Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.924exploits catalogados
38.251CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
TUTOS 1.3 - 'cmd.php' Remote Command Execution
CVE-2008-0148—webappsphp
TUTOS 1.3 does not restrict access to php/admin/cmd.php, which allows remote attackers to execute arbitrary shell comman
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Myspace Clone Script - 'index.php' Remote File Inclusion
CVE-2007-6057—webappsphp
PHP remote file inclusion vulnerability in index.php in datecomm Social Networking Script (aka Myspace Clone Script) all
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mambo Component SMF Forum 1.3.1.3 - Remote File Inclusion
CVE-2006-3773—webappsphp
PHP remote file inclusion vulnerability in smf.php in the SMF-Forum 1.3.1.3 Bridge Component (com_smf) For Joomla! and M
23RIESGO
abrir ↗
Referência✓ VexDay Proof
XAMPP for Windows 1.6.0a - 'mssql_connect()' Remote Buffer Overflow
CVE-2007-2079—remotewindows
The ADONewConnection Connect function in adodb.php in XAMPP 1.6.0a and earlier for Windows uses untrusted input for the
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CityWriter 0.9.7 - 'head.php' Remote File Inclusion
CVE-2007-6324—webappsphp
PHP remote file inclusion vulnerability in head.php in CityWriter 0.9.7 allows remote attackers to execute arbitrary PHP
23RIESGO
abrir ↗
Referência✓ VexDay Proof
LS Simple Guestbook 1.0 - Remote Code Execution
CVE-2007-2093—webappsphp
Direct static code injection vulnerability in index.php in Limesoft Guestbook (LS Simple Guestbook) 1.0 allows remote at
35RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component beamospetition 1.0.12 - SQL Injection / Cross-Site Scripting
CVE-2009-0377—webappsphp
SQL injection vulnerability in the beamospetition (com_beamospetition) 1.0.12 component for Joomla! allows remote attack
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Asterisk 1.2.x - SIP channel driver / in pedantic mode Remote Crash
CVE-2008-2119—dosmultiple
Asterisk Open Source 1.0.x and 1.2.x before 1.2.29 and Business Edition A.x.x and B.x.x before B.2.5.3, when pedantic pa
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ShoutPro 1.5.2 - 'shout.php' Remote Code Injection
CVE-2007-2141—webappsphp
Direct static code injection vulnerability in shoutbox.php in ShoutPro 1.5.2 allows remote attackers to inject arbitrary
35RIESGO
abrir ↗
Referência✓ VexDay Proof
PLog 1.0.6 - 'albumID' SQL Injection
CVE-2008-2629—webappsphp
SQL injection vulnerability in the LifeType (formerly pLog) module for Drupal allows remote attackers to execute arbitra
23RIESGO
abrir ↗
Referência✓ VexDay Proof
IceBB 1.0-rc5 - Remote Create Admin
CVE-2007-1725—webappsphp
SQL injection vulnerability in index.php in IceBB 1.0-rc5 allows remote authenticated users to execute arbitrary SQL com
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ezusermanager 1.6 - Remote File Inclusion
CVE-2006-2424—webappsphp
PHP remote file inclusion vulnerability in ezUserManager 1.6 and earlier, when register_globals is enabled, allows remot
23RIESGO
abrir ↗
Referência✓ VexDay Proof
TightVNC - Authentication Failure Integer Overflow (PoC)
CVE-2009-0388—doswindows
Multiple integer signedness errors in (1) UltraVNC 1.0.2 and 1.0.5 and (2) TightVnc 1.3.9 allow remote VNC servers to ca
28RIESGO
abrir ↗
Referência✓ VexDay Proof
WEBInsta FM 0.1.4 - 'login.php' absolute_path Remote File Inclusion
CVE-2007-2181—webappsphp
PHP remote file inclusion vulnerability in admin/login.php in Webinsta FM Manager 0.1.4 and earlier allows remote attack
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ezpack 4.2b2 - Cross-Site Scripting / SQL Injection
CVE-2009-0105—webappsphp
Cross-site scripting (XSS) vulnerability in index.php in EZpack 4.2b2 allows remote attackers to inject arbitrary web sc
23RIESGO
abrir ↗
Referência✓ VexDay Proof
mebiblio 0.4.7 - SQL Injection / Arbitrary File Upload / Cross-Site Scripting
CVE-2008-2648—webappsphp
Unrestricted file upload vulnerability in upload/uploader.html in meBiblio 0.4.7 allows remote attackers to execute arbi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Foxit Reader 2.0 - 'PDF' Remote Denial of Service
CVE-2007-2186—doswindows
Foxit Reader 2.0 allows remote attackers to cause a denial of service (application crash) via a crafted PDF document.
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SNMPc 7.0.18 - Remote Denial of Service (Metasploit)
CVE-2007-3098—doswindows
The SNMPc Server (crserv.exe) process in Castle Rock Computing SNMPc before 7.0.19 allows remote attackers to cause a de
23RIESGO
abrir ↗
Referência✓ VexDay Proof
C-Arbre 0.6PR7 - 'ROOT_PATH' Remote File Inclusion
CVE-2007-1721—webappsphp
Multiple PHP remote file inclusion vulnerabilities in C-Arbre 0.6PR7 and earlier allow remote attackers to execute arbit
28RIESGO
abrir ↗
Referência✓ VexDay Proof
Corel Paint Shop Pro Photo 11.20 - '.clp' Local Buffer Overflow
CVE-2007-2209—localwindows
Buffer overflow in igcore15d.dll 15.1.2.0 and 15.2.0.0 for AccuSoft ImageGear, as used in Corel Paint Shop Pro Photo 11.
28RIESGO
abrir ↗
Referência✓ VexDay Proof
PHPizabi 0.848b C1 HFP1 - Arbitrary File Upload
CVE-2008-0805—webappsphp
Unrestricted file upload vulnerability in image.php in PHPizabi 0.848b C1 HFP1 allows remote attackers to execute arbitr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SugarCRM Community Edition 4.5.1/5.0.0 - File Disclosure
CVE-2008-2045—webappsphp
Absolute path traversal vulnerability in SugarCRM Sugar Community Edition 4.5.1 and 5.0.0 allows remote attackers to rea
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Elecard MPEG Player 5.5 - '.m3u' Stack Buffer Overflow (PoC)
CVE-2009-0491—doswindows
Stack-based buffer overflow in Elecard MPEG Player 5.5 build 15884.081218 allows remote attackers to execute arbitrary c
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ASP PORTAL - Remote Database Disclosure
CVE-2008-5562—webappsasp
ASPPortal stores sensitive information under the web root with insufficient access control, which allows remote attacker
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Total Video Player 1.31 - 'DefaultSkin.ini' Local Stack Overflow
CVE-2009-0261—localwindows
Stack-based buffer overflow in EffectMatrix Total Video Player 1.31 allows user-assisted attackers to execute arbitrary
43RIESGO
abrir ↗
Referência✓ VexDay Proof
Simple Website Software 0.99 - 'common.php' File Inclusion
CVE-2006-5636—webappsphp
PHP remote file inclusion vulnerability in common.php in Simple Website Software (SWS) 0.99 and earlier allows remote at
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ASPThai.Net Forum 8.5 - Remote Database Disclosure
CVE-2008-6872—webappsasp
ASPThai.NET ASPThai Forums 8.5 stores sensitive information under the web root with insufficient access control, which a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Linksys WRT54G Firmware 1.00.9 - Security Bypass (1)
CVE-2008-1247—remotehardware
The web interface on the Linksys WRT54g router with firmware 1.00.9 does not require credentials when invoking scripts,
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mambo Module Flatmenu 1.07 - Remote File Inclusion
CVE-2007-1702—webappsphp
PHP remote file inclusion vulnerability in mod_flatmenu.php in the Flatmenu 1.07 and earlier Mambo module allows remote
23RIESGO
abrir ↗
Referência✓ VexDay Proof
FipsCMS Light 2.1 - 'db.mdb' Remote Database Disclosure
CVE-2009-2022—webappsasp
fipsCMS Light 2.1 stores sensitive information under the web root with insufficient access control, which allows remote
23RIESGO
abrir ↗
← anteriorpágina 743 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.