Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.759exploits catalogados
38.127CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
SonicWALL SSL-VPN - 'NeLaunchCtrl' ActiveX Control Remote Command Execution
CVE-2007-5603—remotewindows
Stack-based buffer overflow in the SonicWall SSL-VPN NetExtender NELaunchCtrl ActiveX control before 2.1.0.51, and 2.5.x
50RIESGO
abrir ↗
Referência✓ VexDay Proof
ZZ FlashChat 3.1 - 'help.php' Local File Inclusion
CVE-2007-5620—webappsphp
Directory traversal vulnerability in admin/inc/help.php in ZZ:FlashChat 3.1 and earlier allows remote attackers to inclu
23RIESGO
abrir ↗
Referência✓ VexDay Proof
TorrentTrader Classic 1.09 - Multiple Vulnerabilities
CVE-2009-2157—webappsphp
Multiple SQL injection vulnerabilities in TorrentTrader Classic 1.09 allow remote authenticated users to execute arbitra
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Fire Soft Board RC 3 - 'racine' Remote File Inclusion
CVE-2006-4716—webappsphp
PHP remote file inclusion vulnerability in demarrage.php in Fire Soft Board (FSB) RC3 and earlier allows remote attacker
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Iamma Simple Gallery 1.0/2.0 - Arbitrary File Upload
CVE-2008-6084—webappsphp
Unrestricted file upload vulnerability in pages/download.php in Iamma Simple Gallery 1.0 and 2.0 allows remote attackers
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Socketmail 2.2.8 - 'fnc-readmail3.php' Remote File Inclusion
CVE-2007-5627—webappsphp
PHP remote file inclusion vulnerability in content/fnc-readmail3.php in SocketMail 2.2.8 allows remote attackers to exec
23RIESGO
abrir ↗
Referência✓ VexDay Proof
LoudBlog 0.8.0a - 'ajax.php' SQL Injection
CVE-2008-6077—webappsphp
SQL injection vulnerability in loudblog/ajax.php in LoudBlog 0.8.0a and earlier allows remote authenticated users to exe
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PeopleAggregator 1.2pre6-release-53 - Multiple Remote File Inclusions
CVE-2007-5631—webappsphp
Multiple PHP remote file inclusion vulnerabilities in PeopleAggregator 1.2pre6, when register_globals is enabled, allow
35RIESGO
abrir ↗
Referência✓ VexDay Proof
Motorola Timbuktu Pro 8.6.5/8.7 - Directory Traversal / Log Injection
CVE-2008-1117—remotewindows
Directory traversal vulnerability in the Notes (aka Flash Notes or instant messages) feature in tb2ftp.dll in Timbuktu P
50RIESGO
abrir ↗
Referência✓ VexDay Proof
Simple Machines Forum (SMF) 1.1.3 - Blind SQL Injection
CVE-2007-5646—webappsphp
SQL injection vulnerability in Sources/Search.php in Simple Machines Forum (SMF) 1.1.3, when MySQL 5 is used, allows rem
23RIESGO
abrir ↗
Referência✓ VexDay Proof
BosNews 4.0 - 'article' SQL Injection
CVE-2008-4703—webappsphp
SQL injection vulnerability in news.php in BosDev BosNews 4.0 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Opera 9.60 - Persistent Cross-Site Scripting
CVE-2008-4696—remotewindows
Cross-site scripting (XSS) vulnerability in Opera.dll in Opera before 9.61 allows remote attackers to inject arbitrary w
50RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP-Agenda 2.2.4 - 'index.php' Local File Inclusion
CVE-2008-3031—webappsphp
Directory traversal vulnerability in index.php in Simple PHP Agenda 2.2.4 and earlier allows remote attackers to include
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Sports Clubs Web Panel 0.0.1 - 'p' Local File Inclusion
CVE-2008-4592—webappsphp
Directory traversal vulnerability in index.php in Sports Clubs Web Panel 0.0.1 allows remote attackers to include and ex
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Somery 0.4.6 - 'skin_dir' Remote File Inclusion
CVE-2006-4669—webappsphp
PHP remote file inclusion vulnerability in admin/system/include.php in Somery 0.4.6 and earlier, when register_globals i
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Fuzzylime CMS 3.03a - Local Inclusion / Arbitrary File Corruption
CVE-2009-2177—webappsphp
code/display.php in fuzzylime (cms) 3.03a and earlier, when magic_quotes_gpc is disabled, allows remote attackers to con
23RIESGO
abrir ↗
Referência✓ VexDay Proof
phpDatingClub 3.7 - SQL Injection / Cross-Site Scripting Injection
CVE-2009-2179—webappsphp
SQL injection vulnerability in search.php in phpDatingClub 3.7 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗
Referência✓ VexDay Proof
AvailScript Article Script - 'view.php' SQL Injection
CVE-2008-6037—webappsphp
SQL injection vulnerability in view.php in AvailScript Article Script allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗
Referência✓ VexDay Proof
basebuilder 2.0.1 - 'main.inc.php' Remote File Inclusion
CVE-2008-6036—webappsphp
PHP remote file inclusion vulnerability in main.inc.php in BaseBuilder 2.0.1 and earlier allows remote attackers to exec
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component FacileForms 1.4.4 - Remote File Inclusion
CVE-2008-2990—webappsphp
PHP remote file inclusion vulnerability in facileforms.frame.php in the FacileForms (com_facileforms) component 1.4.4 fo
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHPBandManager 0.8 - 'index.php?pg' Remote File Inclusion
CVE-2007-2341—webappsphp
PHP remote file inclusion vulnerability in suite/index.php in phpBandManager 0.8 allows remote attackers to execute arbi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
OTSCMS 2.1.3 - Multiple Remote File Inclusions
CVE-2006-5547—webappsphp
PHP remote file inclusion vulnerability in OTSCMS/OTSCMS.php in Open Tibia Server Content Management System (OTSCMS) 1.0
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WordPress Plugin BackUpWordPress 0.4.2b - Remote File Inclusion
CVE-2007-5800—webappsphp
Multiple PHP remote file inclusion vulnerabilities in the BackUpWordPress 0.4.2b and earlier plugin for WordPress allow
35RIESGO
abrir ↗
Referência✓ VexDay Proof
Star Articles 6.0 - Blind SQL Injection (2)
CVE-2008-7075—webappsphp
Multiple SQL injection vulnerabilities in Kalptaru Infotech Ltd. Star Articles 6.0 allow remote attackers to inject arbi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Campsite 3.3.0 RC1 - Multiple Remote File Inclusions
CVE-2009-2183—webappsphp
Directory traversal vulnerability in admin-files/ad.php in Campsite 3.3.0 RC1 allows remote attackers to read and possib
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP Realtor 1.5 - 'v_cat' SQL Injection
CVE-2008-4496—webappsphp
SQL injection vulnerability in view_cat.php in PHP Realtor 1.5 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP Image 1.2 - Multiple Remote File Inclusions
CVE-2007-5697—webappsphp
Multiple PHP remote file inclusion vulnerabilities in PHP Image 1.2 allow remote attackers to execute arbitrary PHP code
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP-revista 1.1.2 - Remote File Inclusion / SQL Injection / Authentication Bypass / Cross-Site Scripting
CVE-2006-4607—webappsphp
admin/index.php in Longino Jacome php-Revista 1.1.2 allows remote attackers to bypass authentication controls by setting
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Limbo CMS 1.0.4.2L - 'com_contact' Remote Code Execution
CVE-2006-4859—webappsphp
Unrestricted file upload vulnerability in contact.html.php in the Contact (com_contact) component in Limbo (aka Lite Mam
23RIESGO
abrir ↗
Referência✓ VexDay Proof
GOM Player 2.1.6.3499 - 'GomWeb3.dll 1.0.0.12' Remote Overflow
CVE-2007-5779—remotewindows
Buffer overflow in the GomManager (GomWeb Control) ActiveX control in GomWeb3.dll 1.0.0.12 in Gretech Online Movie Playe
60RIESGO
abrir ↗
← anteriorpágina 692 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.