Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.689exploits catalogados
38.075CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
Newswriter SW 1.42 - 'editfunc.inc.php' File Inclusion
CVE-2006-5102—webappsphp
PHP remote file inclusion vulnerability in include/editfunc.inc.php in Sebastian Baumann and Philipp Wolfer Newswriter S
23RIESGO
abrir ↗
Referência✓ VexDay Proof
gelato CMS 0.95 - 'img' Remote File Disclosure
CVE-2008-3675—webappsphp
Directory traversal vulnerability in classes/imgsize.php in Gelato 0.95 allows remote attackers to read arbitrary files
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Falt4 CMS RC4 - 'FCKeditor' Arbitrary File Upload
CVE-2008-6178—webappsphp
Unrestricted file upload vulnerability in editor/filemanager/browser/default/connectors/php/connector.php in FCKeditor 2
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Vivvo Article Manager 3.4 - 'root' Local File Inclusion
CVE-2007-1031—webappsphp
Directory traversal vulnerability in include/db_conn.php in SpoonLabs Vivvo Article Management CMS 3.4 allows remote att
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MG-SOFT Net Inspector 6.5.0.828 - Multiple Vulnerabilities
CVE-2008-1400—remotewindows
Directory traversal vulnerability in the Net Inspector HTTP Server (mghttpd) in MG-SOFT Net Inspector 6.5.0.828 and earl
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MyForum 1.3 - 'lecture.php' SQL Injection
CVE-2008-4760—webappsphp
SQL injection vulnerability in lecture.php in Graphiks MyForum 1.3, when register_globals is enabled, allows remote atta
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHPOF 20040226 - 'DB_adodb.class.php' Remote File Inclusion
CVE-2007-4763—webappsphp
PHP remote file inclusion vulnerability in dbmodules/DB_adodb.class.php in PHP Object Framework (PHPOF) 20040226 and ear
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mini-stream RM-MP3 Converter 3.0.0.7 - '.m3u' Local Stack Overflow
CVE-2009-1328—localwindows
Stack-based buffer overflow in Mini-stream RM-MP3 Converter 3.0.0.7 allows remote attackers to execute arbitrary code vi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PH Pexplorer 0.24 - 'explorer_load_lang.php' Local File Inclusion
CVE-2006-5510—webappsphp
Directory traversal vulnerability in explorer_load_lang.php in PH Pexplorer 0.24 allows remote attackers to include arbi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
FTP Voyager 14.0.0.3 - 'CWD' Remote Stack Overflow (PoC)
CVE-2007-1079—doswindows
Stack-based buffer overflow in Rhino Software, Inc. FTP Voyager 14.0.0.3 and earlier allows remote servers to cause a de
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SuperCali PHP Event Calendar 0.4.0 - SQL Injection
CVE-2007-3582—webappsphp
SQL injection vulnerability in index.php in SuperCali PHP Event Calendar 0.4.0 allows remote attackers to execute arbitr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
b1gbb 2.24.0 - SQL Injection / Cross-Site Scripting
CVE-2007-3589—webappsphp
Multiple SQL injection vulnerabilities in b1gbb 2.24.0 allow remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir ↗
Referência✓ VexDay Proof
TinyButStrong 3.4.0 - 'script' Local File Disclosure
CVE-2009-1653—webappsphp
Directory traversal vulnerability in examples/tbs_us_examples_0view.php in TinyButStrong 3.4.0 allows remote attackers t
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Irola My-Time 3.5 - SQL Injection
CVE-2007-6217—webappsphp
Multiple SQL injection vulnerabilities in login.asp in Irola My-Time (aka Timesheet) 3.5 allow remote attackers to execu
23RIESGO
abrir ↗
Referência✓ VexDay Proof
RunCMS 1.6 - Multiple Vulnerabilities
CVE-2007-6548—webappsphp
Multiple direct static code injection vulnerabilities in RunCMS before 1.6.1 allow remote authenticated administrators t
23RIESGO
abrir ↗
Referência✓ VexDay Proof
HIS-Webshop - 'his-webshop.pl t' Remote File Disclosure
CVE-2008-1541—webappscgi
Directory traversal vulnerability in cgi-bin/his-webshop.pl in HIS Webshop 2.50 allows remote attackers to read arbitrar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
freeSSHd 1.2.1 - (Authenticated) SFTP 'rename' Remote Buffer Overflow (PoC)
CVE-2008-4762—doswindows
Stack-based buffer overflow in freeSSHd 1.2.1 allows remote authenticated users to cause a denial of service (service cr
28RIESGO
abrir ↗
Referência✓ VexDay Proof
Social Site Generator 2.0 - 'path' Remote File Inclusion
CVE-2008-6421—webappsphp
PHP remote file inclusion vulnerability in social_game_play.php in Social Site Generator (SSG) 2.0 allows remote attacke
23RIESGO
abrir ↗
Referência✓ VexDay Proof
2532/Gigs 1.2.1 - 'activateuser.php' Local File Inclusion
CVE-2007-4585—webappsphp
Directory traversal vulnerability in activateuser.php in 2532|Gigs 1.2.1 allows remote attackers to include and execute
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Pollbooth 2.0 - 'pollID' SQL Injection
CVE-2008-4765—webappsphp
SQL injection vulnerability in pollBooth.php in osCommerce Poll Booth Add-On 2.0 allows remote attackers to execute arbi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CyberBrau 0.9.4 - '/forum/track.php' Remote File Inclusion
CVE-2006-5400—webappsphp
PHP remote file inclusion vulnerability in forum/track.php in CyberBrau 0.9.4, when register_globals is enabled, allows
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MyCMS 0.9.8 - Remote Command Execution (1)
CVE-2007-3587—webappsphp
MyCMS 0.9.8 and earlier allows remote attackers to gain privileges via the admin cookie parameter, as demonstrated by a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
EnjoySAP ActiveX rfcguisink.rfcguisink.1 - Remote Heap Overflow (PoC)
CVE-2007-3606—doswindows
Heap-based buffer overflow in the rfcguisink.rfcguisink.1 ActiveX control in the EnjoySAP SAP GUI, on systems using ASCI
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP-Stats 0.1.9.2 - Multiple Vulnerabilities
CVE-2007-5452—webappsphp
Multiple SQL injection vulnerabilities in php-stats.recjs.php in Php-Stats 0.1.9.2 allow remote attackers to execute arb
23RIESGO
abrir ↗
Referência✓ VexDay Proof
xeCMS 1.x - 'view.php' Remote File Disclosure
CVE-2007-6508—webappsphp
Directory traversal vulnerability in view.php in xeCMS 1.0 allows remote attackers to read arbitrary files via a ..%2F (
23RIESGO
abrir ↗
Referência✓ VexDay Proof
vbPortal 3.0.2 < 3.6.0 b1 - 'cookie' Remote Code Execution
CVE-2006-4004—webappsphp
Directory traversal vulnerability in index.php in vbPortal 3.0.2 through 3.6.0 Beta 1, when magic_quotes_gpc is disabled
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Avax Vector 'Avaxswf.dll' 1.0.0.1 - ActiveX Arbitrary Data Write
CVE-2007-3459—remotewindows
A certain ActiveX control in Avaxswf.dll 1.0.0.1 in Civitech Avax Vector 1.3 allows remote attackers to create or overwr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
EnjoySAP ActiveX kweditcontrol.kwedit.1 - Remote Stack Overflow (PoC)
CVE-2007-3608—doswindows
Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to create certai
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP-Nuke Module htmltonuke 2.0alpha - 'htmltonuke.php' Remote File Inclusion
CVE-2006-0308—webappsphp
PHP remote file inclusion vulnerability in htmltonuke.php in the htmltonuke 2.0 alpha, and possibly other versions, modu
23RIESGO
abrir ↗
Referência✓ VexDay Proof
QuoteBook - Remote Configuration File Disclosure
CVE-2009-0828—webappsphp
QuoteBook stores quotes.inc under the web root with insufficient access control, which allows remote attackers to obtain
23RIESGO
abrir ↗
← anteriorpágina 685 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.