Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.759exploits catalogados
38.127CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
MyBulletinBoard (MyBB) 1.2.11 - 'private.php' SQL Injection (1)
CVE-2008-0787—webappsphp
SQL injection vulnerability in inc/datahandlers/pm.php in MyBB before 1.2.12 allows remote authenticated users to execut
23RIESGO
abrir ↗
Referência✓ VexDay Proof
falcon CMS 1.4.3 - Remote File Inclusion / Cross-Site Scripting
CVE-2007-6490—webappsphp
Cross-site request forgery (CSRF) vulnerability in Falcon Series One CMS 1.4.3 allows remote attackers to change a passw
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component xfaq 1.2 - 'aid' SQL Injection
CVE-2008-0795—webappsphp
SQL injection vulnerability in index.php in the MGFi XfaQ (com_xfaq) 1.2 component for Mambo and Joomla! allows remote a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Dokeos 1.8.4 - Arbitrary File Upload
CVE-2007-6479—webappsphp
Unrestricted file upload vulnerability in the "My productions" component for main/auth/profile.php (aka the "My profile"
23RIESGO
abrir ↗
Referência✓ VexDay Proof
gf-3xplorer 2.4 - Cross-Site Scripting / Local File Inclusion
CVE-2007-6474—webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in GF-3XPLORER 2.4 allow remote attackers to inject arbitrary web sc
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Creative Software AutoUpdate Engine - ActiveX Stack Overflow
CVE-2008-0955—remotewindows
Stack-based buffer overflow in the Creative Software AutoUpdate Engine ActiveX control in CTSUEng.ocx allows remote atta
50RIESGO
abrir ↗
Referência✓ VexDay Proof
SNMPv3 - HMAC Validation error Remote Authentication Bypass
CVE-2008-0960—remotemultiple
SNMPv3 HMAC verification in (1) Net-SNMP 5.2.x before 5.2.4.1, 5.3.x before 5.3.2.1, and 5.4.x before 5.4.1.1; (2) UCD-S
35RIESGO
abrir ↗
Referência✓ VexDay Proof
Sun Solaris 10 - snoop(1M) Utility Remote Command Execution
CVE-2008-0964—remotesolaris
Multiple stack-based buffer overflows in snoop on Sun Solaris 8 through 10 and OpenSolaris before snv_96, when the -o op
28RIESGO
abrir ↗
Referência✓ VexDay Proof
TualBLOG 1.0 - 'icerikno' SQL Injection
CVE-2006-4793—webappsasp
Multiple SQL injection vulnerabilities in icerik.asp in TualBLOG 1.0 allow remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Home FTP Server 1.4.5 - Remote Denial of Service
CVE-2008-1478—doswindows
Home FTP Server 1.4.5.89 allows remote attackers to cause a denial of service (crash) by opening a FTP passive mode conn
23RIESGO
abrir ↗
Referência✓ VexDay Proof
EasyNews 40tr - SQL Injection / Cross-Site Scripting / Local File Inclusion
CVE-2008-1650—webappsphp
SQL injection vulnerability in dynamicpages/index.php in EasyNews 4.0 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP-Nuke Platinum 7.6.b.5 - 'dynamic_titles.php' SQL Injection
CVE-2008-1680—webappsphp
PHP-Nuke Platinum 7.6.b.5 allows remote attackers to obtain configuration information via a direct request to maintenanc
23RIESGO
abrir ↗
Referência✓ VexDay Proof
BlogMe PHP 1.1 - 'comments.php' SQL Injection
CVE-2008-2175—webappsphp
SQL injection vulnerability in comments.php in Gamma Scripts BlogMe PHP 1.1 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
wPortfolio 0.3 - Admin Password Changing
CVE-2008-5221—webappsphp
The account_save action in admin/userinfo.php in wPortfolio 0.3 and earlier does not require authentication and does not
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Cplinks 1.03 - Authentication Bypass / SQL Injection / Cross-Site Scripting
CVE-2008-2180—webappsphp
Multiple SQL injection vulnerabilities in cpLinks 1.03, when magic_quotes_gpc is disabled, allow remote attackers to exe
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Online Rental Property Script 4.5 - 'pid' SQL Injection
CVE-2008-2190—webappsphp
SQL injection vulnerability in index.php in Online Rent (aka Online Rental Property Script) 4.5 and earlier allows remot
23RIESGO
abrir ↗
Referência✓ VexDay Proof
KwsPHP 1.0 Module Newsletter - SQL Injection
CVE-2007-5458—webappsphp
SQL injection vulnerability in index.php in the newsletter module 1.0 for KwsPHP, when magic_quotes_gpc is disabled, all
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ScorpNews 1.0 - 'site' Remote File Inclusion
CVE-2008-2193—webappsphp
PHP remote file inclusion vulnerability in example.php in Thomas Gossmann ScorpNews 2.0 allows remote attackers to execu
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Apple iTouch/iPhone 1.1.1 - '.tif' Remote Privilege Escalation 'Jailbreak'
CVE-2007-5450—remoteios
Unspecified vulnerability in Safari on the Apple iPod touch (aka iTouch) and iPhone 1.1.1 allows user-assisted remote at
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Microsoft Internet Explorer - Print Table of Links Cross-Zone Scripting
CVE-2008-2281—remotewindows
Cross-zone scripting vulnerability in the Print Table of Links feature in Internet Explorer 6.0, 7.0, and 8.0b allows us
28RIESGO
abrir ↗
Referência✓ VexDay Proof
idautomation bar code - ActiveX Multiple Vulnerabilities
CVE-2008-2283—remotewindows
IDAutomation allows remote attackers to overwrite arbitrary files via the argument to the (1) SaveBarCode and (2) SaveEn
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Kostenloses Linkmanagementscript - SQL Injection
CVE-2008-2301—webappsphp
SQL injection vulnerability in Kostenloses Linkmanagementscript allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Core Image Fun House 2.0 (OSX) - Arbitrary Code Execution (PoC)
CVE-2008-2304—dososx
Buffer overflow in Apple Core Image Fun House 2.0 and earlier in CoreImage Examples in Xcode tools before 3.1 allows use
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WordPress Plugin PictPress 0.91 - Remote File Disclosure
CVE-2007-6369—webappsphp
Multiple directory traversal vulnerabilities in resize.php in the PictPress 0.91 and earlier plugin for WordPress allow
23RIESGO
abrir ↗
Referência✓ VexDay Proof
newsmanager 2.0 - Remote File Inclusion / File Disclosure / SQL Injection
CVE-2008-2340—webappsphp
Multiple SQL injection vulnerabilities in News Manager 2.0 allow remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗
Referência✓ VexDay Proof
newsmanager 2.0 - Remote File Inclusion / File Disclosure / SQL Injection
CVE-2008-2342—webappsphp
Directory traversal vulnerability in attachments.php in News Manager 2.0 allows remote attackers to read arbitrary files
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Web Group Communication Center (WGCC) 1.0.3 - SQL Injection
CVE-2008-2445—webappsphp
Cross-site scripting (XSS) vulnerability in profile.php in Web Group Communication Center (WGCC) 1.0.3 PreRelease 1 and
23RIESGO
abrir ↗
Referência✓ VexDay Proof
e-107 Plugin ZoGo-Shop 1.16 Beta 13 - SQL Injection
CVE-2008-2447—webappsphp
SQL injection vulnerability in products.php in the Mytipper ZoGo-shop plugin 1.15.5 and 1.16 Beta 13 for e107 allows rem
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ComicShout 2.5 - 'comic_id' SQL Injection
CVE-2008-2456—webappsphp
SQL injection vulnerability in index.php in ComicShout 2.5 and earlier allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Referência✓ VexDay Proof
LibSPF2 < 1.2.8 - DNS TXT Record Parsing Bug Heap Overflow (PoC)
CVE-2008-2469—dosmultiple
Heap-based buffer overflow in the SPF_dns_resolv_lookup function in Spf_dns_resolv.c in libspf2 before 1.2.8 allows remo
28RIESGO
abrir ↗
← anteriorpágina 697 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.