Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.689exploits catalogados
38.075CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
SOTEeSKLEP 3.5RC9 - 'file' Remote File Disclosure
CVE-2007-4369—webappsphp
Directory traversal vulnerability in go/_files in SOTEeSKLEP before 4.0 allows remote attackers to read arbitrary files
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Microsoft Windows Wordpad - '.doc' File Local Denial of Service (PoC)
CVE-2009-0259—doswindows
The Word processor in OpenOffice.org 1.1.2 through 1.1.5 allows remote attackers to cause a denial of service (crash) an
23RIESGO
abrir ↗
Referência✓ VexDay Proof
gCards 1.45 - Multiple Vulnerabilities
CVE-2006-1347—webappsphp
SQL injection vulnerability in loginfunction.php in Greg Neustaetter gCards 1.45 and earlier allows remote attackers to
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Microsoft Windows Server 2000 SP4 (Advanced Server) - Message Queue (MS07-065)
CVE-2007-3039—remotewindows
Stack-based buffer overflow in the Microsoft Message Queuing (MSMQ) service in Microsoft Windows 2000 Server SP4, Window
50RIESGO
abrir ↗
Referência✓ VexDay Proof
Gallery 2.0.3 - 'stepOrder[]' Remote Command Execution
CVE-2006-1219—webappsphp
Directory traversal vulnerability in Gallery 2.0.3 and earlier, and 2.1 before RC-2a, allows remote attackers to include
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ExBB 0.22 - Local/Remote File Inclusion
CVE-2008-1862—webappsphp
ExBB Italia 0.22 and earlier only checks GET requests that use the QUERY_STRING for certain path manipulations, which al
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mantis Bug Tracker 1.1.1 - Code Execution / Cross-Site Scripting / Cross-Site Request Forgery
CVE-2008-2276—webappsphp
Cross-site request forgery (CSRF) vulnerability in manage_user_create.php in Mantis 1.1.1 allows remote attackers to cre
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mozilla Firefox 3.0.5 - Status Bar Obfuscation / Clickjacking
CVE-2009-0253—remotewindows
Mozilla Firefox 3.0.5 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PGOSD - '/misc/function.php3' Remote File Inclusion
CVE-2006-5543—webappsphp
PHP remote file inclusion vulnerability in misc/function.php3 in PHP Generator of Object SQL Database (PGOSD), when regi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Microsoft Windows - GDI+ '.ICO' Remote Division By Zero
CVE-2008-4327—doswindows
gdiplus.dll in GDI+ in Microsoft Windows XP SP3 does not properly handle crafted .ico files, which allows remote attacke
28RIESGO
abrir ↗
Referência✓ VexDay Proof
Ol BookMarks Manager 0.7.5 - Local File Inclusion / Remote File Inclusion / SQL Injection
CVE-2008-6409—webappsphp
SQL injection vulnerability in index.php in ol'bookmarks manager 0.7.5 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Referência✓ VexDay Proof
TorrentTrader Classic 1.04 - Blind SQL Injection
CVE-2008-4494—webappsphp
SQL injection vulnerability in completed-advance.php in TorrentTrader Classic 1.08 and 1.04 and earlier allows remote at
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ContentNow 1.4.1 - Arbitrary File Upload / Cross-Site Scripting
CVE-2008-3181—webappsphp
Unrestricted file upload vulnerability in upload.php in ContentNow CMS 1.4.1 allows remote authenticated users to execut
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Aztek Forum 4.00 - Cross-Site Scripting / SQL Injection
CVE-2006-1112—webappsphp
Aztek Forum 4.0 allows remote attackers to obtain sensitive information via a long login value in a register form, which
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Amaya 11.1 - W3C Editor/Browser 'defer' Remote Stack Overflow
CVE-2009-1209—remotewindows
Stack-based buffer overflow in W3C Amaya Web Browser 11.1 allows remote attackers to execute arbitrary code via a script
28RIESGO
abrir ↗
Referência✓ VexDay Proof
cPanel 11.x - 'Fantastico' Local File Inclusion
CVE-2008-4181—webappsphp
Directory traversal vulnerability in includes/xml.php in the Netenberg Fantastico De Luxe module before 2.10.4 r19 for c
23RIESGO
abrir ↗
Referência✓ VexDay Proof
BBClone 0.31 - 'selectlang.php' Remote File Inclusion
CVE-2007-0508—webappsphp
PHP remote file inclusion vulnerability in lib/selectlang.php in BBClone 0.31 allows remote attackers to execute arbitra
23RIESGO
abrir ↗
Referência✓ VexDay Proof
AT Contenator 1.0 - 'Root_To_Script' Remote File Inclusion
CVE-2007-0983—webappsphp
PHP remote file inclusion vulnerability in _admin/nav.php in AT Contenator 1.0 and earlier allows remote attackers to ex
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Particle Gallery 1.0.1 - SQL Injection
CVE-2007-3065—webappsphp
SQL injection vulnerability in viewimage.php in Particle Soft Particle Gallery 1.0.1 and earlier allows remote attackers
23RIESGO
abrir ↗
Referência✓ VexDay Proof
GeoVision LiveAudio - ActiveX Remote Freed-Memory Access
CVE-2009-1092—remotewindows
Use-after-free vulnerability in the LIVEAUDIO.LiveAudioCtrl.1 ActiveX control in LIVEAU~1.OCX 7.0 for GeoVision DVR syst
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MP3 TrackMaker 1.5 - '.mp3' Local Heap Overflow (PoC)
CVE-2009-0175—doswindows
Heap-based buffer overflow in Heathco Software MP3 TrackMaker 1.5 allows remote attackers to cause a denial of service (
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Ol BookMarks Manager 0.7.5 - Local File Inclusion / Remote File Inclusion / SQL Injection
CVE-2008-6408—webappsphp
PHP remote file inclusion vulnerability in frame.php in ol'bookmarks manager 0.7.5 allows remote attackers to execute ar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
phpBB Import Tools Mod 0.1.4 - Remote File Inclusion
CVE-2006-7147—webappsphp
PHP remote file inclusion vulnerability in includes/functions_mod_user.php in phpBB Import Tools Mod 0.1.4 and earlier a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Flat Chat 2.0 - 'include online.txt' Remote Code Execution
CVE-2007-1394—webappsphp
Direct static code injection vulnerability in startsession.php in Flat Chat 2.0 allows remote attackers to execute arbit
23RIESGO
abrir ↗
Referência✓ VexDay Proof
X.Org xorg-x11-xfs 1.0.2-3.1 - Local Race Condition
CVE-2007-3103—locallinux
The init.d script for the X.Org X11 xfs font server on various Linux distributions might allow local users to change the
23RIESGO
abrir ↗
Referência✓ VexDay Proof
BXCP 0.2.9.9 - 'tid' SQL Injection
CVE-2006-0821—webappsphp
SQL injection vulnerability in index.php in BXCP 0.299 allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CenterIM 4.22.3 - Remote Command Execution
CVE-2008-1467—remotelinux
CenterIM 4.22.3 and earlier allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component xstandard editor 1.5.8 - Local Directory Traversal
CVE-2009-0113—webappsphp
Directory traversal vulnerability in attachmentlibrary.php in the XStandard component for Joomla! 1.5.8 and earlier allo
23RIESGO
abrir ↗
Referência✓ VexDay Proof
OWLLib 1.0 - 'OWLMemoryProperty.php' Remote File Inclusion
CVE-2006-6150—webappsphp
PHP remote file inclusion vulnerability in memory/OWLMemoryProperty.php in OWLLib 1.0 allows remote attackers to execute
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mozilla Firefox XSL - Parsing Remote Memory Corruption (PoC) (1)
CVE-2009-1169—dosmultiple
The txMozillaXSLTProcessor::TransformToDoc function in Mozilla Firefox before 3.0.8 and SeaMonkey before 1.1.16 allows r
28RIESGO
abrir ↗
← anteriorpágina 662 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.