Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
CPCommerce 1.2.8 - 'id_document' Blind SQL Injection
CVE-2009-1345webappsphp
SQL injection vulnerability in document.php in cpCommerce 1.2.8 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
ReferênciaVexDay Proof
PowerCHM 5.7 - Long URL Local Stack Overflow (PoC)
CVE-2009-1352doswindows
Stack-based buffer overflow in Dawningsoft PowerCHM 5.7 allows remote attackers to cause a denial of service (applicatio
23RIESGO
abrir
ReferênciaVexDay Proof
Enthrallweb eNews 1.0 - Remote User Pass Change
CVE-2006-6821webappsasp
myprofile.asp in Enthrallweb eNews does not properly validate the MM_recordId parameter during profile updates, which al
23RIESGO
abrir
ReferênciaVexDay Proof
Yrch 1.0 - 'plug.inc.phppath' Remote File Inclusion
CVE-2006-6823webappsphp
PHP remote file inclusion vulnerability in plugins/metasearch/plug.inc.php in Yrch! 1.0 allows remote attackers to execu
23RIESGO
abrir
ReferênciaVexDay Proof
Macromedia Shockwave 10 'SwDir.dll' Internet Explorer 7 - Denial of Service
CVE-2006-6885doswindows
An ActiveX control in SwDir.dll in Macromedia Shockwave 10 allows remote attackers to cause a denial of service (Interne
23RIESGO
abrir
ReferênciaVexDay Proof
Quote&Ordering System 1.0 - 'ordernum' Multiple Vulnerabilities
CVE-2006-6911webappsasp
SQL injection vulnerability in search.asp in Digitizing Quote And Ordering System 1.0 allows remote authenticated users
23RIESGO
abrir
ReferênciaVexDay Proof
CA BrightStor ARCserve - 'tapeeng.exe' Remote Buffer Overflow
CVE-2006-6917remotewindows
Multiple buffer overflows in Computer Associates (CA) BrightStor ARCserve Backup R11.5 Server before SP2 allows remote a
28RIESGO
abrir
ReferênciaVexDay Proof
CoolPlayer Portable 2.19.1 - '.m3u' Local Stack Overflow (PoC)
CVE-2009-1437doswindows
Stack-based buffer overflow in PortableApps CoolPlayer Portable (aka CoolPlayer+ Portable) 2.19.6 and earlier allows rem
28RIESGO
abrir
ReferênciaVexDay Proof
CoolPlayer Portable 2.19.1 - '.m3u' Local Buffer Overflow (1)
CVE-2009-1437localwindows
Stack-based buffer overflow in PortableApps CoolPlayer Portable (aka CoolPlayer+ Portable) 2.19.6 and earlier allows rem
28RIESGO
abrir
ReferênciaVexDay Proof
Tiny Blogr 1.0.0 rc4 - Authentication Bypass
CVE-2009-1453webappsphp
SQL injection vulnerability in class.eport.php in Tiny Blogr 1.0.0 rc4, when magic_quotes_gpc is disabled, allows remote
23RIESGO
abrir
ReferênciaVexDay Proof
Pragyan CMS 2.6.4 - Multiple SQL Injections
CVE-2009-1480webappsphp
SQL injection vulnerability in index.php Pragyan CMS 2.6.4 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
ReferênciaVexDay Proof
fungamez rc1 - Authentication Bypass / Local File Inclusion
CVE-2009-1488webappsphp
Directory traversal vulnerability in admin/load.php in FunGamez RC1 allows remote attackers to include and execute arbit
23RIESGO
abrir
ReferênciaVexDay Proof
Adobe Reader 8.1.4/9.1 - 'GetAnnots()' Remote Code Execution
CVE-2009-1492remotelinux
The getAnnots Doc method in the JavaScript API in Adobe Reader and Acrobat 9.1, 8.1.4, 7.1.1, and earlier allows remote
28RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component Cmimarketplace - 'viewit' Directory Traversal
CVE-2009-1496webappsphp
Directory traversal vulnerability in the Cmi Marketplace (com_cmimarketplace) component 0.1 for Joomla! allows remote at
38RIESGO
abrir
ReferênciaVexDay Proof
ProjectCMS 1.0b - 'index.php?sn' SQL Injection
CVE-2009-1500webappsphp
SQL injection vulnerability in index.php in ProjectCMS 1.0 Beta allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft GDI Plugin - '.png' Infinite Loop Denial of Service (PoC)
CVE-2009-1511doswindows
GDI+ in Microsoft Windows XP SP3 allows remote attackers to cause a denial of service (infinite loop) via a PNG file tha
28RIESGO
abrir
ReferênciaVexDay Proof
pecio CMS 1.1.5 - 'index.php?language' Local File Inclusion
CVE-2009-1519webappsphp
Directory traversal vulnerability in index.php in Pecio CMS 1.1.5 allows remote attackers to read arbitrary files via a
23RIESGO
abrir
ReferênciaVexDay Proof
MDPro 1.0.76 - 'Cookie PNSVlang' Local File Inclusion
CVE-2006-7112webappsphp
Directory traversal vulnerability in error.php in MD-Pro 1.0.76 and earlier allows remote authenticated users to read an
23RIESGO
abrir
ReferênciaVexDay Proof
PHPGiggle 12.08 - 'CFG_PHPGIGGLE_ROOT' File Inclusion
CVE-2006-7119webappsphp
PHP remote file inclusion vulnerability in kernel/system/startup.php in J. He PHPGiggle 12.08 and earlier, as distribute
23RIESGO
abrir
ReferênciaVexDay Proof
JAF CMS 4.0 RC2 - Multiple Remote File Inclusions
CVE-2006-7127webappsphp
Multiple PHP remote file inclusion vulnerabilities in JAF CMS 4.0 and 4.0 RC2 allow remote attackers to execute arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
JAF CMS 4.0 RC1 - 'forum.php' Remote File Inclusion
CVE-2006-7128webappsphp
PHP remote file inclusion vulnerability in forum/forum.php JAF CMS 4.0 RC1 allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
Jinzora 2.6 - '/extras/mt.php' Remote File Inclusion
CVE-2006-7131webappsphp
PHP remote file inclusion vulnerability in extras/mt.php in Jinzora 2.6 allows remote attackers to execute arbitrary PHP
23RIESGO
abrir
ReferênciaVexDay Proof
Apple QuickTime - 'rtsp URL Handler' Remote Stack Buffer Overflow
CVE-2007-0015remotemultiple
Buffer overflow in Apple QuickTime 7.1.3 allows remote attackers to execute arbitrary code via a long rtsp:// URI.
50RIESGO
abrir
ReferênciaVexDay Proof
Teraway LiveHelp 2.0 - Insecure Cookie Handling
CVE-2009-1618webappsphp
Teraway LiveHelp 2.0 allows remote attackers to bypass authentication and gain administrative access via a pwd=&lvl=1&us
23RIESGO
abrir
ReferênciaVexDay Proof
Teraway FileStream 1.0 - Insecure Cookie Handling
CVE-2009-1619webappsphp
Teraway FileStream 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the tw
23RIESGO
abrir
ReferênciaVexDay Proof
SDP Downloader 2.3.0 - '.asx' Local Heap Overflow (PoC)
CVE-2009-1627doswindows
Stack-based buffer overflow in Streaming Download Project (SDP) Downloader 2.3.0 allows remote attackers to execute arbi
23RIESGO
abrir
ReferênciaVexDay Proof
SDP Downloader 2.3.0 - '.asx' Local Buffer Overflow (SEH) (1)
CVE-2009-1627localwindows
Stack-based buffer overflow in Streaming Download Project (SDP) Downloader 2.3.0 allows remote attackers to execute arbi
23RIESGO
abrir
ReferênciaVexDay Proof
Mini-stream Ripper 3.0.1.1 - '.RAM' Local Buffer Overflow
CVE-2009-1641localwindows
Multiple stack-based buffer overflows in Mini-stream Ripper 3.0.1.1 allow remote attackers to execute arbitrary code via
50RIESGO
abrir
ReferênciaVexDay Proof
Mini-stream ASX to MP3 Converter 3.0.0.7 - '.asx HREF' Local Buffer Overflow
CVE-2009-1642localwindows
Multiple stack-based buffer overflows in Mini-stream ASX to MP3 Converter 3.0.0.7 allow remote attackers to execute arbi
23RIESGO
abrir
ReferênciaVexDay Proof
Mini-stream ASX to MP3 Converter 3.0.0.7 - '.RAM' Local Buffer Overflow
CVE-2009-1642localwindows
Multiple stack-based buffer overflows in Mini-stream ASX to MP3 Converter 3.0.0.7 allow remote attackers to execute arbi
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.