Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.924exploits catalogados
38.251CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
PHP 'FFI' Extension 5.0.5 - 'Safe_mode' Local Bypass
CVE-2007-4528—localwindows
The Foreign Function Interface (ffi) extension in PHP 5.0.5 does not follow safe_mode restrictions, which allows context
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component com_Marketplace 1.1.1 - SQL Injection
CVE-2008-0689—webappsphp
SQL injection vulnerability in index.php in the Marketplace (com_marketplace) 1.1.1 and 1.1.1-pl1 component for Joomla!
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP 5.2.3 - PHP_ntuser ntuser_getuserlist() Local Buffer Overflow (PoC)
CVE-2007-4507—doswindows
Multiple buffer overflows in the php_ntuser component for PHP 5.2.3 allow context-dependent attackers to cause a denial
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WBB2-Addon: Acrotxt 1.0 - 'show' SQL Injection
CVE-2007-4581—webappsphp
SQL injection vulnerability in acrotxt.php in WBB2-Addon: Acrotxt 1 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Yet Another NOCC 0.1.0 - Local File Inclusion
CVE-2009-0515—webappsphp
Directory traversal vulnerability in check_lang.php in Yet Another NOCC (YANOCC) 0.1.0 and earlier allows remote attacke
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Txx CMS 0.2 - Multiple Remote File Inclusions
CVE-2007-4818—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Txx CMS 0.2 allow remote attackers to execute arbitrary PHP code v
35RIESGO
abrir ↗
Referência✓ VexDay Proof
freePHPgallery 0.6 - Cookie Local File Inclusion
CVE-2008-0818—webappsphp
Multiple directory traversal vulnerabilities in freePHPgallery 0.6 allow remote attackers to include and execute arbitra
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Evilsentinel 1.0.9 - Multiple Vulnerabilities Disable
CVE-2008-0350—webappsphp
admin/index.php in Evilsentinel 1.0.9 and earlier sends a redirect to the web browser but does not exit, which allows re
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Txx CMS 0.2 - Multiple Remote File Inclusions
CVE-2007-4819—webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in Txx CMS 0.2 allow remote attackers to inject arbitrary web script
23RIESGO
abrir ↗
Referência✓ VexDay Proof
neuron news 1.0 - 'index.php?q' Local File Inclusion
CVE-2007-5050—webappsphp
Directory traversal vulnerability in index.php in Neuron News 1.0 allows remote attackers to include and execute arbitra
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component MCQuiz 0.9 Final - 'tid' SQL Injection
CVE-2008-0800—webappsphp
SQL injection vulnerability in index.php in the McQuiz (com_mcquiz) 0.9 Final component for Joomla! allows remote attack
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Angelo-Emlak 1.0 - Multiple SQL Injections
CVE-2008-2048—webappsasp
Cross-site scripting (XSS) vulnerability in hpz/admin/Default.asp in Angelo-Emlak 1.0 allows remote attackers to inject
23RIESGO
abrir ↗
Referência✓ VexDay Proof
iziContents rc6 - Local/Remote File Inclusion
CVE-2007-5054—webappsphp
Multiple PHP remote file inclusion vulnerabilities in iziContents 1 RC6 and earlier allow remote attackers to execute ar
35RIESGO
abrir ↗
Referência✓ VexDay Proof
iziContents rc6 - Local/Remote File Inclusion
CVE-2007-5055—webappsphp
Multiple directory traversal vulnerabilities in iziContents 1 RC6 and earlier allow remote attackers to include and exec
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Softbiz Classifieds PLUS - 'id' SQL Injection
CVE-2007-5122—webappsphp
SQL injection vulnerability in store_info.php in SoftBiz Classifieds PLUS allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ActiveKB KnowledgeBase 2.x - 'catId' SQL Injection
CVE-2007-5131—webappsphp
SQL injection vulnerability in index.php in Interspire ActiveKB NX 2.x allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Advanced Image Hosting (AIH) 2.3 - 'gal' Blind SQL Injection
CVE-2009-1032—webappsphp
SQL injection vulnerability in gallery_list.php in YABSoft Advanced Image Hosting (AIH) Script 2.3 allows remote attacke
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP recommend 1.3 - Authentication Bypass / Remote File Inclusion / Code Injection
CVE-2009-1780—webappsphp
admin.php in Frax.dk Php Recommend 1.3 and earlier does not require authentication when the user password is changed, wh
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mambo Component Remository - 'cat' SQL Injection
CVE-2007-4505—webappsphp
SQL injection vulnerability in index.php in the RemoSitory component (com_remository) for Mambo allows remote attackers
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PNPHPBB2 < 1.2i - 'viewforum.php' SQL Injection
CVE-2007-3584—webappsphp
SQL injection vulnerability in viewforum.php in PNphpBB2 1.2i and earlier for Postnuke allows remote attackers to execut
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component live chat - SQL Injection / Open Proxy
CVE-2008-6881—webappsphp
Multiple SQL injection vulnerabilities in the Live Chat (com_livechat) component 1.0 for Joomla! allow remote attackers
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component Phil-a-Form 1.2.0.0 - SQL Injection
CVE-2007-2933—webappsphp
SQL injection vulnerability in index.php in the Phil-a-Form (com_philaform) 1.2.0.0 and earlier component for Joomla! al
23RIESGO
abrir ↗
Referência✓ VexDay Proof
XOOPS Module debaser 0.92 - 'genre.php' Blind SQL Injection
CVE-2007-1805—webappsphp
SQL injection vulnerability in genre.php in the debaser 0.92 and earlier module for Xoops allows remote attackers to exe
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ProfileCMS 1.0 - Arbitrary File Upload
CVE-2007-5720—webappsphp
Unrestricted file upload vulnerability in the profiles script in ProfileCMS 1.0 allows remote attackers to upload and ex
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Okul Otomasyon Portal 2.0 - SQL Injection
CVE-2007-5490—webappsphp
SQL injection vulnerability in default.asp in Okul Otomasyon Portal 2.0 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Oracle 10g/11g - 'SYS.LT.FINDRICSET' SQL Injection (1)
CVE-2007-5511—localmultiple
SQL injection vulnerability in Workspace Manager for Oracle Database before OWM 10.2.0.4.1, OWM 10.1.0.8.0, and OWM 9.2.
50RIESGO
abrir ↗
Referência✓ VexDay Proof
Oracle 10g/11g - 'SYS.LT.FINDRICSET' SQL Injection (2)
CVE-2007-5511—localmultiple
SQL injection vulnerability in Workspace Manager for Oracle Database before OWM 10.2.0.4.1, OWM 10.1.0.8.0, and OWM 9.2.
50RIESGO
abrir ↗
Referência✓ VexDay Proof
Jakarta Slide 2.1 RC1 - Remote File Disclosure
CVE-2007-5731—remotemultiple
Absolute path traversal vulnerability in Apache Jakarta Slide 2.1 and earlier allows remote authenticated users to read
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Vortex Portal 1.0.42 - Remote File Inclusion
CVE-2007-5842—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Vortex Portal 1.0.42 allow remote attackers to execute arbitrary P
35RIESGO
abrir ↗
Referência✓ VexDay Proof
jPORTAL 2 - 'mailer.php' SQL Injection
CVE-2007-5912—webappsphp
SQL injection vulnerability in mailer.php in jPORTAL 2 allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir ↗
← anteriorpágina 753 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.