Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.081exploits catalogados
38.339CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
Mambo Component zOOm Media Gallery 2.5 Beta 2 - Remote File Inclusion
CVE-2007-1992—webappsphp
Multiple PHP remote file inclusion vulnerabilities in the com_zoom 2.5 beta 2 and earlier module for Mambo allow remote
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Thickbox Gallery 2.0 - 'Admins.php' Admin Data Disclosure
CVE-2008-3859—webappsphp
Davlin Thickbox Gallery 2 allows remote attackers to obtain the administrative username and MD5 password hash via a dire
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP Photo Gallery 1.0 - 'photo_id' SQL Injection
CVE-2008-1711—webappsphp
Terong PHP Photo Gallery (aka Advanced Web Photo Gallery) 1.0 stores passwords in cleartext in a MySQL database, which a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Hex Workshop 5.1.4 - Color Mapping File Local Buffer Overflow (PoC)
CVE-2008-5756—doswindows
Buffer overflow in BreakPoint Software Hex Workshop 5.1.4 allows user-assisted attackers to cause a denial of service an
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Acidcat CMS 3.4.1 - Multiple Vulnerabilities
CVE-2008-1990—webappsphp
Multiple SQL injection vulnerabilities in Acidcat CMS 3.4.1 allow remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component com_pccookbook - 'recipe_id' Blind SQL Injection
CVE-2009-0329—webappsphp
SQL injection vulnerability in the PcCookBook (com_pccookbook) component for Joomla! allows remote attackers to execute
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Pakupaku CMS 0.4 - Arbitrary File Upload / Local File Inclusion
CVE-2007-4640—webappsphp
Unrestricted file upload vulnerability in index.php in Pakupaku CMS 0.4 and earlier allows remote attackers to upload an
23RIESGO
abrir ↗
Referência✓ VexDay Proof
LeadTools Raster Thumbnail Object Library - 'LTRTM14e.dll' Remote Buffer Overflow
CVE-2007-2787—remotewindows
Stack-based buffer overflow in the BrowseDir function in the (1) lttmb14E.ocx or (2) LTRTM14e.DLL ActiveX control in Lea
23RIESGO
abrir ↗
Referência✓ VexDay Proof
nightfall personal diary 1.0 - Cross-Site Scripting / File Disclosure
CVE-2008-5592—webappsphp
Nightfall Personal Diary 1.0 stores sensitive information under the web root with insufficient access control, which all
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SubEdit Player build 4066 - subtitle Buffer Overflow (PoC)
CVE-2008-1973—doswindows
Heap-based buffer overflow in SubEdit Player build 4056 and 4066 allows remote attackers to cause a denial of service (c
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Exjune Officer Message System 1 - Multiple Vulnerabilities
CVE-2009-1752—webappsphp
exJune Office Message System 1 does not properly restrict access to (1) configure.asp and (2) addmessage2.asp, which all
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SiteDepth CMS 3.44 - 'ShowImage.php?name' File Disclosure
CVE-2007-3404—webappsphp
Directory traversal vulnerability in ShowImage.php in SiteDepth CMS 3.44 allows remote attackers to read arbitrary files
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Kusaba 1.0.4 - Remote Code Execution (1)
CVE-2008-5663—webappsphp
Multiple unrestricted file upload vulnerabilities in Kusaba 1.0.4 and earlier allow remote authenticated users to execut
23RIESGO
abrir ↗
Referência✓ VexDay Proof
BS.Player 2.34 Build 980 - '.bsl' Local Buffer Overflow (SEH)
CVE-2009-1068—localwindows
Stack-based buffer overflow in BS.Player (bsplayer) 2.32 Build 975 Free and 2.34 Build 980 PRO and earlier allows remote
28RIESGO
abrir ↗
Referência✓ VexDay Proof
DM FileManager 3.9.2 - Insecure Cookie Handling
CVE-2009-2025—webappsphp
admin/login.php in DM FileManager 3.9.2 allows remote attackers to bypass authentication and gain administrative access
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CuteNews aj-fork 167f - 'cutepath' Remote File Inclusion
CVE-2006-6546—webappsphp
PHP remote file inclusion vulnerability in inc/shows.inc.php in cutenews aj-fork (CN:AJ) 167f and earlier allows remote
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Microsoft Internet Explorer - XML Parsing Remote Buffer Overflow
CVE-2008-4844—remotewindows
Use-after-free vulnerability in the CRecordInstance::TransferToDestination function in mshtml.dll in Microsoft Internet
50RIESGO
abrir ↗
Referência✓ VexDay Proof
TurnkeyForms - Text Link Sales Authentication Bypass
CVE-2008-6963—webappsphp
admin.php in TurnkeyForms Text Link Sales allows remote attackers to bypass authentication and gain administrative privi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
minimal ablog 0.4 - SQL Injection / Arbitrary File Upload / Authentication Bypass
CVE-2008-6613—webappsphp
uploader.php in minimal-ablog 0.4 does not properly restrict access, which allows remote attackers to gain administrativ
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Acc PHP eMail 1.1 - Insecure Cookie Handling
CVE-2008-6291—webappsphp
Acc PHP eMail 1.1 allows remote attackers to bypass authentication and gain administrative access by setting the NEWSLET
23RIESGO
abrir ↗
Referência✓ VexDay Proof
FlexCell Grid Control 5.6.9 - Remote File Overwrite
CVE-2009-0301—remotewindows
Multiple insecure method vulnerabilities in the FlexCell.Grid ActiveX control (FlexCell.ocx) in FlexCell Grid Control 5.
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Comdev News Publisher 4.1.2 - SQL Injection
CVE-2008-1872—webappsphp
SQL injection vulnerability in home.news.php in Comdev News Publisher 4.1.2 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Links Directory 1.1 - 'cat_id' SQL Injection
CVE-2008-1871—webappsphp
SQL injection vulnerability in links.php in Scriptsagent.com Links Directory 1.1 allows remote authenticated users to ex
23RIESGO
abrir ↗
Referência✓ VexDay Proof
RantX 1.0 - Insecure Admin Authentication
CVE-2008-2297—webappsphp
The admin.php file in Rantx allows remote attackers to bypass authentication and gain privileges by setting the logininf
23RIESGO
abrir ↗
Referência✓ VexDay Proof
DMXReady Classified Listings Manager 1.1 - SQL Injection
CVE-2009-0426—webappsasp
SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Classified Listings Manager 1.1 and
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Barman 0.0.1r3 - 'Interface.php' Remote File Inclusion
CVE-2006-6611—webappsphp
PHP remote file inclusion vulnerability in interface.php in Barman 0.0.1r3 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
HIOX GUEST BOOK (HGB) 4.0 - Remote Code Execution
CVE-2007-1998—webappsphp
Direct static code injection vulnerability in HIOX Guest Book (HGB) 4.0 allows remote attackers to inject arbitrary PHP
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ADN Forum 1.0b - Insecure Cookie Handling
CVE-2008-6001—webappsphp
index.php in ADN Forum 1.0b and earlier allows remote attackers to bypass authentication and gain sysop access via a fpu
23RIESGO
abrir ↗
Referência✓ VexDay Proof
JMweb - 'src' Local File Inclusion
CVE-2008-4522—webappsphp
Multiple directory traversal vulnerabilities in JMweb MP3 Music Audio Search and Download Script allow remote attackers
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Blog PixelMotion - 'categorie' SQL Injection
CVE-2008-1867—webappsphp
SQL injection vulnerability in Blog Pixel Motion (aka Blog PixelMotion) allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
← anteriorpágina 775 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.