Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.924exploits catalogados
38.251CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
vidshare pro - SQL Injection / Cross-Site Scripting
CVE-2009-1735—webappsphp
Cross-site scripting (XSS) vulnerability in search.php in VidSharePro allows remote attackers to inject arbitrary web sc
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Nitrotech 0.0.3a - Remote File Inclusion / SQL Injection
CVE-2008-5334—webappsphp
PHP remote file inclusion vulnerability in includes/common.php in NitroTech 0.0.3a allows remote attackers to execute ar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component mosmedia 1.0.8 - Remote File Inclusion
CVE-2007-2043—webappsphp
Multiple PHP remote file inclusion vulnerabilities in the Avant-Garde Solutions MOSMedia (com_mosmedia) 1.08 and earlier
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mambo Module Weather - 'absolute_path' Remote File Inclusion
CVE-2007-2044—webappsphp
PHP remote file inclusion vulnerability in mod_weather.php in the Antonis Ventouris Weather module for Mambo and Joomla!
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Java SE Runtime Environment JRE 6 Update 13 - Multiple Vulnerabilities
CVE-2009-1671—doswindows
Multiple buffer overflows in the Deployment Toolkit ActiveX control in deploytk.dll 6.0.130.3 in Sun Java SE Runtime Env
28RIESGO
abrir ↗
Referência✓ VexDay Proof
Miniweb 0.8.19 - Multiple Vulnerabilities
CVE-2008-0337—remotewindows
Heap-based buffer overflow in the _mwProcessReadSocket function in http.c in MiniWeb HTTP Server 0.8.19 allows remote at
23RIESGO
abrir ↗
Referência✓ VexDay Proof
phpMyTeam 2.0 - 'smileys_dir' Remote File Inclusion
CVE-2006-5207—webappsphp
PHP remote file inclusion vulnerability in images/smileys/smileys_packs.php in phpMyTeam 2.0, when register_globals is e
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Invision Gallery 2.0.7 - 'readfile()' / SQL Injection
CVE-2006-5206—webappsphp
SQL injection vulnerability in Invision Gallery 2.0.7 allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Invision Gallery 2.0.7 - 'readfile()' / SQL Injection
CVE-2006-5205—webappsphp
Directory traversal vulnerability in Invision Gallery 2.0.7 allows remote attackers to read arbitrary files via a .. (do
28RIESGO
abrir ↗
Referência✓ VexDay Proof
Mambo Component com_lurm_constructor 0.6b - Remote File Inclusion
CVE-2006-4372—webappsphp
PHP remote file inclusion vulnerability in admin.lurm_constructor.php in the Lurm Constructor component (com_lurm_constr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
LoveCMS 1.6.2 Final (Simple Forum 3.1d) - Change Admin Password
CVE-2008-5308—webappsphp
The Simple Forum 3.1d module for LoveCMS 1.6.2 Final does not properly restrict access to administrator functions, which
23RIESGO
abrir ↗
Referência✓ VexDay Proof
VCDGear 3.56 Build 050213 - 'FILE' Local Code Execution
CVE-2007-2062—localwindows
Stack-based buffer overflow in VCDGear 3.55 and 3.56 BETA allows user-assisted remote attackers to execute arbitrary cod
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CDex 1.70b2 (Windows XP SP3) - '.ogg' Local Buffer Overflow
CVE-2009-1039—localwindows
Buffer overflow in CDex 1.70b2 allows remote attackers to execute arbitrary code via a crafted Info header in an Ogg Vor
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Realty Web-Base 1.0 - Authentication Bypass
CVE-2009-1658—webappsphp
Multiple SQL injection vulnerabilities in admin/admin.php in Realty Webware Technologies Realty Web-Base 1.0 allow remot
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Shutter 0.1.1 - Multiple SQL Injections
CVE-2009-1650—webappsphp
Multiple SQL injection vulnerabilities in photos.php in Shutter 0.1.1 allow remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Advanced Links Management (ALM) 1.52 - SQL Injection
CVE-2008-2529—webappsphp
SQL injection vulnerability in read.php in Advanced Links Management (ALM) 1.5.2 allows remote attackers to execute arbi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SunShop Shopping Cart 3.5 - 'abs_path' Remote File Inclusion
CVE-2007-2070—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools SunShop Shopping Cart before 3.5.1 allow remote
23RIESGO
abrir ↗
Referência✓ VexDay Proof
VideoGirls BiZ - Blind SQL Injection
CVE-2008-5292—webappsphp
SQL injection vulnerability in view_snaps.php in VideoGirls BiZ allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Klinza Professional CMS 5.0.1 - 'show_hlp.php' File Inclusion
CVE-2006-5189—webappsphp
PHP remote file inclusion vulnerability in funzioni/lib/show_hlp.php in klinza professional cms 5.0.1 and earlier allows
23RIESGO
abrir ↗
Referência✓ VexDay Proof
phpBB All Topics Mod 1.5.0 - 'start' SQL Injection
CVE-2006-4367—webappsphp
SQL injection vulnerability in alltopics.php in the All Topics Hack 1.5.0 and earlier for phpBB 2.0.21 allows remote att
23RIESGO
abrir ↗
Referência✓ VexDay Proof
XAMPP for Windows 1.6.0a - 'mssql_connect()' Remote Buffer Overflow
CVE-2007-2079—remotewindows
The ADONewConnection Connect function in adodb.php in XAMPP 1.6.0a and earlier for Windows uses untrusted input for the
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CityWriter 0.9.7 - 'head.php' Remote File Inclusion
CVE-2007-6324—webappsphp
PHP remote file inclusion vulnerability in head.php in CityWriter 0.9.7 allows remote attackers to execute arbitrary PHP
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Sorinara Streaming Audio Player 0.9 - '.pla' Local Stack Overflow
CVE-2009-1644—localwindows
Stack-based buffer overflow in Sorinara Streaming Audio Player 0.9 allows remote attackers to execute arbitrary code via
23RIESGO
abrir ↗
Referência✓ VexDay Proof
LS Simple Guestbook 1.0 - Remote Code Execution
CVE-2007-2093—webappsphp
Direct static code injection vulnerability in index.php in Limesoft Guestbook (LS Simple Guestbook) 1.0 allows remote at
35RIESGO
abrir ↗
Referência✓ VexDay Proof
Clean CMS 1.5 - Blind SQL Injection / Cross-Site Scripting
CVE-2008-5289—webappsphp
SQL injection vulnerability in full_txt.php in Werner Hilversum Clean CMS 1.5 allows remote attackers to execute arbitra
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Sorinara Streaming Audio Player 0.9 - '.pla' Local Stack Overflow (PoC)
CVE-2009-1644—doswindows
Stack-based buffer overflow in Sorinara Streaming Audio Player 0.9 allows remote attackers to execute arbitrary code via
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PPA Gallery 1.0 - 'functions.inc.php' Remote File Inclusion
CVE-2006-5165—webappsphp
PHP remote file inclusion vulnerability in inc/functions.inc.php in Skrypty PPA Gallery 1.0 and earlier allows remote at
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component beamospetition 1.0.12 - SQL Injection / Cross-Site Scripting
CVE-2009-0377—webappsphp
SQL injection vulnerability in the beamospetition (com_beamospetition) 1.0.12 component for Joomla! allows remote attack
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ShoutPro 1.5.2 - 'shout.php' Remote Code Injection
CVE-2007-2141—webappsphp
Direct static code injection vulnerability in shoutbox.php in ShoutPro 1.5.2 allows remote attackers to inject arbitrary
35RIESGO
abrir ↗
Referência✓ VexDay Proof
PLog 1.0.6 - 'albumID' SQL Injection
CVE-2008-2629—webappsphp
SQL injection vulnerability in the LifeType (formerly pLog) module for Drupal allows remote attackers to execute arbitra
23RIESGO
abrir ↗
← anteriorpágina 748 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.