Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.859exploits catalogados
38.203CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
Flexphplink 0.0.x - Authentication Bypass
CVE-2008-6730—webappsphp
Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPLink Pro 0.0.6 and 0.0.7, when magic_quotes_gpc
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ST-Gallery 0.1a - Multiple SQL Injections
CVE-2009-1799—webappsphp
Multiple SQL injection vulnerabilities in the getGalleryImage function in st_admin/gallery_output.php in ST-Gallery 0.1
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Microsoft Windows Explorer - '.zip' Denial of Service
CVE-2008-4323—doswindows
Windows Explorer in Microsoft Windows XP SP3 allows user-assisted attackers to cause a denial of service (application cr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Atomic Photo Album 1.1.0pre4 - Blind SQL Injection
CVE-2008-4335—webappsphp
SQL injection vulnerability in album.php in Atomic Photo Album (APA) 1.1.0pre4 allows remote attackers to execute arbitr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MyBlog 0.9.8 - Insecure Cookie Handling
CVE-2008-4341—webappsphp
add.php in MyBlog 0.9.8 and earlier allows remote attackers to bypass authentication and gain administrative access by s
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CMS Buzz - 'id' SQL Injection
CVE-2008-4374—webappsphp
SQL injection vulnerability in index.php in CMS Buzz allows remote attackers to execute arbitrary SQL commands via the i
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Creator CMS 5.0 - 'sideid' SQL Injection
CVE-2008-4377—webappsasp
SQL injection vulnerability in index.asp in Creative Mind Creator CMS 5.0 allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP-Fusion Module Arcade 1.0 - 'cid' SQL Injection
CVE-2007-1978—webappsphp
SQL injection vulnerability in index.php in the Arcade 1.00 module for PHP-Fusion allows remote attackers to execute arb
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Hot Links SQL-PHP 3 - 'report.php' Multiple Vulnerabilities
CVE-2008-4378—webappsphp
SQL injection vulnerability in report.php in Mr. CGI Guy Hot Links SQL-PHP 3.0 and earlier allows remote attackers to ex
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ErfurtWiki R1.02b - Local File Inclusion
CVE-2008-2672—webappsphp
Multiple directory traversal vulnerabilities in ErfurtWiki R1.02b and earlier, when register_globals is enabled, allow r
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP Autos 2.9.1 - 'catid' SQL Injection
CVE-2008-4498—webappsphp
SQL injection vulnerability in searchresults.php in PHP Autos 2.9.1 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Rianxosencabos CMS 0.9 - Arbitrary Add Admin
CVE-2008-4245—webappsphp
The Admin Control Panel in Rianxosencabos CMS 0.9 does not require administrator privileges, which allows remote authent
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Konqueror 3.5.9 - 'font color' Remote Crash
CVE-2008-4514—doslinux
The HTML parser in KDE Konqueror 3.5.9 allows remote attackers to cause a denial of service (application crash) via a fo
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Fastpublish CMS 1.9999 - Local File Inclusion / SQL Injection
CVE-2008-4518—webappsphp
Multiple SQL injection vulnerabilities in Fastpublish CMS 1.9.9.9.9 d (1.9999 d) allow remote attackers to execute arbit
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Battle Blog 1.25 - 'comment.asp' SQL Injection
CVE-2008-2626—webappsphp
SQL injection vulnerability in comment.asp in Battle Blog 1.25 and earlier allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CafeEngine - Multiple SQL Injections
CVE-2008-4605—webappsphp
SQL injection vulnerability in CafeEngine allows remote attackers to execute arbitrary SQL commands via the id parameter
23RIESGO
abrir ↗
Referência✓ VexDay Proof
UploadImage/UploadScript 1.0 - Remote Change Admin Password
CVE-2008-0246—webappsphp
admin.php in UploadScript 1.0 does not check for the original password before making a change to a new password, which a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component actualite 1.0 - 'id' SQL Injection
CVE-2008-4617—webappsphp
SQL injection vulnerability in the actualite module 1.0 for Joomla! allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗
Referência✓ VexDay Proof
more.groupware 0.74 - 'new_calendarid' SQL Injection
CVE-2006-4906—webappsphp
SQL injection vulnerability in modules/calendar/week.php in More.groupware 0.74 allows remote attackers to execute arbit
23RIESGO
abrir ↗
Referência✓ VexDay Proof
EZContents 1.4.5 - 'index.php?link' Remote File Disclosure
CVE-2007-6368—webappsphp
Directory traversal vulnerability in index.php in ezContents 1.4.5 allows remote attackers to read arbitrary files via a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Ultimate WebBoard 3.00 - 'Category' SQL Injection
CVE-2008-4666—webappsphp
SQL injection vulnerability in webboard.php in Ultimate Webboard 3.00 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component Highwood Design hwdVideoShare - SQL Injection
CVE-2008-0916—webappsphp
SQL injection vulnerability in the Highwood Design hwdVideoShare (com_hwdvideoshare) 1.1.3 Alpha component for Joomla!
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ourvideo CMS 9.5 - Local File Inclusion / Remote File Inclusion / Cross-Site Scripting
CVE-2008-2978—webappsphp
Directory traversal vulnerability in phpi/rss.php in Ourvideo CMS 9.5, when register_globals is enabled, allows remote a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ArabCMS - 'rss.php' Local File Inclusion
CVE-2008-4667—webappsphp
Directory traversal vulnerability in rss.php in ArabCMS 2.0 beta 1 allows remote attackers to include and execute arbitr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
eDNews 2.0 - Local File Inclusion
CVE-2008-5819—webappsphp
Directory traversal vulnerability in eDNews_archive.php in eDreamers eDNews 2, when magic_quotes_gpc is disabled, allows
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Apple Mac OSX 10.5.0 (Leopard) - vpnd Remote Denial of Service (PoC)
CVE-2007-6276—dososx
The accept_connections function in the virtual private network daemon (vpnd) in Apple Mac OS X 10.5 before 10.5.4 allows
23RIESGO
abrir ↗
Referência✓ VexDay Proof
YourFreeWorld Classifieds Blaster - SQL Injection
CVE-2008-4900—webappsphp
SQL injection vulnerability in tr.php in YourFreeWorld Classifieds Blaster Script allows remote attackers to execute arb
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Apache Tomcat Connector jk2-2.0.2 mod_jk2 - Remote Overflow
CVE-2007-6258—remotelinux
Multiple stack-based buffer overflows in the legacy mod_jk2 2.0.3-DEV and earlier Apache module allow remote attackers t
35RIESGO
abrir ↗
Referência✓ VexDay Proof
Article Publisher PRO - 'userid' SQL Injection
CVE-2008-4902—webappsphp
SQL injection vulnerability in contact_author.php in Article Publisher Pro 1.5 allows remote attackers to execute arbitr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ModernBill 4.4.x - Cross-Site Scripting / Remote File Inclusion
CVE-2008-5059—webappsphp
Cross-site scripting (XSS) vulnerability in index.php in ModernBill 4.4 and earlier allows remote attackers to inject ar
23RIESGO
abrir ↗
← anteriorpágina 725 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.