Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.689exploits catalogados
38.075CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
EZContents CMS 2.0.3 - Multiple Local File Inclusions
CVE-2008-7054—webappsphp
Multiple directory traversal vulnerabilities in ezContents 2.0.3 allow remote attackers to include and execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MailEnable Professional/Enterprise 2.37 - 'APPEND' Remote Buffer Overflow
CVE-2007-1301—remotewindows
Stack-based buffer overflow in the IMAP service in MailEnable Enterprise and Professional Editions 2.37 and earlier allo
28RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component beamospetition 1.0.12 - SQL Injection / Cross-Site Scripting
CVE-2009-0377—webappsphp
SQL injection vulnerability in the beamospetition (com_beamospetition) 1.0.12 component for Joomla! allows remote attack
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WholeHogSoftware Password Protect - Insecure Cookie Handling
CVE-2009-0461—webappsphp
Whole Hog Password Protect: Enhanced 1.x allows remote attackers to bypass authentication and obtain administrative acce
23RIESGO
abrir ↗
Referência✓ VexDay Proof
LS Simple Guestbook 1.0 - Remote Code Execution
CVE-2007-2093—webappsphp
Direct static code injection vulnerability in index.php in Limesoft Guestbook (LS Simple Guestbook) 1.0 allows remote at
35RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component EasyBook 1.1 - 'gbid' SQL Injection
CVE-2008-2569—webappsphp
SQL injection vulnerability in the EasyBook (com_easybook) component 1.1 for Joomla! allows remote attackers to execute
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ShoutPro 1.5.2 - 'shout.php' Remote Code Injection
CVE-2007-2141—webappsphp
Direct static code injection vulnerability in shoutbox.php in ShoutPro 1.5.2 allows remote attackers to inject arbitrary
35RIESGO
abrir ↗
Referência✓ VexDay Proof
PLog 1.0.6 - 'albumID' SQL Injection
CVE-2008-2629—webappsphp
SQL injection vulnerability in the LifeType (formerly pLog) module for Drupal allows remote attackers to execute arbitra
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Snircd 1.3.4 - 'send_user_mode' Denial of Service
CVE-2008-1501—dosmultiple
The send_user_mode function in s_user.c in (1) Undernet ircu 2.10.12.12 and earlier, (2) snircd 1.3.4 and earlier, and u
23RIESGO
abrir ↗
Referência✓ VexDay Proof
xoops module tsdisplay4xoops 0.1 - Remote File Inclusion
CVE-2007-2091—webappsphp
PHP remote file inclusion vulnerability in blocks/tsdisplay4xoops_block2.php in tsdisplay4xoops (TSD4XOOPS, aka the Team
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Blog:CMS 4.1.3 - 'NP_UserSharing.php' Remote File Inclusion
CVE-2006-6552—webappsphp
PHP remote file inclusion vulnerability in admin/plugins/NP_UserSharing.php in BLOG:CMS 4.1.3 and earlier allows remote
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component Com BazaarBuilder Shopping Cart 5.0 - SQL Injection
CVE-2009-0381—webappsphp
SQL injection vulnerability in the BazaarBuilder Ecommerce Shopping Cart (com_prod) 5.0 component for Joomla! allows rem
23RIESGO
abrir ↗
Referência✓ VexDay Proof
phpsmartcom 0.2 - Local File Inclusion / SQL Injection
CVE-2008-4352—webappsphp
SQL injection vulnerability in inc/pages/viewprofile.php in phpSmartCom 0.2 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
eFront 3.5.1 / build 2710 - Arbitrary File Upload
CVE-2008-7026—webappsphp
Unrestricted file upload vulnerability in filesystem3.class.php in eFront 3.5.1 build 2710 and earlier allows remote att
23RIESGO
abrir ↗
Referência✓ VexDay Proof
fipsForum 2.6 - 'default2.asp' SQL Injection
CVE-2006-6116—webappsasp
SQL injection vulnerability in default2.asp in fipsForum 2.6 and earlier allows remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! / Mambo Component New Article 1.1 - Remote File Inclusion
CVE-2007-2089—webappsphp
Multiple PHP remote file inclusion vulnerabilities in the Jx Development Article 1.1 and earlier component for Mambo and
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Microsoft Internet Explorer 7 - Clickjacking
CVE-2009-0369—remotewindows
Microsoft Internet Explorer 7 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick acti
28RIESGO
abrir ↗
Referência✓ VexDay Proof
iBoutique 4.0 - 'cat' SQL Injection
CVE-2008-4354—webappsphp
SQL injection vulnerability in the products module in NetArt Media iBoutique 4.0 allows remote attackers to execute arbi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Jupiter CMS 1.1.5 - '/index.php' Local/Remote File Inclusion
CVE-2007-0986—webappsphp
PHP remote file inclusion vulnerability in index.php in Jupiter CMS 1.1.5, when PHP 5.0.0 or later is used, allows remot
23RIESGO
abrir ↗
Referência✓ VexDay Proof
AjPortal2Php - 'PagePrefix' Remote File Inclusion
CVE-2007-2142—webappsphp
Multiple PHP remote file inclusion vulnerabilities in AjPortal2Php allow remote attackers to execute arbitrary PHP code
23RIESGO
abrir ↗
Referência✓ VexDay Proof
cf shopkart 5.2.2 - SQL Injection / File Disclosure
CVE-2008-6320—webappsasp
SQL injection vulnerability in index.cfm in CF Shopkart 5.2.2 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Winamp 5.3 - '.wmv' Remote Denial of Service
CVE-2007-2180—doswindows
Buffer overflow in Nullsoft Winamp 5.3 allows user-assisted remote attackers to cause a denial of service (crash) via a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHPress 0.2.0 - 'adisplay.php?lang' Local File Inclusion
CVE-2007-4524—webappsphp
PHP remote file inclusion vulnerability in adisplay.php in PhPress 0.2.0 allows remote attackers to execute arbitrary PH
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CitectSCADA ODBC Server - Remote Stack Buffer Overflow (Metasploit)
CVE-2008-2639—remotewindows
Stack-based buffer overflow in the ODBC server service in Citect CitectSCADA 6 and 7, and CitectFacilities 7, allows rem
60RIESGO
abrir ↗
Referência✓ VexDay Proof
CityWriter 0.9.7 - 'head.php' Remote File Inclusion
CVE-2007-6324—webappsphp
PHP remote file inclusion vulnerability in head.php in CityWriter 0.9.7 allows remote attackers to execute arbitrary PHP
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ezusermanager 1.6 - Remote File Inclusion
CVE-2006-2424—webappsphp
PHP remote file inclusion vulnerability in ezUserManager 1.6 and earlier, when register_globals is enabled, allows remot
23RIESGO
abrir ↗
Referência✓ VexDay Proof
TightVNC - Authentication Failure Integer Overflow (PoC)
CVE-2009-0388—doswindows
Multiple integer signedness errors in (1) UltraVNC 1.0.2 and 1.0.5 and (2) TightVnc 1.3.9 allow remote VNC servers to ca
28RIESGO
abrir ↗
Referência✓ VexDay Proof
WEBInsta FM 0.1.4 - 'login.php' absolute_path Remote File Inclusion
CVE-2007-2181—webappsphp
PHP remote file inclusion vulnerability in admin/login.php in Webinsta FM Manager 0.1.4 and earlier allows remote attack
23RIESGO
abrir ↗
Referência✓ VexDay Proof
XAMPP for Windows 1.6.0a - 'mssql_connect()' Remote Buffer Overflow
CVE-2007-2079—remotewindows
The ADONewConnection Connect function in adodb.php in XAMPP 1.6.0a and earlier for Windows uses untrusted input for the
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Chilkat IMAP ActiveX 7.9 - File Execution / Denial of Service
CVE-2008-7022—remotewindows
Insecure method vulnerability in ChilkatMail_v7_9.dll in the Chilkat Software IMAP ActiveX control (ChilkatMail2.Chilkat
23RIESGO
abrir ↗
← anteriorpágina 683 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.