Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
OTSCMS 2.1.3 - Multiple Remote File Inclusions
CVE-2006-5547webappsphp
PHP remote file inclusion vulnerability in OTSCMS/OTSCMS.php in Open Tibia Server Content Management System (OTSCMS) 1.0
23RIESGO
abrir
ReferênciaVexDay Proof
OTSCMS 2.1.3 - Multiple Remote File Inclusions
CVE-2006-5548webappsphp
PHP remote file inclusion vulnerability in OTSCMS/OTSCMS.php in Open Tibia Server Content Management System (OTSCMS) 2.0
23RIESGO
abrir
ReferênciaVexDay Proof
RevilloC MailServer 1.x - 'RCPT TO' Remote Denial of Service
CVE-2006-5552doswindows
Multiple heap-based buffer overflows in RevilloC MailServer 1.21 and earlier allow remote attackers to cause a denial of
23RIESGO
abrir
ReferênciaVexDay Proof
Imageview 5 - '/Cookie/index.php' Local/Remote File Inclusion
CVE-2006-5554webappsphp
Directory traversal vulnerability in index.php in Imageview 5 allows remote attackers to read or execute arbitrary local
23RIESGO
abrir
ReferênciaVexDay Proof
EPNadmin 0.7 - 'constantes.inc.php' Remote File Inclusion
CVE-2006-5555webappsphp
PHP remote file inclusion vulnerability in constantes.inc.php in EPNadmin 0.7 and 0.7.1 allows remote attackers to execu
23RIESGO
abrir
ReferênciaVexDay Proof
ESET Smart Security 3.0.667.0 - Privilege Escalation (PoC)
CVE-2008-7107doswindows
easdrv.sys in ESET Smart Security 3.0.667.0 allows local users to cause a denial of service (crash) via a crafted IOCTL
23RIESGO
abrir
ReferênciaVexDay Proof
iFdate 2.0.3 - SQL Injection
CVE-2008-7114webappsphp
SQL injection vulnerability in members_search.php in iFusion Services iFdate 2.0.3 and earlier allows remote attackers t
23RIESGO
abrir
ReferênciaVexDay Proof
webid 0.5.4 - Multiple Vulnerabilities
CVE-2008-7116webappsphp
SQL injection vulnerability in the admin panel (admin/) in WeBid auction script 0.5.4 allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
WeBid 0.5.4 - 'item.php' SQL Injection
CVE-2008-7119webappsphp
SQL injection vulnerability in item.php in WeBid auction script 0.5.4 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
ReferênciaVexDay Proof
Techno Dreams FAQ Manager 1.0 - SQL Injection
CVE-2006-4892webappsasp
SQL injection vulnerability in faqview.asp in Techno Dreams FAQ Manager Package 1.0 allows remote attackers to execute a
23RIESGO
abrir
ReferênciaVexDay Proof
zKup CMS 2.0 < 2.3 - Arbitrary File Upload
CVE-2008-7124webappsphp
zKup CMS 2.0 through 2.3 does not require administrative authentication for admin/configuration/modifier.php, which allo
23RIESGO
abrir
ReferênciaVexDay Proof
zKup CMS 2.0 < 2.3 - Remote Add Admin
CVE-2008-7124webappsphp
zKup CMS 2.0 through 2.3 does not require administrative authentication for admin/configuration/modifier.php, which allo
23RIESGO
abrir
ReferênciaVexDay Proof
Docebo 3.5.0.3 - '/lib.regset.php/non-blind' SQL Injection
CVE-2008-7153webappsphp
SQL injection vulnerability in the autoDetectRegion function in doceboCore/lib/lib.regset.php in Docebo 3.5.0.3 and earl
23RIESGO
abrir
ReferênciaVexDay Proof
Docebo 3.5.0.3 - 'lib.regset.php' Command Execution
CVE-2008-7153webappsphp
SQL injection vulnerability in the autoDetectRegion function in doceboCore/lib/lib.regset.php in Docebo 3.5.0.3 and earl
23RIESGO
abrir
ReferênciaVexDay Proof
EkinBoard 1.1.0 - Arbitrary File Upload / Authentication Bypass
CVE-2008-7157webappsphp
Unrestricted file upload vulnerability in EkinBoard 1.1.0 and earlier allows remote attackers to execute arbitrary code
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component jabode - 'id' SQL Injection
CVE-2008-7169webappsphp
SQL injection vulnerability in Jabode horoscope extension (com_jabode) for Joomla! allows remote attackers to execute ar
23RIESGO
abrir
ReferênciaVexDay Proof
Lightweight news portal (LNP) 1.0b - Multiple Vulnerabilities
CVE-2008-7172webappsphp
Lightweight news portal (LNP) 1.0b does not properly restrict access to administrator functionality, which allows remote
23RIESGO
abrir
ReferênciaVexDay Proof
Facil-CMS 0.1RC - Multiple Local File Inclusions
CVE-2008-7176webappsphp
Multiple directory traversal vulnerabilities in Facil CMS 0.1RC allow remote attackers to read arbitrary files via a ..
23RIESGO
abrir
ReferênciaVexDay Proof
OTManager CMS 2.4 - Insecure Cookie Handling
CVE-2008-7179webappsphp
OTManager CMS 2.4 allows remote attackers to bypass authentication and gain administrator privileges by setting the ADMI
23RIESGO
abrir
ReferênciaVexDay Proof
Half-Life CSTRIKE Server 1.6 - 'no-steam' Denial of Service
CVE-2008-7203dosmultiple
Valve Software Half-Life Counter-Strike 1.6 allows remote attackers to cause a denial of service (crash) via multiple cr
23RIESGO
abrir
ReferênciaVexDay Proof
OneCMS 2.4 - SQL Injection / Upload
CVE-2008-7209webappsphp
Unrestricted file upload vulnerability in the add2 action in a_upload.php in OneCMS 2.4, and possibly earlier, allows re
23RIESGO
abrir
ReferênciaVexDay Proof
Mozilla Firefox 3.0.6 - BODY onload Remote Crash
CVE-2009-0071dosmultiple
Mozilla Firefox 3.0.5 and earlier 3.0.x versions, when designMode is enabled, allows remote attackers to cause a denial
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Internet Explorer 7 - Memory Corruption (PoC) (MS09-002)
CVE-2009-0075doswindows
Microsoft Internet Explorer 7 does not properly handle errors during attempted access to deleted objects, which allows r
60RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Internet Explorer 7 (Windows 2003 SP2) - Memory Corruption (MS09-002)
CVE-2009-0075remotewindows
Microsoft Internet Explorer 7 does not properly handle errors during attempted access to deleted objects, which allows r
60RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Internet Explorer 7 (Windows XP SP2) - Memory Corruption (MS09-002)
CVE-2009-0075remotewindows
Microsoft Internet Explorer 7 does not properly handle errors during attempted access to deleted objects, which allows r
60RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Internet Explorer 7 - Memory Corruption (MS09-002)
CVE-2009-0075remotewindows
Microsoft Internet Explorer 7 does not properly handle errors during attempted access to deleted objects, which allows r
60RIESGO
abrir
ReferênciaVexDay Proof
ZoomStats 1.0.2 - 'mysql.php' Remote File Inclusion
CVE-2006-5065webappsphp
PHP remote file inclusion vulnerability in libs/dbmax/mysql.php in ZoomStats 1.0.2 and earlier, when register_globals is
23RIESGO
abrir
ReferênciaVexDay Proof
BrudaGB 1.1 - '/admin/index.php' Remote File Inclusion
CVE-2006-5068webappsphp
PHP remote file inclusion vulnerability in admin/index.php in Brudaswen (1) BrudaNews 1.1 and earlier and (2) BrudaGB 1.
23RIESGO
abrir
ReferênciaVexDay Proof
BrudaNews 1.1 - '/admin/index.php' Remote File Inclusion
CVE-2006-5068webappsphp
PHP remote file inclusion vulnerability in admin/index.php in Brudaswen (1) BrudaNews 1.1 and earlier and (2) BrudaGB 1.
23RIESGO
abrir
ReferênciaVexDay Proof
Mozilla Firefox 3.0.5 - Status Bar Obfuscation / Clickjacking
CVE-2009-0253remotewindows
Mozilla Firefox 3.0.5 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action that
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.