Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.081exploits catalogados
38.339CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
AdaptCMS Lite 1.3 - Blind SQL Injection
CVE-2008-4524—webappsphp
SQL injection vulnerability in the "Check User" feature (includes/check_user.php) in AdaptCMS Lite and AdaptCMS Pro 1.3
23RIESGO
abrir ↗
Referência✓ VexDay Proof
DoSePa 1.0.4 - 'textview.php' Information Disclosure
CVE-2006-6028—webappsphp
Directory traversal vulnerability in textview.php in Anton Vlasov DoSePa 1.0.4 allows remote attackers to read arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
XOOPS Module Tutoriais - 'viewcat.php' SQL Injection
CVE-2007-1816—webappsphp
SQL injection vulnerability in viewcat.php in the Tutoriais module for Xoops allows remote attackers to execute arbitrar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
phpDatingClub 3.7 - SQL Injection / Cross-Site Scripting Injection
CVE-2009-2178—webappsphp
Cross-site scripting (XSS) vulnerability in website.php in phpDatingClub 3.7 allows remote attackers to inject arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
BT-sondage 1.12 - 'gestion_sondage.php' Remote File Inclusion
CVE-2007-1812—webappsphp
PHP remote file inclusion vulnerability in utilitaires/gestion_sondage.php in BT-Sondage 112 allows remote attackers to
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WinAsm Studio 5.1.5.0 - Local Heap Overflow (PoC)
CVE-2009-1040—doswindows
Buffer overflow in WinAsm Studio 5.1.5.0 allows user-assisted remote attackers to execute arbitrary code via a crafted p
23RIESGO
abrir ↗
Referência✓ VexDay Proof
AAA EasyGrid ActiveX 3.51 - Remote File Overwrite
CVE-2009-0134—remotewindows
Insecure method vulnerability in the EasyGrid.SGCtrl.32 ActiveX control in EasyGrid.ocx 1.0.0.1 in AAA EasyGrid ActiveX
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Devalcms 1.4a - Cross-Site Scripting / Remote Code Execution
CVE-2008-6982—webappsphp
Cross-site scripting (XSS) vulnerability in index.php in devalcms 1.4a allows remote attackers to inject arbitrary web s
38RIESGO
abrir ↗
Referência✓ VexDay Proof
Md-Pro 1.0.8x - Topics topicid SQL Injection
CVE-2007-3938—webappsphp
SQL injection vulnerability in index.php in MAXdev MDPro (MD-Pro) 1.0.8x and earlier before 20070720 allows remote attac
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MailMachine Pro 2.2.4 - SQL Injection
CVE-2007-6551—webappsphp
SQL injection vulnerability in showMsg.php in MailMachine Pro 2.2.4, and other versions before 2.2.6, allows remote atta
23RIESGO
abrir ↗
Referência✓ VexDay Proof
asg-sentry 7.0.0 - Multiple Vulnerabilities
CVE-2008-1320—dosmultiple
Multiple buffer overflows in ASG-Sentry Network Manager 7.0.0 and earlier allow remote attackers to execute arbitrary co
28RIESGO
abrir ↗
Referência✓ VexDay Proof
TUTOS 1.3 - 'cmd.php' Remote Command Execution
CVE-2008-0148—webappsphp
TUTOS 1.3 does not restrict access to php/admin/cmd.php, which allows remote attackers to execute arbitrary shell comman
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Myspace Clone Script - 'index.php' Remote File Inclusion
CVE-2007-6057—webappsphp
PHP remote file inclusion vulnerability in index.php in datecomm Social Networking Script (aka Myspace Clone Script) all
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mambo Component SMF Forum 1.3.1.3 - Remote File Inclusion
CVE-2006-3773—webappsphp
PHP remote file inclusion vulnerability in smf.php in the SMF-Forum 1.3.1.3 Bridge Component (com_smf) For Joomla! and M
23RIESGO
abrir ↗
Referência✓ VexDay Proof
DataLife Engine 4.1 - SQL Injection
CVE-2006-3221—webappsphp
SQL injection vulnerability in index.php in DataLife Engine 4.1 and earlier allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MyioSoft EasyBookMarker 4.0 - Authentication Bypass
CVE-2008-5652—webappsphp
SQL injection vulnerability in the loginADP function in ajaxp.php in MyioSoft EasyBookMarker 4.0 allows remote attackers
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Goople 1.8.2 - 'FrontPage.php' Blind SQL Injection
CVE-2009-0111—webappsphp
SQL injection vulnerability in frontpage.php in Goople CMS 1.8.2 and earlier allows remote attackers to execute arbitrar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
AsteriDex 3.0 - 'callboth.php' Remote Code Execution
CVE-2007-3621—webappsphp
Multiple CRLF injection vulnerabilities in callboth.php in AsteriDex 3.0 and earlier allow remote attackers to inject ar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ProfileCMS 1.0 - 'id' SQL Injection
CVE-2007-6058—webappsphp
Multiple SQL injection vulnerabilities in index.php in ProfileCMS 1.0 and earlier allow remote attackers to execute arbi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Microsoft Internet Explorer 6 / Provideo Camimage - 'ISSCamControl.dll 1.0.1.5' Remote Buffer Overflow
CVE-2007-3111—remotewindows
Buffer overflow in the Provideo Camimage ActiveX control in ISSCamControl.dll 1.0.1.5, when Internet Explorer 6 is used
35RIESGO
abrir ↗
Referência✓ VexDay Proof
Exhibit Engine 1.5 RC 4 - 'photo_comment.php' File Inclusion
CVE-2006-5292—webappsphp
PHP remote file inclusion vulnerability in photo_comment.php in Exhibit Engine 1.5 RC 4 and earlier allows remote attack
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CMS Made Simple 1.2.2 Module TinyMCE - SQL Injection
CVE-2007-6656—webappsphp
SQL injection vulnerability in content_css.php in the TinyMCE module for CMS Made Simple 1.2.2 and earlier allows remote
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ezpack 4.2b2 - Cross-Site Scripting / SQL Injection
CVE-2009-0104—webappsphp
SQL injection vulnerability in index.php in EZpack 4.2b2 allows remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHPEasyData 1.5.4 - 'cat_id' SQL Injection
CVE-2008-2113—webappsphp
SQL injection vulnerability in annuaire.php in PHPEasyData 1.5.4 allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗
Referência✓ VexDay Proof
DVD X Player 4.1 Professional - '.PLF' File Buffer Overflow
CVE-2007-3068—localwindows
Stack-based buffer overflow in DVD X Player 4.1 Professional allows remote attackers to execute arbitrary code via a PLF
50RIESGO
abrir ↗
Referência✓ VexDay Proof
Active Trade 2 - 'catid' SQL Injection
CVE-2007-1705—webappsasp
SQL injection vulnerability in default.asp in Active Trade 2 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Brim 2.0.0 - SQL Injection / Cross-Site Scripting
CVE-2008-4083—webappsphp
Cross-site scripting (XSS) vulnerability in the Bookmarks plugin in Brim 2.0 allows remote authenticated users to inject
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Microsoft Internet Explorer 7 (Windows 2003 SP2) - Memory Corruption (MS09-002)
CVE-2009-0075—remotewindows
Microsoft Internet Explorer 7 does not properly handle errors during attempted access to deleted objects, which allows r
60RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component Community Builder 1.0.1 - Blind SQL Injection
CVE-2008-2093—webappsphp
SQL injection vulnerability in the Profiler (com_comprofiler) component in Community Builder for Mambo and Joomla! allow
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Microsoft FoxServer - 'vfp6r.dll 6.0.8862.0' ActiveX Command Execution
CVE-2008-0236—remotewindows
An ActiveX control for Microsoft Visual FoxPro (vfp6r.dll 6.0.8862.0) allows remote attackers to execute arbitrary comma
28RIESGO
abrir ↗
← anteriorpágina 773 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.