Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.689exploits catalogados
38.075CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
Simple Web Content Management System - SQL Injection
CVE-2007-0093—webappsphp
SQL injection vulnerability in page.php in Simple Web Content Management System allows remote attackers to execute arbit
23RIESGO
abrir ↗
Referência✓ VexDay Proof
forum livre 1.0 - SQL Injection / Cross-Site Scripting
CVE-2007-0589—webappsasp
SQL injection vulnerability in Forum Livre 1.0 allows remote attackers to execute arbitrary SQL commands via the user pa
23RIESGO
abrir ↗
Referência✓ VexDay Proof
forum livre 1.0 - SQL Injection / Cross-Site Scripting
CVE-2007-0590—webappsasp
Cross-site scripting (XSS) vulnerability in busca2.asp in Forum Livre 1.0 remote attackers to inject arbitrary web scrip
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Virtual Path 1.0 - '/vp/configure.php' Remote File Inclusion
CVE-2007-0591—webappsphp
PHP remote file inclusion vulnerability in configure.php in Vu Le An Virtual Path (VirtualPath) 1.0 allows remote attack
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHPSiteBackup 0.1 - 'pcltar.lib.php' Remote File Inclusion
CVE-2007-2199—webappsphp
PHP remote file inclusion vulnerability in lib/pcltar.lib.php (aka pcltar.php) in the PclTar module 1.3 and 1.3.1 for Vi
35RIESGO
abrir ↗
Referência✓ VexDay Proof
ASPapp Knowledge Base - 'CatId' SQL Injection (1)
CVE-2008-1430—webappsasp
SQL injection vulnerability in links.asp in ASPapp allows remote attackers to execute arbitrary SQL commands via the Cat
23RIESGO
abrir ↗
Referência✓ VexDay Proof
FluentCMS - 'view.php' SQL Injection
CVE-2008-6642—webappsphp
SQL injection vulnerability in view.php in DotContent FluentCMS 4.x allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Bitweaver 1.3 - 'tmpImagePath' Attachment mod_mime
CVE-2006-3102—webappsphp
Race condition in articles/BitArticle.php in Bitweaver 1.3, when run on Apache with the mod_mime extension, allows remot
23RIESGO
abrir ↗
Referência✓ VexDay Proof
makit Newsposter Script 3.0 - SQL Injection
CVE-2007-0600—webappsasp
SQL injection vulnerability in news_page.asp in Martyn Kilbryde Newsposter Script (aka makit news/blog poster) 3 and ear
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MyNews 4.2.2 - 'themefunc.php' Remote File Inclusion
CVE-2007-0633—webappsphp
PHP remote file inclusion vulnerability in include/themes/themefunc.php in MyNews 4.2.2 and earlier allows remote attack
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SkaDate Online 5.0/6.0 - Remote File Disclosure
CVE-2007-5299—webappsphp
Multiple directory traversal vulnerabilities in SkaDate 5.0 and 6.0, and possibly later versions such as 6.482, allow re
23RIESGO
abrir ↗
Referência✓ VexDay Proof
OneCMS 2.5 - Blind SQL Injection
CVE-2008-6652—webappsphp
SQL injection vulnerability in asd.php in OneCMS 2.5 allows remote attackers to execute arbitrary SQL commands via the s
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Opera Web Browser 9.00 - 'iframe' Remote Denial of Service
CVE-2006-3353—dosmultiple
Opera 9 allows remote attackers to cause a denial of service (crash) via a crafted web page that triggers an out-of-boun
23RIESGO
abrir ↗
Referência✓ VexDay Proof
GuppY 4.5.16 - Remote Command Execution
CVE-2007-0639—webappsphp
Multiple static code injection vulnerabilities in error.php in GuppY 4.5.16 and earlier allow remote attackers to inject
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Opera 9.2 - '.torrent' Remote Denial of Service
CVE-2007-2274—dosmultiple
The BitTorrent implementation in Opera 9.2 allows remote attackers to cause a denial of service (CPU consumption and app
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Data Dynamics ActiveBar (Actbar3.ocx 3.2) - Multiple Insecure Methods
CVE-2007-3883—remotewindows
The Data Dynamics ActiveBar ActiveX control (actbar3.ocx) 3.2 and earlier allows remote attackers to create or overwrite
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Hunkaray Duyuru Scripti - 'tr' SQL Injection
CVE-2007-0688—webappsasp
SQL injection vulnerability in oku.asp in Hunkaray Duyuru Scripti allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mini Web Calendar 1.2 - File Disclosure / Cross-Site Scripting
CVE-2008-5062—webappsphp
Directory traversal vulnerability in php/cal_pdf.php in Mini Web Calendar (mwcal) 1.2 allows remote attackers to read ar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHPmotion 2.1 - Cross-Site Request Forgery
CVE-2008-6729—webappsphp
Multiple cross-site request forgery (CSRF) vulnerabilities in password.php in PHPmotion 2.1 and earlier allow remote att
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ACGVannu 1.3 - 'index2.php' Remote User Pass Change
CVE-2007-0697—webappsphp
index2.php in ACGVannu 1.3 and earlier allows remote attackers to change the password or profile of a user via a modifie
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CoD2: DreamStats 4.2 - 'index.php' Remote File Inclusion
CVE-2007-0757—webappsphp
PHP remote file inclusion vulnerability in index.php in Miguel Nunes Call of Duty 2 (CoD2) DreamStats System 4.2 and ear
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Simple Machines Forum (SMF) 1.1.4 - SQL Injection
CVE-2008-6741—webappsphp
SQL injection vulnerability in Load.php in Simple Machines Forum (SMF) 1.1.4 and earlier allows remote attackers to exec
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Chicken of the VNC 2.0 - 'NULL-pointer' Remote Denial of Service
CVE-2007-0756—dososx
Chicken of the VNC (cotv) 2.0 allows remote attackers to cause a denial of service (application crash) via a large compu
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Smart Publisher 1.0.1 - 'filedata' Remote Code Execution
CVE-2008-0503—webappsphp
Eval injection vulnerability in admin/op/disp.php in Netwerk Smart Publisher 1.0.1 allows remote attackers to execute ar
28RIESGO
abrir ↗
Referência✓ VexDay Proof
JAF CMS 4.0 RC2 - Multiple Remote File Inclusions
CVE-2008-1609—webappsphp
Multiple PHP remote file inclusion vulnerabilities in just another flat file (JAF) CMS 4.0 RC2 allow remote attackers to
35RIESGO
abrir ↗
Referência✓ VexDay Proof
Shadows Rising RPG 0.0.5b - Remote File Inclusion
CVE-2006-4329—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Shadows Rising RPG (Pre-Alpha) 0.0.5b and earlier allow remote att
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Downline Goldmine Builder - SQL Injection
CVE-2008-4178—webappsphp
SQL injection vulnerability in tr.php in DownlineGoldmine Special Category Addon, Downline Builder Pro, New Addon, and D
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Autodesk DWF Viewer Control / LiveUpdate Module - Remote Code Execution
CVE-2008-4472—remotewindows
The UpdateEngine class in the LiveUpdate ActiveX control (LiveUpdate16.DLL 17.2.56), as used in Revit Architecture 2009
23RIESGO
abrir ↗
Referência✓ VexDay Proof
phpBB ezBoard Converter 0.2 - 'ezconvert_dir' Remote File Inclusion
CVE-2007-0761—webappsphp
PHP remote file inclusion vulnerability in config.php in phpBB ezBoard converter (ezconvert) 0.2 allows remote attackers
23RIESGO
abrir ↗
Referência✓ VexDay Proof
BlogPHP 2.0 - Privilege Escalation / SQL Injection
CVE-2008-6745—webappsphp
index.php in BlogPHP 2.0 allows remote attackers to gain administrator privileges via a crafted email parameter in a reg
23RIESGO
abrir ↗
← anteriorpágina 666 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.