Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.689exploits catalogados
38.075CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
Plan 9 Kernel - 'devenv.c OTRUNC/pwrite' Local Privilege Escalation
CVE-2007-1189—localplan9
Integer overflow in the envwrite function in the Alcatel-Lucent Bell Labs Plan 9 kernel allows local users to overwrite
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Formbankserver 1.9 - 'Name' Remote Denial of Service
CVE-2006-6910—doswindows
formbankcgi.exe in Fersch Formbankserver 1.9, when the PATH_INFO begins with Abfrage, allows remote attackers to cause a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
XM Easy Personal FTP Server 5.6.0 - Remote Denial of Service
CVE-2008-5626—doswindows
XM Easy Personal FTP Server 5.6.0 allows remote authenticated users to cause a denial of service via a crafted argument
50RIESGO
abrir ↗
Referência✓ VexDay Proof
Acoustica Mixcraft 4.2 - Universal Stack Overflow (SEH)
CVE-2008-3877—localwindows
Stack-based buffer overflow in Acoustica Mixcraft 4.1 Build 96 and 4.2 Build 98 allows user-assisted attackers to execut
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP-Address Book 4.0.x - Multiple SQL Injections
CVE-2008-2565—webappsphp
Multiple SQL injection vulnerabilities in PHP Address Book 3.1.5 and earlier allow remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
P-Book 1.17 - 'pb_lang' Remote File Inclusion
CVE-2006-5667—webappsphp
Multiple PHP remote file inclusion vulnerabilities in P-Book 1.17 and earlier allow remote attackers to execute arbitrar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHPOCS 0.1-beta3 - 'act' Local File Inclusion
CVE-2008-4331—webappsphp
Directory traversal vulnerability in library/pagefunctions.inc.php in phpOCS 0.1 beta3 and earlier allows remote attacke
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP infoBoard 7 - Plus Insecure Cookie Handling
CVE-2008-4334—webappsphp
PHP infoBoard V.7 Plus allows remote attackers to bypass authentication and gain administrative access by setting the in
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Acc Real Estate 4.0 - Insecure Cookie Handling
CVE-2008-6293—webappsphp
admin/Index.php in Acc Real Estate 4.0 allows remote attackers to bypass authentication and gain administrative access b
23RIESGO
abrir ↗
Referência✓ VexDay Proof
XZero Community Classifieds 4.95.11 - Local File Inclusion / SQL Injection
CVE-2007-6567—webappsphp
Directory traversal vulnerability in index.php in XZero Community Classifieds 4.95.11 and earlier allows remote attacker
23RIESGO
abrir ↗
Referência✓ VexDay Proof
DM Guestbook 0.4.1 - Multiple Local File Inclusions
CVE-2007-5821—webappsphp
Multiple directory traversal vulnerabilities in DM Guestbook 0.4.1 and earlier allow remote attackers to include and exe
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ContentNow 1.4.1 - Arbitrary File Upload / Cross-Site Scripting
CVE-2008-3181—webappsphp
Unrestricted file upload vulnerability in upload.php in ContentNow CMS 1.4.1 allows remote authenticated users to execut
23RIESGO
abrir ↗
Referência✓ VexDay Proof
DD-WRT HTTPd Daemon/Service - Remote Command Execution
CVE-2008-6975—remotehardware
Multiple cross-site request forgery (CSRF) vulnerabilities in apply.cgi in DD-WRT 24 sp2 allow remote attackers to hijac
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP-Address Book 3.1.5 - SQL Injection / Cross-Site Scripting
CVE-2008-2565—webappsphp
Multiple SQL injection vulnerabilities in PHP Address Book 3.1.5 and earlier allow remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
AuraCMS 2.1 - Remote File Attachment / Local File Inclusion
CVE-2007-4905—webappsphp
Unrestricted file upload vulnerability in mod/contak.php in AuraCMS 2.1 allows remote attackers to upload and execute ar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP Classifieds 7.1 - 'detail.php' SQL Injection
CVE-2006-5828—webappsphp
SQL injection vulnerability in detail.php in DeltaScripts PHP Classifieds 7.1 and earlier allows remote attackers to exe
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Magic News Pro 1.0.3 - 'script_path' Remote File Inclusion
CVE-2006-4823—webappsphp
PHP remote file inclusion vulnerability in scripts/news_page.php in Reamday Enterprises Magic News Pro 1.0.3 and earlier
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ScriptsFeed (SF) Auto Classifieds Software - Arbitrary File Upload
CVE-2008-6944—webappsphp
Unrestricted file upload vulnerability in ScriptsFeed Auto Classifieds allows remote authenticated users to execute arbi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
HispaH textlinksads - 'index.php' SQL Injection
CVE-2008-6154—webappsphp
SQL injection vulnerability in index.php in Hispah Text Links Ads 1.1 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Cold BBS - Remote Database Disclosure
CVE-2008-5597—webappsasp
Cold BBS stores sensitive information under the web root with insufficient access control, which allows remote attackers
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MyCars Automotive - Authentication Bypass
CVE-2009-2018—webappsphp
SQL injection vulnerability in admin/index.php in Jared Eckersley MyCars, when magic_quotes_gpc is disabled, allows remo
23RIESGO
abrir ↗
Referência✓ VexDay Proof
OxYProject 0.85 - 'edithistory.php' Remote Code Execution
CVE-2008-6651—webappsphp
Static code injection vulnerability in edithistory.php in OxYProject OxYBox 0.85 allows remote attackers to inject arbit
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Sinapis 2.2 Gastebuch - 'sinagb.php?fuss' Remote File Inclusion
CVE-2007-1130—webappsphp
PHP remote file inclusion vulnerability in sinagb.php in Sinapis Gastebuch 2.2 allows remote attackers to execute arbitr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
phpBB Import Tools Mod 0.1.4 - Remote File Inclusion
CVE-2006-7147—webappsphp
PHP remote file inclusion vulnerability in includes/functions_mod_user.php in phpBB Import Tools Mod 0.1.4 and earlier a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Micro CMS 0.3.5 - 'microcms_path' Remote File Inclusion
CVE-2006-3144—webappsphp
PHP remote file inclusion vulnerability in micro_cms_files/microcms-include.php in Implied By Design (IBD) Micro CMS 3.5
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Flat Chat 2.0 - 'include online.txt' Remote Code Execution
CVE-2007-1394—webappsphp
Direct static code injection vulnerability in startsession.php in Flat Chat 2.0 allows remote attackers to execute arbit
23RIESGO
abrir ↗
Referência✓ VexDay Proof
KingSoft - 'UpdateOcx2.dll SetUninstallName()' Heap Overflow (PoC)
CVE-2008-1307—doswindows
Heap-based buffer overflow in the KUpdateObj2 Class ActiveX control in UpdateOcx2.dll in Beijing KingSoft Antivirus Onli
28RIESGO
abrir ↗
Referência✓ VexDay Proof
X.Org xorg-x11-xfs 1.0.2-3.1 - Local Race Condition
CVE-2007-3103—locallinux
The init.d script for the X.Org X11 xfs font server on various Linux distributions might allow local users to change the
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CenterIM 4.22.3 - Remote Command Execution
CVE-2008-1467—remotelinux
CenterIM 4.22.3 and earlier allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ASP AutoDealer - Remote Database Disclosure
CVE-2008-5608—webappsasp
ASP AutoDealer stores sensitive information under the web root with insufficient access control, which allows remote att
23RIESGO
abrir ↗
← anteriorpágina 661 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.