Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.689exploits catalogados
38.075CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
XMB 1.9.6 - 'mq=off' 'u2uid' SQL Injection
CVE-2006-3994—webappsphp
SQL injection vulnerability in the u2u_send_recp function in u2u.inc.php in XMB (aka extreme message board) 1.9.6 Alpha
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SaveWeb Portal 3.4 - 'SITE_Path' Remote File Inclusion
CVE-2006-4012—webappsphp
Multiple PHP remote file inclusion vulnerabilities in circeOS SaveWeb Portal 3.4 allow remote attackers to execute arbit
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SH-News 3.0 - 'comments.php' SQL Injection
CVE-2007-6391—webappsphp
SQL injection vulnerability in patch/comments.php in SH-News 3.0 allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Ace Image Hosting Script - 'id' SQL Injection
CVE-2007-6393—webappsphp
SQL injection vulnerability in albums.php in Ace Image Hosting Script allows remote authenticated users to execute arbit
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Flat PHP Board 1.2 - Multiple Vulnerabilities
CVE-2007-6399—webappsphp
index.php in Flat PHP Board 1.2 and earlier allows remote authenticated users to obtain the password for the current use
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Web Calendar 4.1 - Blind SQL Injection
CVE-2008-1954—webappsphp
SQL injection vulnerability in one_day.php in Web Calendar Pro 4.1 and earlier allows remote attackers to execute arbitr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Shadowed Portal Module Character Roster - 'mod_root' Remote File Inclusion
CVE-2006-6850—webappsphp
PHP remote file inclusion vulnerability in include.php in the Roster Module (character_roster) in Shadowed Portal 5.7 al
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP-Fusion Mod Kroax 4.42 - 'category' SQL Injection
CVE-2008-5196—webappsphp
SQL injection vulnerability in kroax.php in the Kroax (the_kroax) 4.42 and earlier module for PHP-Fusion allows remote a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PostNuke Module PostSchedule 1.0 - 'eid' SQL Injection
CVE-2008-2012—webappsphp
SQL injection vulnerability in index.php in the PostSchedule 1.0 module for PostNuke allows remote attackers to execute
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SebracCMS 0.4 - Multiple SQL Injections
CVE-2008-5195—webappsphp
Multiple SQL injection vulnerabilities in SebracCMS (sbcms) 0.4 allow remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗
Referência✓ VexDay Proof
FreeWebShop 2.2.1 - Blind SQL Injection
CVE-2007-6466—webappsphp
Multiple SQL injection vulnerabilities in index.php in FreeWebshop 2.2.1 allow remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SePortal 2.4 - 'poll_id' SQL Injection
CVE-2008-5191—webappsphp
Multiple SQL injection vulnerabilities in SePortal 2.4 allow remote attackers to execute arbitrary SQL commands via the
43RIESGO
abrir ↗
Referência✓ VexDay Proof
phpskelsite 1.4 - Local File Inclusion / Remote File Inclusion / Cross-Site Scripting
CVE-2009-0596—webappsphp
Directory traversal vulnerability in skysilver/login.tpl.php in phpSkelSite 1.4, when register_globals is enabled, allow
23RIESGO
abrir ↗
Referência✓ VexDay Proof
OpenX 2.6.3 - 'MAX_type' Local File Inclusion
CVE-2009-0291—webappsphp
Directory traversal vulnerability in fc.php in OpenX 2.6.3 allows remote attackers to include and execute arbitrary file
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SoftComplex PHP Image Gallery - 'ctg' SQL Injection
CVE-2008-6485—webappsphp
SQL injection vulnerability in index.php in SoftComplex PHP Image Gallery allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MOG-WebShop - 'index.php?group' SQL Injection
CVE-2007-6466—webappsphp
Multiple SQL injection vulnerabilities in index.php in FreeWebshop 2.2.1 allow remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WordPress Plugin Enigma 2 Bridge - 'boarddir' Remote File Inclusion
CVE-2006-6863CRITICALwebappsphp
PHP remote file inclusion vulnerability in the Enigma2 plugin (Enigma2.php) in Enigma WordPress Bridge allows remote att
53RIESGO
abrir ↗
Referência✓ VexDay Proof
WFTPD Explorer Pro 1.0 - Remote Heap Overflow (PoC)
CVE-2007-6473—doswindows
Heap-based buffer overflow in Texas Imperial Software WFTPD Pro Explorer 1.0 allows remote FTP servers to execute arbitr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Connectix Boards 0.7 - 'p_skin' Multiple Vulnerabilities
CVE-2007-1255—webappsphp
Unrestricted file upload vulnerability in admin.bbcode.php in Connectix Boards 0.7 and earlier allows remote authenticat
23RIESGO
abrir ↗
Referência✓ VexDay Proof
StatIt 4 - 'statitpath' Remote File Inclusion
CVE-2006-2253—webappsphp
PHP remote file inclusion vulnerability in visible_count_inc.php in Statit 4 (060207) allows remote attackers to execute
23RIESGO
abrir ↗
Referência✓ VexDay Proof
falcon CMS 1.4.3 - Remote File Inclusion / Cross-Site Scripting
CVE-2007-6489—webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in Falcon Series One CMS 1.4.3 allow remote attackers to inject arbi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mozilla Firefox 3.0.5 - location.hash Remote Crash
CVE-2008-5715—doswindows
Mozilla Firefox 3.0.5 on Windows Vista allows remote attackers to cause a denial of service (application crash) via Java
23RIESGO
abrir ↗
Referência✓ VexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
CVE-2007-6495—webappsasp
inc_newuser.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to change the permis
23RIESGO
abrir ↗
Referência✓ VexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
CVE-2007-6496—webappsasp
Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to register arbitrary users via a request to host
23RIESGO
abrir ↗
Referência✓ VexDay Proof
AINS 0.02b - 'ains_main.php?ains_path' Remote File Inclusion
CVE-2007-0570—webappsphp
PHP remote file inclusion vulnerability in ains_main.php in Johannes Gijsbers (aka Taradino) Ad Fundum Integratable News
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Dream4 Koobi Pro 6.25 Poll - 'poll_id' SQL Injection
CVE-2008-2036—webappsphp
SQL injection vulnerability in index.php in dream4 Koobi Pro 6.25 allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir ↗
Referência✓ VexDay Proof
asg-sentry 7.0.0 - Multiple Vulnerabilities
CVE-2008-1322—dosmultiple
The File Check Utility (fcheck.exe) in ASG-Sentry Network Manager 7.0.0 and earlier allows remote attackers to cause a d
23RIESGO
abrir ↗
Referência✓ VexDay Proof
zBlog 1.2 - SQL Injection
CVE-2007-6577—webappsphp
Multiple SQL injection vulnerabilities in index.php in zBlog 1.2 allow remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗
Referência✓ VexDay Proof
AimStats 3.2 - 'process.php?update' Remote Code Execution
CVE-2007-2167—webappsphp
Static code injection vulnerability in process.php in AimStats 3.2 allows remote attackers to inject PHP code into confi
35RIESGO
abrir ↗
Referência✓ VexDay Proof
MyServer 0.8.11 - '204 No Content' error Remote Denial of Service
CVE-2008-5160—doswindows
Unspecified vulnerability in MyServer 0.8.11 allows remote attackers to cause a denial of service (daemon crash) via mul
23RIESGO
abrir ↗
← anteriorpágina 671 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.