Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.912exploits catalogados
38.247CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
KwsPHP 1.3.456 Module Galerie - 'id_gal' SQL Injection
CVE-2008-6197—webappsphp
SQL injection vulnerability in index.php in the galerie module for KwsPHP 1.3.456 allows remote attackers to execute arb
23RIESGO
abrir ↗
Referência✓ VexDay Proof
2532/Gigs 1.2.2 - Arbitrary Database Backup/Download
CVE-2008-6199—webappsphp
2532designs 2532|Gigs 1.2.2 and earlier allows remote attackers to trigger a backup and obtain sensitive information via
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mambo Component com_videodb 0.3en - Remote File Inclusion
CVE-2006-3736—webappsphp
PHP remote file inclusion vulnerability in core/videodb.class.xml.php in the VideoDB component for Mambo 0.3 and earlier
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Microsoft Internet Explorer - WebViewFolderIcon setSlice() Overflow (Metasploit) (1)
CVE-2006-3730HIGHremotewindows
Integer overflow in Microsoft Internet Explorer 6 on Windows XP SP2 allows remote attackers to cause a denial of service
68RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP Live! 3.2.2 - 'questid' SQL Injection (1)
CVE-2008-0821—webappsphp
SQL injection vulnerability in admin/traffic/knowledge_searchm.php in OSI Codes Inc. PHP Live! 3.2.2 allows remote attac
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mediatheka 4.2 - Blind SQL Injection
CVE-2008-5895—webappsphp
SQL injection vulnerability in connection.php in Mediatheka 4.2 and earlier allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SysInfo 1.21 - 'sysinfo.cgi' Remote Command Execution
CVE-2006-1831—webappscgi
Direct static code injection vulnerability in sysinfo.cgi in sysinfo 1.21 and possibly other versions before 2.25 allows
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Simple CMS 1.0.3 - 'area' SQL Injection
CVE-2008-0835—webappsphp
SQL injection vulnerability in indexen.php in Simple CMS 1.0.3 and earlier allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CiBlog 3.1 - 'id' SQL Injection
CVE-2008-2971—webappsphp
SQL injection vulnerability in links-extern.php in CiBlog 3.1 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗
Referência✓ VexDay Proof
TinXCMS 1.1 - Local File Inclusion / Cross-Site Scripting
CVE-2008-2975—webappsphp
Cross-site scripting (XSS) vulnerability in admin/objects/obj_image.php in TinX/cms 1.1 allows remote attackers to injec
23RIESGO
abrir ↗
Referência✓ VexDay Proof
clickandemail - SQL Injection / Cross-Site Scripting
CVE-2008-5892—webappsasp
Multiple SQL injection vulnerabilities in ClickAndEmail allow remote attackers to execute arbitrary SQL commands via (1)
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Click&Rank - SQL Injection / Cross-Site Scripting
CVE-2008-5888—webappsasp
Multiple SQL injection vulnerabilities in Click&Rank allow remote attackers to execute arbitrary SQL commands via the id
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Discussion Web 4 - Remote Database Disclosure
CVE-2008-5886—webappsasp
TAKempis Discussion Web 4.0 stores sensitive information under the web root with insufficient access control, which allo
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PlaySms 0.9.3 - Multiple Local/Remote File Inclusions
CVE-2008-5881—webappsphp
Multiple directory traversal vulnerabilities in playSMS 0.9.3 allow remote attackers to include and execute arbitrary lo
23RIESGO
abrir ↗
Referência✓ VexDay Proof
phpclanwebsite 1.23.3 fix pack #5 - Multiple Vulnerabilities
CVE-2008-5879—webappsphp
Cross-site scripting (XSS) vulnerability in index.php in Phpclanwebsite (aka PCW) 1.23.3 Fix Pack 5 and earlier, allows
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Downline Goldmine Category Addon - SQL Injection
CVE-2008-4178—webappsphp
SQL injection vulnerability in tr.php in DownlineGoldmine Special Category Addon, Downline Builder Pro, New Addon, and D
23RIESGO
abrir ↗
Referência✓ VexDay Proof
HomePH Design 2.10 RC2 - Local File Inclusion / Remote File Inclusion / Cross-Site Scripting
CVE-2008-2982—webappsphp
Multiple directory traversal vulnerabilities in HomePH Design 2.10 RC2, when register_globals is enabled, allow remote a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
cmreams CMS 1.3.1.1 beta2 - Local File Inclusion / Cross-Site Scripting
CVE-2008-2984—webappsphp
Cross-site scripting (XSS) vulnerability in backend/umleitung.php in CMReams CMS 1.3.1.1 Beta 2 allows remote attackers
23RIESGO
abrir ↗
Referência✓ VexDay Proof
phpDMCA 1.0.0 - Multiple Remote File Inclusions
CVE-2008-2986—webappsphp
Multiple PHP remote file inclusion vulnerabilities in phpDMCA 1.0.0 allow remote attackers to execute arbitrary PHP code
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Article Publisher PRO 1.5 - Authentication Bypass
CVE-2008-4901—webappsphp
SQL injection vulnerability in admin/admin.php in Article Publisher Pro 1.5 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
eXV2 Module MyAnnonces - 'lid' SQL Injection
CVE-2008-1406—webappsphp
SQL injection vulnerability in annonces-p-f.php in the MyAnnonces 1.8 module for eXV2 allows remote attackers to execute
23RIESGO
abrir ↗
Referência✓ VexDay Proof
XnView 1.92.1 - 'FontName' Slideshow Buffer Overflow
CVE-2008-0069—localwindows
Stack-based buffer overflow in XnView 1.92 and 1.92.1 allows user-assisted remote attackers to execute arbitrary code vi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Supasite 1.23b - Multiple Remote File Inclusions
CVE-2007-2185—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Supasite 1.23b allow remote attackers to execute arbitrary PHP cod
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Gravity Board X 2.0 Beta - SQL Injection / Cross-Site Scripting
CVE-2008-2997—webappsphp
Cross-site scripting (XSS) vulnerability in index.php in Gravity Board X (GBX) 2.0 Beta allows remote attackers to injec
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Apache mod_dav / svn - Remote Denial of Service
CVE-2009-1955—dosmultiple
The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav
35RIESGO
abrir ↗
Referência✓ VexDay Proof
CWB PRO 1.5 - 'INCLUDE_PATH' Remote File Inclusion
CVE-2007-1809—webappsphp
Multiple PHP remote file inclusion vulnerabilities in GraFX Company WebSite Builder (CWB) PRO 1.5 allow remote attackers
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MyTopix 1.3.0 - SQL Injection
CVE-2008-6330—webappsphp
SQL injection vulnerability in index.php in MyTopix 1.3.0 and earlier allows remote authenticated users to execute arbit
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP Generic library & Framework - 'INCLUDE_PATH' Remote File Inclusion
CVE-2007-0584—webappsphp
PHP remote file inclusion vulnerability in membres/membreManager.php in PhP Generic Library & Framework for comm (g-neri
45RIESGO
abrir ↗
Referência✓ VexDay Proof
PHPmotion 2.0 - 'update_profile.php' Arbitrary File Upload
CVE-2008-3117—webappsphp
Unrestricted file upload vulnerability in update_profile.php in PHPmotion 2.0 and earlier allows remote authenticated us
23RIESGO
abrir ↗
Referência✓ VexDay Proof
UNAK-CMS 1.5 - 'dirroot' Remote File Inclusion
CVE-2006-4890—webappsphp
Multiple PHP remote file inclusion vulnerabilities in UNAK-CMS 1.5 and earlier allow remote attackers to execute arbitra
23RIESGO
abrir ↗
← anteriorpágina 741 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.