Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.924exploits catalogados
38.251CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
Galatolo Web Manager 1.0 - SQL Injection
CVE-2008-2700—webappsphp
SQL injection vulnerability in view.php in Galatolo WebManager 1.0 and earlier allows remote attackers to execute arbitr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component beamospetition 1.0.12 - SQL Injection / Cross-Site Scripting
CVE-2009-0377—webappsphp
SQL injection vulnerability in the beamospetition (com_beamospetition) 1.0.12 component for Joomla! allows remote attack
23RIESGO
abrir ↗
Referência✓ VexDay Proof
BabbleBoard 1.1.6 - Cross-Site Request Forgery/Cookie Grabber
CVE-2008-6905—webappsphp
Cross-site request forgery (CSRF) vulnerability in index.php in BabbleBoard 1.1.6 allows remote authenticated users to h
23RIESGO
abrir ↗
Referência✓ VexDay Proof
LS Simple Guestbook 1.0 - Remote Code Execution
CVE-2007-2093—webappsphp
Direct static code injection vulnerability in index.php in Limesoft Guestbook (LS Simple Guestbook) 1.0 allows remote at
35RIESGO
abrir ↗
Referência✓ VexDay Proof
CityWriter 0.9.7 - 'head.php' Remote File Inclusion
CVE-2007-6324—webappsphp
PHP remote file inclusion vulnerability in head.php in CityWriter 0.9.7 allows remote attackers to execute arbitrary PHP
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Simple HTTPd 1.38 - Multiple Vulnerabilities
CVE-2007-6404—remotewindows
Directory traversal vulnerability in Sergey Lyubka Simple HTTPD (shttpd) 1.38 and earlier on Windows allows remote attac
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Acc Autos 4.0 - Insecure Cookie Handling
CVE-2008-6292—webappsphp
Acc Autos 4.0 allows remote attackers to bypass authentication and gain administrative access by setting the (1) usernam
23RIESGO
abrir ↗
Referência✓ VexDay Proof
AvailScript Jobs Portal Script - (Authenticated) Arbitrary File Upload
CVE-2008-7021—webappsphp
Unrestricted file upload vulnerability in editlogo.php in AvailScript Jobs Portal Script allows remote authenticated use
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PowerNews 2.5.4 - 'newsid' SQL Injection
CVE-2009-0705—webappsphp
SQL injection vulnerability in news.php in PowerScripts PowerNews 2.5.4, when magic_quotes_gpc is disabled, allows remot
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Discussion Web 4 - Remote Database Disclosure
CVE-2008-5886—webappsasp
TAKempis Discussion Web 4.0 stores sensitive information under the web root with insufficient access control, which allo
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WordPress Plugin WP-Cal 0.3 - 'editevent.php' SQL Injection
CVE-2008-0490—webappsphp
SQL injection vulnerability in functions/editevent.php in the WP-Cal 0.3 plugin for WordPress allows remote attackers to
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Popcorn 1.87 - Remote Heap Overflow (PoC)
CVE-2009-1647—doswindows
Heap-based buffer overflow in popcorn.exe in Ultrafunk Popcorn 1.87 allows remote POP3 servers to cause a denial of serv
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WordPress Plugin Download - 'dl_id' SQL Injection
CVE-2008-1646—webappsphp
SQL injection vulnerability in wp-download.php in the WP-Download 1.2 plugin for WordPress allows remote attackers to ex
23RIESGO
abrir ↗
Referência✓ VexDay Proof
XAMPP for Windows 1.6.0a - 'mssql_connect()' Remote Buffer Overflow
CVE-2007-2079—remotewindows
The ADONewConnection Connect function in adodb.php in XAMPP 1.6.0a and earlier for Windows uses untrusted input for the
23RIESGO
abrir ↗
Referência✓ VexDay Proof
HomePH Design 2.10 RC2 - Local File Inclusion / Remote File Inclusion / Cross-Site Scripting
CVE-2008-2981—webappsphp
PHP remote file inclusion vulnerability in admin/templates/template_thumbnail.php in HomePH Design 2.10 RC2, when regist
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SunShop Shopping Cart 3.5 - 'abs_path' Remote File Inclusion
CVE-2007-2070—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Turnkey Web Tools SunShop Shopping Cart before 3.5.1 allow remote
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PlaySms 0.9.3 - Multiple Local/Remote File Inclusions
CVE-2008-5881—webappsphp
Multiple directory traversal vulnerabilities in playSMS 0.9.3 allow remote attackers to include and execute arbitrary lo
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Miniweb 0.8.19 - Multiple Vulnerabilities
CVE-2008-0337—remotewindows
Heap-based buffer overflow in the _mwProcessReadSocket function in http.c in MiniWeb HTTP Server 0.8.19 allows remote at
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mambo Module Weather - 'absolute_path' Remote File Inclusion
CVE-2007-2044—webappsphp
PHP remote file inclusion vulnerability in mod_weather.php in the Antonis Ventouris Weather module for Mambo and Joomla!
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component mosmedia 1.0.8 - Remote File Inclusion
CVE-2007-2043—webappsphp
Multiple PHP remote file inclusion vulnerabilities in the Avant-Garde Solutions MOSMedia (com_mosmedia) 1.08 and earlier
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ASP Smiley 1.0 - 'default.asp' Authentication Bypass / SQL Injection
CVE-2006-5952—webappsasp
SQL injection vulnerability in admin/default.asp in ASP Smiley 1.0 allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗
Referência✓ VexDay Proof
blogit! - SQL Injection / File Disclosure / Cross-Site Scripting
CVE-2009-0337—webappsphp
SQL injection vulnerability in index.asp in Katy Whitton BlogIt! allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗
Referência✓ VexDay Proof
S-Gastebuch 1.5.3 - 'gb_pfad' Remote File Inclusion
CVE-2007-1011—webappsphp
PHP remote file inclusion vulnerability in functions_inc.php in VS-Gastebuch 1.5.3 and earlier allows remote attackers t
23RIESGO
abrir ↗
Referência✓ VexDay Proof
phpclanwebsite 1.23.3 fix pack #5 - Multiple Vulnerabilities
CVE-2008-5879—webappsphp
Cross-site scripting (XSS) vulnerability in index.php in Phpclanwebsite (aka PCW) 1.23.3 Fix Pack 5 and earlier, allows
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mambo Component zOOm Media Gallery 2.5 Beta 2 - Remote File Inclusion
CVE-2007-1992—webappsphp
Multiple PHP remote file inclusion vulnerabilities in the com_zoom 2.5 beta 2 and earlier module for Mambo allow remote
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component com_pccookbook - 'recipe_id' Blind SQL Injection
CVE-2009-0329—webappsphp
SQL injection vulnerability in the PcCookBook (com_pccookbook) component for Joomla! allows remote attackers to execute
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Hex Workshop 5.1.4 - Color Mapping File Local Buffer Overflow (PoC)
CVE-2008-5756—doswindows
Buffer overflow in BreakPoint Software Hex Workshop 5.1.4 allows user-assisted attackers to cause a denial of service an
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Free Arcade Script 1.0 - Local File Inclusion Command Execution
CVE-2009-0731—webappsphp
Directory traversal vulnerability in pages/play.php in Free Arcade Script 1.0 allows remote attackers to include and exe
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Web Oddity Web Server 0.09b - Directory Traversal
CVE-2007-4726—remotelinux
Directory traversal vulnerability in Web Oddity 0.09b allows remote attackers to read arbitrary files via a .. (dot dot)
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SiteBuilderElite 1.2 - Multiple Remote File Inclusions
CVE-2008-1123—webappsphp
Multiple PHP remote file inclusion vulnerabilities in SiteBuilder Elite 1.2 allow remote attackers to execute arbitrary
23RIESGO
abrir ↗
← anteriorpágina 750 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.