Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.689exploits catalogados
38.075CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
Dyncms Release 6 - 'x_admindir' Remote File Inclusion
CVE-2006-4589—webappsphp
PHP remote file inclusion vulnerability in 0_admin/modules/Wochenkarte/frontend/index.php in DynCMS 6 and earlier allows
23RIESGO
abrir ↗
Referência✓ VexDay Proof
e107 Plugin BLOG Engine 2.2 - 'uid' SQL Injection
CVE-2008-6438—webappsphp
SQL injection vulnerability in macgurublog_menu/macgurublog.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows re
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Tucows Client Code Suite (CSS) 1.2.1015 - Remote File Inclusion
CVE-2006-6551—webappsphp
PHP remote file inclusion vulnerability in libs/tucows/api/cartridges/crt_TUCOWS_domains/lib/domainutils.inc.php in Tuco
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Constructr CMS 3.02.5 stable - Multiple Vulnerabilities
CVE-2008-5859—webappsphp
SQL injection vulnerability in index.php in Constructr CMS 3.02.5 and earlier, when register_globals is enabled and magi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component Ice Gallery 0.5b2 - 'catid' Blind SQL Injection
CVE-2008-6852—webappsphp
SQL injection vulnerability in the Ice Gallery (com_ice) component 0.5 beta 2 for Joomla! allows remote attackers to exe
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Harlandscripts Pro Traffic One - 'mypage.php' SQL Injection
CVE-2008-6213—webappsphp
SQL injection vulnerability in mypage.php in Harlandscripts Pro Traffic One allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Censura 1.15.04 - 'censura.php?vendorid' SQL Injection
CVE-2007-2673—webappsphp
SQL injection vulnerability in includes/funcs_vendors.php in Censura 1.15.04, and other versions before 1.16.04, allows
23RIESGO
abrir ↗
Referência✓ VexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
CVE-2007-6500—webappsasp
Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to delete
23RIESGO
abrir ↗
Referência✓ VexDay Proof
mxBB Module ErrorDocs 1.0 - 'common.php' Remote File Inclusion
CVE-2006-6545—webappsphp
PHP remote file inclusion vulnerability in includes/common.php in the ErrorDocs 1.0.0 and earlier module for mxBB (mx_er
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Wireshark 1.0.6 - PN-DCP Format String (PoC)
CVE-2009-1210—dosmultiple
Format string vulnerability in the PROFINET/DCP (PN-DCP) dissector in Wireshark 1.0.6 and earlier allows remote attacker
28RIESGO
abrir ↗
Referência✓ VexDay Proof
zKup CMS 2.0 < 2.3 - Remote Add Admin
CVE-2008-7124—webappsphp
zKup CMS 2.0 through 2.3 does not require administrative authentication for admin/configuration/modifier.php, which allo
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP 5.2.3 - 'snmpget()' Object id Local Buffer Overflow
CVE-2007-1413—localwindows
Buffer overflow in the snmpget function in the snmp extension in PHP 5.2.3 and earlier, including PHP 4.4.6 and probably
28RIESGO
abrir ↗
Referência✓ VexDay Proof
MyioSoft EasyCalendar - Authentication Bypass
CVE-2008-5654—webappsphp
SQL injection vulnerability in the loginADP function in ajaxp.php in MyioSoft EasyCalendar 4.0 allows remote attackers t
23RIESGO
abrir ↗
Referência✓ VexDay Proof
LushiWarPlaner 1.0 - 'register.php' SQL Injection
CVE-2007-0864—webappsphp
SQL injection vulnerability in register.php in LushiWarPlaner 1.0 allows remote attackers to inject arbitrary SQL comman
23RIESGO
abrir ↗
Referência✓ VexDay Proof
FileZilla FTP Server 0.9.21 - 'LIST/NLST' Denial of Service
CVE-2006-6565—doswindows
FileZilla Server before 0.9.22 allows remote attackers to cause a denial of service (crash) via a wildcard argument to t
60RIESGO
abrir ↗
Referência✓ VexDay Proof
5 star review - Cross-Site Scripting / SQL Injection
CVE-2008-3779—webappsphp
Cross-site scripting (XSS) vulnerability in search/index.php in Five Star Review Script allows remote attackers to injec
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHPVID 0.9.9 - 'categories_type.php' SQL Injection
CVE-2007-3610—webappsphp
SQL injection vulnerability in categories_type.php in phpVID 0.9.9 allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Sponge News 2.2 - 'sndir' Remote File Inclusion
CVE-2006-4647—webappsphp
PHP remote file inclusion vulnerability in news.php in Sponge News 2.2 and earlier allows remote attackers to execute ar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PMB Services 3.0.13 - Multiple Remote File Inclusions
CVE-2007-1415—webappsphp
Multiple PHP remote file inclusion vulnerabilities in PMB Services 3.0.13 and earlier allow remote attackers to execute
23RIESGO
abrir ↗
Referência✓ VexDay Proof
linksnet newsfeed 1.0 - Remote File Inclusion
CVE-2007-2707—webappsphp
PHP remote file inclusion vulnerability in linksnet_linkslog_rss.php in Linksnet Newsfeed 1.0 allows remote attackers to
35RIESGO
abrir ↗
Referência✓ VexDay Proof
Feindt Computerservice News 2.0 - 'newsadmin.php?action' Remote File Inclusion
CVE-2007-2708—webappsphp
PHP remote file inclusion vulnerability in newsadmin.php in Feindt Computerservice News (News-Script) 2.0 allows remote
35RIESGO
abrir ↗
Referência✓ VexDay Proof
Fonality trixbox - 'langChoice' Local File Inclusion (connect-back) (2)
CVE-2008-6825—webappslinux
Directory traversal vulnerability in user/index.php in Fonality trixbox CE 2.6.1 and earlier allows remote attackers to
43RIESGO
abrir ↗
Referência✓ VexDay Proof
AIMP 2.51 build 330 - ID3v1/ID3v2 Tag Remote Stack Buffer Overflow (PoC) (SEH)
CVE-2009-1944—doswindows
Stack-based buffer overflow in AIMP 2.51 build 330 allows remote attackers to execute arbitrary code via an MP3 file wit
28RIESGO
abrir ↗
Referência✓ VexDay Proof
DivX Player 6.4.1 - DivXBrowserPlugin 'npdivx32.dll' IE Denial of Service
CVE-2007-0429—doswindows
DivXBrowserPlugin (aka DivX Web Player) npdivx32.dll, as distributed with DivX Player 6.4.1, allows remote attackers to
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Microsoft Visual Basic 6.0 Project - Description Stack Overflow (PoC)
CVE-2007-2884—doswindows
Multiple stack-based buffer overflows in Microsoft Visual Basic 6 allow user-assisted remote attackers to cause a denial
35RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component RWCards 3.0.11 - Local File Inclusion
CVE-2008-6172—webappsphp
Directory traversal vulnerability in captcha/captcha_image.php in the RWCards (com_rwcards) 3.0.11 component for Joomla!
43RIESGO
abrir ↗
Referência✓ VexDay Proof
ProArcadeScript 1.3 - 'random' SQL Injection
CVE-2008-4173—webappsphp
SQL injection vulnerability in ProArcadeScript 1.3 allows remote attackers to execute arbitrary SQL commands via the ran
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Campsite 3.3.0 RC1 - Multiple Remote File Inclusions
CVE-2009-2181—webappsphp
Cross-site scripting (XSS) vulnerability in admin-files/templates/list_dir.php in Campsite 3.3.0 RC1 allows remote attac
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Ext 1.0 - 'feed-proxy.php?feed' Remote File Disclosure
CVE-2007-2285—webappsphp
Directory traversal vulnerability in examples/layout/feed-proxy.php in Jack Slocum Ext 1.0 alpha1 (Ext JS) allows remote
28RIESGO
abrir ↗
Referência✓ VexDay Proof
PHPStore Complete Classifieds Script - Arbitrary File Upload
CVE-2008-6928—webappsphp
Unrestricted file upload vulnerability in PHPStore Complete Classifieds allows remote authenticated users to execute arb
23RIESGO
abrir ↗
← anteriorpágina 686 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.