Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.004exploits catalogados
38.306CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
acute control panel 1.0.0 - SQL Injection / Remote File Inclusion
CVE-2009-1248—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Acute Control Panel 1.0.0 allow remote attackers to execute arbitr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mini-stream Ripper - '.m3u' Local Stack Overflow (PoC)
CVE-2009-1325—doswindows
Stack-based buffer overflow in Mini-stream Ripper 3.0.1.1 allows remote attackers to execute arbitrary code via a long U
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Vote-Pro 4.0 - 'poll_frame.php?poll_id' Remote Code Execution
CVE-2007-0504—webappsphp
Eval injection vulnerability in poll_frame.php in Vote! Pro 4.0, and possibly other scripts, allows remote attackers to
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Flat PHP Board 1.2 - Multiple Vulnerabilities
CVE-2007-6398—webappsphp
Flat PHP Board 1.2 and earlier allows remote attackers to bypass authentication and obtain limited access to an arbitrar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
RantX 1.0 - Insecure Admin Authentication
CVE-2008-2297—webappsphp
The admin.php file in Rantx allows remote attackers to bypass authentication and gain privileges by setting the logininf
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ADN Forum 1.0b - Insecure Cookie Handling
CVE-2008-6001—webappsphp
index.php in ADN Forum 1.0b and earlier allows remote attackers to bypass authentication and gain sysop access via a fpu
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Acc PHP eMail 1.1 - Insecure Cookie Handling
CVE-2008-6291—webappsphp
Acc PHP eMail 1.1 allows remote attackers to bypass authentication and gain administrative access by setting the NEWSLET
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Pinnacle Studio 12 - '.hfz' Directory Traversal
CVE-2009-1743—localwindows
Directory traversal vulnerability in InstallHFZ.exe 6.5.201.0 in Pinnacle Hollywood Effects 6, a module in Pinnacle Syst
23RIESGO
abrir ↗
Referência✓ VexDay Proof
minimal ablog 0.4 - SQL Injection / Arbitrary File Upload / Authentication Bypass
CVE-2008-6613—webappsphp
uploader.php in minimal-ablog 0.4 does not properly restrict access, which allows remote attackers to gain administrativ
23RIESGO
abrir ↗
Referência✓ VexDay Proof
TurnkeyForms - Text Link Sales Authentication Bypass
CVE-2008-6963—webappsphp
admin.php in TurnkeyForms Text Link Sales allows remote attackers to bypass authentication and gain administrative privi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
EkinBoard 1.1.0 - Arbitrary File Upload / Authentication Bypass
CVE-2008-7157—webappsphp
Unrestricted file upload vulnerability in EkinBoard 1.1.0 and earlier allows remote attackers to execute arbitrary code
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Exjune Officer Message System 1 - Multiple Vulnerabilities
CVE-2009-1752—webappsphp
exJune Office Message System 1 does not properly restrict access to (1) configure.asp and (2) addmessage2.asp, which all
23RIESGO
abrir ↗
Referência✓ VexDay Proof
E RESERV 2.1 - 'index.php' SQL Injection
CVE-2008-1975—webappsphp
SQL injection vulnerability in index.php in E-RESERV 2.1 allows remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Dayfox Blog 4 - 'postpost.php' Remote Code Execution
CVE-2007-1525—webappsphp
Direct static code injection vulnerability in postpost.php in Dayfox Blog (dfblog) 4 allows remote attackers to execute
35RIESGO
abrir ↗
Referência✓ VexDay Proof
PacPoll 4.0 - Database Disclosure
CVE-2008-5981—webappsphp
PacPoll 4.0 stores sensitive information under the web root with insufficient access control, which allows remote attack
23RIESGO
abrir ↗
Referência✓ VexDay Proof
OraMon 2.0.1 - Remote Configuration File Disclosure
CVE-2008-6869—webappsphp
Oramon Oracle Database Monitoring Tool 2.0.1 stores sensitive information under the web root with insufficient access co
23RIESGO
abrir ↗
Referência✓ VexDay Proof
vhostadmin 0.1 - 'MODULES_DIR' Remote File Inclusion
CVE-2007-0558—webappsphp
PHP remote file inclusion vulnerability in modules/mail/main.php in Inter7 vHostAdmin 1.0 allows remote attackers to exe
23RIESGO
abrir ↗
Referência✓ VexDay Proof
webid 0.5.4 - Multiple Vulnerabilities
CVE-2008-7118—webappsphp
WeBid auction script 0.5.4 stores sensitive information under the web root with insufficient access control, which allow
23RIESGO
abrir ↗
Referência✓ VexDay Proof
jGallery 1.3 - 'index.php' Remote File Inclusion
CVE-2007-2158—webappsphp
PHP remote file inclusion vulnerability in index.php in jGallery 1.3 allows remote attackers to execute arbitrary PHP co
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CodeAvalanche FreeForum - Database Disclosure
CVE-2008-5932—webappsasp
CodeAvalanche FreeForum stores sensitive information under the web root with insufficient access control, which allows r
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Squirrelcart 1.x - 'cart.php' Remote File Inclusion
CVE-2007-4439—webappsphp
PHP remote file inclusion vulnerability in popup_window.php in Squirrelcart 1.x.x and earlier allows remote attackers to
23RIESGO
abrir ↗
Referência✓ VexDay Proof
RM Downloader 3.0.0.9 - '.m3u' Universal Stack Overflow
CVE-2009-1326—localwindows
Stack-based buffer overflow in Mini-stream RM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PEEL CMS 3.x - Admin Hash Extraction / Arbitrary File Upload
CVE-2008-1506—webappsphp
PEEL, possibly 3.x and earlier, allows remote attackers to obtain configuration information via a direct request to phpi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WM Downloader 3.0.0.9 - '.m3u' Universal Stack Overflow
CVE-2009-1327—localwindows
Stack-based buffer overflow in Mini-stream WM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Zomplog 3.8.2 - 'newuser.php' Arbitrary Add Admin
CVE-2008-2349—webappsphp
Zomplog 3.8.2 and earlier allows remote attackers to gain administrative access by creating an admin account via a direc
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WebLog - 'index.php' Remote File Disclosure
CVE-2007-1487—webappsphp
Directory traversal vulnerability in index.php in Sascha Schroeder (aka CyberTeddy or Cyber-inside) WebLog allows remote
23RIESGO
abrir ↗
Referência✓ VexDay Proof
DreamAccount 3.1 - 'da_path' Remote File Inclusion
CVE-2006-2881—webappsphp
Multiple PHP remote file inclusion vulnerabilities in DreamAccount 3.1 and earlier, when register_globals is enabled, al
28RIESGO
abrir ↗
Referência✓ VexDay Proof
wbblog - Cross-Site Scripting / SQL Injection
CVE-2007-1482—webappsphp
Cross-site scripting (XSS) vulnerability in index.php in WBBlog allows remote attackers to inject arbitrary web script o
23RIESGO
abrir ↗
Referência✓ VexDay Proof
creative Guestbook 1.0 - Multiple Vulnerabilities
CVE-2007-1480—webappsphp
Creative Guestbook 1.0 allows remote attackers to add an administrative account via a direct request to createadmin.php
23RIESGO
abrir ↗
Referência✓ VexDay Proof
LokiCMS 0.3.4 - 'admin.php' Create Local File Inclusion
CVE-2008-4662—webappsphp
Directory traversal vulnerability in admin.php in LokiCMS 0.3.4, when magic_quotes_gpc is disabled, allows remote attack
23RIESGO
abrir ↗
← anteriorpágina 762 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.