Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.924exploits catalogados
38.251CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
Joomla! Component joom12pic 1.0 - Remote File Inclusion
CVE-2007-4954—webappsphp
PHP remote file inclusion vulnerability in admin.joom12pic.php in the joom12Pic (com_joom12pic) 1.0 component for Joomla
28RIESGO
abrir ↗
Referência✓ VexDay Proof
SimpCMS - 'keyword' SQL Injection
CVE-2007-4953—webappsphp
SQL injection vulnerability in index.php in SimpCMS allows remote attackers to execute arbitrary SQL commands via the ke
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Microsoft Visual FoxPro 6.0 - FPOLE.OCX 6.0.8450.0 Remote (PoC)
CVE-2007-4790—doswindows
Stack-based buffer overflow in certain ActiveX controls in (1) FPOLE.OCX 6.0.8450.0 and (2) Foxtlib.ocx, as used in the
35RIESGO
abrir ↗
Referência✓ VexDay Proof
EDraw Office Viewer Component 5.1 - HttpDownloadFile() Insecure Method
CVE-2007-4420—remotewindows
Absolute path traversal vulnerability in a certain ActiveX control in officeviewer.ocx 5.1.199.1 in EDraw Office Viewer
23RIESGO
abrir ↗
Referência✓ VexDay Proof
DivX Player 6.6.0 - ActiveX 'SetPassword()' Denial of Service (PoC)
CVE-2008-0090—doswindows
A certain ActiveX control in npUpload.dll in DivX Player 6.6.0 allows remote attackers to cause a denial of service (Int
28RIESGO
abrir ↗
Referência✓ VexDay Proof
IBM Rational ClearQuest - Web Authentication Bypass / SQL Injection
CVE-2007-4368—webappscgi
SQL injection vulnerability in /main in IBM Rational ClearQuest (CQ) Web 7.0.0.0-IFIX02 and 7.0.0.1 allows remote attack
23RIESGO
abrir ↗
Referência✓ VexDay Proof
iManage CMS 4.0.12 - 'absolute_path' Remote File Inclusion
CVE-2006-3771—webappsphp
Multiple PHP remote file inclusion vulnerabilities in component.php in iManage CMS 4.0.12 and earlier allow remote attac
28RIESGO
abrir ↗
Referência✓ VexDay Proof
Prozilla Webring Website Script - 'category.php?cat' SQL Injection
CVE-2007-4362—webappsphp
SQL injection vulnerability in category.php in Prozilla Webring allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗
Referência✓ VexDay Proof
mail2forum phpBB Mod 1.2 - 'm2f_root_path' Remote File Inclusion
CVE-2006-3735—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Mail2Forum (module for phpBB) 1.2 and earlier allow remote attacke
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mambo Component com_downloads - SQL Injection
CVE-2008-0652—webappsphp
SQL injection vulnerability in index.php in the Downloads (com_downloads) component for Mambo and Joomla! allows remote
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP 5.2.3 Win32std - 'win_shell_execute' Safe Mode / disable_functions Bypass
CVE-2007-4010—localwindows
The win32std extension in PHP 5.2.3 does not follow safe_mode and disable_functions restrictions, which allows remote at
23RIESGO
abrir ↗
Referência✓ VexDay Proof
InoutMailingListManager 3.1 - Remote Command Execution
CVE-2006-0658—webappsphp
Incomplete blacklist vulnerability in connector.php in FCKeditor 2.0 and 2.2, as used in products such as RunCMS, allows
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP 4.4.7/5.2.3 - MySQL/MySQLi 'Safe_Mode' Bypass
CVE-2007-3997—localmultiple
The (1) MySQL and (2) MySQLi extensions in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to bypass
28RIESGO
abrir ↗
Referência✓ VexDay Proof
Microsoft Windows RSH daemon 1.7 - Remote Buffer Overflow
CVE-2007-4005—remotewindows
Stack-based buffer overflow in Mike Dubman Windows RSH daemon (rshd) 1.7 allows remote attackers to execute arbitrary co
28RIESGO
abrir ↗
Referência✓ VexDay Proof
BitchX 1.1-final - 'EXEC' Remote Command Execution
CVE-2007-3360—remotelinux
hook.c in BitchX 1.1-final allows remote IRC servers to execute arbitrary commands by sending a client certain data cont
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Solar Empire 2.9.1.1 - Blind SQL Injection / Hash Retrieve
CVE-2007-3307—webappsphp
SQL injection vulnerability in game_listing.php in Solar Empire 2.9.1.1 and earlier allows remote attackers to execute a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CA BrightStor Backup 11.5.2.0 - 'Mediasvr.exe' Denial of Service
CVE-2007-2772—doswindows
(1) caloggerd.exe (camt70.dll) and (2) mediasvr.exe (catirpc.dll and rwxdr.dll) in CA BrightStor Backup 11.5.2.0 SP2 all
28RIESGO
abrir ↗
Referência✓ VexDay Proof
CA BrightStor Backup 11.5.2.0 - 'caloggderd.exe' Denial of Service
CVE-2007-2772—doswindows
(1) caloggerd.exe (camt70.dll) and (2) mediasvr.exe (catirpc.dll and rwxdr.dll) in CA BrightStor Backup 11.5.2.0 SP2 all
28RIESGO
abrir ↗
Referência✓ VexDay Proof
Eudora 7.1 - SMTP ResponseRemote Remote Buffer Overflow
CVE-2007-2770—remotewindows
Stack-based buffer overflow in Eudora 7.1 allows user-assisted, remote SMTP servers to execute arbitrary code via a long
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Build it Fast (bif3) 0.4.1 - Multiple Remote File Inclusions
CVE-2007-2762—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Build it Fast (bif3) 0.4.1 allow remote attackers to execute arbit
23RIESGO
abrir ↗
Referência✓ VexDay Proof
runawaysoft haber portal 1.0 - 'tr' Multiple Vulnerabilities
CVE-2007-2753—webappsasp
RunawaySoft Haber portal 1.0 stores sensitive information under the web root with insufficient access control, which all
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHPtree 1.3 - 'cms2.php?s_dir' Remote File Inclusion
CVE-2007-2573—webappsphp
PHP remote file inclusion vulnerability in plugin/HP_DEV/cms2.php in PHPtree 1.3 allows remote attackers to execute arbi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
NoAh 0.9 pre 1.2 - 'mfa_theme.php' Remote File Inclusion
CVE-2007-2572—webappsphp
PHP remote file inclusion vulnerability in modules/noevents/templates/mfa_theme.php in NoAh (aka PHP Content Architect,
23RIESGO
abrir ↗
Referência✓ VexDay Proof
XOOPS Module wfquotes 1.0 - SQL Injection
CVE-2007-2571—webappsphp
SQL injection vulnerability in index.php in the wfquotes 1.0 0 module for XOOPS allows remote attackers to execute arbit
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Wikivi5 - 'show.php?sous_rep' Remote File Inclusion
CVE-2007-2570—webappsphp
PHP remote file inclusion vulnerability in handlers/page/show.php in Wikivi5 allows remote attackers to execute arbitrar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ACGVAnnu 1.3 - 'acgv.php?rubrik' Local File Inclusion
CVE-2007-2560—webappsphp
Directory traversal vulnerability in theme/acgv.php in ACGVannu 1.3 and earlier allows remote attackers to read arbitrar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Streamline PHP Media Server 1.0-beta4 - Remote File Inclusion
CVE-2007-5015—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Streamline PHP Media Server 1.0-beta4 allow remote attackers to ex
35RIESGO
abrir ↗
Referência✓ VexDay Proof
ABC-View Manager 1.42 - '.psp' Local Buffer Overflow
CVE-2007-2284—localwindows
Buffer overflow in ABC-View Manager 1.42 allows user-assisted remote attackers to execute arbitrary code via a crafted .
23RIESGO
abrir ↗
Referência✓ VexDay Proof
USP FOSS Distribution 1.01 - 'dnld' Remote File Disclosure
CVE-2007-2271—webappsphp
Directory traversal vulnerability in Rajneel Lal TotaRam USP FOSS Distribution 1.01 allows remote attackers to read arbi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Linksys SPA941 - Remote Reboot (Denial of Service)
CVE-2007-2270—doshardware
The Linksys SPA941 VoIP Phone allows remote attackers to cause a denial of service (device reboot) via a 0377 (0xff) cha
23RIESGO
abrir ↗
← anteriorpágina 747 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.