Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.859exploits catalogados
38.203CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
BS.Player 2.34 Build 980 - '.bsl' Local Buffer Overflow (SEH)
CVE-2009-1068—localwindows
Stack-based buffer overflow in BS.Player (bsplayer) 2.32 Build 975 Free and 2.34 Build 980 PRO and earlier allows remote
28RIESGO
abrir ↗
Referência✓ VexDay Proof
Blog PixelMotion - 'sauvBase.php' Arbitrary Database Backup
CVE-2008-1868—webappsphp
admin/sauvBase.php in Blog Pixel Motion (aka Blog PixelMotion) does not require authentication, which allows remote atta
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Barman 0.0.1r3 - 'Interface.php' Remote File Inclusion
CVE-2006-6611—webappsphp
PHP remote file inclusion vulnerability in interface.php in Barman 0.0.1r3 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
nightfall personal diary 1.0 - Cross-Site Scripting / File Disclosure
CVE-2008-5592—webappsphp
Nightfall Personal Diary 1.0 stores sensitive information under the web root with insufficient access control, which all
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Thickbox Gallery 2.0 - 'Admins.php' Admin Data Disclosure
CVE-2008-3859—webappsphp
Davlin Thickbox Gallery 2 allows remote attackers to obtain the administrative username and MD5 password hash via a dire
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SimpleBlog 2.0 - 'comments.asp' SQL Injection (1)
CVE-2006-4300—webappsasp
SQL injection vulnerability in comments.asp in SimpleBlog 2.0 and earlier allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗
Referência✓ VexDay Proof
TualBLOG 1.0 - 'icerikno' SQL Injection
CVE-2006-4793—webappsasp
Multiple SQL injection vulnerabilities in icerik.asp in TualBLOG 1.0 allow remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Scientific Image DataBase 0.41 - Blind SQL Injection
CVE-2008-2834—webappsphp
SQL injection vulnerability in projects.php in Scientific Image DataBase 0.41 allows remote attackers to execute arbitra
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Noticeware Email Server 4.6.1.0 - Denial of Service
CVE-2008-1713—doswindows
MailServer.exe in NoticeWare Email Server 4.6.1.0 allows remote attackers to cause a denial of service (application cras
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Pixie CMS - Cross-Site Scripting / SQL Injection
CVE-2009-1067—webappsphp
Cross-site scripting (XSS) vulnerability in index.php in Pixie CMS 1.01a allows remote attackers to inject arbitrary web
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Web Wiz Rich Text Editor 4.0 - Multiple Vulnerabilities
CVE-2008-0473—webappsasp
RTE_popup_save_file.asp in Web Wiz Rich Text Editor 4.0 allows remote attackers to upload (1) .html and (2) .htm files v
23RIESGO
abrir ↗
Referência✓ VexDay Proof
gf-3xplorer 2.4 - Cross-Site Scripting / Local File Inclusion
CVE-2007-6474—webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in GF-3XPLORER 2.4 allow remote attackers to inject arbitrary web sc
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Orbit Downloader 2.8.7 - Arbitrary File Deletion
CVE-2009-1064—remotewindows
Argument injection vulnerability in orbitmxt.dll 2.1.0.2 in the Orbit Downloader 2.8.7 and earlier ActiveX control allow
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Dokeos 1.8.4 - Arbitrary File Upload
CVE-2007-6479—webappsphp
Unrestricted file upload vulnerability in the "My productions" component for main/auth/profile.php (aka the "My profile"
23RIESGO
abrir ↗
Referência✓ VexDay Proof
falcon CMS 1.4.3 - Remote File Inclusion / Cross-Site Scripting
CVE-2007-6490—webappsphp
Cross-site request forgery (CSRF) vulnerability in Falcon Series One CMS 1.4.3 allows remote attackers to change a passw
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Online Grades 3.2.4 - Authentication Bypass
CVE-2009-0453—webappsphp
Online Grades 3.2.4 allows remote attackers to obtain configuration information via a direct request to phpinfo.php, whi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHPEasyNews 1.13 RC2 - 'POST' SQL Injection
CVE-2008-2823—webappsphp
SQL injection vulnerability in newsarchive.php in PHPeasyblog (formerly phpeasynews) 1.13 RC2 and earlier allows remote
23RIESGO
abrir ↗
Referência✓ VexDay Proof
NetProxy 4.03 - Web Filter Evasion / Bypass Logging
CVE-2007-1224—remotewindows
Grok Developments NetProxy 4.03 allows remote attackers to bypass URL filtering via a request that omits "http://" from
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Socketwiz BookMarks 2.0 - 'root_dir' Remote File Inclusion
CVE-2006-7069—webappsphp
PHP remote file inclusion vulnerability in smarty_config.php in Socketwiz Bookmarks 2.0 and earlier allows remote attack
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WordPress MU < 2.7 - 'HOST' HTTP Header Cross-Site Scripting
CVE-2009-1030—webappsphp
Cross-site scripting (XSS) vulnerability in the choose_primary_blog function in wp-includes/wpmu-functions.php in WordPr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
APC ActionApps CMS 2.8.1 - Remote File Inclusion
CVE-2006-2686—webappsphp
PHP remote file inclusion vulnerabilities in ActionApps 2.8.1 allow remote attackers to execute arbitrary PHP code via a
28RIESGO
abrir ↗
Referência✓ VexDay Proof
ZenPhoto 1.1.3 - 'rss.php?albumnr' SQL Injection
CVE-2007-6666—webappsphp
SQL injection vulnerability in rss.php in Zenphoto 1.1 through 1.1.3 allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MyPHP Forum 3.0 (Final) - Multiple SQL Injections
CVE-2007-6667—webappsphp
SQL injection vulnerability in faq.php in MyPHP Forum 3.0 and earlier allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Easy-Clanpage 3.0b1 - 'section' Local File Inclusion
CVE-2008-2818—webappsphp
Directory traversal vulnerability in Easy-Clanpage 3.0 b1 allows remote attackers to include and execute arbitrary local
23RIESGO
abrir ↗
Referência✓ VexDay Proof
DodosMail 2.0.1 - 'dodosmail.php' Remote File Inclusion
CVE-2006-5841—webappsphp
Multiple PHP remote file inclusion vulnerabilities in dodosmail.php in DodosMail 2.0.1 and earlier, and possibly 2.1, al
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Webmin 1.962 - 'Package Updates' Escape Bypass RCE (Metasploit)
CVE-2020-35606—webappslinux
Arbitrary command execution can occur in Webmin through 1.962. Any user authorized for the Package Updates module can ex
28RIESGO
abrir ↗
Referência✓ VexDay Proof
registroTL - 'main.php' Remote File Inclusion
CVE-2006-5316—webappsphp
registroTL stores sensitive information under the web root with insufficient access control, which allows remote attacke
23RIESGO
abrir ↗
Referência✓ VexDay Proof
unclassified NewsBoard 1.6.4 - Multiple Vulnerabilities
CVE-2009-1949—webappsphp
import_wbb1.php in Unclassified NewsBoard (UNB) 1.6.4 allows remote attackers to obtain sensitive information via a dire
23RIESGO
abrir ↗
Referência✓ VexDay Proof
AlkalinePHP 0.80.00 Beta - 'thread.php' SQL Injection
CVE-2008-2395—webappsphp
SQL injection vulnerability in thread.php in AlkalinePHP 0.80.00 beta and earlier allows remote attackers to execute arb
23RIESGO
abrir ↗
Referência✓ VexDay Proof
FicHive 1.0 - 'category' Blind SQL Injection
CVE-2008-2416—webappsphp
SQL injection vulnerability in index.php in FicHive 1.0 allows remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir ↗
← anteriorpágina 728 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.