Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.759exploits catalogados
38.127CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
Comdev Web Blogger 4.1.3 - 'arcmonth' SQL Injection
CVE-2008-6250—webappsphp
SQL injection vulnerability in Comdev Web Blogger 4.1.3 and earlier allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Microsoft Windows - GDI (CreateDIBPatternBrushPt) Heap Overflow (PoC)
CVE-2008-1083HIGHdoswindows
Heap-based buffer overflow in the CreateDIBPatternBrushPt function in GDI in Microsoft Windows 2000 SP4, XP SP2, Server
53RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP 5.2.0 (Windows x86) - 'PHP_win32sti' Local Buffer Overflow
CVE-2007-4441—doswindows_x86
Buffer overflow in php_win32std.dll in the win32std extension for PHP 5.2.0 and earlier allows context-dependent attacke
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Easy Photo Gallery 2.1 - Cross-Site Scripting / File Disclosure/Bypass / SQL Injection
CVE-2008-6988—webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in Easy Photo Gallery (aka Ezphotogallery) 2.1 allow remote attacker
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Webdrivers Simple Forum - 'message_details.php' SQL Injection
CVE-2006-5802—webappsphp
SQL injection vulnerability in message_details.php in The Web Drivers Simple Forum, dated 20060318, allows remote attack
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHPKB 1.5 Professional - Multiple SQL Injections
CVE-2008-5088—webappsphp
Multiple SQL injection vulnerabilities in PHPKB Knowledge Base Software 1.5 Professional allow remote attackers to execu
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Orca 2.0/2.0.2 - 'params.php?gConf[dir][layouts]' Remote File Inclusion
CVE-2008-5167—webappsphp
PHP remote file inclusion vulnerability in layout/default/params.php in Boonex Orca 2.0 and 2.0.2, when register_globals
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Tips Complete Website 1.2.0 - 'tipid' SQL Injection
CVE-2008-5168—webappsphp
SQL injection vulnerability in tip.php in Tips Complete Website 1.2.0 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ASPNuke 0.80 - 'register.asp' SQL Injection
CVE-2006-6070—webappsasp
SQL injection vulnerability in module/account/register/register.asp in ASP Nuke 0.80 and earlier allows remote attackers
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Centreon 1.4.2.3 - 'get_image.php' Remote File Disclosure
CVE-2008-1119—webappsphp
Directory traversal vulnerability in include/doc/get_image.php in Centreon 1.4.2.3 and earlier allows remote attackers t
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Cheats Complete Website 1.1.1 - 'itemID' SQL Injection
CVE-2008-5170—webappsphp
SQL injection vulnerability in item.php in Cheats Complete Website 1.1.1 allows remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗
Referência✓ VexDay Proof
NewsLetter MX 1.0.2 - 'ID' SQL Injection
CVE-2006-6787—webappsasp
SQL injection vulnerability in admin/admin_mail_adressee.asp in Newsletter MX 1.0.2 and earlier allows remote attackers
23RIESGO
abrir ↗
Referência✓ VexDay Proof
paBugs 2.0 Beta 3 - 'main.php?cid' SQL Injection
CVE-2007-4183—webappsphp
SQL injection vulnerability in main.php in paBugs 2.0 Beta 3 and earlier allows remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Pie Cart Pro - 'Home_Path' Remote File Inclusion
CVE-2006-4970—webappsphp
PHP remote file inclusion vulnerability in enc/content.php in WAHM E-Commerce Pie Cart Pro allows remote attackers to ex
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP Blue Dragon CMS 2.9.1 - Cross-Site Scripting / SQL Injection Code Execution
CVE-2006-4961—webappsphp
SQL injection vulnerability in the GetModuleConfig function in public_includes/pub_kernel/pbd_modules.php in Php Blue Dr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Easysitenetwork Jokes Complete Website 2.1.3 - 'jokeid' SQL Injection
CVE-2008-5174—webappsphp
SQL injection vulnerability in joke.php in Jokes Complete Website 2.1.3 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Opera 9.62 - 'file://' Local Heap Overflow
CVE-2008-5178—localwindows
Heap-based buffer overflow in Opera 9.62 on Windows allows remote attackers to execute arbitrary code via a long file://
35RIESGO
abrir ↗
Referência✓ VexDay Proof
eazyPortal 1.0 - 'cookie' SQL Injection
CVE-2008-1121—webappsphp
SQL injection vulnerability in index.php in eazyPortal 1.0 and earlier allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Referência✓ VexDay Proof
bcoos 1.0.13 - 'viewcat.php' SQL Injection
CVE-2008-6381—webappsphp
SQL injection vulnerability in modules/adresses/viewcat.php in bcoos 1.0.13, and possibly earlier, allows remote authent
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Wysi Wiki Wyg 1.0 - Local File Inclusion / Cross-Site Scripting / PHPInfo
CVE-2008-5323—webappsphp
Cross-site scripting (XSS) vulnerability in index.php in Wysi Wiki Wyg 1.0 allows remote attackers to inject arbitrary w
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PNPHPBB2 < 1.2g - 'phpbb_root_path' Remote File Inclusion
CVE-2006-4968—webappsphp
PHP remote file inclusion vulnerability in includes/functions_admin.php in PNphpBB 1.2g allows remote attackers to execu
23RIESGO
abrir ↗
Referência✓ VexDay Proof
FlashGet 1.9 - 'FTP PWD Response' Remote Buffer Overflow (PoC)
CVE-2008-4321—doswindows
Buffer overflow in FlashGet (formerly JetCar) FTP 1.9 allows remote FTP servers to execute arbitrary code via a long res
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component Car Manager 1.1 - SQL Injection
CVE-2007-1704—webappsphp
SQL injection vulnerability in index.php in the Car Manager (com_resman) 1.1 and earlier component for Joomla! allows re
23RIESGO
abrir ↗
Referência✓ VexDay Proof
celerbb 0.0.2 - Multiple Vulnerabilities
CVE-2009-0851—webappsphp
Multiple SQL injection vulnerabilities in CelerBB 0.0.2, when magic_quotes_gpc is disabled, allow remote attackers to ex
23RIESGO
abrir ↗
Referência✓ VexDay Proof
XOOPS Module myAlbum-P 2.0 - 'cid' SQL Injection
CVE-2007-1807—webappsphp
SQL injection vulnerability in modules/myalbum/viewcat.php in the myAlbum-P 2.0 and earlier module for Xoops allows remo
23RIESGO
abrir ↗
Referência✓ VexDay Proof
guanxiCRM Business Solution 0.9.1 - Remote File Inclusion
CVE-2006-4898—webappsphp
PHP remote file inclusion vulnerability in include/phpxd/phpXD.php in guanxiCRM 0.9.1 and earlier allows remote attacker
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CMtextS 1.0 - '/users_logins/admin.txt' Credentials Disclosure
CVE-2006-4897—webappsphp
CMtextS 1.0 and earlier stores users_logins/admin.txt under the web document root with insufficient access control, whic
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Dokeos 1.8.0 - 'my_progress.php?course' SQL Injection
CVE-2007-2902—webappsphp
SQL injection vulnerability in main/auth/my_progress.php in Dokeos 1.8.0 and earlier allows remote authenticated users t
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP-Fusion 7.00.1 - 'messages.php' SQL Injection
CVE-2008-5335—webappsphp
SQL injection vulnerability in messages.php in PHP-Fusion 6.01.15 and 7.00.1, when magic_quotes_gpc is disabled, allows
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Artmedic CMS 3.4 - 'index.php' Local File Inclusion
CVE-2007-5600—webappsphp
Incomplete blacklist vulnerability in index.php in Artmedic CMS 3.4 and earlier allows remote attackers to execute arbit
23RIESGO
abrir ↗
← anteriorpágina 713 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.