Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.759exploits catalogados
38.127CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
WebprojectDB 0.1.3 - 'INCDIR' Remote File Inclusion
CVE-2006-2995—webappsphp
Multiple PHP remote file inclusion vulnerabilities in WebprojectDB 0.1.3 and earlier allow remote attackers to execute a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
phpBB Links MOD 1.2.2 - SQL Injection
CVE-2007-4653—webappsphp
SQL injection vulnerability in links.php in the Links MOD 1.2.2 and earlier for phpBB 2.0.22 and earlier allows remote a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Nortel SSL VPN Linux Client 6.0.3 - Local Privilege Escalation
CVE-2007-1057—locallinux
The Net Direct client for Linux before 6.0.5 in Nortel Application Switch 2424, VPN 3050 and 3070, and SSL VPN Module 10
23RIESGO
abrir ↗
Referência✓ VexDay Proof
News Rover 12.1 Rev 1 - Stack Overflow (1)
CVE-2007-1041—localwindows
Multiple stack-based buffer overflows in S&H Computer Systems News Rover 12.1 Rev 1 allow remote attackers to execute ar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Advanced Image Hosting (AIH) 2.1 - SQL Injection
CVE-2008-2536—webappsphp
SQL injection vulnerability in out.php in YABSoft Advanced Image Hosting (AIH) Script 2.1 and earlier allows remote atta
23RIESGO
abrir ↗
Referência✓ VexDay Proof
BP Blog 6.0 - 'id' Blind SQL Injection
CVE-2008-2554—webappsasp
Multiple SQL injection vulnerabilities in BP Blog 6.0 allow remote attackers to execute arbitrary SQL commands via the (
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Snitz Forums 2000 3.1 SR4 - 'pop_profile.asp' SQL Injection
CVE-2007-1023—webappsasp
SQL injection vulnerability in pop_profile.asp in Snitz Forums 2000 3.1 SR4 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
OPENi-CMS Site Protection Plugin - Remote File Inclusion
CVE-2007-0881—webappsphp
PHP remote file inclusion vulnerability in the Seitenschutz plugin for OPENi-CMS 1.0 allows remote attackers to execute
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Somery 0.4.6 - 'skin_dir' Remote File Inclusion
CVE-2007-0704—webappsphp
PHP remote file inclusion vulnerability in install.php in Somery 0.4.6 allows remote attackers to execute arbitrary PHP
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHPNuke-Clan 4.2.0 - 'mvcw_conver.php' Remote File Inclusion
CVE-2007-4606—webappsphp
PHP remote file inclusion vulnerability in convert/mvcw_conver.php in the Virtual War (VWar) module for PHPNuke-Clan (PN
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component SimpleShop 3.4 - SQL Injection
CVE-2008-2568—webappsphp
SQL injection vulnerability in the Simple Shop Galore (com_simpleshop) component 3.4 and earlier for Joomla! allows remo
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Roundcube Webmail 0.2b - Remote Code Execution
CVE-2008-5619—webappsphp
html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail)
35RIESGO
abrir ↗
Referência✓ VexDay Proof
phpMyAdmin 3.1.0 - Cross-Site Request Forgery / SQL Injection
CVE-2008-5621—webappsphp
Cross-site request forgery (CSRF) vulnerability in phpMyAdmin 2.11.x before 2.11.9.4 and 3.x before 3.1.1.0 allows remot
23RIESGO
abrir ↗
Referência✓ VexDay Proof
DL PayCart 1.01 - 'viewitem.php?ItemID' Blind SQL Injection
CVE-2007-4604—webappsphp
SQL injection vulnerability in viewitem.php in DL PayCart 1.01 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗
Referência✓ VexDay Proof
freeSSHd 1.2.1 - (Authenticated) Remote Stack Overflow (PoC)
CVE-2008-2573—doswindows
Stack-based buffer overflow in SFTP in freeSSHd 1.2.1 allows remote authenticated users to execute arbitrary code via a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
freeSSHd 1.2.1 - (Authenticated) Remote Overflow (SEH)
CVE-2008-2573—remotewindows
Stack-based buffer overflow in SFTP in freeSSHd 1.2.1 allows remote authenticated users to execute arbitrary code via a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Epistemon 1.0 - 'common.php?inc_path' Remote File Inclusion
CVE-2007-0701—webappsphp
PHP remote file inclusion vulnerability in inc/common.inc.php in Epistemon 1.0 allows remote attackers to execute arbitr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
TeamCal Pro 2.8.001 - 'app_root' Remote File Inclusion
CVE-2006-4845—webappsphp
PHP remote file inclusion vulnerability in includes/footer.html.inc.php in TeamCal Pro 2.8.001 and earlier allows remote
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Active Photo Gallery 6.2 - Authentication Bypass
CVE-2008-5641—webappsphp
SQL injection vulnerability in account.asp in Active Photo Gallery 6.2 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ASP NEWS 3.0 - 'news_detail.asp' SQL Injection
CVE-2007-0566—webappsasp
SQL injection vulnerability in news_detail.asp in ASP NEWS 3 and earlier allows remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component com_books - 'book_id' SQL Injection
CVE-2008-5643—webappsphp
SQL injection vulnerability in the Books (com_books) component for Joomla! allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
DELTAScripts PHP Shop 1.0 - Authentication Bypass
CVE-2008-5648—webappsphp
SQL injection vulnerability in admin/login.php in DeltaScripts PHP Shop 1.0 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WinFTP Server 2.3.0 - 'PASV Mode' Remote Denial of Service
CVE-2008-5666—doswindows
WinFTP FTP Server 2.3.0, when passive (aka PASV) mode is used, allows remote authenticated users to cause a denial of se
43RIESGO
abrir ↗
Referência✓ VexDay Proof
Xero Portal - 'phpbb_root_path' Remote File Inclusion
CVE-2007-0561—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Xero Portal 1.2 allow remote attackers to execute arbitrary PHP co
28RIESGO
abrir ↗
Referência✓ VexDay Proof
RPW 1.0.2 - 'config.php?sql_language' Remote File Inclusion
CVE-2007-0559—webappsphp
PHP remote file inclusion vulnerability in config.php in RPW 1.0.2 allows remote attackers to execute arbitrary PHP code
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Surgemail 38k - 'Search' Remote Buffer Overflow
CVE-2007-4377—remotewindows
Stack-based buffer overflow in the IMAP service in SurgeMail 38k allows remote authenticated users to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Sami HTTP Server 2.0.1 - HTTP 404 Object not found Denial of Service
CVE-2007-0548—doswindows
KarjaSoft Sami HTTP Server 2.0.1 allows remote attackers to cause a denial of service (daemon hang) via a large number o
23RIESGO
abrir ↗
Referência✓ VexDay Proof
BolinOS 4.5.5 - 'gBRootPath' Remote File Inclusion
CVE-2006-4850—webappsphp
PHP remote file inclusion vulnerability in system/_b/contentFiles/gBIndex.php in BolinOS 4.5.5 and earlier allows remote
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Q-Shop 3.5 - 'browse.asp' SQL Injection
CVE-2006-4852—webappsasp
SQL injection vulnerability in browse.asp in QuadComm Q-Shop 3.5 allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗
Referência✓ VexDay Proof
smeweb 1.4b - SQL Injection / Cross-Site Scripting
CVE-2008-2652—webappsphp
Multiple SQL injection vulnerabilities in catalog.php in SMEWeb 1.4b and 1.4f allow remote attackers to execute arbitrar
23RIESGO
abrir ↗
← anteriorpágina 703 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.