Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.689exploits catalogados
38.075CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
LushiNews 1.01 - 'comments.php' SQL Injection
CVE-2007-0865—webappsphp
SQL injection vulnerability in comments.php in LushiNews 1.01 and earlier allows remote authenticated users to inject ar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
EsFaq 2.0 - 'idcat' SQL Injection
CVE-2008-3952—webappsphp
SQL injection vulnerability in questions.php in EsFaq 2.0 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PowerClan 1.14a - 'footer.inc.php' Remote File Inclusion
CVE-2006-6715—webappsphp
PHP remote file inclusion vulnerability in footer.inc.php in PowerClan 1.14a and earlier, when register_globals is enabl
23RIESGO
abrir ↗
Referência✓ VexDay Proof
QuickTime 7.4.1 - 'QTPlugin.ocx' Multiple Stack Overflow Vulnerabilities
CVE-2008-0778—doswindows
Multiple stack-based buffer overflows in an ActiveX control in QTPlugin.ocx for Apple QuickTime 7.4.1 and earlier allow
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ABG Blocking Script 1.0a - 'abg_path' Remote File Inclusion
CVE-2008-3570—webappsphp
PHP remote file inclusion vulnerability in index.php in Africa Be Gone (ABG) 1.0a allows remote attackers to execute arb
23RIESGO
abrir ↗
Referência✓ VexDay Proof
nuBoard 0.5 - 'ssid' SQL Injection
CVE-2008-0796—webappsphp
SQL injection vulnerability in threads.php in Nuboard 0.5 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component paxxgallery 0.2 - 'iid' SQL Injection
CVE-2008-0801—webappsphp
SQL injection vulnerability in index.php in the PAXXGallery (com_paxxgallery) 0.2 component for Mambo and Joomla! allow
23RIESGO
abrir ↗
Referência✓ VexDay Proof
E-PHP CMS - 'article.php' SQL Injection
CVE-2008-4142—webappsphp
SQL injection vulnerability in article.php in E-Php CMS allows remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir ↗
Referência✓ VexDay Proof
LookStrike Lan Manager 0.9 - Local/Remote File Inclusion
CVE-2008-0803—webappsphp
Multiple PHP remote file inclusion vulnerabilities in LookStrike Lan Manager 0.9 allow remote attackers to execute arbit
35RIESGO
abrir ↗
Referência✓ VexDay Proof
AuraCMS 1.62 - Multiple SQL Injections
CVE-2008-0811—webappsphp
Multiple SQL injection vulnerabilities in AuraCMS 1.62 allow remote attackers to execute arbitrary SQL commands via (1)
23RIESGO
abrir ↗
Referência✓ VexDay Proof
XPWeb 3.3.2 - 'url' Remote File Disclosure
CVE-2008-0813—webappsphp
Directory traversal vulnerability in Download.php in XPWeb 3.0.1, 3.3.2, and possibly other versions, allows remote atta
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Microsoft Windows Server 2000/2003 - Code Execution (MS08-067)
CVE-2008-4250CRITICALbajo ataqueremotewindows
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RIESGO
abrir ↗
Referência✓ VexDay Proof
TRUC 0.11.0 - 'download.php' Remote File Disclosure
CVE-2008-0814—webappsphp
Directory traversal vulnerability in download.php in Tracking Requirements & Use Cases (TRUC) 0.11.0 allows remote attac
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Atomic Photo Album 1.1.0pre4 - Cross-Site Scripting / SQL Injection
CVE-2008-4335—webappsphp
SQL injection vulnerability in album.php in Atomic Photo Album (APA) 1.1.0pre4 allows remote attackers to execute arbitr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Atomic Photo Album 1.1.0pre4 - Cross-Site Scripting / SQL Injection
CVE-2008-4336—webappsphp
Cross-site scripting (XSS) vulnerability in album.php in Atomic Photo Album (APA) 1.1.0pre4 allows remote attackers to i
23RIESGO
abrir ↗
Referência✓ VexDay Proof
DESlock+ 3.2.7 - 'vdlptokn.sys' Local Denial of Service
CVE-2008-4362—doswindows
The Virtual Token driver (vdlptokn.sys) 1.0.2.43 in DESlock+ 3.2.7 allows local users to cause a denial of service (syst
23RIESGO
abrir ↗
Referência✓ VexDay Proof
DESlock+ < 3.2.7 - 'probe read' Local Kernel Denial of Service (PoC)
CVE-2008-4363—doswindows
DLMFENC.sys 1.0.0.28 in DESlock+ 3.2.7 allows local users to cause a denial of service (system crash) or potentially exe
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ParsaWeb CMS - 'Search' SQL Injection
CVE-2008-4364—webappsasp
SQL injection vulnerability in default.aspx in ParsaGostar ParsaWeb CMS allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Referência✓ VexDay Proof
BandSite CMS 1.1.1 - 'ROOT_PATH' Remote File Inclusion
CVE-2006-3193—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Grayscale BandSite CMS 1.1.1, when register_globals is enabled, al
28RIESGO
abrir ↗
Referência✓ VexDay Proof
TCPDB 3.8 - Arbitrary Add Admin Account
CVE-2009-1670—webappsphp
user/index.php in TCPDB 3.8 does not require administrative authentication, which allows remote attackers to add admin a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Ad Manager Pro 2.6 - 'ipath' Remote File Inclusion
CVE-2006-3192—webappsphp
PHP remote file inclusion vulnerability in Ad Manager Pro 2.6 allows remote attackers to execute arbitrary PHP code via
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Connectix Boards 0.7 - 'p_skin' Multiple Vulnerabilities
CVE-2007-1254—webappsphp
SQL injection vulnerability in part.userprofile.php in Connectix Boards 0.7 and earlier allows remote authenticated user
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Calendar Script 1.1 - Authentication Bypass
CVE-2008-5737—webappsphp
SQL injection vulnerability in index.php in Nodstrum MySQL Calendar 1.1 and 1.2 allows remote attackers to execute arbit
23RIESGO
abrir ↗
Referência✓ VexDay Proof
StormBoard 1.0.1 - SQL Injection
CVE-2008-5726—webappsphp
SQL injection vulnerability in thread.php in stormBoards 1.0.1 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Now SMS/Mms Gateway 5.5 - Remote Buffer Overflow
CVE-2008-0871—remotewindows
Multiple stack-based buffer overflows in Now SMS/MMS Gateway 2007.06.27 and earlier allow remote attackers to execute ar
50RIESGO
abrir ↗
Referência✓ VexDay Proof
SAWStudio 3.9i - '.prf' Local Buffer Overflow (PoC)
CVE-2008-5722—doswindows
Buffer overflow in SAWStudio 3.9i allows user-assisted remote attackers to cause a denial of service (application crash)
28RIESGO
abrir ↗
Referência✓ VexDay Proof
OSSIM 0.9.9rc5 - Cross-Site Scripting / SQL Injection
CVE-2008-0919—webappsphp
Cross-site scripting (XSS) vulnerability in session/login.php in Open Source Security Information Management (OSSIM) 0.9
23RIESGO
abrir ↗
Referência✓ VexDay Proof
FaceBook PhotoUploader 5.0.14.0 - Remote Buffer Overflow
CVE-2008-5711—remotewindows
Heap-based buffer overflow in the Facebook PhotoUploader ActiveX control 5.0.14.0 and earlier allows remote attackers to
50RIESGO
abrir ↗
Referência✓ VexDay Proof
OSSIM 0.9.9rc5 - Cross-Site Scripting / SQL Injection
CVE-2008-0920—webappsphp
SQL injection vulnerability in port/modifyportform.php in Open Source Security Information Management (OSSIM) 0.9.9 rc5
23RIESGO
abrir ↗
Referência✓ VexDay Proof
RunCMS Module MyAnnonces - 'cid' SQL Injection
CVE-2008-0878—webappsphp
SQL injection vulnerability in index.php in the MyAnnonces 1.7 and earlier module for RunCMS allows remote attackers to
23RIESGO
abrir ↗
← anteriorpágina 679 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.