Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.759exploits catalogados
38.127CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
phpQuiz 0.1.2 - SQL Injection / Code Execution
CVE-2006-4979—webappsphp
Direct static code injection vulnerability in cfgphpquiz/install.php in Walter Beschmout PhpQuiz 1.2 and earlier allows
23RIESGO
abrir ↗
Referência✓ VexDay Proof
cPanel 11.x - Cross-Site Scripting / Local File Inclusion
CVE-2008-6927—webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in autoinstall4imagesgalleryupgrade.php in the Fantastico De Luxe Mo
23RIESGO
abrir ↗
Referência✓ VexDay Proof
netForo! 0.1 - 'down.php?file_to_download' Remote File Disclosure
CVE-2007-1392—webappsphp
Directory traversal vulnerability in down.php in netForo! 0.1g allows remote attackers to read arbitrary files via a ..
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Winamp 5.541 - '.mp3'/'.aiff' File Multiple Denial of Service Vulnerabilities
CVE-2009-0263—doswindows
Multiple buffer overflows in Winamp 5.541 and earlier allow remote attackers to cause a denial of service and possibly e
28RIESGO
abrir ↗
Referência✓ VexDay Proof
phpsyncml 0.1.2 - Remote File Inclusion
CVE-2007-4978—webappsphp
Multiple PHP remote file inclusion vulnerabilities in phpSyncML 0.1.2 and earlier allow remote attackers to execute arbi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
mutiple timesheets 5.0 - Multiple Vulnerabilities
CVE-2008-1415—webappsphp
Directory traversal vulnerability in index.php in Multiple Time Sheets (MTS) 5.0 and earlier allows remote attackers to
23RIESGO
abrir ↗
Referência✓ VexDay Proof
phpinv 0.8.0 - Local File Inclusion / Cross-Site Scripting
CVE-2008-2694—webappsphp
Cross-site scripting (XSS) vulnerability in search.php in phpInv 0.8.0 allows remote attackers to inject arbitrary web s
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component com_hbssearch 1.0 - Blind SQL Injection
CVE-2008-5865—webappsphp
SQL injection vulnerability in the com_hbssearch component 1.0 in the Hotel Booking Reservation System (aka HBS) 1.0.0 f
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Absolute Content Rotator 6.0 - Insecure Cookie Handling
CVE-2008-6862—webappsphp
Absolute Content Rotator 6.0 allows remote attackers to bypass authentication and gain administrative access by setting
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Axigen 2.0.0b1 - Remote Denial of Service (2)
CVE-2007-0887—doslinux
axigen 1.2.6 through 2.0.0b1 does not properly parse login credentials, which allows remote attackers to cause a denial
28RIESGO
abrir ↗
Referência✓ VexDay Proof
mxBB Module newssuite 1.03 - Remote File Inclusion
CVE-2006-6553—webappsphp
PHP remote file inclusion vulnerability in includes/newssuite_constants.php in the NewsSuite 1.03 module for mxBB allows
23RIESGO
abrir ↗
Referência✓ VexDay Proof
torrentflux 2.2 - Arbitrary File Create/ Execute/Delete
CVE-2006-6329—webappsphp
index.php for TorrentFlux 2.2 allows remote attackers to delete files by specifying the target filename in the delfile p
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Coppermine Photo Gallery 1.4.18 - Local File Inclusion / Remote Code Execution
CVE-2008-3481—webappsphp
themes/sample/theme.php in Coppermine Photo Gallery (CPG) 1.4.18 and earlier allows remote attackers to obtain sensitive
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Google Chrome - 'ChromeHTML://' Remote Parameter Injection
CVE-2008-5750—remotewindows
Argument injection vulnerability in Microsoft Internet Explorer 8 beta 2 on Windows XP SP3 allows remote attackers to ex
28RIESGO
abrir ↗
Referência✓ VexDay Proof
Simple HTTPd 1.38 - Multiple Vulnerabilities
CVE-2007-6404—remotewindows
Directory traversal vulnerability in Sergey Lyubka Simple HTTPD (shttpd) 1.38 and earlier on Windows allows remote attac
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Acc Autos 4.0 - Insecure Cookie Handling
CVE-2008-6292—webappsphp
Acc Autos 4.0 allows remote attackers to bypass authentication and gain administrative access by setting the (1) usernam
23RIESGO
abrir ↗
Referência✓ VexDay Proof
AvailScript Jobs Portal Script - (Authenticated) Arbitrary File Upload
CVE-2008-7021—webappsphp
Unrestricted file upload vulnerability in editlogo.php in AvailScript Jobs Portal Script allows remote authenticated use
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PowerNews 2.5.4 - 'newsid' SQL Injection
CVE-2009-0705—webappsphp
SQL injection vulnerability in news.php in PowerScripts PowerNews 2.5.4, when magic_quotes_gpc is disabled, allows remot
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP Hosting Directory 2.0 - Insecure Cookie Handling
CVE-2008-3454—webappsphp
JnSHosts PHP Hosting Directory 2.0 allows remote attackers to bypass authentication and gain administrative access by se
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CitectSCADA ODBC Server - Remote Stack Buffer Overflow (Metasploit)
CVE-2008-2639—remotewindows
Stack-based buffer overflow in the ODBC server service in Citect CitectSCADA 6 and 7, and CitectFacilities 7, allows rem
60RIESGO
abrir ↗
Referência✓ VexDay Proof
PHPress 0.2.0 - 'adisplay.php?lang' Local File Inclusion
CVE-2007-4524—webappsphp
PHP remote file inclusion vulnerability in adisplay.php in PhPress 0.2.0 allows remote attackers to execute arbitrary PH
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WordPress Plugin WP-Cal 0.3 - 'editevent.php' SQL Injection
CVE-2008-0490—webappsphp
SQL injection vulnerability in functions/editevent.php in the WP-Cal 0.3 plugin for WordPress allows remote attackers to
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Popcorn 1.87 - Remote Heap Overflow (PoC)
CVE-2009-1647—doswindows
Heap-based buffer overflow in popcorn.exe in Ultrafunk Popcorn 1.87 allows remote POP3 servers to cause a denial of serv
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WordPress Plugin Download - 'dl_id' SQL Injection
CVE-2008-1646—webappsphp
SQL injection vulnerability in wp-download.php in the WP-Download 1.2 plugin for WordPress allows remote attackers to ex
23RIESGO
abrir ↗
Referência✓ VexDay Proof
BulletProof FTP Client 2.63 - Local Heap Overflow (PoC)
CVE-2008-5753—doswindows
Stack-based buffer overflow in BulletProof FTP Client 2.63 and 2010 allows user-assisted attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
HomePH Design 2.10 RC2 - Local File Inclusion / Remote File Inclusion / Cross-Site Scripting
CVE-2008-2981—webappsphp
PHP remote file inclusion vulnerability in admin/templates/template_thumbnail.php in HomePH Design 2.10 RC2, when regist
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Pligg 9.9.5b - Arbitrary File Upload / SQL Injection
CVE-2008-5739—webappsphp
SQL injection vulnerability in evb/check_url.php in Pligg CMS 9.9.5 Beta allows remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mobius 1.4.4.1 - SQL Injection
CVE-2008-3420—webappsphp
Multiple SQL injection vulnerabilities in Mobius for Mimsy XG 1 1.4.4.1 and earlier allow remote attackers to execute ar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Winamp 5.3 - '.wmv' Remote Denial of Service
CVE-2007-2180—doswindows
Buffer overflow in Nullsoft Winamp 5.3 allows user-assisted remote attackers to cause a denial of service (crash) via a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Crob FTP Server 3.6.1 build 263 - 'LIST/NLST' Denial of Service
CVE-2006-6558—doswindows
Crob FTP Server 3.6.1 b.263 allows remote attackers to cause a denial of service via a long series of "?A" sequences in
23RIESGO
abrir ↗
← anteriorpágina 698 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.