Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.004exploits catalogados
38.306CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
PHP Webquest 2.6 - Get Database Credentials
CVE-2008-0249—webappsphp
PHP Webquest 2.6 allows remote attackers to retrieve database credentials via a direct request to admin/backup_phpwebque
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Talkback 2.3.6 - Multiple Local File Inclusion / PHPInfo Disclosure Vulnerabilities
CVE-2008-4115—webappsphp
TalkBack 2.3.6 allows remote attackers to obtain configuration information via a direct request to install/info.php, whi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PowerStrip 3.84 - 'pstrip.sys' Local Privilege Escalation
CVE-2008-5725—localwindows
The NT kernel-mode driver (aka pstrip.sys) 5.0.1.1 and earlier in EnTech Taiwan PowerStrip 3.84 and earlier allows local
23RIESGO
abrir ↗
Referência✓ VexDay Proof
eLineStudio Site Composer (ESC) 2.6 - Multiple Vulnerabilities
CVE-2008-2863—webappsphp
Multiple absolute path traversal vulnerabilities in eLineStudio Site Composer (ESC) 2.6 allow remote attackers to create
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Nukedit 4.9.8 - Remote Database Disclosure
CVE-2008-5773—webappsasp
Nukedit 4.9.8 stores sensitive information under the web root with insufficient access control, which allows remote atta
23RIESGO
abrir ↗
Referência✓ VexDay Proof
HotScripts Clone Script - SQL Injection
CVE-2007-6084—webappsphp
SQL injection vulnerability in software-description.php in HotScripts Clone Script allows remote attackers to execute ar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joovili 3.1.4 - Insecure Cookie Handling
CVE-2008-6269—webappsphp
Joovili 3.1.4 allows remote attackers to bypass authentication and gain privileges as other users, including the adminis
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Free PHP VX Guestbook 1.06 - Insecure Cookie Handling
CVE-2008-7007—webappsphp
Free PHP VX Guestbook 1.06 allows remote attackers to bypass authentication and gain administrative access by setting th
23RIESGO
abrir ↗
Referência✓ VexDay Proof
XOOPS Module xhresim - SQL Injection
CVE-2008-5665—webappsphp
SQL injection vulnerability in index.php in the xhresim module in XOOPS allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Woltlab Burning Board 1.0.2/2.3.6 - 'search.php' SQL Injection (2)
CVE-2007-0388—webappsphp
SQL injection vulnerability in search.php in Woltlab Burning Board (wBB) 1.0.2 and earlier, and 2.3.6 and earlier in the
23RIESGO
abrir ↗
Referência✓ VexDay Proof
e-Ark 1.0 - '/src/ark_inc.php' Remote File Inclusion
CVE-2006-6086—webappsphp
PHP remote file inclusion vulnerability in src/ark_inc.php in e-Ark 1.0 allows remote attackers to execute arbitrary PHP
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MyioSoft EasyCalendar - Authentication Bypass
CVE-2008-5654—webappsphp
SQL injection vulnerability in the loginADP function in ajaxp.php in MyioSoft EasyCalendar 4.0 allows remote attackers t
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Campsite 3.3.0 RC1 - Multiple Remote File Inclusions
CVE-2009-2181—webappsphp
Cross-site scripting (XSS) vulnerability in admin-files/templates/list_dir.php in Campsite 3.3.0 RC1 allows remote attac
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP Live Helper 2.0.1 - Multiple Vulnerabilities
CVE-2008-3763—webappsphp
Variable overwrite vulnerability in libsecure.php in Turnkey PHP Live Helper 2.0.1 and earlier, when register_globals is
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Active Membership 2 - Authentication Bypass
CVE-2008-5635—webappsasp
SQL injection vulnerability in account.asp in Active Membership 2.0 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗
Referência✓ VexDay Proof
XMPlay 3.3.0.4 - '.M3U' Filename Local Buffer Overflow
CVE-2006-6063—localwindows
Stack-based buffer overflow in Un4seen XMPlay 3.3.0.5 and earlier allows remote attackers to execute arbitrary code via
50RIESGO
abrir ↗
Referência✓ VexDay Proof
TlGuestBook 1.2 - Insecure Cookie Handling
CVE-2008-5065—webappsphp
TlGuestBook 1.2 allows remote attackers to bypass authentication and gain administrative access by setting the tlGuestBo
23RIESGO
abrir ↗
Referência✓ VexDay Proof
mini-pub 0.3 - Local Directory Traversal / File Disclosure
CVE-2008-5883—webappsphp
Absolute path traversal vulnerability in front-end/dir.php in mini-pub 0.3 and earlier allows remote attackers to list a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
nuseo PHP enterprise 1.6 - Remote File Inclusion
CVE-2007-5409—webappsphp
PHP remote file inclusion vulnerability in admin/nuseo_admin_d.php in NuSEO PHP Enterprise 1.6 (NuSEO.PHP), when registe
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Microsoft Office - MSODataSourceControl COM-object Buffer Overflow (PoC)
CVE-2007-3282—doswindows
Buffer overflow in the Microsoft Office MSODataSourceControl ActiveX object allows remote attackers to cause a denial of
35RIESGO
abrir ↗
Referência✓ VexDay Proof
EncapsCMS 0.3.6 - '/core/core.php' Remote File Inclusion
CVE-2006-5895—webappsphp
PHP remote file inclusion vulnerability in core/core.php in EncapsCMS 0.3.6 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Crux Gallery 1.32 - Insecure Cookie Handling
CVE-2008-4484—webappsphp
main.php in Crux Gallery 1.32 and earlier allows remote attackers to gain administrative access by setting the name para
23RIESGO
abrir ↗
Referência✓ VexDay Proof
tbdev 01-01-2008 - Multiple Vulnerabilities
CVE-2009-2138—webappsphp
Multiple open redirect vulnerabilities in TBDev.NET 01-01-08 allow remote attackers to redirect users to arbitrary web s
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Profense Web Application Firewall 2.6.2 - Cross-Site Request Forgery / Cross-Site Scripting
CVE-2009-0467—remotewindows
Cross-site scripting (XSS) vulnerability in proxy.html in Profense Web Application Firewall 2.6.2 and 2.6.3 allows remot
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Enthusiast 3.1.4 - 'show_joined.php' Remote File Inclusion
CVE-2008-5792—webappsphp
PHP remote file inclusion vulnerability in show_joined.php in Indiscripts Enthusiast 3.1.4, and possibly earlier, allows
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Xcode OpenBase 10.0.0 (OSX) - Unsafe System Call Privilege Escalation
CVE-2006-5852—localosx
Untrusted search path vulnerability in openexec in OpenBase SQL before 10.0.1 allows local users to gain privileges via
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Xcode OpenBase 10.0.0 (OSX) - Symlink Privilege Escalation
CVE-2006-5851—localosx
openexec in OpenBase SQL before 10.0.1 allows local users to create arbitrary files via a symlink attack on the /tmp/out
23RIESGO
abrir ↗
Referência✓ VexDay Proof
IceBB 1.0-rc5 - Remote Code Execution
CVE-2007-1726—webappsphp
Unrestricted file upload vulnerability in index.php in IceBB 1.0-rc5 allows remote authenticated users to upload arbitra
23RIESGO
abrir ↗
Referência✓ VexDay Proof
TurnkeyForms Local Classifieds - Authentication Bypass
CVE-2008-6302—webappsphp
TurnkeyForms Local Classifieds allows remote attackers to bypass authentication and gain administrative access via a dir
23RIESGO
abrir ↗
Referência✓ VexDay Proof
AJ Auction - Authentication Bypass
CVE-2008-6965—webappsphp
AJ Square AJ Auction OOPD, Pro Platinum Skin #1, Pro Platinum Skin #2, and Web 2.0 send a redirect but do not exit when
23RIESGO
abrir ↗
← anteriorpágina 755 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.