Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.759exploits catalogados
38.127CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
Thyme Calendar 1.3 - SQL Injection
CVE-2007-2621—webappsphp
SQL injection vulnerability in event_view.php in Thyme Calendar 1.3 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Dew-NewPHPLinks 2.0 - Local File Inclusion / Cross-Site Scripting
CVE-2009-1623—webappsphp
Cross-site scripting (XSS) vulnerability in index.php in Dew-NewPHPLinks 2.0 allows remote attackers to inject arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
News Bin Pro 5.33 - '.nbi' Local Buffer Overflow
CVE-2007-1074—localwindows
Multiple buffer overflows in NewsBin Pro 5.33 and NewsBin Pro 4.x allow user-assisted remote attackers to execute arbitr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
open-medium.CMS 0.25 - '404.php' Remote File Inclusion
CVE-2006-2683—webappsphp
PHP remote file inclusion vulnerability in 404.php in open-medium.CMS 0.25 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Ottoman CMS 1.1.3 - '?default_path=' Remote File Inclusion (1)
CVE-2006-2767—webappsphp
PHP remote file inclusion vulnerability in Ottoman 1.1.2, when register_globals is enabled, allows remote attackers to e
23RIESGO
abrir ↗
Referência✓ VexDay Proof
phpCommunityCalendar 4.0.3 - Cross-Site Scripting / SQL Injection
CVE-2006-2798—webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in phpCommunityCalendar 4.0.3 allow remote attackers to inject arbit
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Venalsur on-line Booking Centre - Cross-Site Scripting / SQL Injection
CVE-2008-6216—webappsphp
SQL injection vulnerability in cadena_ofertas_ext.php in Venalsur Booking Centre Booking System for Hotels Group allows
23RIESGO
abrir ↗
Referência✓ VexDay Proof
TurboFTP Server 5.30 Build 572 - 'newline/LIST' Multiple Remote Denial of Service Vulnerabilities
CVE-2007-1075—doswindows
TurboFTP 5.30 Build 572 allows remote servers to cause a denial of service (CPU consumption) via a response with a large
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Family Connections CMS 1.4 - Multiple SQL Injections
CVE-2008-2901—webappsphp
Multiple SQL injection vulnerabilities in Haudenschilt Family Connections CMS (FCMS) 1.4 allow remote authenticated user
23RIESGO
abrir ↗
Referência✓ VexDay Proof
BigACE 2.4 - Multiple Remote File Inclusions
CVE-2008-2520—webappsphp
Multiple PHP remote file inclusion vulnerabilities in BigACE 2.4, when register_globals is enabled, allow remote attacke
23RIESGO
abrir ↗
Referência✓ VexDay Proof
AJ Auction - Authentication Bypass
CVE-2008-6966—webappsphp
AJ Square AJ Auction Pro Platinum Skin #1 sends a redirect but does not exit when it is called directly, which allows re
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Tuned Studios Templates - Local File Inclusion
CVE-2008-0231—webappsphp
Multiple directory traversal vulnerabilities in index.php in Tuned Studios (1) Subwoofer, (2) Freeze Theme, (3) Orange C
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mini Blog 1.0.1 - 'index.php' Multiple Local File Inclusions
CVE-2008-5594—webappsphp
Multiple directory traversal vulnerabilities in index.php in Mini Blog 1.0.1 allow remote attackers to include and execu
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Ipswitch WS_FTP Home/Professional FTP Client - Remote Format String (PoC)
CVE-2008-3795—doswindows
Buffer overflow in Ipswitch WS_FTP Home client allows remote FTP servers to have an unknown impact via a long "message r
28RIESGO
abrir ↗
Referência✓ VexDay Proof
vp-asp shopping cart 6.09 - SQL Injection / Cross-Site Scripting
CVE-2007-0225—webappsasp
Cross-site scripting (XSS) vulnerability in shopcustadmin.asp in VP-ASP Shopping Cart 6.09 and earlier allows remote att
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Acoustica Mixcraft 4.2 Build 98 - 'mx4' Local Buffer Overflow
CVE-2008-3877—localwindows
Stack-based buffer overflow in Acoustica Mixcraft 4.1 Build 96 and 4.2 Build 98 allows user-assisted attackers to execut
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Pc4Uploader 9.0 - Blind SQL Injection
CVE-2009-1742—webappsphp
code.php in PC4Arb Pc4 Uploader 9.0 and earlier makes it easier for remote attackers to conduct SQL injection attacks vi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHPNS 1.1 - 'shownews.php?id' SQL Injection
CVE-2007-4628—webappsphp
SQL injection vulnerability in shownews.php in phpns 1.1 allows remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Anserv Auction XL - 'cat' SQL Injection
CVE-2008-2189—webappsphp
SQL injection vulnerability in viewfaqs.php in AnServ Auction XL allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗
Referência✓ VexDay Proof
GForge 4.5.19 - Multiple SQL Injections
CVE-2008-6187—webappsphp
SQL injection vulnerability in frs/shownotes.php in Gforge 4.5.19 and earlier allows remote attackers to execute arbitra
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Enthrallweb eClassifieds 1.0 - Remote User Pass Change
CVE-2006-6822—webappsasp
myprofile.asp in Enthrallweb eClassifieds does not properly validate the MM_recordId parameter during profile updates, w
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WebprojectDB 0.1.3 - 'INCDIR' Remote File Inclusion
CVE-2006-2995—webappsphp
Multiple PHP remote file inclusion vulnerabilities in WebprojectDB 0.1.3 and earlier allow remote attackers to execute a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
TurnkeyForms Web Hosting Directory - Multiple Vulnerabilities
CVE-2008-6941—webappsphp
SQL injection vulnerability in the login functionality in TurnkeyForms Web Hosting Directory allows remote attackers to
23RIESGO
abrir ↗
Referência✓ VexDay Proof
aePartner 0.8.3 - 'dir[data]' Remote File Inclusion
CVE-2006-2996—webappsphp
PHP remote file inclusion vulnerability in inc/design.inc.php in LoveCompass aePartner 0.8.3 and earlier allows remote a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Belkin F5D9230-4 Wireless G Plus MIMO Router - Authentication Bypass
CVE-2008-0403—remotehardware
The web server in Belkin Wireless G Plus MIMO Router F5D9230-4 does not require authentication for SaveCfgFile.cgi, whic
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Apple Mac OSX xnu 1228.3.13 - 'zip-notify' Remote Kernel Overflow (PoC)
CVE-2009-1236—dososx
Heap-based buffer overflow in the AppleTalk networking stack in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and e
23RIESGO
abrir ↗
Referência✓ VexDay Proof
BaoFeng2 - 'mps.dll' ActiveX Multiple Remote Buffer Overflows (PoC)
CVE-2007-4816—doswindows
Multiple buffer overflows in the BaoFeng2 storm ActiveX control in Mps.dll allow remote attackers to have an unknown imp
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mambo Component 'com_catalogshop' 1.0b1 - SQL Injection
CVE-2008-0557—webappsphp
SQL injection vulnerability in index.php in the CatalogShop (com_catalogshop) 1.0b1 componenent for Mambo and Joomla! al
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CMME 1.12 - Local File Inclusion / Cross-Site Scripting / Cross-Site Request Forgery/Download Backup/Make Directory
CVE-2008-3924—webappsphp
The "Make a backup" functionality in Content Management Made Easy (CMME) 1.12 stores sensitive information under the web
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Cahier de texte 2.0 - 'lire.php' SQL Injection
CVE-2006-5221—webappsphp
Multiple SQL injection vulnerabilities in Cahier de texte 2.0 allow remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗
← anteriorpágina 704 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.