Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.759exploits catalogados
38.127CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
FreeForum 0.9.7 - 'forum.php' Remote File Inclusion
CVE-2006-5230—webappsphp
PHP remote file inclusion vulnerability in forum.php in FreeForum 0.9.7 and earlier allows remote attackers to execute a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Avax Vector 'Avaxswf.dll' 1.0.0.1 - ActiveX Arbitrary Data Write
CVE-2007-3459—remotewindows
A certain ActiveX control in Avaxswf.dll 1.0.0.1 in Civitech Avax Vector 1.3 allows remote attackers to create or overwr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
EnjoySAP ActiveX kweditcontrol.kwedit.1 - Remote Stack Overflow (PoC)
CVE-2007-3608—doswindows
Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to create certai
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component prayercenter 1.4.9 - 'id' SQL Injection
CVE-2008-6429—webappsphp
SQL injection vulnerability in the PrayerCenter (com_prayercenter) component 1.4.9 and earlier for Joomla! allows remote
23RIESGO
abrir ↗
Referência✓ VexDay Proof
FlexCell Grid Control 5.6.9 - Remote File Overwrite
CVE-2009-0301—remotewindows
Multiple insecure method vulnerabilities in the FlexCell.Grid ActiveX control (FlexCell.ocx) in FlexCell Grid Control 5.
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Squid < 3.1 5 - HTTP Version Number Parsing Denial of Service
CVE-2009-0478—dosmultiple
Squid 2.7 to 2.7.STABLE5, 3.0 to 3.0.STABLE12, and 3.1 to 3.1.0.4 allows remote attackers to cause a denial of service v
45RIESGO
abrir ↗
Referência✓ VexDay Proof
Gallery MX 2.0.0 - Blind SQL Injection
CVE-2008-6379—webappsasp
SQL injection vulnerability in pics_pre.asp in Gallery MX 2.0.0 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Discuz! - Remote Reset User Password
CVE-2008-6957—webappsphp
member.php in Crossday Discuz! Board allows remote attackers to reset passwords of arbitrary users via crafted (1) lostp
23RIESGO
abrir ↗
Referência✓ VexDay Proof
DFLabs PTK 1.0 - Local Command Execution
CVE-2008-6793—webappsphp
The get_file_type function in lib/file_content.php in DFLabs PTK 0.1, 0.2, and 1.0 allows remote attackers to execute ar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CuteNews aj-fork 167f - 'cutepath' Remote File Inclusion
CVE-2006-6546—webappsphp
PHP remote file inclusion vulnerability in inc/shows.inc.php in cutenews aj-fork (CN:AJ) 167f and earlier allows remote
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP-Nuke Module htmltonuke 2.0alpha - 'htmltonuke.php' Remote File Inclusion
CVE-2006-0308—webappsphp
PHP remote file inclusion vulnerability in htmltonuke.php in the htmltonuke 2.0 alpha, and possibly other versions, modu
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Sun xVM VirtualBox < 1.6.4 - Privilege Escalation (PoC)
CVE-2008-3431HIGHbajo ataquedosmultiple
The VBoxDrvNtDeviceControl function in VBoxDrv.sys in Sun xVM VirtualBox before 1.6.4 uses the METHOD_NEITHER communicat
71RIESGO
abrir ↗
Referência✓ VexDay Proof
QuoteBook - Remote Configuration File Disclosure
CVE-2009-0828—webappsphp
QuoteBook stores quotes.inc under the web root with insufficient access control, which allows remote attackers to obtain
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Ocean12 FAQ Manager Pro - 'ID' Blind SQL Injection
CVE-2008-6372—webappsphp
SQL injection vulnerability in default.asp in Ocean12 FAQ Manager Pro 1.0 allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Bloginator 1a - Cookie Bypass / SQL Injection
CVE-2009-1050—webappsphp
Bloginator 1A allows remote attackers to bypass authentication and gain administrative access by setting the identifyYou
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Flatnux - html/JavaScript Injection Cookie Grabber
CVE-2008-5761—webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in FlatnuX CMS (aka Flatnuke3) 2008-12-11 allow remote attackers to
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PortailPHP mod_phpalbum 2.1.5 - 'chemin' Remote File Inclusion
CVE-2006-4498—webappsphp
PHP remote file inclusion vulnerability in sommaire_admin.php in PhpAlbum (mod_phpalbum) 2.15 for PortailPHP allows remo
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MojoPersonals - Blind SQL Injection
CVE-2008-3403—webappscgi
SQL injection vulnerability in mojoClassified.cgi in MojoPersonals allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗
Referência✓ VexDay Proof
sBLOG 0.7.3 Beta - '/inc/lang.php' Local File Inclusion
CVE-2007-1801—webappsphp
Directory traversal vulnerability in inc/lang.php in sBLOG 0.7.3 Beta allows remote attackers to include and execute arb
23RIESGO
abrir ↗
Referência✓ VexDay Proof
XOOPS Module Jobs 2.4 - 'cid' SQL Injection
CVE-2007-2370—webappsphp
SQL injection vulnerability in index.php in the John Mordo Jobs 2.4 and earlier module for XOOPS allows remote attackers
23RIESGO
abrir ↗
Referência✓ VexDay Proof
EnjoySAP ActiveX rfcguisink.rfcguisink.1 - Remote Heap Overflow (PoC)
CVE-2007-3608—doswindows
Multiple unspecified vulnerabilities in ActiveX controls in the EnjoySAP SAP GUI allow remote attackers to create certai
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Chilkat Zip ActiveX Component 12.4 - Multiple Insecure Methods
CVE-2007-3633—remotewindows
Absolute path traversal vulnerability in the Chilkat Software Chilkat Zip ActiveX control in ChilkatZip2.dll 12.4.2.0 al
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Litespeed Web Server 3.2.3 - Source Code Disclosure
CVE-2007-5654—remotemultiple
LiteSpeed Web Server before 3.2.4 allows remote attackers to trigger use of an arbitrary MIME type for a file via a "%00
35RIESGO
abrir ↗
Referência✓ VexDay Proof
asiCMS alpha 0.208 - Multiple Remote File Inclusions
CVE-2008-4529—webappsphp
Multiple PHP remote file inclusion vulnerabilities in asiCMS alpha 0.208 allow remote attackers to execute arbitrary PHP
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Wireshark < 0.99.5 - DNP3 Dissector Infinite Loop
CVE-2007-6113—doslinux
Integer signedness error in the DNP3 dissector in Wireshark (formerly Ethereal) 0.10.12 to 0.99.6 allows remote attacker
23RIESGO
abrir ↗
Referência✓ VexDay Proof
aflog 1.01 - Multiple Insecure Cookie Handling Vulnerabilities
CVE-2008-4784—webappsphp
aflog 1.01 allows remote attackers to bypass authentication and gain administrative access by setting the aflog_auth_a c
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Virtual DJ 5.0 - '.m3u' Local Buffer Overflow
CVE-2007-4735—localwindows
Buffer overflow in Next Generation Software Virtual DJ (VDJ) 5.0 allows user-assisted remote attackers to execute arbitr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SunOS Release 5.11 snv_101b - Remote IPv6 Crash
CVE-2009-0304—dossolaris
The kernel in Sun Solaris 10 and 11 snv_101b, and OpenSolaris before snv_108, allows remote attackers to cause a denial
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Freenews 1.1 - 'moteur.php' Remote File Inclusion
CVE-2006-5226—webappsphp
PHP remote file inclusion vulnerability in moteur/moteur.php in Prologin.fr Freenews 1.1 and earlier allows remote attac
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Dimension of phpBB 0.2.6 - 'phpbb_root_path' Remote File Inclusions
CVE-2006-5222—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Dimension of phpBB 0.2.6 and earlier allow remote attackers to exe
23RIESGO
abrir ↗
← anteriorpágina 700 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.