ VexDay Proof
pNews 2.08 - 'shownews' SQL Injection
CVE-2008-2673—webappsphp
SQL injection vulnerability in index.php in Powie pNews 2.08 and 2.10, when magic_quotes_gpc is disabled, allows remote
23RIESGO
abrir ↗
Referência✓ VexDay Proof
HRS Multi - 'key' Blind SQL Injection
CVE-2008-3266—webappsasp
SQL injection vulnerability in picture_pic_bv.asp in SoftAcid Hotel Reservation System (HRS) Multi allows remote attacke
23RIESGO
abrir ↗
Referência✓ VexDay Proof
DL PayCart 1.34 - Admin Password Changing
CVE-2008-5565—webappsphp
Cross-site request forgery (CSRF) vulnerability in admin/settings.php in DL PayCart 1.34 and earlier allows remote attac
23RIESGO
abrir ↗
Referência✓ VexDay Proof
VS-News-System 1.2.1 - 'newsordner' Remote File Inclusion
CVE-2007-1017—webappsphp
PHP remote file inclusion vulnerability in show_news_inc.php in VirtualSystem VS-News-System 1.2.1 and earlier allows re
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHPmyGallery 1.0beta2 - Local/Remote File Inclusion
CVE-2008-6316—webappsphp
Directory traversal vulnerability in _conf/core/common-tpl-vars.php in PHPmyGallery 1.0 beta2 allows remote attackers to
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Absolute NewsLetter 6.1 - Insecure Cookie Handling
CVE-2008-6861—webappsphp
Xigla Software Absolute Newsletter 6.0 and 6.1 allows remote attackers to bypass authentication and gain administrative
23RIESGO
abrir ↗
Referência✓ VexDay Proof
TWiki 4.2.0 - 'configure' Remote File Disclosure
CVE-2008-3195—webappscgi
Directory traversal vulnerability in bin/configure in TWiki before 4.2.3, when a certain step in the installation guide
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Million Pixels 3 - 'id_cat' SQL Injection
CVE-2008-3204—webappsphp
SQL injection vulnerability in tops_top.php in E-topbiz Million Pixels 3 allows remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Pragyan CMS 2.6.2 - 'sourceFolder' Remote File Inclusion
CVE-2008-3207—webappsphp
PHP remote file inclusion vulnerability in cms/modules/form.lib.php in Pragyan CMS 2.6.2, when register_globals is enabl
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Htaccess Passwort Generator 1.1 - 'ht_pfad' Remote File Inclusion
CVE-2007-1013—webappsphp
PHP remote file inclusion vulnerability in generate.php in VirtualSystem Htaccess Passwort Generator 1.1 allows remote a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Yerba SACphp 6.3 - Local File Inclusion
CVE-2008-4486—webappsphp
Directory traversal vulnerability in index.php in SAC.php (SACphp), as used in Yerba 6.3 and earlier, allows remote atta
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Numark Cue 5.0 rev 2 - '.m3u' File Local Stack Buffer Overflow
CVE-2008-4470—localwindows
Stack-based buffer overflow in Numark CUE 5.0 rev2 allows user-assisted attackers to cause a denial of service (applicat
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Vastal I-Tech Toner Cart - 'id' SQL Injection
CVE-2008-4467—webappsphp
SQL injection vulnerability in show_series_ink.php in Vastal I-Tech Toner Cart allows remote attackers to execute arbitr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
YouTube blog 0.1 - Remote File Inclusion / SQL Injection / Cross-Site Scripting
CVE-2008-3307—webappsphp
SQL injection vulnerability in todos.php in C. Desseno YouTube Blog (ytb) 0.1 allows remote attackers to execute arbitra
23RIESGO
abrir ↗
Referência✓ VexDay Proof
YouTube blog 0.1 - Remote File Inclusion / SQL Injection / Cross-Site Scripting
CVE-2008-3308—webappsphp
PHP remote file inclusion vulnerability in cuenta/cuerpo.php in C. Desseno YouTube Blog (ytb) 0.1, when register_globals
23RIESGO
abrir ↗
Referência✓ VexDay Proof
DeluxeBB 1.07 - Remote Create Admin
CVE-2006-3304—webappsphp
SQL injection vulnerability in cp.php in DeluxeBB 1.07 and earlier allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Pre Survey Poll - 'catid' SQL Injection
CVE-2008-3310—webappsasp
SQL injection vulnerability in default.asp in Pre Survey Poll allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Prozilla Top 100 1.2 - Arbitrary Delete Stats
CVE-2008-1785—webappsphp
delete.php in Prozilla Top 100 1.2 allows remote authenticated users to delete statistics and accounts of arbitrary user
23RIESGO
abrir ↗
Referência✓ VexDay Proof
NaviCOPA Web Server 2.01 - 'GET' Remote Buffer Overflow
CVE-2006-5112—remotewindows
Buffer overflow in InterVations NaviCOPA Web Server 2.01 allows remote attackers to execute arbitrary code via a long HT
50RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component Restaurante - Arbitrary File Upload
CVE-2007-4817—webappsphp
Unrestricted file upload vulnerability in the Restaurante (com_restaurante) component for Joomla! allows remote attacker
23RIESGO
abrir ↗
← anteriorpágina 660 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.