Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.759exploits catalogados
38.127CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
Numark Cue 5.0 rev 2 - '.m3u' File Local Stack Buffer Overflow
CVE-2008-4470—localwindows
Stack-based buffer overflow in Numark CUE 5.0 rev2 allows user-assisted attackers to cause a denial of service (applicat
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Vastal I-Tech Toner Cart - 'id' SQL Injection
CVE-2008-4467—webappsphp
SQL injection vulnerability in show_series_ink.php in Vastal I-Tech Toner Cart allows remote attackers to execute arbitr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CS-Cart 1.3.5 - Authentication Bypass
CVE-2008-6394—webappsphp
SQL injection vulnerability in core/user.php in CS-Cart 1.3.5 and earlier allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗
Referência✓ VexDay Proof
OpenSSL 0.9.8c-1 < 0.9.8g-9 (Debian and Derivatives) - Predictable PRNG Brute Force SSH
CVE-2008-3280—remotelinux
It was found that various OpenID Providers (OPs) had TLS Server Certificates that used weak keys, as a result of the Deb
23RIESGO
abrir ↗
Referência✓ VexDay Proof
EZWebAlbum - Insecure Cookie Handling
CVE-2008-3292—webappsphp
constants.inc in EZWebAlbum 1.0 allows remote attackers to bypass authentication and gain administrator privileges by se
23RIESGO
abrir ↗
Referência✓ VexDay Proof
bilboblog 2.1 - Multiple Vulnerabilities
CVE-2008-3304—webappsphp
BilboBlog 0.2.1 allows remote attackers to obtain sensitive information via (1) an enable_cache=false query string to fo
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Codefixer MailingListPro - Database Disclosure
CVE-2008-6374—webappsasp
CodefixerSoftware MailingListPro Free Edition stores sensitive information under the web root with insufficient access c
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Vastal I-Tech Software Zone - 'cat_id' SQL Injection
CVE-2008-6209—webappsphp
SQL injection vulnerability in view_product.php in Vastal I-Tech Software Zone allows remote attackers to execute arbitr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Carbon Communities 2.4 - Multiple Vulnerabilities
CVE-2008-1896—webappsasp
Multiple cross-site scripting (XSS) vulnerabilities in Carbon Communities 2.4 and earlier allow remote attackers to inje
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mantis Bug Tracker 1.1.1 - Code Execution / Cross-Site Scripting / Cross-Site Request Forgery
CVE-2008-3332—webappsphp
Eval injection vulnerability in adm_config_set.php in Mantis before 1.1.2 allows remote authenticated administrators to
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Atom Photoblog 1.1.5b1 - 'photoId' SQL Injection
CVE-2008-3351—webappsphp
SQL injection vulnerability in atomPhotoBlog.php in Atom PhotoBlog 1.0.9.1 and 1.1.5b1 allows remote attackers to execut
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Vastal I-Tech DVD Zone - 'cat_id' SQL Injection
CVE-2008-4465—webappsphp
SQL injection vulnerability in view_mags.php in Vastal I-Tech DVD Zone allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Referência✓ VexDay Proof
IntelliTamper 2.07 - HTTP Header Remote Code Execution
CVE-2008-3361—remotewindows
Stack-based buffer overflow in IntelliTamper 2.07 allows remote web sites to execute arbitrary code via a long HTTP Serv
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Vastal I-Tech Jobs Zone - 'news_id' SQL Injection
CVE-2008-4463—webappsphp
SQL injection vulnerability in view_news.php in Vastal I-Tech Jobs Zone allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Vastal I-Tech MMORPG Zone - 'game_id' SQL Injection
CVE-2008-4460—webappsphp
SQL injection vulnerability in game.php in Vastal I-Tech MMORPG Zone allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Phpjobscheduler 3.0 - 'installed_config_file' File Inclusion
CVE-2006-5928—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Phpjobscheduler 3.0 allow remote attackers to execute arbitrary PH
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MySQL Quick Admin 1.5.5 - 'cookie' Local File Inclusion
CVE-2008-4455—webappsphp
Directory traversal vulnerability in index.php in EKINdesigns MySQL Quick Admin 1.5.5 and earlier, when magic_quotes_gpc
23RIESGO
abrir ↗
Referência✓ VexDay Proof
mIRC 6.34 - Remote Buffer Overflow (PoC)
CVE-2008-4449—doswindows
Stack-based buffer overflow in mIRC 6.34 allows remote attackers to execute arbitrary code via a long hostname in a PRIV
50RIESGO
abrir ↗
Referência✓ VexDay Proof
RsGallery2 < 1.11.2 - 'rsgallery.html.php' File Inclusion
CVE-2006-6962—webappsphp
PHP remote file inclusion vulnerability in rsgallery2.html.php in the RS Gallery2 component (com_rsgallery2) 1.11.2 for
23RIESGO
abrir ↗
Referência✓ VexDay Proof
pPIM 1.0 - Upload/Change Password
CVE-2008-4427—webappsphp
changepassword.php in Phlatline's Personal Information Manager (pPIM) 1.0 and earlier does not require administrative au
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CMS Faethon 2.2 Ultimate - Remote File Inclusion / Cross-Site Scripting
CVE-2008-2127—webappsphp
Cross-site scripting (XSS) vulnerability in search.php in CMS Faethon 2.2 Ultimate allows remote attackers to inject arb
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PixelPost 1.7.1 - 'language_full' Local File Inclusion
CVE-2008-3365—webappsphp
Directory traversal vulnerability in index.php in Pixelpost 1.7.1 on Windows, when register_globals is enabled, allows r
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Absolute News Feed 1.0 - Remote Insecure Cookie Handling
CVE-2008-6855—webappsphp
Xigla Software Absolute News Feed 1.0 and possibly 1.5 allows remote attackers to bypass authentication and gain adminis
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PrecisionID Barcode ActiveX 1.3 - Denial of Service
CVE-2007-2657—doswindows
Unspecified vulnerability in the PrecisionID Barcode 1.3 ActiveX control in PrecisionID_DataMatrix.DLL allows remote att
23RIESGO
abrir ↗
Referência✓ VexDay Proof
EZContents CMS 2.0.0 - Multiple SQL Injections
CVE-2008-2135—webappsphp
Multiple SQL injection vulnerabilities in VisualShapers ezContents 2.0.0 allow remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Hot Links SQL-PHP 3 - 'report.php' Multiple Vulnerabilities
CVE-2008-4379—webappsphp
Cross-site scripting (XSS) vulnerability in report.php in Mr. CGI Guy Hot Links SQL-PHP 3.0 and earlier allows remote at
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CentiPaid 1.4.2 - 'centipaid_class.php' Remote File Inclusion
CVE-2006-6976—webappsphp
PHP remote file inclusion vulnerability in centipaid_class.php in CentiPaid 1.4.2 and earlier allows remote attackers to
23RIESGO
abrir ↗
Referência✓ VexDay Proof
NULL FTP Server 1.1.0.7 - 'Site' Command Injection
CVE-2008-6534—remotewindows
Incomplete blacklist vulnerability in NULL FTP Server Free and Pro 1.1.0.7 allows remote authenticated users to execute
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Live TV Script - 'index.php?mid' SQL Injection
CVE-2008-4376—webappsphp
SQL injection vulnerability in index.php in Live TV Script allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Weblogicnet - 'files_dir' Multiple Remote File Inclusions
CVE-2007-4715—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Weblogicnet allow remote attackers to execute arbitrary PHP code v
23RIESGO
abrir ↗
← anteriorpágina 694 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.