Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.689exploits catalogados
38.075CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
PHP Krazy Image Hosting 0.7a - 'display.php' SQL Injection
CVE-2006-5140—webappsphp
SQL injection vulnerability in display.php in Lappy512 PHP Krazy Image Host Script (phpkimagehost) 0.7a allows remote at
23RIESGO
abrir ↗
Referência✓ VexDay Proof
cattaDoc 2.21 - 'download2.php?fn1' Remote File Disclosure
CVE-2007-1930—webappsphp
Directory traversal vulnerability in download2.php in cattaDoc 2.21, and possibly other versions including 3.0, allows r
23RIESGO
abrir ↗
Referência✓ VexDay Proof
OpenGoo 1.1 - Local File Inclusion
CVE-2009-0286—webappsphp
Directory traversal vulnerability in upgrade/index.php in OpenGoo 1.1, when register_globals is enabled and magic_quotes
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SFS EZ Gaming Cheats - SQL Injection
CVE-2008-6244—webappsphp
SQL injection vulnerability in view_reviews.php in Scripts for Sites (SFS) EZ Gaming Cheats allows remote attackers to e
23RIESGO
abrir ↗
Referência✓ VexDay Proof
phpQuiz 0.1.2 - SQL Injection / Code Execution
CVE-2006-4977—webappsphp
Multiple unrestricted file upload vulnerabilities in (1) back/upload_img.php and (2) admin/upload_img.php in Walter Besc
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mozilla Firefox 3.0.6 - BODY onload Remote Crash
CVE-2009-0071—dosmultiple
Mozilla Firefox 3.0.5 and earlier 3.0.x versions, when designMode is enabled, allows remote attackers to cause a denial
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SmodCMS 2.10 - Slownik ssid SQL Injection
CVE-2007-1931—webappsphp
SQL injection vulnerability in index.php in the slownik module in SmodCMS 2.10 and earlier allows remote attackers to ex
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PcP-Guestbook 3.0 - 'lang' Local File Inclusion
CVE-2007-1933—webappsphp
Multiple directory traversal vulnerabilities in PcP-Guestbook (PcP-Book) 3.0 allow remote attackers to include and execu
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CliServ Web Community 0.65 - 'cl_headers' Include
CVE-2006-7068—webappsphp
PHP remote file inclusion vulnerability in CliServ Web Community 0.65 and earlier allows remote attackers to execute arb
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ActualAnalyzer Lite (free) 2.78 - Local File Inclusion
CVE-2008-2076—webappsphp
Directory traversal vulnerability in admin.php in ActualScripts ActualAnalyzer Lite 2.78 allows remote attackers to incl
23RIESGO
abrir ↗
Referência✓ VexDay Proof
phpList 2.10.8 - Local File Inclusion
CVE-2009-0422—webappsphp
Dynamic variable evaluation vulnerability in lists/admin.php in phpList 2.10.8 and earlier, when register_globals is dis
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Moodle 1.5.2 - 'moodledata' Remote Session Disclosure
CVE-2007-1647—webappsphp
Moodle 1.5.2 and earlier stores sensitive information under the web root with insufficient access control, and provides
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Microsoft SQL Server - 'sp_replwritetovarbin()' Heap Overflow
CVE-2008-5416—localwindows
Heap-based buffer overflow in Microsoft SQL Server 2000 SP4, 8.00.2050, 8.00.2039, and earlier; SQL Server 2000 Desktop
60RIESGO
abrir ↗
Referência✓ VexDay Proof
SFS EZ Webstore - 'where' SQL Injection
CVE-2008-6242—webappsphp
SQL injection vulnerability in SearchResults.php in Scripts For Sites (SFS) EZ e-store allows remote attackers to execut
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MyBulletinBoard (MyBB) 1.2.3 - Remote Code Execution
CVE-2007-1963—webappsphp
SQL injection vulnerability in the create_session function in class_session.php in MyBB (aka MyBulletinBoard) 1.2.3 and
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MyBlog: PHP and MySQL Blog/CMS software - Remote File Inclusion
CVE-2007-1968—webappsphp
PHP remote file inclusion vulnerability in games.php in Sam Crew MyBlog, possibly 1.0 through 1.6, allows remote attacke
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Jokes Site Script - 'jokes.php' SQL Injection
CVE-2008-2065—webappsphp
SQL injection vulnerability in jokes.php in YourFreeWorld Jokes Site Script allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
RTS Sentry Digital Surveillance - 'CamPanel.dll 2.1.0.2' Remote Buffer Overflow
CVE-2008-4548—remotewindows
Stack-based buffer overflow in the PTZCamPanelCtrl ActiveX control (CamPanel.dll) in RTS Sentry 2.1.0.2 allows remote at
23RIESGO
abrir ↗
Referência✓ VexDay Proof
FutureSoft TFTP Server 2000 - Remote Overwrite (SEH)
CVE-2007-1645—remotewindows
Buffer overflow in FutureSoft TFTP Server 2000 on Microsoft Windows 2000 SP4 allows remote attackers to execute arbitrar
28RIESGO
abrir ↗
Referência✓ VexDay Proof
Active Photo Gallery - 'catid' SQL Injection
CVE-2007-1629—webappsasp
SQL injection vulnerability in default.asp in ActiveWebSoftwares Active Photo Gallery allows remote attackers to execute
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Flexphpsite 0.0.1 - Authentication Bypass
CVE-2008-6241—webappsphp
Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPSite 0.0.1 and 0.0.7, when magic_quotes_gpc is d
23RIESGO
abrir ↗
Referência✓ VexDay Proof
EO Video 1.36 - Local Heap Overflow Denial of Service / (PoC)
CVE-2008-3733—doswindows
Stack-based buffer overflow in EO Video (eo-video) 1.36 allows remote attackers to cause a denial of service (applicatio
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Active PHP Bookmark Notes 0.2.5 - Remote File Inclusion
CVE-2007-1621—webappsphp
PHP remote file inclusion vulnerability in templates/head.php in Active PHP Bookmark Notes (APB) 0.2.5 and earlier allow
23RIESGO
abrir ↗
Referência✓ VexDay Proof
XOOPS Module Zmagazine 1.0 - 'print.php' SQL Injection
CVE-2007-1974—webappsphp
SQL injection vulnerability in the getArticle function in class/wfsarticle.php in WF-Section (aka WF-Sections) 1.0.1, as
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Download Accelerator Plus DAP 8.x - '.m3u' Local Buffer Overflow
CVE-2008-3182—localwindows
Stack-based buffer overflow in DAP.exe in Download Accelerator Plus (DAP) 7.0.1.3, 8.6.6.3, and other 8.x versions allow
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP DB Designer 1.02 - Remote File Inclusion
CVE-2007-1620—webappsphp
Multiple PHP remote file inclusion vulnerabilities in PHP DB Designer 1.02 and earlier allow remote attackers to execute
28RIESGO
abrir ↗
Referência✓ VexDay Proof
MetaForum 0.513 Beta - Arbitrary File Upload
CVE-2007-1552—webappsphp
Unrestricted file upload vulnerability in usercp.php in MetaForum 0.513 Beta restricts file types based on the MIME type
23RIESGO
abrir ↗
Referência✓ VexDay Proof
TalkBack 2.3.5 - 'Language' Local File Inclusion
CVE-2008-3371—webappsphp
Directory traversal vulnerability in install/help.php in TalkBack 2.3.5, and other versions before 2.3.6.2, allows remot
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Yahoo! Music Jukebox 2.2 - 'AddImage()' ActiveX Remote Buffer Overflow (PoC)
CVE-2008-0623—doswindows
Stack-based buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! Music Jukebox 2.2.2.056 allows
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Really Simple PHP and Ajax (RSPA) 2007-03-23 - Remote File Inclusion
CVE-2007-1982—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Really Simple PHP and Ajax (RSPA) 2007-03-23 and earlier allow rem
23RIESGO
abrir ↗
← anteriorpágina 668 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.