Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
PHPWebThings 1.5.2 - 'help.php?module' Local File Inclusion
CVE-2009-2081webappsphp
Directory traversal vulnerability in help.php in phpWebThings 1.5.2 and earlier, when magic_quotes_gpc is disabled, allo
23RIESGO
abrir
ReferênciaVexDay Proof
Mundi Mail 0.8.2 - 'top' Remote File Inclusion
CVE-2009-2095webappsphp
PHP remote file inclusion vulnerability in template/simpledefault/admin/_masterlayout.php in Mundi Mail 0.8.2, when regi
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Help Workshop 4.03.0002 - '.cnt' Local Buffer Overflow
CVE-2007-0352localwindows
Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitr
35RIESGO
abrir
ReferênciaVexDay Proof
Apple Mac OSX 10.4.8 - SLP Daemon Service Registration Buffer Overflow (PoC)
CVE-2007-0355dososx
Buffer overflow in the Apple Minimal SLP v2 Service Agent (slpd) in Mac OS X 10.4.11 and earlier, including 10.4.8, allo
23RIESGO
abrir
ReferênciaVexDay Proof
CCRP Folder Treeview Control (ccrpftv6.ocx) - IE Denial of Service
CVE-2007-0356doswindows
The Common Controls Replacement Project (CCRP) FolderTreeview (FTV) ActiveX control (ccrpftv6.ocx) allows remote attacke
28RIESGO
abrir
ReferênciaVexDay Proof
OCS Inventory NG 1.02 - Remote File Disclosure
CVE-2009-2166webappsphp
Absolute path traversal vulnerability in cvs.php in OCS Inventory NG before 1.02.1 on Unix allows remote attackers to re
23RIESGO
abrir
ReferênciaVexDay Proof
vBulletin Radio and TV Player AddOn - HTML Injection
CVE-2009-2172webappsphp
Cross-site scripting (XSS) vulnerability in forum/radioandtv.php in the Radio and TV Player addon for vBulletin allows r
23RIESGO
abrir
ReferênciaVexDay Proof
phpDatingClub 3.7 - SQL Injection / Cross-Site Scripting Injection
CVE-2009-2179webappsphp
SQL injection vulnerability in search.php in phpDatingClub 3.7 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
pc4 Uploader 10.0 - Remote File Disclosure
CVE-2009-2180webappsphp
Multiple directory traversal vulnerabilities in upfiles/index.php in Pc4 Uploader 10.0 and earlier allow remote attacker
23RIESGO
abrir
ReferênciaVexDay Proof
Campsite 3.3.0 RC1 - Multiple Remote File Inclusions
CVE-2009-2183webappsphp
Directory traversal vulnerability in admin-files/ad.php in Campsite 3.3.0 RC1 allows remote attackers to read and possib
23RIESGO
abrir
ReferênciaVexDay Proof
RS-CMS 2.1 - 'key' SQL Injection
CVE-2009-2209webappsphp
SQL injection vulnerability in rscms_mod_newsview.php in RS-CMS 2.1 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
ReferênciaVexDay Proof
VisoHotlink 1.01 - 'functions.visohotlink.php' Remote File Inclusion
CVE-2007-0489webappsphp
PHP remote file inclusion vulnerability in includes/functions.visohotlink.php in VisoHotlink 1.01 and possibly earlier a
23RIESGO
abrir
ReferênciaVexDay Proof
PHPSherpa - '/include/config.inc.php' Remote File Inclusion
CVE-2007-0495webappsphp
PHP remote file inclusion vulnerability in include/config.inc.php in PhpSherpa allows remote attackers to execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
webSPELL 4.01.02 - 'gallery.php' Blind SQL Injection
CVE-2007-0502webappsphp
SQL injection vulnerability in gallery.php in webSPELL 4.01.02 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
phpXD 0.3 - 'path' Remote File Inclusion
CVE-2007-0511webappsphp
Multiple PHP remote file inclusion vulnerabilities in phpXMLDOM (phpXD) 0.3 and earlier allow remote attackers to execut
23RIESGO
abrir
ReferênciaVexDay Proof
Sami HTTP Server 2.0.1 - HTTP 404 Object not found Denial of Service
CVE-2007-0548doswindows
KarjaSoft Sami HTTP Server 2.0.1 allows remote attackers to cause a denial of service (daemon hang) via a large number o
23RIESGO
abrir
ReferênciaVexDay Proof
RPW 1.0.2 - 'config.php?sql_language' Remote File Inclusion
CVE-2007-0559webappsphp
PHP remote file inclusion vulnerability in config.php in RPW 1.0.2 allows remote attackers to execute arbitrary PHP code
23RIESGO
abrir
ReferênciaVexDay Proof
nsGalPHP - '/includes/config.inc.php?racineTBS' Remote File Inclusion
CVE-2007-0573webappsphp
PHP remote file inclusion vulnerability in includes/config.inc.php in nsGalPHP 0.41 and earlier allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
Foro Domus 2.10 - 'phpbb_root_path' Remote File Inclusion
CVE-2007-0580webappsphp
PHP remote file inclusion vulnerability in menu.php in Foro Domus 2.10 allows remote attackers to execute arbitrary PHP
23RIESGO
abrir
ReferênciaVexDay Proof
EclipseBB 0.5.0 Lite - 'phpbb_root_path' Remote File Inclusion
CVE-2007-0581webappsphp
PHP remote file inclusion vulnerability in functions.php in EclipseBB 0.5.0 Lite allows remote attackers to execute arbi
23RIESGO
abrir
ReferênciaVexDay Proof
forum livre 1.0 - SQL Injection / Cross-Site Scripting
CVE-2007-0589webappsasp
SQL injection vulnerability in Forum Livre 1.0 allows remote attackers to execute arbitrary SQL commands via the user pa
23RIESGO
abrir
ReferênciaVexDay Proof
forum livre 1.0 - SQL Injection / Cross-Site Scripting
CVE-2007-0590webappsasp
Cross-site scripting (XSS) vulnerability in busca2.asp in Forum Livre 1.0 remote attackers to inject arbitrary web scrip
23RIESGO
abrir
ReferênciaVexDay Proof
LushiNews 1.01 - 'comments.php' SQL Injection
CVE-2007-0865webappsphp
SQL injection vulnerability in comments.php in LushiNews 1.01 and earlier allows remote authenticated users to inject ar
23RIESGO
abrir
ReferênciaVexDay Proof
Connectix Boards 0.7 - 'p_skin' Multiple Vulnerabilities
CVE-2007-1254webappsphp
SQL injection vulnerability in part.userprofile.php in Connectix Boards 0.7 and earlier allows remote authenticated user
23RIESGO
abrir
ReferênciaVexDay Proof
PHP 4.4.6 - 'crack_opendict()' Local Buffer Overflow
CVE-2007-1401localwindows
Buffer overflow in the crack extension (CrackLib), as bundled with PHP 4.4.6 and other versions before 5.0.0, might allo
23RIESGO
abrir
ReferênciaVexDay Proof
Macromedia 10.1.4.20 - 'SwDir.dll' Internet Explorer Stack Overflow Denial of Service
CVE-2007-1403doswindows
Multiple stack-based buffer overflows in an ActiveX control in SwDir.dll 10.1.4.20 in Macromedia Shockwave allow remote
28RIESGO
abrir
ReferênciaVexDay Proof
ProSysInfo TFTP Server TFTPDWIN 0.4.2 - 'UDP' Denial of Service
CVE-2007-1404doswindows
tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 allows remote attackers to cause a denial of service via a long UDP p
35RIESGO
abrir
ReferênciaVexDay Proof
PHP 4.4.6 - 'cpdf_open()' Local Source Code Disclosure
CVE-2007-1412localmultiple
The cpdf_open function in the ClibPDF (cpdf) extension in PHP 4.4.6 allows context-dependent attackers to obtain sensiti
23RIESGO
abrir
ReferênciaVexDay Proof
PHP 4.4.6 - 'snmpget()' Object id Local Buffer Overflow
CVE-2007-1413localwindows
Buffer overflow in the snmpget function in the snmp extension in PHP 5.2.3 and earlier, including PHP 4.4.6 and probably
28RIESGO
abrir
ReferênciaVexDay Proof
PHP 5.2.3 - 'snmpget()' Object id Local Buffer Overflow
CVE-2007-1413localwindows
Buffer overflow in the snmpget function in the snmp extension in PHP 5.2.3 and earlier, including PHP 4.4.6 and probably
28RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.