Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.046exploits catalogados
38.339CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
S-CMS 1.1 Stable - Insecure Cookie Handling / Mass Page Delete
CVE-2009-0864—webappsphp
S-Cms 1.1 Stable allows remote attackers to bypass authentication and obtain administrative access via an OK value for t
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Trawler Web CMS 1.8.1 - Multiple Remote File Inclusions
CVE-2006-5495—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Trawler Web CMS 1.8.1 and earlier allow remote attackers to execut
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ID Automation Linear Barcode - ActiveX Denial of Service
CVE-2007-2658—doswindows
Unspecified vulnerability in the ID Automation Linear Barcode 1.6.0.5 ActiveX control in IDAutomationLinear6.dll allows
23RIESGO
abrir ↗
Referência✓ VexDay Proof
GeekLog 2.x - 'ImageImageMagick.php' Remote File Inclusion
CVE-2007-2793—webappsphp
PHP remote file inclusion vulnerability in ImageImageMagick.php in Geeklog 2.x allows remote attackers to execute arbitr
35RIESGO
abrir ↗
Referência✓ VexDay Proof
K&S Shopsysteme - Arbitrary File Upload
CVE-2008-6768—webappsphp
Unrestricted file upload vulnerability in admin/editor/images.php in K&S Shopsoftware allows remote attackers to execute
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Alstrasoft Live Support 1.21 - Admin Credential Retrieve
CVE-2007-2775—webappsphp
AlstraSoft Live Support 1.21 sends a redirect to the web browser but does not exit when administrative credentials are m
23RIESGO
abrir ↗
Referência✓ VexDay Proof
DBGuestbook 1.1 - 'dbs_base_path' Remote File Inclusion
CVE-2007-1165—webappsphp
Multiple PHP remote file inclusion vulnerabilities in DBGuestbook 1.1 allow remote attackers to execute arbitrary PHP co
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Acoustica MP3 CD Burner 4.32 - Local Buffer Overflow (PoC)
CVE-2007-3006—doswindows
Buffer overflow in Acoustica MP3 CD Burner 4.32 allows user-assisted remote attackers to execute arbitrary code via a .a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Ext 1.0 - 'feed-proxy.php?feed' Remote File Disclosure
CVE-2007-2285—webappsphp
Directory traversal vulnerability in examples/layout/feed-proxy.php in Jack Slocum Ext 1.0 alpha1 (Ext JS) allows remote
28RIESGO
abrir ↗
Referência✓ VexDay Proof
OtsTurntables 1.00 - '.m3u' Local Buffer Overflow
CVE-2007-4734—localwindows
Buffer overflow in Ots Labs OTSTurntables 1.00 allows user-assisted remote attackers to execute arbitrary code via a lon
23RIESGO
abrir ↗
Referência✓ VexDay Proof
5 star review - Cross-Site Scripting / SQL Injection
CVE-2008-3779—webappsphp
Cross-site scripting (XSS) vulnerability in search/index.php in Five Star Review Script allows remote attackers to injec
23RIESGO
abrir ↗
Referência✓ VexDay Proof
EasyNews 40tr - SQL Injection / Cross-Site Scripting / Local File Inclusion
CVE-2008-1651—webappsphp
Directory traversal vulnerability in admin/login.php in EasyNews 4.0 allows remote attackers to include and execute arbi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
gapicms 9.0.2 - 'dirDepth' Remote File Inclusion
CVE-2008-3183—webappsphp
PHP remote file inclusion vulnerability in ktmlpro/includes/ktedit/toolbar.php in gapicms 9.0.2 allows remote attackers
23RIESGO
abrir ↗
Referência✓ VexDay Proof
HIOX Random Ad 1.3 - Remote File Inclusion
CVE-2008-3401—webappsphp
PHP remote file inclusion vulnerability in hioxRandomAd.php in HIOX Random Ad (HRA) 1.3 allows remote attackers to execu
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Hotel Reservation System - 'city.asp' Blind SQL Injection
CVE-2008-4204—webappsasp
SQL injection vulnerability in city.asp in SoftAcid Hotel Reservation System (HRS) allows remote attackers to execute ar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Feindt Computerservice News 2.0 - 'newsadmin.php?action' Remote File Inclusion
CVE-2007-2708—webappsphp
PHP remote file inclusion vulnerability in newsadmin.php in Feindt Computerservice News (News-Script) 2.0 allows remote
35RIESGO
abrir ↗
Referência✓ VexDay Proof
Sponge News 2.2 - 'sndir' Remote File Inclusion
CVE-2006-4647—webappsphp
PHP remote file inclusion vulnerability in news.php in Sponge News 2.2 and earlier allows remote attackers to execute ar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
linksnet newsfeed 1.0 - Remote File Inclusion
CVE-2007-2707—webappsphp
PHP remote file inclusion vulnerability in linksnet_linkslog_rss.php in Linksnet Newsfeed 1.0 allows remote attackers to
35RIESGO
abrir ↗
Referência✓ VexDay Proof
PHPBasket - 'pro_id' SQL Injection
CVE-2008-3713—webappsphp
SQL injection vulnerability in product.php in PHPBasket allows remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir ↗
Referência✓ VexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
CVE-2007-6500—webappsasp
Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to delete
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Censura 1.15.04 - 'censura.php?vendorid' SQL Injection
CVE-2007-2673—webappsphp
SQL injection vulnerability in includes/funcs_vendors.php in Censura 1.15.04, and other versions before 1.16.04, allows
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Dyncms Release 6 - 'x_admindir' Remote File Inclusion
CVE-2006-4589—webappsphp
PHP remote file inclusion vulnerability in 0_admin/modules/Wochenkarte/frontend/index.php in DynCMS 6 and earlier allows
23RIESGO
abrir ↗
Referência✓ VexDay Proof
BitsCast 0.13.0 - invalid string Remote Denial of Service
CVE-2007-2726—doswindows
BitsCast 0.13.0 allows remote attackers to cause a denial of service (application crash) via an RSS 2.0 feed item with c
23RIESGO
abrir ↗
Referência✓ VexDay Proof
webSPELL 4.2.0e - 'page' Blind SQL Injection
CVE-2009-1912—webappsphp
Directory traversal vulnerability in src/func/language.php in webSPELL 4.2.0e and earlier allows remote attackers to inc
23RIESGO
abrir ↗
Referência✓ VexDay Proof
YapBB 1.2 - 'forumID' Blind SQL Injection
CVE-2009-0768—webappsphp
SQL injection vulnerability in forumhop.php in YapBB 1.2 and earlier allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗
Referência✓ VexDay Proof
mUnky 0.0.1 - 'zone' Local File Inclusion
CVE-2008-2876—webappsphp
Directory traversal vulnerability in index.php in mUnky 0.0.1 allows remote attackers to include and execute arbitrary l
23RIESGO
abrir ↗
Referência✓ VexDay Proof
eZip Wizard 3.0 - Local Stack Buffer Overflow (PoC) (SEH)
CVE-2009-1058—doswindows
Stack-based buffer overflow in ZipGenius might allow remote attackers to execute arbitrary code via a crafted .zip file
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP FirstPost 0.1 - 'block.php?Include' Remote File Inclusion
CVE-2007-2665—webappsphp
PHP remote file inclusion vulnerability in block.php in PhpFirstPost 0.1 allows remote attackers to execute arbitrary PH
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Microsoft Windows Server 2000 SP4 (Advanced Server) - Message Queue (MS07-065)
CVE-2007-3039—remotewindows
Stack-based buffer overflow in the Microsoft Message Queuing (MSMQ) service in Microsoft Windows 2000 Server SP4, Window
50RIESGO
abrir ↗
Referência✓ VexDay Proof
events Calendar 1.1 - Remote File Inclusion
CVE-2008-4673—webappsphp
PHP remote file inclusion vulnerability in panel/common/theme/default/header_setup.php in WebBiscuits Software Events Ca
23RIESGO
abrir ↗
← anteriorpágina 771 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.