Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.859exploits catalogados
38.203CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
McAfee E-Business Server 8.5.2 - Remote Code Execution / Denial of Service (PoC)
CVE-2008-0127—dosmultiple
The administration interface in McAfee E-Business Server 8.5.2 and earlier allows remote attackers to cause a denial of
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Alcatel OmniPCX Office 210/061.1 - Remote Command Execution
CVE-2008-1331—webappscgi
cgi-data/FastJSData.cgi in OmniPCX Office with Internet Access services OXO210 before 210/091.001, OXO600 before 610/014
23RIESGO
abrir ↗
Referência✓ VexDay Proof
AINS 0.02b - 'ains_main.php?ains_path' Remote File Inclusion
CVE-2007-0570—webappsphp
PHP remote file inclusion vulnerability in ains_main.php in Johannes Gijsbers (aka Taradino) Ad Fundum Integratable News
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mozilla Firefox 3.0.5 - location.hash Remote Crash
CVE-2008-5715—doswindows
Mozilla Firefox 3.0.5 on Windows Vista allows remote attackers to cause a denial of service (application crash) via Java
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Google Chrome - 'ChromeHTML://' Remote Parameter Injection
CVE-2008-5750—remotewindows
Argument injection vulnerability in Microsoft Internet Explorer 8 beta 2 on Windows XP SP3 allows remote attackers to ex
28RIESGO
abrir ↗
Referência✓ VexDay Proof
torrentflux 2.2 - Arbitrary File Create/ Execute/Delete
CVE-2006-6329—webappsphp
index.php for TorrentFlux 2.2 allows remote attackers to delete files by specifying the target filename in the delfile p
23RIESGO
abrir ↗
Referência✓ VexDay Proof
HP Data Protector 4.00-SP1b43064 - Remote Memory Leak/Denial of Service (Metasploit)
CVE-2009-0714—doswindows
Unspecified vulnerability in the dpwinsup module (dpwinsup.dll) for dpwingad (dpwingad.exe) in HP Data Protector Express
35RIESGO
abrir ↗
Referência✓ VexDay Proof
BLOG 1.55B - 'image_upload.php' Arbitrary File Upload
CVE-2008-5732—webappsphp
Unrestricted file upload vulnerability in lib/image_upload.php in KafooeyBlog 1.55b allows remote attackers to execute a
28RIESGO
abrir ↗
Referência✓ VexDay Proof
PGP Desktop 9.0.6 - 'PGPwded.sys' Local Denial of Service
CVE-2008-5731—doswindows
The PGPwded device driver (aka PGPwded.sys) in PGP Corporation PGP Desktop 9.0.6 build 6060 and 9.9.0 build 397 allows l
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Drunken:Golem Portal 0.5.1 Alpha 2 - Remote File Inclusion
CVE-2007-0572—webappsphp
PHP remote file inclusion vulnerability in include/irc/phpIRC.php in Drunken:Golem Gaming Portal 0.5.1 Alpha 2 and earli
23RIESGO
abrir ↗
Referência✓ VexDay Proof
nsGalPHP - '/includes/config.inc.php?racineTBS' Remote File Inclusion
CVE-2007-0573—webappsphp
PHP remote file inclusion vulnerability in includes/config.inc.php in nsGalPHP 0.41 and earlier allows remote attackers
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Hacks List phpBB Mod 1.21 - SQL Injection
CVE-2006-6216—webappsphp
SQL injection vulnerability in admin_hacks_list.php in the Nivisec Hacks List 1.21 and earlier phpBB module allows remot
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mp3 ToolBox 1.0 Beta 5 - 'skin_file' Remote File Inclusion
CVE-2007-6139—webappsphp
PHP remote file inclusion vulnerability in index.php in Mp3 ToolBox 1.0 beta 5 allows remote attackers to execute arbitr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component com_phocadocumentation - 'id' SQL Injection
CVE-2009-0702—webappsphp
SQL injection vulnerability in the Phoca Documentation (com_phocadocumentation) component for Joomla! allows remote atta
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PowerStrip 3.84 - 'pstrip.sys' Local Privilege Escalation
CVE-2008-5725—localwindows
The NT kernel-mode driver (aka pstrip.sys) 5.0.1.1 and earlier in EnTech Taiwan PowerStrip 3.84 and earlier allows local
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Maran PHP Forum - 'forum_write.php' Remote Code Execution
CVE-2007-2182—webappsphp
Unrestricted file upload vulnerability in forum_write.php in Maran PHP Forum allows remote attackers to upload and execu
23RIESGO
abrir ↗
Referência✓ VexDay Proof
EclipseBB 0.5.0 Lite - 'phpbb_root_path' Remote File Inclusion
CVE-2007-0581—webappsphp
PHP remote file inclusion vulnerability in functions.php in EclipseBB 0.5.0 Lite allows remote attackers to execute arbi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mambo Component com_flyspray < 1.0.1 - Remote File Disclosure
CVE-2006-6203—webappsphp
Directory traversal vulnerability in startdown.php in the Flyspray ME 1.0.1 (com_flyspray) component for Mambo allows re
23RIESGO
abrir ↗
Referência✓ VexDay Proof
chernobiLe Portal 1.0 - 'default.asp' SQL Injection
CVE-2007-0582—webappsasp
SQL injection vulnerability in default.asp in ChernobiLe 1.0 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗
Referência✓ VexDay Proof
BBS E-Market - 'postscript.php?p_mode' Remote File Inclusion
CVE-2007-3934—webappsphp
PHP remote file inclusion vulnerability in postscript/postscript.php in BBS E-Market allows remote attackers to execute
23RIESGO
abrir ↗
Referência✓ VexDay Proof
HP Compaq Notebooks - ActiveX Remote Code Execution
CVE-2007-6332—remotewindows
The HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 i
23RIESGO
abrir ↗
Referência✓ VexDay Proof
asg-sentry 7.0.0 - Multiple Vulnerabilities
CVE-2008-1321—dosmultiple
The FxIAList service in ASG-Sentry Network Manager 7.0.0 and earlier does require authentication, which allows remote at
23RIESGO
abrir ↗
Referência✓ VexDay Proof
HotScripts Clone Script - SQL Injection
CVE-2007-6084—webappsphp
SQL injection vulnerability in software-description.php in HotScripts Clone Script allows remote attackers to execute ar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WEBBDOMAIN Petition 1.02/2.0/3.0 - Authentication Bypass
CVE-2008-6624—webappsphp
SQL injection vulnerability in getin.php in WEBBDOMAIN Petition 1.02, 2.0, and 3.0 allows remote attackers to execute ar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component LMO 1.0b2 - Remote File Inclusion
CVE-2006-3970—webappsphp
PHP remote file inclusion vulnerability in lmo.php in the LMO Component (com_lmo) 1.0b2 and earlier for Joomla! allows r
23RIESGO
abrir ↗
Referência✓ VexDay Proof
UNAK-CMS 1.5 - 'dirroot' Remote File Inclusion
CVE-2006-4890—webappsphp
Multiple PHP remote file inclusion vulnerabilities in UNAK-CMS 1.5 and earlier allow remote attackers to execute arbitra
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP Generic library & Framework - 'INCLUDE_PATH' Remote File Inclusion
CVE-2007-0584—webappsphp
PHP remote file inclusion vulnerability in membres/membreManager.php in PhP Generic Library & Framework for comm (g-neri
45RIESGO
abrir ↗
Referência✓ VexDay Proof
CWB PRO 1.5 - 'INCLUDE_PATH' Remote File Inclusion
CVE-2007-1809—webappsphp
Multiple PHP remote file inclusion vulnerabilities in GraFX Company WebSite Builder (CWB) PRO 1.5 allow remote attackers
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Supasite 1.23b - Multiple Remote File Inclusions
CVE-2007-2185—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Supasite 1.23b allow remote attackers to execute arbitrary PHP cod
23RIESGO
abrir ↗
Referência✓ VexDay Proof
XnView 1.92.1 - 'FontName' Slideshow Buffer Overflow
CVE-2008-0069—localwindows
Stack-based buffer overflow in XnView 1.92 and 1.92.1 allows user-assisted remote attackers to execute arbitrary code vi
23RIESGO
abrir ↗
← anteriorpágina 720 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.