Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.746exploits catalogados
38.126CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
Web Wiz Guestbook 8.21 - Database Disclosure
CVE-2003-1571—webappsasp
Web Wiz Guestbook 6.0 stores sensitive information under the web root with insufficient access control, which allows rem
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component com_extplorer 2.0.0 RC2 - Local Directory Traversal
CVE-2008-4764—webappsphp
Directory traversal vulnerability in the eXtplorer module (com_extplorer) 2.0.0 RC2 and earlier in Joomla! allows remote
43RIESGO
abrir ↗
Referência✓ VexDay Proof
SmartFTP Client 2.0.1002 - Remote Heap Overflow Denial of Service
CVE-2007-0790—doswindows
Heap-based buffer overflow in SmartFTP 2.0.1002 allows remote FTP servers to execute arbitrary code via a large banner.
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP 'Perl' Extension - 'Safe_mode' Bypass
CVE-2007-4596—localwindows
The perl extension in PHP does not follow safe_mode restrictions, which allows context-dependent attackers to execute ar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Charrays CMS 0.9.3 - Multiple Remote File Inclusions
CVE-2007-6179—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Charray's CMS 0.9.3 allow remote attackers to execute arbitrary PH
23RIESGO
abrir ↗
Referência✓ VexDay Proof
RedDot CMS 7.5 - 'LngId' SQL Injection
CVE-2008-1613—webappsasp
SQL injection vulnerability in ioRD.asp in RedDot CMS 7.5 Build 7.5.0.48, and possibly other versions including 6.5 and
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Maian Links 3.1 - Insecure Cookie Handling
CVE-2008-3319—webappsphp
admin/index.php in Maian Links 3.1 and earlier allows remote attackers to bypass authentication and gain administrative
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SMA-DB 0.3.9 - 'settings.php' Remote File Inclusion
CVE-2007-0797—webappsphp
PHP remote file inclusion vulnerability in theme/settings.php in bluevirus-design SMA-DB 0.3.9 and earlier allows remote
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Oracle 10g - MDSYS.SDO_TOPO_DROP_FTBL SQL Injection (Metasploit)
CVE-2008-3979—localmultiple
Unspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5 and 10.2.0.2 allows remote authent
50RIESGO
abrir ↗
Referência✓ VexDay Proof
freeSSHd 1.2.1 - (Authenticated) SFTP 'realpath' Remote Buffer Overflow (PoC)
CVE-2008-4762—doswindows
Stack-based buffer overflow in freeSSHd 1.2.1 allows remote authenticated users to cause a denial of service (service cr
28RIESGO
abrir ↗
Referência✓ VexDay Proof
AvailScript Article Script - Arbitrary File Upload
CVE-2008-6900—webappsphp
Unrestricted file upload vulnerability in "Add Pen/Author Name" feature in addpen.php in AvailScript Article Script allo
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Pre Real Estate Listings - Authentication Bypass
CVE-2008-6796—webappsphp
SQL injection vulnerability in manager/login.php in Pre Projects Pre Real Estate Listings allows remote attackers to exe
23RIESGO
abrir ↗
Referência✓ VexDay Proof
FOG Forum 0.8.1 - Multiple Local File Inclusions
CVE-2008-2993—webappsphp
Multiple directory traversal vulnerabilities in index.php in FOG Forum 0.8.1 allow remote attackers to include and execu
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Aj RSS Reader - 'url' SQL Injection
CVE-2008-4753—webappsphp
SQL injection vulnerability in EditUrl.php in AJ Square RSS Reader allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SFS EZ Gaming Directory - 'cat_id' SQL Injection
CVE-2008-6781—webappsphp
SQL injection vulnerability in directory.php in Sites for Scripts (SFS) Gaming Directory allows remote attackers to exec
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Categories hierarchy phpBB Mod 2.1.2 - 'phpbb_root_path' Remote File Inclusion
CVE-2007-0809—webappsphp
PHP remote file inclusion vulnerability in includes/class_template.php in Categories hierarchy (aka CH or mod-CH) 2.1.2
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Woltlab Burning Board Lite 1.0.2pl3e - 'pms.php' SQL Injection
CVE-2007-0812—webappsphp
SQL injection vulnerability in pms.php in Woltlab Burning Board (wBB) Lite 1.0.2pl3e and earlier allows remote authentic
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mini File Host 1.x - Arbitrary '.PHP' File Upload
CVE-2008-6785—webappsphp
Unrestricted file upload vulnerability in Mini File Host 1.5 allows remote attackers to execute arbitrary code by upload
23RIESGO
abrir ↗
Referência✓ VexDay Proof
db Software Laboratory VImpX - 'VImpX.ocx' Multiple Vulnerabilities
CVE-2008-4750—remotewindows
Stack-based buffer overflow in the VImpX.VImpAX ActiveX control (VImpX.ocx) 4.8.8.0 in DB Software Laboratory VImp X, po
23RIESGO
abrir ↗
Referência✓ VexDay Proof
KVIrc 3.4.0 - Virgo Remote Format String (PoC)
CVE-2008-4748—doswindows
Format string vulnerability in the URI handler in KVirc 3.4.0, when set as the default application for processing IRC UR
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Geeklog 2 - 'BaseView.php' Remote File Inclusion
CVE-2007-0810—webappsphp
PHP remote file inclusion vulnerability in MVCnPHP/BaseView.php in GeekLog 2 and earlier allows remote attackers to exec
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CA BrightStor ARCserve 11.5.2.0 - 'catirpc.dll' RPC Server Denial of Service
CVE-2007-0816—doswindows
The RPC Server service (catirpc.exe) in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 SP2 and earlie
28RIESGO
abrir ↗
Referência✓ VexDay Proof
WordPress Plugin Wp-FileManager 1.2 - Arbitrary File Upload
CVE-2008-0222—webappsphp
Unrestricted file upload vulnerability in ajaxfilemanager.php in the Wp-FileManager 1.2 plugin for WordPress allows remo
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Titan FTP Server 6.03 - 'USER/PASS' Remote Heap Overflow (PoC)
CVE-2008-0702—doswindows
Multiple heap-based buffer overflows in Titan FTP Server 6.03 and 6.0.5.549 allow remote attackers to cause a denial of
38RIESGO
abrir ↗
Referência✓ VexDay Proof
PumpKIN TFTP Server 2.7.2.0 - Denial of Service (Metasploit)
CVE-2008-6791—doswindows
PumpKIN TFTP Server 2.7.2.0 allows remote attackers to cause a denial of service via a write request with a long mode fi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component Alphacontent 2.5.8 - 'id' SQL Injection
CVE-2008-1559—webappsphp
SQL injection vulnerability in the Bernard Gilly AlphaContent (com_alphacontent) 2.5.8 component for Joomla! allows remo
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MindDezign Photo Gallery 2.2 - Arbitrary Add Admin
CVE-2008-6790—webappsphp
The admin module in MindDezign Photo Gallery 2.2 allows remote attackers to add administrative users and gain privileges
23RIESGO
abrir ↗
Referência✓ VexDay Proof
TurnkeyForms Local Classifieds - Cross-Site Scripting / SQL Injection
CVE-2008-6350—webappsphp
SQL injection vulnerability in listtest.php in TurnkeyForms Local Classifieds allows remote attackers to execute arbitra
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MPlayer 1.0 rc2 - 'sdpplin_parse()' Array Indexing Buffer Overflow (PoC)
CVE-2008-1558—doslinux
Uncontrolled array index in the sdpplin_parse function in stream/realrtsp/sdpplin.c in MPlayer 1.0 rc2 allows remote att
28RIESGO
abrir ↗
Referência✓ VexDay Proof
Opera 9.60 - Persistent Cross-Site Scripting
CVE-2008-4725—remotewindows
Cross-site scripting (XSS) vulnerability in Opera.dll in Opera 9.52 allows remote attackers to inject arbitrary web scri
23RIESGO
abrir ↗
← anteriorpágina 688 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.