Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.759exploits catalogados
38.127CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
Stash 1.0.3 - SQL Injection User Credentials Disclosure
CVE-2008-4590—webappsphp
Multiple SQL injection vulnerabilities in Stash 1.0.3 allow remote attackers to execute arbitrary SQL commands via (1) t
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Eserv 3.x - FTP Server (ABOR) Remote Stack Overflow (PoC)
CVE-2008-4588—doswindows
Stack-based buffer overflow in the FTP server in Etype Eserv 3.x, possibly 3.26, allows remote attackers to cause a deni
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Macrovision FlexNet DownloadManager - Insecure Methods
CVE-2008-4587—remotewindows
Insecure method vulnerability in the MSVNClientDownloadManager61Lib.DownloadManager.1 ActiveX control (ISDM.exe 6.1.100.
28RIESGO
abrir ↗
Referência✓ VexDay Proof
Zune Software - ActiveX Arbitrary File Overwrite
CVE-2008-1933—remotewindows
Absolute path traversal vulnerability in a certain ActiveX control in Zune allows user-assisted remote attackers to over
28RIESGO
abrir ↗
Referência✓ VexDay Proof
Mambo Component garyscookbook 1.1.1 - SQL Injection
CVE-2008-1137—webappsphp
SQL injection vulnerability in the Garys Cookbook (com_garyscookbook) 1.1.1 and earlier component for Mambo and Joomla!
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Solaris 9 (UltraSPARC) - 'sadmind' Remote Code Execution
CVE-2008-4556—remotesolaris
Stack-based buffer overflow in the adm_build_path function in sadmind in Sun Solstice AdminSuite on Solaris 8 and 9 allo
50RIESGO
abrir ↗
Referência✓ VexDay Proof
pPIM 1.01 - 'notes.php' Local File Inclusion
CVE-2008-4528—webappsphp
Directory traversal vulnerability in notes.php in Phlatline's Personal Information Manager (pPIM) 1.01 allows remote att
23RIESGO
abrir ↗
Referência✓ VexDay Proof
IP Reg 0.4 - Blind SQL Injection
CVE-2008-4523—webappsphp
SQL injection vulnerability in login.php in IP Reg 0.4 and earlier allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Microsoft Works 7 - 'WkImgSrv.dll' ActiveX Denial of Service (PoC)
CVE-2008-1898—doswindows
A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and
50RIESGO
abrir ↗
Referência✓ VexDay Proof
Yourownbux 4.0 - 'cookie' SQL Injection
CVE-2008-4492—webappsphp
SQL injection vulnerability in referrals.php in YourOwnBux 4.0 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗
Referência✓ VexDay Proof
pNews 2.08 - 'shownews' SQL Injection
CVE-2008-2673—webappsphp
SQL injection vulnerability in index.php in Powie pNews 2.08 and 2.10, when magic_quotes_gpc is disabled, allows remote
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Yerba SACphp 6.3 - Local File Inclusion
CVE-2008-4486—webappsphp
Directory traversal vulnerability in index.php in SAC.php (SACphp), as used in Yerba 6.3 and earlier, allows remote atta
23RIESGO
abrir ↗
Referência✓ VexDay Proof
XOOPS Module Tutoriais - 'viewcat.php' SQL Injection
CVE-2007-1816—webappsphp
SQL injection vulnerability in viewcat.php in the Tutoriais module for Xoops allows remote attackers to execute arbitrar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component Car Manager 1.1 - SQL Injection
CVE-2007-1704—webappsphp
SQL injection vulnerability in index.php in the Car Manager (com_resman) 1.1 and earlier component for Joomla! allows re
23RIESGO
abrir ↗
Referência✓ VexDay Proof
eNdonesia 8.4 (Calendar Module) - SQL Injection
CVE-2008-3452—webappsphp
SQL injection vulnerability in the Calendar module in eNdonesia 8.4 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗
Referência✓ VexDay Proof
FlashGet 1.9 - 'FTP PWD Response' Remote Buffer Overflow (PoC)
CVE-2008-4321—doswindows
Buffer overflow in FlashGet (formerly JetCar) FTP 1.9 allows remote FTP servers to execute arbitrary code via a long res
23RIESGO
abrir ↗
Referência✓ VexDay Proof
NewsLetter MX 1.0.2 - 'ID' SQL Injection
CVE-2006-6787—webappsasp
SQL injection vulnerability in admin/admin_mail_adressee.asp in Newsletter MX 1.0.2 and earlier allows remote attackers
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ASPNuke 0.80 - 'register.asp' SQL Injection
CVE-2006-6070—webappsasp
SQL injection vulnerability in module/account/register/register.asp in ASP Nuke 0.80 and earlier allows remote attackers
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Webdrivers Simple Forum - 'message_details.php' SQL Injection
CVE-2006-5802—webappsphp
SQL injection vulnerability in message_details.php in The Web Drivers Simple Forum, dated 20060318, allows remote attack
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Comdev Web Blogger 4.1.3 - 'arcmonth' SQL Injection
CVE-2008-6250—webappsphp
SQL injection vulnerability in Comdev Web Blogger 4.1.3 and earlier allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗
Referência✓ VexDay Proof
F-PROT AntiVirus 6.2.1.4252 - Malformed Archive Infinite Loop Denial of Service
CVE-2008-3447—dosmultiple
The scanning engine in F-Prot Antivirus 6.2.1 4252 allows remote attackers to cause a denial of service (infinite loop)
23RIESGO
abrir ↗
Referência✓ VexDay Proof
phpMyRealty 2.0.0 - 'location' SQL Injection
CVE-2008-3445—webappsphp
SQL injection vulnerability in index.php in phpMyRealty (PMR) 2.0.0 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Arctic Issue Tracker 2.0.0 - 'filter' SQL Injection (2)
CVE-2008-3250—webappsphp
SQL injection vulnerability in index.php in Arctic Issue Tracker 2.0.0 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WebCMS Portal Edition - 'id' SQL Injection
CVE-2008-3213—webappsphp
SQL injection vulnerability in secciones/tablon/tablon.php in WebCMS Portal Edition allows remote attackers to execute a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Pluck CMS 4.5.1 (Windows) - 'blogpost' Local File Inclusion
CVE-2008-3194—webappsphp
Multiple directory traversal vulnerabilities in data/inc/themes/predefined_variables.php in pluck 4.5.1 allow remote att
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Article Friendly Pro/Standard - SQL Injection
CVE-2008-3670—webappsphp
SQL injection vulnerability in authordetail.php in Article Friendly Pro allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Referência✓ VexDay Proof
TutorialCMS 1.02 - 'Username' SQL Injection
CVE-2008-0254—webappsphp
SQL injection vulnerability in activate.php in TutorialCMS (aka Photoshop Tutorials) 1.02, when magic_quotes_gpc is disa
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WinRAR 3.60 Beta 6 (French) - SFX Path Local Stack Overflow
CVE-2006-3912—localwindows
Stack-based buffer overflow in the SFX module in WinRAR before 3.60 beta 8 has unspecified vectors and impact.
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Def-Blog 1.0.3 - 'comadd.php' SQL Injection
CVE-2006-5383—webappsphp
SQL injection vulnerability in comadd.php in Def-Blog 1.0.1 and earlier allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ezcms 1.2 - Blind SQL Injection / Authentication Bypass
CVE-2008-2921—webappsphp
SQL injection vulnerability in index.php in EZTechhelp EZCMS 1.2 and earlier allows remote attackers to execute arbitrar
23RIESGO
abrir ↗
← anteriorpágina 701 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.