Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.004exploits catalogados
38.306CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
Categories hierarchy phpBB Mod 2.1.2 - 'phpbb_root_path' Remote File Inclusion
CVE-2007-0809—webappsphp
PHP remote file inclusion vulnerability in includes/class_template.php in Categories hierarchy (aka CH or mod-CH) 2.1.2
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP-Nuke Module Kose_Yazilari - 'artid' SQL Injection
CVE-2008-1053—webappsphp
Multiple SQL injection vulnerabilities in the Kose_Yazilari module for PHP-Nuke allow remote attackers to execute arbitr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WordPress Plugin Sniplets 1.1.2 - Remote File Inclusion / Cross-Site Scripting / Remote Code Execution
CVE-2008-1060—webappsphp
Eval injection vulnerability in modules/execute.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allows remote a
35RIESGO
abrir ↗
Referência✓ VexDay Proof
WordPress Plugin Sniplets 1.1.2 - Remote File Inclusion / Cross-Site Scripting / Remote Code Execution
CVE-2008-1061—webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in the Sniplets 1.1.2 and 1.2.2 plugin for WordPress allow remote at
38RIESGO
abrir ↗
Referência✓ VexDay Proof
Mambo Component SimpleBoard 1.0.3 - 'catid' SQL Injection
CVE-2008-1077—webappsphp
SQL injection vulnerability in index.php in the Simpleboard (com_simpleboard) 1.0.3 Stable component for Mambo and Jooml
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Libxine 1.14 - MPEG Stream Buffer Overflow (PoC)
CVE-2008-1110—doslinux
Buffer overflow in demuxers/demux_asf.c (aka the ASF demuxer) in the xineplug_dmx_asf.so plugin in xine-lib before 1.1.1
28RIESGO
abrir ↗
Referência✓ VexDay Proof
SFS EZ Gaming Directory - 'cat_id' SQL Injection
CVE-2008-6781—webappsphp
SQL injection vulnerability in directory.php in Sites for Scripts (SFS) Gaming Directory allows remote attackers to exec
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Motorola Timbuktu Pro 8.6.5 - File Deletion/Creation
CVE-2008-1117—remotewindows
Directory traversal vulnerability in the Notes (aka Flash Notes or instant messages) feature in tb2ftp.dll in Timbuktu P
50RIESGO
abrir ↗
Referência✓ VexDay Proof
Motorola Timbuktu Pro 8.6.5/8.7 - Directory Traversal / Log Injection
CVE-2008-1118—remotewindows
Timbuktu Pro 8.6.5 for Windows, and possibly 8.7 for Mac OS X, does not perform input validation before logging informat
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Dream4 Koobi Pro 5.7 - 'categ' SQL Injection
CVE-2008-1122—webappsphp
SQL injection vulnerability in the downloads module in Koobi Pro 5.7 allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PortalApp 4.0 - SQL Injection / Cross-Site Scripting / Authentication Bypass
CVE-2008-4614—webappsasp
PortalApp 4.0 does not require authentication for (1) forums.asp and (2) content.asp, which allows remote attackers to c
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Podcast Generator 1.0 Beta 2 - Remote File Inclusion / File Disclosure
CVE-2008-1124—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Podcast Generator 1.0 BETA 2 and earlier allow remote attackers to
28RIESGO
abrir ↗
Referência✓ VexDay Proof
Podcast Generator 1.0 Beta 2 - Remote File Inclusion / File Disclosure
CVE-2008-1125—webappsphp
Multiple directory traversal vulnerabilities in Podcast Generator 1.0 BETA 2 and earlier allow remote attackers to read
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PowerTCP FTP Module - Multiple Techniques (SEH HeapSpray)
CVE-2008-4652—remotewindows
Buffer overflow in the ActiveX control (DartFtp.dll) in Dart Communications PowerTCP FTP for ActiveX 2.0.2 0 allows remo
28RIESGO
abrir ↗
Referência✓ VexDay Proof
XOOPS Module makale 0.26 - SQL Injection
CVE-2008-4653—webappsphp
SQL injection vulnerability in makale.php in Makale 0.26 and possibly other versions, a module for XOOPS, allows remote
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Oracle 10g - MDSYS.SDO_TOPO_DROP_FTBL SQL Injection (Metasploit)
CVE-2008-3979—localmultiple
Unspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5 and 10.2.0.2 allows remote authent
50RIESGO
abrir ↗
Referência✓ VexDay Proof
Barryvan Compo Manager 0.3 - Remote File Inclusion
CVE-2008-1126—webappsphp
PHP remote file inclusion vulnerability in main.php in Barryvan Compo Manager 0.3 allows remote attackers to execute arb
28RIESGO
abrir ↗
Referência✓ VexDay Proof
Crysis 1.1.1.5879 - Remote Format String Denial of Service (PoC)
CVE-2008-1127—doswindows
Format string vulnerability in the cryactio function in Crysis 1.1.1.5879 allows remote authenticated users to execute a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SMA-DB 0.3.9 - 'settings.php' Remote File Inclusion
CVE-2007-0797—webappsphp
PHP remote file inclusion vulnerability in theme/settings.php in bluevirus-design SMA-DB 0.3.9 and earlier allows remote
23RIESGO
abrir ↗
Referência✓ VexDay Proof
DESlock+ < 3.2.6 - 'DLMFENC.sys' Local Kernel Ring0 link list zero (PoC)
CVE-2008-1138—doswindows
DLMFENC.sys 1.0.0.26 in DESlock+ 3.2.6 and earlier allows local users to cause a denial of service (system crash) via a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component imagebrowser 0.1.5 rc2 - Directory Traversal
CVE-2008-4668—webappsphp
Directory traversal vulnerability in the Image Browser (com_imagebrowser) 0.1.5 component for Joomla! allows remote atta
43RIESGO
abrir ↗
Referência✓ VexDay Proof
Maian Links 3.1 - Insecure Cookie Handling
CVE-2008-3319—webappsphp
admin/index.php in Maian Links 3.1 and earlier allows remote attackers to bypass authentication and gain administrative
23RIESGO
abrir ↗
Referência✓ VexDay Proof
RedDot CMS 7.5 - 'LngId' SQL Injection
CVE-2008-1613—webappsasp
SQL injection vulnerability in ioRD.asp in RedDot CMS 7.5 Build 7.5.0.48, and possibly other versions including 6.5 and
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Charrays CMS 0.9.3 - Multiple Remote File Inclusions
CVE-2007-6179—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Charray's CMS 0.9.3 allow remote attackers to execute arbitrary PH
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP 'Perl' Extension - 'Safe_mode' Bypass
CVE-2007-4596—localwindows
The perl extension in PHP does not follow safe_mode restrictions, which allows context-dependent attackers to execute ar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SmartFTP Client 2.0.1002 - Remote Heap Overflow Denial of Service
CVE-2007-0790—doswindows
Heap-based buffer overflow in SmartFTP 2.0.1002 allows remote FTP servers to execute arbitrary code via a large banner.
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Web Wiz Guestbook 8.21 - Database Disclosure
CVE-2003-1571—webappsasp
Web Wiz Guestbook 6.0 stores sensitive information under the web root with insufficient access control, which allows rem
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mambo Module Calendar (Agenda) 1.5.5 - Remote File Inclusion
CVE-2007-2049—webappsphp
Multiple PHP remote file inclusion vulnerabilities in the Calendar Module (com_calendar) 1.5.5 for Mambo allow remote at
23RIESGO
abrir ↗
Referência✓ VexDay Proof
yourplace 1.0.2 - Multiple Vulnerabilities / Remote Code Execution
CVE-2008-6771—webappsphp
YourPlace 1.0.2 and earlier allows remote attackers to obtain sensitive system information via a direct request via a di
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Pilot Group eTraining - 'news_read.php' SQL Injection
CVE-2008-4709—webappsphp
SQL injection vulnerability in news_read.php in Pilot Group (PG) eTraining allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
← anteriorpágina 754 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.