Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.759exploits catalogados
38.127CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
Simple Forum 3.2 - File Disclosure / Cross-Site Scripting
CVE-2008-0542—webappsphp
Directory traversal vulnerability in thumbnail.php in Gerd Tentler Simple Forum 3.2 allows remote attackers to read arbi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP iCalendar 2.24 - 'cookie_language' Local File Inclusion / Arbitrary File Upload
CVE-2008-5968—webappsphp
Directory traversal vulnerability in print.php in PHP iCalendar 2.24 and earlier allows remote attackers to include and
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Symphony 1.7.01 (non-patched) - Remote Code Execution
CVE-2008-3592—webappsphp
Unrestricted file upload vulnerability in the File Manager in the admin panel in Twentyone Degrees Symphony 1.7.01 and e
23RIESGO
abrir ↗
Referência✓ VexDay Proof
GreenCart PHP Shopping Cart - 'id' SQL Injection
CVE-2008-3585—webappsphp
Multiple SQL injection vulnerabilities in PozScripts GreenCart PHP Shopping Cart allow remote attackers to execute arbit
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Online Grades 3.2.4 - Authentication Bypass
CVE-2009-0453—webappsphp
Online Grades 3.2.4 allows remote attackers to obtain configuration information via a direct request to phpinfo.php, whi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Orbit Downloader 2.8.7 - Arbitrary File Deletion
CVE-2009-1064—remotewindows
Argument injection vulnerability in orbitmxt.dll 2.1.0.2 in the Orbit Downloader 2.8.7 and earlier ActiveX control allow
23RIESGO
abrir ↗
Referência✓ VexDay Proof
IntelliTamper 2.07 - 'imgsrc' Remote Buffer Overflow
CVE-2008-3583—remotewindows
Buffer overflow in the HTML parser in IntelliTamper 2.07 allows remote attackers to execute arbitrary code via a long UR
23RIESGO
abrir ↗
Referência✓ VexDay Proof
k-links directory - SQL Injection / Cross-Site Scripting
CVE-2008-3581—webappsphp
Cross-site scripting (XSS) vulnerability in index.php in Qsoft K-Links allows remote attackers to inject arbitrary web s
23RIESGO
abrir ↗
Referência✓ VexDay Proof
k-links directory - SQL Injection / Cross-Site Scripting
CVE-2008-3580—webappsphp
Multiple SQL injection vulnerabilities in Qsoft K-Links allow remote attackers to execute arbitrary SQL commands via (1)
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Web Wiz Rich Text Editor 4.0 - Multiple Vulnerabilities
CVE-2008-0473—webappsasp
RTE_popup_save_file.asp in Web Wiz Rich Text Editor 4.0 allows remote attackers to upload (1) .html and (2) .htm files v
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Pixie CMS - Cross-Site Scripting / SQL Injection
CVE-2009-1067—webappsphp
Cross-site scripting (XSS) vulnerability in index.php in Pixie CMS 1.01a allows remote attackers to inject arbitrary web
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Noticeware Email Server 4.6.1.0 - Denial of Service
CVE-2008-1713—doswindows
MailServer.exe in NoticeWare Email Server 4.6.1.0 allows remote attackers to cause a denial of service (application cras
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Scientific Image DataBase 0.41 - Blind SQL Injection
CVE-2008-2834—webappsphp
SQL injection vulnerability in projects.php in Scientific Image DataBase 0.41 allows remote attackers to execute arbitra
23RIESGO
abrir ↗
Referência✓ VexDay Proof
KAPhotoservice - 'album.asp' SQL Injection
CVE-2008-1426—webappsasp
SQL injection vulnerability in album.asp in KAPhotoservice allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Easy-Clanpage 2.2 - 'id' SQL Injection
CVE-2008-1425—webappsphp
SQL injection vulnerability in index.php in the gallery module in Easy-Clanpage 2.2 allows remote attackers to execute a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Wsn (Multiple Products) - Local File Inclusion / Code Execution
CVE-2008-3555—webappsphp
Directory traversal vulnerability in index.php in (1) WSN Forum 4.1.43 and earlier, (2) Gallery 4.1.30 and earlier, (3)
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Easy Photo Gallery 2.1 - Arbitrary Add Admin / remove user
CVE-2008-4167—webappsphp
useradmin.php in Easy Photo Gallery (aka Ezphotogallery) 2.1 does not require administrative authentication, which allow
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WordPress Plugin WP-Forum 1.7.4 - SQL Injection
CVE-2008-0388—webappsphp
SQL injection vulnerability in the WP-Forum 1.7.4 plugin for WordPress allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Referência✓ VexDay Proof
LoveCMS 1.6.2 Final - Arbitrary File Delete
CVE-2008-5794—webappsphp
Directory traversal vulnerability in system/admin/images.php in LoveCMS 1.6.2 Final allows remote attackers to delete ar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Eznet 3.5.0 - Remote Stack Overflow / Denial of Service
CVE-2003-1339—remotewindows
Stack-based buffer overflow in eZnet.exe, as used in eZ (a) eZphotoshare, (b) eZmeeting, (c) eZnetwork, and (d) eZshare
35RIESGO
abrir ↗
Referência✓ VexDay Proof
Apple Safari - RSS 'feed://' Buffer Overflow via libxml2 (PoC)
CVE-2008-3529—doswindows
Heap-based buffer overflow in the xmlParseAttValueComplex function in parser.c in libxml2 before 2.7.0 allows context-de
28RIESGO
abrir ↗
Referência✓ VexDay Proof
fhttpd 0.4.2 - 'un64()' Remote Denial of Service
CVE-2008-7014—doslinux
fhttpd 0.4.2 allows remote attackers to cause a denial of service (crash) via an Authorization HTTP header with an inval
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Hot Open Tickets 11012004 - 'CLASS_PATH' Remote File Inclusion
CVE-2006-2730—webappsphp
PHP remote file inclusion vulnerability in admin/lib_action_step.php in Hot Open Tickets (HOT) 11012004_ver2f, when regi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PPLive 1.9.21 - '/LoadModule' URI Handlers Argument Injection
CVE-2009-1087—remotewindows
Multiple argument injection vulnerabilities in PPLive.exe in PPLive 1.9.21 and earlier allow remote attackers to execute
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Drupal 4.7 - 'Attachment mod_mime' Remote Command Execution
CVE-2006-2743—webappsphp
Drupal 4.6.x before 4.6.7 and 4.7.0, when running on Apache with mod_mime, does not properly handle files with multiple
28RIESGO
abrir ↗
Referência✓ VexDay Proof
Azucar CMS 1.3 - '/admin/index_sitios.php' File Inclusion
CVE-2006-6720—webappsphp
PHP remote file inclusion vulnerability in admin/index_sitios.php in Azucar CMS 1.3 allows remote attackers to execute a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
TemaTres 1.0.3 - Authentication Bypass / SQL Injection / Cross-Site Scripting
CVE-2009-1584—webappsphp
Multiple SQL injection vulnerabilities in TemaTres 1.0.3 and 1.031, when magic_quotes_gpc is disabled, allow remote atta
23RIESGO
abrir ↗
Referência✓ VexDay Proof
LightBlog 8.4.1.1 - Remote Code Execution
CVE-2007-5374—webappsphp
cp_memberedit.php in LightBlog 8.4.1.1 does not check for administrative credentials when processing an admin action, wh
23RIESGO
abrir ↗
Referência✓ VexDay Proof
FS4104-AW VDSL Device (Rooter) - GoAhead WebServer Disclosure
CVE-2007-6702—remotehardware
goform/QuickStart_c0 on the GoAhead Web Server on the FS4104-AW (aka rooter) VDSL device contains a password in the type
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Maxtrade AIO 1.3.23 - 'categori' SQL Injection
CVE-2008-2847—webappsphp
SQL injection vulnerability in the Trade module in Maxtrade AIO 1.3.23 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
← anteriorpágina 696 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.