Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
ReVou Twitter Clone - Arbitrary File Upload
CVE-2008-6751webappsphp
Unrestricted file upload vulnerability in index.php in the Twitter Clone (TClone) plugin for ReVou Micro Blogging allows
23RIESGO
abrir
ReferênciaVexDay Proof
PhpHostBot 1.06 - 'svr_rootscript' Remote File Inclusion
CVE-2007-4231webappsphp
PHP remote file inclusion vulnerability in order/login.php in IDevSpot PhpHostBot 1.06 and earlier allows remote attacke
23RIESGO
abrir
ReferênciaVexDay Proof
e107 module 123 flash chat 6.8.0 - Remote File Inclusion
CVE-2008-1989webappsphp
PHP remote file inclusion vulnerability in 123flashchat.php in the 123 Flash Chat 6.8.0 module for e107, when register_g
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component Jotloader 1.2.1.a - Blind SQL Injection
CVE-2008-2564webappsphp
SQL injection vulnerability in the JotLoader (com_jotloader) component 1.2.1.a and earlier for Joomla! allows remote att
23RIESGO
abrir
ReferênciaVexDay Proof
PHPMyDesk 1.0 Beta - 'viewticket.php' Local File Inclusion
CVE-2006-7132webappsphp
Directory traversal vulnerability in pmd-config.php in PHPMyDesk 1.0beta allows remote attackers to include arbitrary lo
23RIESGO
abrir
ReferênciaVexDay Proof
TFT Gallery 0.10 - Password Disclosure
CVE-2006-1412webappsphp
TFT Gallery 0.10 stores sensitive information under the web root with insufficient access control, which allows remote a
23RIESGO
abrir
ReferênciaVexDay Proof
Social Engine 2.0 - Multiple Local File Inclusions
CVE-2007-6581webappsphp
Multiple directory traversal vulnerabilities in Social Engine 2.0 allow remote attackers to include and execute arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
SezHoo 0.1 - Remote File Inclusion
CVE-2008-4704webappsphp
PHP remote file inclusion vulnerability in SezHooTabsAndActions.php in SezHoo 0.1 allows remote attackers to execute arb
23RIESGO
abrir
ReferênciaVexDay Proof
TemaTres 1.0.3 - Authentication Bypass / SQL Injection / Cross-Site Scripting
CVE-2009-1583webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in TemaTres 1.0.3 and 1.031 allow remote attackers to inject arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
ISPworker 1.21 - 'download.php' Remote File Disclosure
CVE-2007-5813webappsphp
Multiple directory traversal vulnerabilities in download.php in ISPworker 1.21 allow remote attackers to read arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
FlashBlog - 'articulo_id' SQL Injection
CVE-2008-2572webappsphp
SQL injection vulnerability in php/leer_comentarios.php in FlashBlog allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir
ReferênciaVexDay Proof
freeSSHd 1.2.1 - (Authenticated) Remote Overflow (SEH)
CVE-2008-2573remotewindows
Stack-based buffer overflow in SFTP in freeSSHd 1.2.1 allows remote authenticated users to execute arbitrary code via a
23RIESGO
abrir
ReferênciaVexDay Proof
phpCMS 1.2.2 - 'file' Remote File Disclosure
CVE-2008-0513webappsphp
Directory traversal vulnerability in parser/include/class.cache_phpcms.php in phpCMS 1.2.2 allows remote attackers to re
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component acctexp 0.12.x - Blind SQL Injection
CVE-2008-2632webappsphp
SQL injection vulnerability in the acctexp (com_acctexp) component 0.12.x and earlier for Joomla! allows remote attacker
23RIESGO
abrir
ReferênciaVexDay Proof
XM Easy Personal FTP Server 1.0 - 'Port' Remote Overflow (PoC)
CVE-2006-2226doswindows
Buffer overflow in XM Easy Personal FTP Server 4.2 and 5.0.1 allows remote authenticated users to cause a denial of serv
23RIESGO
abrir
ReferênciaVexDay Proof
Pre News Manager 1.0 - 'id' SQL Injection
CVE-2006-2763webappsphp
SQL injection vulnerability in Pre News Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the (1
23RIESGO
abrir
ReferênciaVexDay Proof
SAPID 1.2.3.05 - 'ROOT_PATH' Remote File Inclusion
CVE-2006-4026webappsphp
PHP remote file inclusion vulnerability in SAPID CMS 123 rc3 allows remote attackers to execute arbitrary PHP code via a
23RIESGO
abrir
ReferênciaVexDay Proof
PHP-revista 1.1.2 - Remote File Inclusion / SQL Injection / Authentication Bypass / Cross-Site Scripting
CVE-2006-4607webappsphp
admin/index.php in Longino Jacome php-Revista 1.1.2 allows remote attackers to bypass authentication controls by setting
23RIESGO
abrir
ReferênciaVexDay Proof
mebiblio 0.4.7 - SQL Injection / Arbitrary File Upload / Cross-Site Scripting
CVE-2008-2646webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in meBiblio 0.4.7 allow remote attackers to inject arbitrary web scr
23RIESGO
abrir
ReferênciaVexDay Proof
mebiblio 0.4.7 - SQL Injection / Arbitrary File Upload / Cross-Site Scripting
CVE-2008-2647webappsphp
SQL injection vulnerability in admin/journal_change_mask.inc.php in meBiblio 0.4.7 allows remote attackers to execute ar
23RIESGO
abrir
ReferênciaVexDay Proof
saPHP Lesson 2.0 - 'forumid' SQL Injection
CVE-2005-3363webappsphp
SQL injection vulnerability in Saphp Lesson, possibly saphp Lesson1.1 and saphpLesson2.0, allows remote attackers to exe
23RIESGO
abrir
ReferênciaVexDay Proof
Nuked-klaN 1.7.6 - Remote Code Execution
CVE-2007-2556webappsphp
SQL injection vulnerability in Nuked-klaN 1.7.6 allows remote attackers to execute arbitrary SQL commands via the X-Forw
23RIESGO
abrir
ReferênciaVexDay Proof
Built2Go PHP Movie Review 2B - Remote File Inclusion
CVE-2006-2008webappsphp
PHP remote file inclusion vulnerability in movie_cls.php in Built2Go PHP Movie Review 2B and earlier allows remote attac
23RIESGO
abrir
ReferênciaVexDay Proof
sk.log 0.5.3 - 'skin_url' Remote File Inclusion
CVE-2007-5089webappsphp
PHP remote file inclusion vulnerability in php-inc/log.inc.php in sk.log 0.5.3 and earlier allows remote attackers to ex
23RIESGO
abrir
ReferênciaVexDay Proof
mg.applanix 1.3.1 - 'apx_root_path' Remote File Inclusion
CVE-2006-6341webappsphp
Multiple PHP remote file inclusion vulnerabilities in mg.applanix 1.3.1 and earlier allow remote attackers to execute ar
23RIESGO
abrir
ReferênciaVexDay Proof
Insanely Simple Blog 0.5 - SQL Injection
CVE-2008-2670webappsphp
Multiple SQL injection vulnerabilities in index.php in Insanely Simple Blog 0.5 allow remote attackers to execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component iJoomla! News Portal 1.0 - 'itemID' SQL Injection
CVE-2008-2676webappsphp
SQL injection vulnerability in the iJoomla News Portal (com_news_portal) component 1.0 and earlier for Joomla! allows re
23RIESGO
abrir
ReferênciaVexDay Proof
reSIProcate 1.3.2 - Remote Denial of Service (PoC)
CVE-2008-3210dosmultiple
rutil/dns/DnsStub.cxx in ReSIProcate 1.3.2, as used by repro, allows remote attackers to cause a denial of service (daem
23RIESGO
abrir
ReferênciaVexDay Proof
CCMS 3.1 - 'skin' Local File Inclusion
CVE-2008-4526webappsphp
Multiple directory traversal vulnerabilities in CCMS 3.1 allow remote attackers to include and execute arbitrary local f
23RIESGO
abrir
ReferênciaVexDay Proof
Collabtive 0.4.8 - Cross-Site Scripting / Authentication Bypass / Arbitrary File Upload
CVE-2008-6946webappsphp
Cross-site scripting (XSS) vulnerability in manageproject.php in Collabtive 0.4.8 allows user-assisted remote attackers
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.