Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.759exploits catalogados
38.127CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
XOOPS module Articles 1.02 - 'print.php?id' SQL Injection
CVE-2007-3311—webappsphp
SQL injection vulnerability in print.php in the Articles 1.02 and earlier module for Xoops allows remote attackers to ex
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mambo Component bigAPE-Backup 1.1 - Remote File Inclusion
CVE-2006-4296—webappsphp
PHP remote file inclusion vulnerability in classes/Tar.php in bigAPE-Backup component (com_babackup) for Mambo 1.1 allow
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ZEELYRICS 2.0 - 'bannerclick.php' SQL Injection
CVE-2008-4717—webappsphp
SQL injection vulnerability in bannerclick.php in ZEELYRICS 2.0 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗
Referência✓ VexDay Proof
BluSky CMS - 'news_id' SQL Injection
CVE-2009-1548—webappsphp
SQL injection vulnerability in index.php in BluSky CMS allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir ↗
Referência✓ VexDay Proof
phpFullAnnu (PFA) 6.0 - SQL Injection
CVE-2007-5068—webappsphp
SQL injection vulnerability in index.php in phpFullAnnu (PFA) 6.0 allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir ↗
Referência✓ VexDay Proof
JobSite Professional 2.0 - 'file.php' SQL Injection
CVE-2007-5785—webappsphp
SQL injection vulnerability in file.php in JobSite Professional 2.0 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Content Injector 1.53 - 'index.php' SQL Injection
CVE-2007-6394—webappsphp
SQL injection vulnerability in index.php in Content Injector 1.53 allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir ↗
Referência✓ VexDay Proof
blogme 3.0 - Cross-Site Scripting / Authentication Bypass
CVE-2006-5975—webappsasp
Multiple cross-site scripting (XSS) vulnerabilities in comments.asp in BlogMe 3.0 allow remote attackers to inject arbit
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Photoshop CS2/CS3 / Paint Shop Pro 11.20 - '.png' Local Buffer Overflow
CVE-2007-2366—localwindows
Buffer overflow in Corel Paint Shop Pro 11.20 allows user-assisted remote attackers to execute arbitrary code via a craf
35RIESGO
abrir ↗
Referência✓ VexDay Proof
phpPrintAnalyzer 1.2 - Remote File Inclusion
CVE-2006-4164—webappsphp
PHP remote file inclusion vulnerability in inc/header.inc.php in phpPrintAnalyzer 1.2 and earlier allows remote attacker
23RIESGO
abrir ↗
Referência✓ VexDay Proof
DigiLeave 1.2 - 'book_id' Blind SQL Injection
CVE-2008-3309—webappsasp
SQL injection vulnerability in info_book.asp in DigiLeave 1.2 and earlier allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Spaminator 1.7 - 'page' Remote File Inclusion
CVE-2006-4158—webappsphp
PHP remote file inclusion vulnerability in Login.php in Spaminator 1.7 and earlier allows remote attackers to execute ar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Powies pForum 1.29a - 'editpoll.php' SQL Injection
CVE-2006-6038—webappsphp
SQL injection vulnerability in editpoll.php in Powie's PHP Forum (pForum) 1.29a and earlier allows remote attackers to e
23RIESGO
abrir ↗
Referência✓ VexDay Proof
FLDS 1.2a - 'lpro.php' SQL Injection
CVE-2008-5779—webappsphp
SQL injection vulnerability in lpro.php in Free Links Directory Script (FLDS) 1.2a allows remote attackers to execute ar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Foxit Reader 9.7.1 - Remote Command Execution (Javascript API)
CVE-2020-14425—localwindows
Foxit Reader before 10.0 allows Remote Command Execution via the app.opencPDFWebPage JavsScript API. An attacker can exe
35RIESGO
abrir ↗
Referência✓ VexDay Proof
Md-Pro 1.0.8x - Topics topicid SQL Injection
CVE-2007-3938—webappsphp
SQL injection vulnerability in index.php in MAXdev MDPro (MD-Pro) 1.0.8x and earlier before 20070720 allows remote attac
23RIESGO
abrir ↗
Referência✓ VexDay Proof
phNNTP 1.3 - 'article-raw.php' Remote File Inclusion
CVE-2006-4103—webappsphp
PHP remote file inclusion vulnerability in article-raw.php in Jason Alexander phNNTP 1.3 and earlier allows remote attac
23RIESGO
abrir ↗
Referência✓ VexDay Proof
NMDeluxe 1.0.1 - 'footer.php?template' Local File Inclusion
CVE-2007-2303—webappsphp
Directory traversal vulnerability in includes/footer.php in News Manager Deluxe (NMDeluxe) 1.0.1 allows remote attackers
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Michelles L2J Dropcalc 4 - SQL Injection
CVE-2007-0687—webappsphp
SQL injection vulnerability in i-search.php in Michelle's L2J Dropcalc 4 and earlier allows remote authenticated users t
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PhotoFiltre Studio 8.1.1 - '.tif' Local Buffer Overflow
CVE-2007-2192—localwindows
Buffer overflow in Photofiltre Studio 8.1.1 allows user-assisted remote attackers to execute arbitrary code via a crafte
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHPSherpa - '/include/config.inc.php' Remote File Inclusion
CVE-2007-0495—webappsphp
PHP remote file inclusion vulnerability in include/config.inc.php in PhpSherpa allows remote attackers to execute arbitr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
NEWSolved Lite 1.9.2 - 'abs_path' Remote File Inclusion
CVE-2006-4059—webappsphp
Multiple PHP remote file inclusion vulnerabilities in USOLVED NEWSolved Lite 1.9.2, and possibly earlier, allow remote a
28RIESGO
abrir ↗
Referência✓ VexDay Proof
CoolPlayer 2.17 - '.m3u' Local Stack Overflow
CVE-2006-6288—localwindows
Multiple buffer overflows in Niek Albers CoolPlayer 216 and earlier allow remote attackers to execute arbitrary code via
23RIESGO
abrir ↗
Referência✓ VexDay Proof
F-Prot AntiVirus 4.6.6 - CHM Heap Overflow (PoC)
CVE-2006-6293—doslinux
Heap-based buffer overflow in FRISK Software F-Prot Antivirus before 4.6.7 allows user-assisted remote attackers to exec
28RIESGO
abrir ↗
Referência✓ VexDay Proof
TSEP 0.942 - 'colorswitch.php' Remote File Inclusion
CVE-2006-4055—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Olaf Noehring The Search Engine Project (TSEP) 0.942 and earlier a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP Simple Shop 2.0 - 'abs_path' Remote File Inclusion
CVE-2006-4052—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools PHP Simple Shop 2.0 and earlier allow remote att
28RIESGO
abrir ↗
Referência✓ VexDay Proof
Crafty Syntax Image Gallery 3.1g - Remote Code Execution
CVE-2006-1667—webappsphp
SQL injection vulnerability in slides.php in Eric Gerdes Crafty Syntax Image Gallery (CSIG) (aka PHP thumbnail Photo Gal
23RIESGO
abrir ↗
Referência✓ VexDay Proof
AskPert - Authentication Bypass
CVE-2008-6309—webappsphp
SQL injection vulnerability in index.php in W3matter AskPert allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Orca 2.0/2.0.2 - 'params.php?gConf[dir][layouts]' Remote File Inclusion
CVE-2008-5167—webappsphp
PHP remote file inclusion vulnerability in layout/default/params.php in Boonex Orca 2.0 and 2.0.2, when register_globals
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mambo Component mambatStaff 3.1b - Remote File Inclusion
CVE-2006-3947—webappsphp
PHP remote file inclusion vulnerability in components/com_mambatstaff/mambatstaff.php in the Mambatstaff 3.1b and earlie
23RIESGO
abrir ↗
← anteriorpágina 705 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.