Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.689exploits catalogados
38.075CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
MPlayer 1.0 rc2 - 'sdpplin_parse()' Array Indexing Buffer Overflow (PoC)
CVE-2008-1558—doslinux
Uncontrolled array index in the sdpplin_parse function in stream/realrtsp/sdpplin.c in MPlayer 1.0 rc2 allows remote att
28RIESGO
abrir ↗
Referência✓ VexDay Proof
Opera 9.60 - Persistent Cross-Site Scripting
CVE-2008-4725—remotewindows
Cross-site scripting (XSS) vulnerability in Opera.dll in Opera 9.52 allows remote attackers to inject arbitrary web scri
23RIESGO
abrir ↗
Referência✓ VexDay Proof
docpile:we 0.2.2 - 'INIT_PATH' Remote File Inclusion
CVE-2006-4075—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Wim Fleischhauer docpile: wim's edition (docpile:we) 0.2.2 and ear
28RIESGO
abrir ↗
Referência✓ VexDay Proof
Social Site Generator 2.0 - 'sgc_id' SQL Injection
CVE-2008-6419—webappsphp
Multiple SQL injection vulnerabilities in Social Site Generator (SSG) 2.0 allow remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHPstore Wholesale - 'id' SQL Injection
CVE-2008-5493—webappsphp
SQL injection vulnerability in track.php in PHPStore Wholesales (aka Wholesale) allows remote attackers to execute arbit
23RIESGO
abrir ↗
Referência✓ VexDay Proof
OllyDbg 1.10 - Local Format String
CVE-2004-0733—localwindows
Format string vulnerability in OllyDbg 1.10 allows remote attackers to cause a denial of service (crash) and possibly ex
23RIESGO
abrir ↗
Referência✓ VexDay Proof
GdPicture Pro - ActiveX 'gdpicture4s.ocx' File Overwrite / Exec
CVE-2008-4453—remotewindows
The GdPicture (1) Light Imaging Toolkit 4.7.1 GdPicture4S.Imaging ActiveX control (gdpicture4s.ocx) 4.7.0.1 and (2) Pro
28RIESGO
abrir ↗
Referência✓ VexDay Proof
Post Comments 3.0 - Insecure Cookie Handling
CVE-2008-4721—webappsphp
PHP Jabbers Post Comment 3.0 allows remote attackers to bypass authentication and gain administrative access by setting
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Techno Dreams Guestbook 1.0 - 'key' SQL Injection
CVE-2006-5640—webappsasp
SQL injection vulnerability in guestbookview.asp in Techno Dreams Guest Book 1.0 earlier allows remote attackers to exec
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Lycos FileUploader Control - ActiveX Remote Buffer Overflow
CVE-2008-0443—remotewindows
Heap-based buffer overflow in the FileUploader.FUploadCtl.1 ActiveX control in FileUploader.dll 2.0.0.2 in Lycos FileUpl
28RIESGO
abrir ↗
Referência✓ VexDay Proof
Comodo AntiVirus 2.0 - 'ExecuteStr()' Remote Command Execution
CVE-2008-0470—remotewindows
A certain ActiveX control in Comodo AntiVirus 2.0 allows remote attackers to execute arbitrary commands via the ExecuteS
35RIESGO
abrir ↗
Referência✓ VexDay Proof
Web Wiz Forums 9.07 - 'sub' Directory Traversal
CVE-2008-0480—webappsasp
Multiple directory traversal vulnerabilities in Web Wiz Forums 9.07 and earlier allow remote attackers to list arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WordPress Plugin fGallery 2.4.1 - 'fimrss.php' SQL Injection
CVE-2008-0491—webappsphp
SQL injection vulnerability in fim_rss.php in the fGallery 2.4.1 plugin for WordPress allows remote attackers to execute
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WordPress Plugin Adserve 0.2 - 'adclick.php' SQL Injection
CVE-2008-0507—webappsphp
SQL injection vulnerability in adclick.php in the AdServe 0.2 plugin for WordPress allows remote attackers to execute ar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mambo Component 'com_fq' - 'listid' SQL Injection
CVE-2008-0512—webappsphp
SQL injection vulnerability in index.php in the fq (com_fq) component for Mambo and Joomla! allows remote attackers to e
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mambo Component 'com_glossary' 2.0 - 'catid' SQL Injection
CVE-2008-0514—webappsphp
SQL injection vulnerability in index.php in the Glossary (com_glossary) 2.0 component for Mambo and Joomla! allows remot
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mambo Component EstateAgent 0.1 - SQL Injection
CVE-2008-0517—webappsphp
SQL injection vulnerability in index.php in the Darko Selesi EstateAgent (com_estateagent) 0.1 component for Mambo 4.5.x
23RIESGO
abrir ↗
Referência✓ VexDay Proof
IntelliTamper 2.0.7 - HTML Parser Remote Buffer Overflow
CVE-2008-3360—remotewindows
Stack-based buffer overflow in the HTML parser in IntelliTamper 2.0.7 allows remote attackers to execute arbitrary code
23RIESGO
abrir ↗
Referência✓ VexDay Proof
IntelliTamper 2.0.7 - HTML Parser Remote Buffer Overflow
CVE-2008-3360—remotewindows
Stack-based buffer overflow in the HTML parser in IntelliTamper 2.0.7 allows remote attackers to execute arbitrary code
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Techno Dreams Announcement - 'key' SQL Injection
CVE-2006-5641—webappsasp
SQL injection vulnerability in MainAnnounce2.asp in Techno Dreams Announcement allows remote attackers to execute arbitr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
The Gemini Portal 4.7 - 'lang' Remote File Inclusion
CVE-2008-4720—webappsphp
Multiple PHP remote file inclusion vulnerabilities in The Gemini Portal 4.7 allow remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joovili 3.0 - Multiple SQL Injections
CVE-2008-4711—webappsphp
SQL injection vulnerability in Joovili 3.0 and earlier, when magic_quotes_gpc is disabled, allows remote attackers to ex
23RIESGO
abrir ↗
Referência✓ VexDay Proof
My PHP Dating - 'id' SQL Injection
CVE-2008-4705—webappsphp
SQL injection vulnerability in success_story.php in php Online Dating Software MyPHPDating allows remote attackers to ex
23RIESGO
abrir ↗
Referência✓ VexDay Proof
LoveCMS 1.6.2 Final - Update Settings
CVE-2008-3509—webappsphp
LoveCMS 1.6.2 does not require administrative authentication for (1) addblock.php, (2) blocks.php, and (3) themes.php in
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mambo Component SOBI2 RC 2.8.2 - SQL Injection
CVE-2009-0380—webappsphp
SQL injection vulnerability in the Sigsiu Online Business Index 2 (SOBI2, com_sobi2) RC 2.8.2 component for Joomla! and
23RIESGO
abrir ↗
Referência✓ VexDay Proof
phpIP 4.3.2 - Multiple SQL Injections
CVE-2008-0538—webappsphp
Multiple SQL injection vulnerabilities in phpIP Management 4.3.2 allow remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Explay CMS 2.1 - Insecure Cookie Handling
CVE-2008-6411—webappsphp
Explay CMS 2.1 and earlier allows remote attackers to bypass authentication and gain administrative access by setting th
23RIESGO
abrir ↗
Referência✓ VexDay Proof
jetAudio 7.0.5 - '.asx' Remote Stack Overflow (PoC)
CVE-2008-0747—doswindows
Stack-based buffer overflow in COWON America jetAudio 7.0.5 and earlier allows user-assisted remote attackers to execute
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Fastpublish CMS 1.9999 - config[fsBase] Remote File Inclusion
CVE-2007-6325—webappsphp
PHP remote file inclusion vulnerability in adminbereich/designconfig.php in Fastpublish CMS 1.9999 allows remote attacke
28RIESGO
abrir ↗
Referência✓ VexDay Proof
Fuzzylime CMS 3.01 - 'admindir' Remote File Inclusion
CVE-2008-1405—webappsphp
PHP remote file inclusion vulnerability in code/display.php in fuzzylime (cms) 3.01 allows remote attackers to execute a
35RIESGO
abrir ↗
← anteriorpágina 680 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.