Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.859exploits catalogados
38.203CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
phpMyClub 0.0.1 - 'page_courante' Local File Inclusion
CVE-2008-0501—webappsphp
Directory traversal vulnerability in phpMyClub 0.0.1 allows remote attackers to include and execute arbitrary local file
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Debian OpenSSH - (Authenticated) Remote SELinux Privilege Escalation
CVE-2008-3234—remotelinux
sshd in OpenSSH 4 on Debian GNU/Linux, and the 20070303 OpenSSH snapshot, allows remote authenticated users to obtain ac
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PhotoKorn Gallery 1.543 - 'pic' SQL Injection
CVE-2008-0614—webappsphp
SQL injection vulnerability in index.php in Photokorn Gallery 1.543 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗
Referência✓ VexDay Proof
NERO Media Player 1.4.0.35b - '.m3u' File Buffer Overflow (PoC)
CVE-2008-0619—doswindows
Buffer overflow in NeroMediaPlayer.exe in Nero Media Player 1.4.0.35 and earlier allows remote attackers to execute arbi
28RIESGO
abrir ↗
Referência✓ VexDay Proof
Plogger 3.0 - SQL Injection
CVE-2008-3563—webappsphp
Multiple SQL injection vulnerabilities in Plogger 3.0 and earlier allow remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Zeeways Shaadi Clone 2.0 - Authentication Bypass (1)
CVE-2008-6912—webappsphp
Zeeways SHAADICLONE 2.0 allows remote attackers to bypass authentication and gain administrative privileges via a direct
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MyBulletinBoard (MyBB) 1.2.11 - 'private.php' SQL Injection (1)
CVE-2008-0787—webappsphp
SQL injection vulnerability in inc/datahandlers/pm.php in MyBB before 1.2.12 allows remote authenticated users to execut
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component xfaq 1.2 - 'aid' SQL Injection
CVE-2008-0795—webappsphp
SQL injection vulnerability in index.php in the MGFi XfaQ (com_xfaq) 1.2 component for Mambo and Joomla! allows remote a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP-Fusion Mod Classifieds - 'lid' SQL Injection
CVE-2008-5197—webappsphp
SQL injection vulnerability in classifieds.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP-Nuke Modules Okul 1.0 - 'okulid' SQL Injection
CVE-2008-0881—webappsphp
SQL injection vulnerability in modules.php in the Okul 1.0 module for PHP-Nuke allows remote attackers to execute arbitr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Globsy 1.0 - 'file' Remote File Disclosure
CVE-2008-0905—webappsphp
Directory traversal vulnerability in globsy_edit.php in Globsy 1.0 allows remote attackers to read arbitrary files via a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP-Nuke Module Docum - 'artid' SQL Injection
CVE-2008-0906—webappsphp
SQL injection vulnerability in the Docum module in PHP-Nuke allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
DFF PHP Framework API - 'Data Feed File' Remote File Inclusion
CVE-2008-4502—webappsphp
Multiple PHP remote file inclusion vulnerabilities in DataFeedFile (DFF) PHP Framework API allow remote attackers to exe
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP-Nuke Module Inhalt - 'cid' SQL Injection
CVE-2008-0907—webappsphp
SQL injection vulnerability in the Inhalt module for PHP-Nuke allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MultiCart 2.0 - 'productdetails.php' SQL Injection
CVE-2008-0911—webappsphp
SQL injection vulnerability in productdetails.php in iScripts MultiCart 2.0 allows remote authenticated users to execute
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Home FTP Server 1.4.5 - Remote Denial of Service
CVE-2008-1478—doswindows
Home FTP Server 1.4.5.89 allows remote attackers to cause a denial of service (crash) by opening a FTP passive mode conn
23RIESGO
abrir ↗
Referência✓ VexDay Proof
IP Reg 0.4 - Multiple SQL Injections
CVE-2008-4606—webappsphp
Multiple SQL injection vulnerabilities in IP Reg 0.4 and earlier allow remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Eurologon CMS - 'files.php' Arbitrary File Download
CVE-2007-6185—webappsphp
Directory traversal vulnerability in users/files.php in Eurologon CMS allows remote attackers to read arbitrary files vi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Quick TFTP Server Pro 2.1 - Remote Overflow (SEH)
CVE-2008-1610—remotewindows
Stack-based buffer overflow in TallSoft Quick TFTP Server Pro 2.1 allows remote attackers to cause a denial of service o
50RIESGO
abrir ↗
Referência✓ VexDay Proof
TFTP Server 1.4 - ST Buffer Overflow
CVE-2008-1611—remotewindows
Stack-based buffer overflow in TFTP Server SP 1.4 for Windows allows remote attackers to cause a denial of service or ex
50RIESGO
abrir ↗
Referência✓ VexDay Proof
Neat weblog 0.2 - 'articleId' SQL Injection
CVE-2008-1639—webappsphp
SQL injection vulnerability in index.php in Neat weblog 0.2 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Borland Interbase 2007 - 'ibserver.exe' Buffer Overflow (PoC)
CVE-2008-1910—doswindows
Stack-based buffer overflow in the database service (ibserver.exe) in Borland InterBase 2007 SP2 allows remote attackers
23RIESGO
abrir ↗
Referência✓ VexDay Proof
DivX Player 6.7 - '.srt' File Subtitle Parsing Buffer Overflow
CVE-2008-1912—localwindows
Stack-based buffer overflow in DivX Player 6.7 build 6.7.0.22 and earlier allows user-assisted remote attackers to cause
28RIESGO
abrir ↗
Referência✓ VexDay Proof
BlogWorx 1.0 - 'id' SQL Injection
CVE-2008-1915—webappsphp
SQL injection vulnerability in view.asp in DevWorx BlogWorx 1.0 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗
Referência✓ VexDay Proof
BlogMe PHP 1.1 - 'comments.php' SQL Injection
CVE-2008-2175—webappsphp
SQL injection vulnerability in comments.php in Gamma Scripts BlogMe PHP 1.1 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
wPortfolio 0.3 - Admin Password Changing
CVE-2008-5221—webappsphp
The account_save action in admin/userinfo.php in wPortfolio 0.3 and earlier does not require authentication and does not
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Cplinks 1.03 - Authentication Bypass / SQL Injection / Cross-Site Scripting
CVE-2008-2180—webappsphp
Multiple SQL injection vulnerabilities in cpLinks 1.03, when magic_quotes_gpc is disabled, allow remote attackers to exe
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Online Rental Property Script 4.5 - 'pid' SQL Injection
CVE-2008-2190—webappsphp
SQL injection vulnerability in index.php in Online Rent (aka Online Rental Property Script) 4.5 and earlier allows remot
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ScorpNews 1.0 - 'site' Remote File Inclusion
CVE-2008-2193—webappsphp
PHP remote file inclusion vulnerability in example.php in Thomas Gossmann ScorpNews 2.0 allows remote attackers to execu
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Microsoft Internet Explorer - Print Table of Links Cross-Zone Scripting
CVE-2008-2281—remotewindows
Cross-zone scripting vulnerability in the Print Table of Links feature in Internet Explorer 6.0, 7.0, and 8.0b allows us
28RIESGO
abrir ↗
← anteriorpágina 739 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.