Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.759exploits catalogados
38.127CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
ASP PORTAL - Remote Database Disclosure
CVE-2008-5562—webappsasp
ASPPortal stores sensitive information under the web root with insufficient access control, which allows remote attacker
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SugarCRM Community Edition 4.5.1/5.0.0 - File Disclosure
CVE-2008-2045—webappsphp
Absolute path traversal vulnerability in SugarCRM Sugar Community Edition 4.5.1 and 5.0.0 allows remote attackers to rea
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHPizabi 0.848b C1 HFP1 - Arbitrary File Upload
CVE-2008-0805—webappsphp
Unrestricted file upload vulnerability in image.php in PHPizabi 0.848b C1 HFP1 allows remote attackers to execute arbitr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Corel Paint Shop Pro Photo 11.20 - '.clp' Local Buffer Overflow
CVE-2007-2209—localwindows
Buffer overflow in igcore15d.dll 15.1.2.0 and 15.2.0.0 for AccuSoft ImageGear, as used in Corel Paint Shop Pro Photo 11.
28RIESGO
abrir ↗
Referência✓ VexDay Proof
ID Automation Linear Barcode - ActiveX Denial of Service
CVE-2007-2658—doswindows
Unspecified vulnerability in the ID Automation Linear Barcode 1.6.0.5 ActiveX control in IDAutomationLinear6.dll allows
23RIESGO
abrir ↗
Referência✓ VexDay Proof
TutorialCMS 1.01 - Authentication Bypass
CVE-2007-2822—webappsphp
TutorialCMS 1.01 and earlier, when register_globals is enabled, allows remote attackers to bypass authentication via the
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PLog 1.0.6 - 'albumID' SQL Injection
CVE-2008-2629—webappsphp
SQL injection vulnerability in the LifeType (formerly pLog) module for Drupal allows remote attackers to execute arbitra
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ShoutPro 1.5.2 - 'shout.php' Remote Code Injection
CVE-2007-2141—webappsphp
Direct static code injection vulnerability in shoutbox.php in ShoutPro 1.5.2 allows remote attackers to inject arbitrary
35RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component beamospetition 1.0.12 - SQL Injection / Cross-Site Scripting
CVE-2009-0377—webappsphp
SQL injection vulnerability in the beamospetition (com_beamospetition) 1.0.12 component for Joomla! allows remote attack
23RIESGO
abrir ↗
Referência✓ VexDay Proof
LS Simple Guestbook 1.0 - Remote Code Execution
CVE-2007-2093—webappsphp
Direct static code injection vulnerability in index.php in Limesoft Guestbook (LS Simple Guestbook) 1.0 allows remote at
35RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component EasyBook 1.1 - 'gbid' SQL Injection
CVE-2008-2569—webappsphp
SQL injection vulnerability in the EasyBook (com_easybook) component 1.1 for Joomla! allows remote attackers to execute
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Snircd 1.3.4 - 'send_user_mode' Denial of Service
CVE-2008-1501—dosmultiple
The send_user_mode function in s_user.c in (1) Undernet ircu 2.10.12.12 and earlier, (2) snircd 1.3.4 and earlier, and u
23RIESGO
abrir ↗
Referência✓ VexDay Proof
xoops module tsdisplay4xoops 0.1 - Remote File Inclusion
CVE-2007-2091—webappsphp
PHP remote file inclusion vulnerability in blocks/tsdisplay4xoops_block2.php in tsdisplay4xoops (TSD4XOOPS, aka the Team
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! / Mambo Component New Article 1.1 - Remote File Inclusion
CVE-2007-2089—webappsphp
Multiple PHP remote file inclusion vulnerabilities in the Jx Development Article 1.1 and earlier component for Mambo and
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Microsoft Internet Explorer 7 - Clickjacking
CVE-2009-0369—remotewindows
Microsoft Internet Explorer 7 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick acti
28RIESGO
abrir ↗
Referência✓ VexDay Proof
CityWriter 0.9.7 - 'head.php' Remote File Inclusion
CVE-2007-6324—webappsphp
PHP remote file inclusion vulnerability in head.php in CityWriter 0.9.7 allows remote attackers to execute arbitrary PHP
23RIESGO
abrir ↗
Referência✓ VexDay Proof
XAMPP for Windows 1.6.0a - 'mssql_connect()' Remote Buffer Overflow
CVE-2007-2079—remotewindows
The ADONewConnection Connect function in adodb.php in XAMPP 1.6.0a and earlier for Windows uses untrusted input for the
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SunShop Shopping Cart 3.5 - 'abs_path' Remote File Inclusion
CVE-2007-2070—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools SunShop Shopping Cart before 3.5.1 allow remote
23RIESGO
abrir ↗
Referência✓ VexDay Proof
RKD Software BarCode ActiveX Control 'BarCodeAx.dll' 4.9 - Remote Overflow
CVE-2007-3435—remotewindows
Stack-based buffer overflow in the BeginPrint method in a certain ActiveX control in RKD Software (barcodetools.com) Bar
50RIESGO
abrir ↗
Referência✓ VexDay Proof
StoreFront for Gallery - 'GALLERY_BASEDIR' Remote File Inclusion
CVE-2007-2068—webappsphp
Multiple PHP remote file inclusion vulnerabilities in the StoreFront mods for Gallery allow remote attackers to execute
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Web Slider 0.6 - 'path' Remote File Inclusion
CVE-2007-2067—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Marco Antonio Islas Cruz Web Slider (WebSlider) 0.6 allow remote a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PrecisionID Barcode ActiveX 1.9 - Arbitrary File Overwrite
CVE-2007-2755—remotewindows
The PrecisionID Barcode 1.9 ActiveX control in PrecisionID_Barcode.dll, when Internet Explorer 6 is used, allows remote
23RIESGO
abrir ↗
Referência✓ VexDay Proof
JV2 Folder Gallery 3.0 - Remote File Inclusion
CVE-2007-0682—webappsphp
PHP remote file inclusion vulnerability in theme/include_mode/template.php in JV2 Folder Gallery 3.0.2 and earlier allow
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Merak Media Player 3.2 - '.m3u' File Local Buffer Overflow (PoC)
CVE-2009-0350—doswindows
Stack-based buffer overflow in Merak Media Player 3.2 allows remote attackers to execute arbitrary code via a long strin
28RIESGO
abrir ↗
Referência✓ VexDay Proof
Advanced Links Management (ALM) 1.52 - SQL Injection
CVE-2008-2529—webappsphp
SQL injection vulnerability in read.php in Advanced Links Management (ALM) 1.5.2 allows remote attackers to execute arbi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CDex 1.70b2 (Windows XP SP3) - '.ogg' Local Buffer Overflow
CVE-2009-1039—localwindows
Buffer overflow in CDex 1.70b2 allows remote attackers to execute arbitrary code via a crafted Info header in an Ogg Vor
23RIESGO
abrir ↗
Referência✓ VexDay Proof
VCDGear 3.56 Build 050213 - 'FILE' Local Code Execution
CVE-2007-2062—localwindows
Stack-based buffer overflow in VCDGear 3.55 and 3.56 BETA allows user-assisted remote attackers to execute arbitrary cod
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Miniweb 0.8.19 - Multiple Vulnerabilities
CVE-2008-0337—remotewindows
Heap-based buffer overflow in the _mwProcessReadSocket function in http.c in MiniWeb HTTP Server 0.8.19 allows remote at
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mambo Module Weather - 'absolute_path' Remote File Inclusion
CVE-2007-2044—webappsphp
PHP remote file inclusion vulnerability in mod_weather.php in the Antonis Ventouris Weather module for Mambo and Joomla!
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Cisco Router - HTTP Administration Cross-Site Request Forgery / Command Execution (1)
CVE-2008-4128HIGHbajo ataqueremotehardware
Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the
83RIESGO
abrir ↗
← anteriorpágina 699 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.