Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.081exploits catalogados
38.339CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
Joomla! Component Jumi - 'fileid' Blind SQL Injection
CVE-2009-2102—webappsphp
SQL injection vulnerability in the Jumi (com_jumi) component 2.0.3 and possibly other versions for Joomla allows remote
23RIESGO
abrir ↗
Referência✓ VexDay Proof
fungamez rc1 - Authentication Bypass / Local File Inclusion
CVE-2009-1487—webappsphp
SQL injection vulnerability in pages/login.php in FunGamez RC1 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PowerBook 1.21 - 'index.php' Local File Inclusion
CVE-2008-1537—webappsphp
Directory traversal vulnerability in pb_inc/admincenter/index.php in PowerScripts PowerBook 1.21 allows remote attackers
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mambo Component com_serverstat 0.4.4 - Remote File Inclusion
CVE-2006-4858—webappsphp
PHP remote file inclusion vulnerability in install.serverstat.php in the Serverstat (com_serverstat) 0.4.4 and earlier c
23RIESGO
abrir ↗
Referência✓ VexDay Proof
FeedMon 2.7.0.0 - outline Tag Buffer Overflow (PoC)
CVE-2009-0546—doswindows
Stack-based buffer overflow in NewsGator FeedDemon 2.7 and earlier allows user-assisted remote attackers to execute arbi
50RIESGO
abrir ↗
Referência✓ VexDay Proof
Vinagre < 2.24.2 - 'show_error()' Remote Format String (PoC)
CVE-2008-5660—doswindows
Format string vulnerability in the vinagre_utils_show_error function (src/vinagre-utils.c) in Vinagre 0.5.x before 0.5.2
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Alstrasoft Web Host Directory - Authentication Bypass
CVE-2008-5650—webappsphp
SQL injection vulnerability in the login directory in AlstraSoft Web Host Directory allows remote attackers to execute a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Real Player - 'rmoc3260.dll' ActiveX Control Remote Code Execution
CVE-2008-1309—remotewindows
The RealAudioObjects.RealAudio ActiveX control in rmoc3260.dll in RealNetworks RealPlayer Enterprise, RealPlayer 10, Rea
50RIESGO
abrir ↗
Referência✓ VexDay Proof
Haberx 1.02 < 1.1 - 'tr' SQL Injection
CVE-2006-4853—webappsasp
SQL injection vulnerability in kategorix.asp in Haberx 1.02 through 1.1 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Referência✓ VexDay Proof
RhinoSoft Serv-U FTP Server 7.3 - (Authenticated) 'stou con:1' Denial of Service
CVE-2008-4500—doswindows
Serv-U 7.0.0.1 through 7.3, including 7.2.0.1, allows remote authenticated users to cause a denial of service (CPU consu
28RIESGO
abrir ↗
Referência✓ VexDay Proof
jPORTAL 2 - 'humor.php' SQL Injection
CVE-2008-6451—webappsphp
SQL injection vulnerability in humor.php in jPORTAL 2 allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Multi-Page Comment System 1.1.0 - Insecure Cookie Handling
CVE-2008-2293—webappsphp
admin.php in Multi-Page Comment System (MPCS) 1.0 and 1.1 allows remote attackers to bypass authentication and gain priv
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Galatolo Web Manager 1.0 - SQL Injection
CVE-2008-2700—webappsphp
SQL injection vulnerability in view.php in Galatolo WebManager 1.0 and earlier allows remote attackers to execute arbitr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
AyeView 2.20 - Invalid Bitmap Header Parsing Crash
CVE-2008-5937—doswindows
AyeView 2.20 allows user-assisted attackers to cause a denial of service (memory consumption or application crash) via a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
easyLink 1.1.0 - 'detail.php' SQL Injection
CVE-2008-6471—webappsphp
SQL injection vulnerability in detail.php in MountainGrafix easyLink 1.1.0 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
XOOPS Module myTopics - 'articleId' SQL Injection
CVE-2008-0847—webappsphp
SQL injection vulnerability in print.php in the myTopics module for XOOPS allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗
Referência✓ VexDay Proof
phpBB Plus 1.53 - 'phpbb_root_path' Remote File Inclusion
CVE-2007-5009—webappsphp
PHP remote file inclusion vulnerability in language/lang_german/lang_main_album.php in phpBB Plus 1.53, and 1.53a before
35RIESGO
abrir ↗
Referência✓ VexDay Proof
jetAudio 7.x - ActiveX 'DownloadFromMusicStore()' Code Execution
CVE-2007-4983—remotewindows
Directory traversal vulnerability in the JetAudio.Interface.1 ActiveX control in JetFlExt.dll in jetAudio 7.0.3 Basic an
35RIESGO
abrir ↗
Referência✓ VexDay Proof
Active Trade 2 - Authentication Bypass
CVE-2008-5627—webappsasp
SQL injection vulnerability in account.asp in Active Trade 2 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗
Referência✓ VexDay Proof
My Simple Forum 3.0 - Local File Inclusion
CVE-2008-5604—webappsphp
Directory traversal vulnerability in index.php in My Simple Forum 3.0 and 4.1, when magic_quotes_gpc is disabled, allows
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Tribiq CMS 5.0.9a (Beta) - Insecure Cookie Handling
CVE-2008-6804—webappsphp
Tribiq CMS 5.0.9a beta allows remote attackers to bypass authentication and gain administrative access by setting the CO
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MW6 Technologies QRCode ActiveX 3.0 - Remote File Overwrite
CVE-2007-4982—remotewindows
Multiple absolute path traversal vulnerabilities in the MW6QRCode.QRCode.1 ActiveX control in MW6QRCode.dll in MW6 Techn
28RIESGO
abrir ↗
Referência✓ VexDay Proof
Prozilla Pub Site Directory - 'Directory.php?cat' SQL Injection
CVE-2007-4258—webappsphp
SQL injection vulnerability in directory.php in Prozilla Pub Site Directory allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Merlix Teamworx Server - File Disclosure/Bypass
CVE-2008-5599—webappsphp
SQL injection vulnerability in default.asp in Merlix Teamworx Server allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗
Referência✓ VexDay Proof
mcGalleryPRO 2006 - 'path_to_folder' Remote File Inclusion
CVE-2006-4720—webappsphp
PHP remote file inclusion vulnerability in random2.php in mcGalleryPRO 2006 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
nightfall personal diary 1.0 - Cross-Site Scripting / File Disclosure
CVE-2008-5591—webappsphp
Cross-site scripting (XSS) vulnerability in login.asp in Nightfall Personal Diary 1.0 allows remote attackers to inject
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Product Sale Framework 0.1b - SQL Injection
CVE-2008-5590—webappsphp
SQL injection vulnerability in customer.forumtopic.php in Kalptaru Infotech Product Sale Framework 0.1 beta allows remot
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Web Oddity Web Server 0.09b - Directory Traversal
CVE-2007-4726—remotelinux
Directory traversal vulnerability in Web Oddity 0.09b allows remote attackers to read arbitrary files via a .. (dot dot)
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SiteBuilderElite 1.2 - Multiple Remote File Inclusions
CVE-2008-1123—webappsphp
Multiple PHP remote file inclusion vulnerabilities in SiteBuilder Elite 1.2 allow remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component GameQ 4.0 - SQL Injection
CVE-2008-2701—webappsphp
SQL injection vulnerability in the GameQ (com_gameq) component 4.0 and earlier for Joomla! allows remote attackers to ex
23RIESGO
abrir ↗
← anteriorpágina 779 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.