Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
NewzCrawler 1.8 - invalid string Remote Denial of Service
CVE-2007-2722doswindows
Unspecified vulnerability in NewzCrawler 1.8 allows remote attackers to cause a denial of service (application instabili
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Internet Explorer - Print Table of Links Cross-Zone Scripting
CVE-2008-2281remotewindows
Cross-zone scripting vulnerability in the Print Table of Links feature in Internet Explorer 6.0, 7.0, and 8.0b allows us
28RIESGO
abrir
ReferênciaVexDay Proof
Internet PhotoShow (Special Edition) - Insecure Cookie Handling
CVE-2008-2282webappsphp
admin.php in Internet Photoshow and Internet Photoshow Special Edition (SE) allows remote attackers to bypass authentica
23RIESGO
abrir
ReferênciaVexDay Proof
Hunkaray Duyuru Scripti - 'tr' SQL Injection
CVE-2007-0688webappsasp
SQL injection vulnerability in oku.asp in Hunkaray Duyuru Scripti allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir
ReferênciaVexDay Proof
Mantis Bug Tracker 1.1.1 - Code Execution / Cross-Site Scripting / Cross-Site Request Forgery
CVE-2008-3332webappsphp
Eval injection vulnerability in adm_config_set.php in Mantis before 1.1.2 allows remote authenticated administrators to
23RIESGO
abrir
ReferênciaVexDay Proof
idautomation bar code - ActiveX Multiple Vulnerabilities
CVE-2008-2283remotewindows
IDAutomation allows remote attackers to overwrite arbitrary files via the argument to the (1) SaveBarCode and (2) SaveEn
23RIESGO
abrir
ReferênciaVexDay Proof
Geeklog 2 - 'BaseView.php' Remote File Inclusion
CVE-2007-0810webappsphp
PHP remote file inclusion vulnerability in MVCnPHP/BaseView.php in GeekLog 2 and earlier allows remote attackers to exec
23RIESGO
abrir
ReferênciaVexDay Proof
Drake CMS 0.4.11 - Blind SQL Injection
CVE-2008-6475webappsphp
SQL injection vulnerability in the guestbook component (components/guestbook/guestbook.php) in Drake CMS 0.4.11 and earl
23RIESGO
abrir
ReferênciaVexDay Proof
Woltlab Burning Board Lite 1.0.2pl3e - 'pms.php' SQL Injection
CVE-2007-0812webappsphp
SQL injection vulnerability in pms.php in Woltlab Burning Board (wBB) Lite 1.0.2pl3e and earlier allows remote authentic
23RIESGO
abrir
ReferênciaVexDay Proof
XOOPS Module resmanager 1.21 - Blind SQL Injection
CVE-2007-2735webappsphp
SQL injection vulnerability in edit_day.php in the ResManager 1.2.1 and earlier module for Xoops allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
Achievo 1.1.0 - 'config_atkroot' Remote File Inclusion
CVE-2007-2736webappsphp
PHP remote file inclusion vulnerability in index.php in Achievo 1.1.0 allows remote attackers to execute arbitrary PHP c
23RIESGO
abrir
ReferênciaVexDay Proof
Kostenloses Linkmanagementscript - SQL Injection
CVE-2008-2301webappsphp
SQL injection vulnerability in Kostenloses Linkmanagementscript allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
ReferênciaVexDay Proof
Core Image Fun House 2.0 (OSX) - Arbitrary Code Execution (PoC)
CVE-2008-2304dososx
Buffer overflow in Apple Core Image Fun House 2.0 and earlier in CoreImage Examples in Xcode tools before 3.1 allows use
23RIESGO
abrir
ReferênciaVexDay Proof
otscms 2.1.5 - SQL Injection / Cross-Site Scripting
CVE-2007-0847webappsphp
SQL injection vulnerability in mod/PM/reply.php in Open Tibia Server CMS (OTSCMS) 2.1.5 and earlier allows remote attack
23RIESGO
abrir
ReferênciaVexDay Proof
PHPFootball 1.6 - SQL Injection
CVE-2008-3387webappsphp
SQL injection vulnerability in show.php in PHPFootball 1.6 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
ReferênciaVexDay Proof
SoftComplex PHP Image Gallery - 'ctg' SQL Injection
CVE-2008-6485webappsphp
SQL injection vulnerability in index.php in SoftComplex PHP Image Gallery allows remote attackers to execute arbitrary S
23RIESGO
abrir
ReferênciaVexDay Proof
DigiAffiliate 1.4 - Authentication Bypass
CVE-2008-6487webappsasp
Multiple SQL injection vulnerabilities in login.asp in Digiappz DigiAffiliate 1.4 and earlier allow remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
OpenX 2.6.3 - 'MAX_type' Local File Inclusion
CVE-2009-0291webappsphp
Directory traversal vulnerability in fc.php in OpenX 2.6.3 allows remote attackers to include and execute arbitrary file
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component MyAlbum 1.0 - 'album' SQL Injection
CVE-2008-6489webappsphp
SQL injection vulnerability in MyAlbum component (com_myalbum) 1.0 for Joomla! allows remote attackers to execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
FAQEngine 4.16.03 - 'question.php?questionref' SQL Injection
CVE-2007-2749webappsphp
SQL injection vulnerability in question.php in FAQEngine 4.16.03 and earlier allows remote attackers to execute arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
Build it Fast (bif3) 0.4.1 - Multiple Remote File Inclusions
CVE-2007-2762webappsphp
Multiple PHP remote file inclusion vulnerabilities in Build it Fast (bif3) 0.4.1 allow remote attackers to execute arbit
23RIESGO
abrir
ReferênciaVexDay Proof
SunLight CMS 5.3 - 'root' Remote File Inclusion
CVE-2007-2774webappsphp
Multiple PHP remote file inclusion vulnerabilities in SunLight CMS 5.3 allow remote attackers to execute arbitrary PHP c
23RIESGO
abrir
ReferênciaVexDay Proof
Ol BookMarks Manager 0.7.4 - SQL Injection
CVE-2007-2817webappsphp
SQL injection vulnerability in read/index.php in ol'bookmarks 0.7.4 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
ReferênciaVexDay Proof
IMGallery 2.5 - Multiple SQL Injections
CVE-2008-2337webappsphp
Multiple SQL injection vulnerabilities in IMGallery 2.5, when magic_quotes_gpc is disabled, allow remote attackers to ex
23RIESGO
abrir
ReferênciaVexDay Proof
newsmanager 2.0 - Remote File Inclusion / File Disclosure / SQL Injection
CVE-2008-2340webappsphp
Multiple SQL injection vulnerabilities in News Manager 2.0 allow remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
ReferênciaVexDay Proof
newsmanager 2.0 - Remote File Inclusion / File Disclosure / SQL Injection
CVE-2008-2342webappsphp
Directory traversal vulnerability in attachments.php in News Manager 2.0 allows remote attackers to read arbitrary files
23RIESGO
abrir
ReferênciaVexDay Proof
HP Software Update - 'Hpufunction.dll 4.0.0.1' Insecure Method
CVE-2008-2390remotewindows
Hpufunction.dll 4.0.0.1 in HP Software Update exposes the unsafe (1) ExecuteAsync and (2) Execute methods, which allows
23RIESGO
abrir
ReferênciaVexDay Proof
TAGWORX.CMS 3.00.02 - Multiple SQL Injections
CVE-2008-2394webappsphp
Multiple SQL injection vulnerabilities in TAGWORX.CMS 3.00.02 allow remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
ReferênciaVexDay Proof
XnView 1.93.6 - '.taac' Local Buffer Overflow
CVE-2008-2427localwindows
Stack-based buffer overflow in NConvert 4.92, GFL SDK 2.82, and XnView 1.93.6 on Windows and 1.70 on Linux and FreeBSD a
28RIESGO
abrir
ReferênciaVexDay Proof
CaLogic Calendars 1.2.2 - 'langsel' SQL Injection
CVE-2008-2444webappsphp
SQL injection vulnerability in userreg.php in CaLogic Calendars 1.2.2 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.