Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.843exploits catalogados
38.202CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
ScriptMagix Jokes 2.0 - 'index.php?catid' SQL Injection
CVE-2007-1615—webappsphp
SQL injection vulnerability in index.php in ScriptMagix Jokes 2.0 and earlier allows remote attackers to execute arbitra
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mambo Component Security Images 3.0.5 - Remote File Inclusion
CVE-2006-5048—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Security Images (com_securityimages) component 3.0.5 and earlier f
28RIESGO
abrir ↗
Referência✓ VexDay Proof
faceStones personal 2.0.42 - 'fs_form_links.php' File Inclusion
CVE-2006-5070—webappsphp
PHP remote file inclusion vulnerability in fsl2/objects/fs_form_links.php in faceStones Personal 2.0.42 and earlier allo
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CMS MAXSITE Component Guestbook - Remote Command Execution
CVE-2008-6446—webappsphp
Static code injection vulnerability in the Guestbook component in CMS MAXSITE allows remote attackers to inject arbitrar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
EfesTECH Haber 5.0 - 'id' SQL Injection
CVE-2007-2662—webappsphp
SQL injection vulnerability in EfesTECH Haber 5.0 allows remote attackers to execute arbitrary SQL commands via the id p
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Millewin 13.39.146.1 - Local Privilege Escalation
CVE-2021-3394—localwindows
Millennium Millewin (also known as "Cartella clinica") 13.39.028, 13.39.28.3342, and 13.39.146.1 has insecure folder per
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Freelance Auction Script 1.0 - 'browseproject.php' SQL Injection
CVE-2008-2279—webappsphp
Freelance Auction Script 1.0 stores user passwords in plaintext in the tbl_users table, which allows attackers to gain p
23RIESGO
abrir ↗
Referência✓ VexDay Proof
XZero Community Classifieds 4.95.11 - Remote File Inclusion
CVE-2007-6568—webappsphp
PHP remote file inclusion vulnerability in config.inc.php in XZero Community Classifieds 4.95.11 and earlier allows remo
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MonGoose 2.4 (Windows) - WebServer Directory Traversal
CVE-2009-1354—remotewindows
Directory traversal vulnerability in Mongoose 2.4 allows remote attackers to read arbitrary files via a .. (dot dot) in
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Einstein 1.01 - Local Password Disclosure
CVE-2005-0619—localwindows
Einstein 1.0.1 stores sensitive information such as usernames and passwords in plaintext in the registry, which allows l
23RIESGO
abrir ↗
Referência✓ VexDay Proof
phpMyAgenda 3.1 - '/templates/header.php3' Local File Inclusion
CVE-2006-5263—webappsphp
Directory traversal vulnerability in templates/header.php3 in phpMyAgenda 3.1 and earlier allows remote attackers to inc
23RIESGO
abrir ↗
Referência✓ VexDay Proof
xweblog 2.1 - 'kategori.asp' SQL Injection
CVE-2006-5023—webappsasp
SQL injection vulnerability in kategori.asp in xweblog 2.1 and earlier allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Snort 2.6.1 - DCE/RPC Preprocessor Remote Buffer Overflow (Denial of Service) (PoC)
CVE-2006-5276—dosmultiple
Stack-based buffer overflow in the DCE/RPC preprocessor in Snort before 2.6.1.3, and 2.7 before beta 2; and Sourcefire I
60RIESGO
abrir ↗
Referência✓ VexDay Proof
E-Smart Cart 1.0 - 'Product_ID' SQL Injection
CVE-2007-0092—webappsasp
SQL injection vulnerability in productdetail.asp in E-SMARTCART 1.0 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Falt4 CMS rc4 10.9.2007 - Multiple Vulnerabilities
CVE-2007-6310—webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in Falt4Extreme RC4 10.9.2007 allow remote attackers to inject arbit
23RIESGO
abrir ↗
Referência✓ VexDay Proof
n@board 3.1.9e - 'naboard_pnr.php' Remote File Inclusion
CVE-2006-5281—webappsphp
PHP remote file inclusion vulnerability in naboard_pnr.php in n@board 3.1.9e and earlier allows remote attackers to exec
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SH-News 3.1 - 'scriptpath' Remote File Inclusion
CVE-2006-5282—webappsphp
Multiple PHP remote file inclusion vulnerabilities in SH-News 3.1 and earlier allow remote attackers to execute arbitrar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP News Reader 2.6.4 - 'phpBB.inc.php' Remote File Inclusion
CVE-2006-5284—webappsphp
PHP remote file inclusion vulnerability in auth/phpbb.inc.php in Shen Cheng-Da PHP News Reader (aka pnews) 2.6.4 and ear
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Microsoft Office 2003 - '.PPT' Local Buffer Overflow (PoC)
CVE-2006-5296—doswindows
PowerPoint in Microsoft Office 2003 does not properly handle a container object whose position value exceeds the record
28RIESGO
abrir ↗
Referência✓ VexDay Proof
phpBB lat2cyr Mod 1.0.1 - 'lat2cyr.php' Remote File Inclusion
CVE-2006-5305—webappsphp
PHP remote file inclusion vulnerability in lat2cyr.php in the lat2cyr 1.0.1 and earlier phpbb module allows remote attac
23RIESGO
abrir ↗
Referência✓ VexDay Proof
eDocStore - 'doc.php?doc_id' SQL Injection
CVE-2007-3452—webappsphp
SQL injection vulnerability in essentials/minutes/doc.php in eDocStore allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Open Conference Systems 1.1.4 - 'fullpath' File Inclusion
CVE-2006-5308—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Open Conference Systems (OCS) before 1.1.6 allow remote attackers
23RIESGO
abrir ↗
Referência✓ VexDay Proof
phpBB ACP User Registration Mod 1.0 - Remote File Inclusion
CVE-2006-5390—webappsphp
PHP remote file inclusion vulnerability in includes/functions_mod_user.php in the ACP User Registration (MMW) 1.00 modul
23RIESGO
abrir ↗
Referência✓ VexDay Proof
webSPELL 4.01.01 - 'getsquad' SQL Injection
CVE-2006-5388—webappsphp
SQL injection vulnerability in index.php in WebSPELL 4.01.01 and earlier allows remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ASP Product Catalog 1.0 - Cross-Site Scripting / File Disclosure
CVE-2009-1322—webappsphp
ASP Product Catalog 1.0 stores sensitive information under the web root with insufficient access control, which allows r
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Microsoft Windows Media Encoder (XP SP2) - 'wmex.dll' ActiveX Buffer Overflow (MS08-053)
CVE-2008-3008—remotewindows
Stack-based buffer overflow in the WMEncProfileManager ActiveX control in wmex.dll in Microsoft Windows Media Encoder 9
50RIESGO
abrir ↗
Referência✓ VexDay Proof
PHPSpamManager 0.53b - 'body.php' Remote File Disclosure
CVE-2008-1645—webappsphp
Directory traversal vulnerability in body.php in phpSpamManager (phpSM) 0.53 beta allows remote attackers to read arbitr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Open Meetings Filing Application - Remote File Inclusion
CVE-2006-5517—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Rhode Island Open Meetings Filing Application (OMFA) allow remote
28RIESGO
abrir ↗
Referência✓ VexDay Proof
Free Image Hosting 1.0 - 'forgot_pass.php' File Inclusion
CVE-2006-5670—webappsphp
PHP remote file inclusion vulnerability in forgot_pass.php in Free Image Hosting 1.0 and earlier allows remote attackers
23RIESGO
abrir ↗
Referência✓ VexDay Proof
QnECMS 2.5.6 - 'adminfolderpath' Remote File Inclusion
CVE-2006-5627—webappsphp
Multiple PHP remote file inclusion vulnerabilities in QnECMS 2.5.6 and earlier allow remote attackers to execute arbitra
28RIESGO
abrir ↗
← anteriorpágina 715 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.