Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.689exploits catalogados
38.075CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
Joomla! Component com_colorlab 1.0 - Remote File Inclusion
CVE-2007-5451—webappsphp
PHP remote file inclusion vulnerability in admin.color.php in the com_colorlab (aka com_color) 1.0 component for Joomla!
35RIESGO
abrir ↗
Referência✓ VexDay Proof
Ext 1.0 - 'feed-proxy.php?feed' Remote File Disclosure
CVE-2007-2285—webappsphp
Directory traversal vulnerability in examples/layout/feed-proxy.php in Jack Slocum Ext 1.0 alpha1 (Ext JS) allows remote
28RIESGO
abrir ↗
Referência✓ VexDay Proof
Alstrasoft Live Support 1.21 - Admin Credential Retrieve
CVE-2007-2775—webappsphp
AlstraSoft Live Support 1.21 sends a redirect to the web browser but does not exit when administrative credentials are m
23RIESGO
abrir ↗
Referência✓ VexDay Proof
GeekLog 2.x - 'ImageImageMagick.php' Remote File Inclusion
CVE-2007-2793—webappsphp
PHP remote file inclusion vulnerability in ImageImageMagick.php in Geeklog 2.x allows remote attackers to execute arbitr
35RIESGO
abrir ↗
Referência✓ VexDay Proof
K&S Shopsysteme - Arbitrary File Upload
CVE-2008-6768—webappsphp
Unrestricted file upload vulnerability in admin/editor/images.php in K&S Shopsoftware allows remote attackers to execute
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MyCars Automotive - Authentication Bypass
CVE-2009-2018—webappsphp
SQL injection vulnerability in admin/index.php in Jared Eckersley MyCars, when magic_quotes_gpc is disabled, allows remo
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Cold BBS - Remote Database Disclosure
CVE-2008-5597—webappsasp
Cold BBS stores sensitive information under the web root with insufficient access control, which allows remote attackers
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP Classifieds 7.1 - 'detail.php' SQL Injection
CVE-2006-5828—webappsphp
SQL injection vulnerability in detail.php in DeltaScripts PHP Classifieds 7.1 and earlier allows remote attackers to exe
23RIESGO
abrir ↗
Referência✓ VexDay Proof
XM Easy Personal FTP Server 5.2.1 - Remote Denial of Service
CVE-2006-5728—doswindows
XM Easy Personal FTP Server 5.2.1 and earlier allows remote authenticated users to cause a denial of service via a long
23RIESGO
abrir ↗
Referência✓ VexDay Proof
virtue news - SQL Injection / Cross-Site Scripting
CVE-2009-2019—webappsphp
SQL injection vulnerability in news_detail.php in Virtue News Manager allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PLE CMS 1.0 Beta 4.2 - Blind SQL Injection
CVE-2009-0394—webappsphp
SQL injection vulnerability in login.php in Pre Lecture Exercises (PLEs) CMS 1.0 beta 4.2 allows remote attackers to exe
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Professional Download Assistant 0.1 - Database Disclosure
CVE-2008-5572—webappsasp
Professional Download Assistant 0.1 stores sensitive information under the web root with insufficient access control, wh
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHPEasyData Pro 2.2.2 - 'index.php' SQL Injection
CVE-2006-5707—webappsphp
SQL injection vulnerability in index.php in PHPEasyData Pro 1.4.1 and 2.2.1 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mambo Component SOBI2 RC 2.8.2 - SQL Injection
CVE-2009-0380—webappsphp
SQL injection vulnerability in the Sigsiu Online Business Index 2 (SOBI2, com_sobi2) RC 2.8.2 component for Joomla! and
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PrecisionID Barcode ActiveX 1.9 - Arbitrary File Overwrite
CVE-2007-2755—remotewindows
The PrecisionID Barcode 1.9 ActiveX control in PrecisionID_Barcode.dll, when Internet Explorer 6 is used, allows remote
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Techno Dreams Announcement - 'key' SQL Injection
CVE-2006-5641—webappsasp
SQL injection vulnerability in MainAnnounce2.asp in Techno Dreams Announcement allows remote attackers to execute arbitr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Techno Dreams Guestbook 1.0 - 'key' SQL Injection
CVE-2006-5640—webappsasp
SQL injection vulnerability in guestbookview.asp in Techno Dreams Guest Book 1.0 earlier allows remote attackers to exec
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Virtue Book Store - 'cid' SQL Injection
CVE-2009-2017—webappsphp
SQL injection vulnerability in products.php in Virtue Book Store allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗
Referência✓ VexDay Proof
N/X WCMS 4.1 - 'nxheader.inc.php' Remote File Inclusion
CVE-2006-5625—webappsphp
PHP remote file inclusion vulnerability in wwwdev/nxheader.inc.php in N/X 2002 Professional Edition Web Content Manageme
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Cisco Router - HTTP Administration Cross-Site Request Forgery / Command Execution (1)
CVE-2008-4128HIGHbajo ataqueremotehardware
Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the
83RIESGO
abrir ↗
Referência✓ VexDay Proof
phpCC 4.2 Beta - 'base_dir' Remote File Inclusion
CVE-2006-4073—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Fabian Hainz phpCC Beta 4.2 allow remote attackers to execute arbi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHPstore Wholesale - 'id' SQL Injection
CVE-2008-5493—webappsphp
SQL injection vulnerability in track.php in PHPStore Wholesales (aka Wholesale) allows remote attackers to execute arbit
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Media Commands - '.m3u' / '.m3l' / '.TXT' / '.LRC' Local Heap Overflow (PoC)
CVE-2009-0885—doswindows
Multiple heap-based buffer overflows in Media Commands 1.0 allow remote attackers to execute arbitrary code or cause a d
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Ocean FTP Server 1.00 - Denial of Service
CVE-2005-0847—doswindows
Code Ocean FTP server 1.0 allows remote attackers to cause a denial of service via a large number of connections.
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MyPHPcommander 2.0 - 'package.php' Remote File Inclusion
CVE-2007-0568—webappsphp
PHP remote file inclusion vulnerability in system/lib/package.php in MyPHPCommander 2.0 allows remote attackers to execu
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Versado CMS 1.07 - 'ajax_listado.php?urlModulo' Remote File Inclusion
CVE-2007-2541—webappsphp
PHP remote file inclusion vulnerability in includes/ajax_listado.php in Versado CMS 1.07 allows remote attackers to exec
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Dokeos 1.8.0 - 'my_progress.php?course' SQL Injection
CVE-2007-2901—webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in Dokeos 1.8.0 and earlier allow remote attackers to inject arbitra
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SourceForge 1.0.4 - 'database.php' Remote File Inclusion
CVE-2006-5562—webappsphp
PHP remote file inclusion vulnerability in include/database.php in SourceForge (aka alexandria) 1.0.4 allows remote atta
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WordPress Plugin Spreadsheet 0.6 - SQL Injection
CVE-2008-1982—webappsphp
SQL injection vulnerability in ss_load.php in the Spreadsheet (wpSS) 0.6 and earlier plugin for WordPress allows remote
23RIESGO
abrir ↗
Referência✓ VexDay Proof
RSS-aggregator - 'path' Remote File Inclusion
CVE-2008-2884—webappsphp
PHP remote file inclusion vulnerability in display.php in RSS-aggregator allows remote attackers to execute arbitrary PH
23RIESGO
abrir ↗
← anteriorpágina 677 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.