Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.081exploits catalogados
38.339CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
32bit FTP (09.04.24) - 'CWD Response' Remote Buffer Overflow
CVE-2009-1611—remotewindows_x86
Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
32bit FTP (09.04.24) - 'CWD Response' Universal Overwrite (SEH)
CVE-2009-1611—remotewindows_x86
Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP Photo Album 0.8b - 'preview' Local File Inclusion
CVE-2009-0423—webappsphp
Directory traversal vulnerability in index.php in Php Photo Album (PHPPA) 0.8 BETA allows remote attackers to include an
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Active Test 2.1 - 'QuizID' Blind SQL Injection
CVE-2008-5958—webappsasp
Multiple SQL injection vulnerabilities in Active Test 2.1 allow remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Paristemi 0.8.3b - 'buycd.php' Remote File Inclusion
CVE-2006-6739—webappsphp
PHP remote file inclusion vulnerability in buycd.php in Paristemi 0.8.3 allows remote attackers to execute arbitrary PHP
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SmartSiteCMS 1.0 - Blind SQL Injection
CVE-2009-0405—webappsphp
SQL injection vulnerability in articles.php in smartSite CMS 1.0 allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Netartmedia Car Portal 1.0 - Authentication Bypass
CVE-2009-0395—webappsphp
SQL injection vulnerability in the login feature in NetArt Media Car Portal 1.0 allows remote attackers to execute arbit
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component RSfiles 1.0.2 - 'path' File Download
CVE-2007-4504—webappsphp
Directory traversal vulnerability in index.php in the RSfiles component (com_rsfiles) 1.0.2 and earlier for Joomla! allo
38RIESGO
abrir ↗
Referência✓ VexDay Proof
cwmVote 1.0 - 'archive.php' Remote File Inclusion
CVE-2006-6732—webappsphp
PHP remote file inclusion vulnerability in archive.php in cwmVote 1.0 allows remote attackers to execute arbitrary PHP c
23RIESGO
abrir ↗
Referência✓ VexDay Proof
No-IP DUC 2.1.7 - Remote Code Execution
CVE-2008-5297—remotelinux
Buffer overflow in No-IP DUC 2.1.7 and earlier allows remote HTTP servers to execute arbitrary code via a crafted respon
28RIESGO
abrir ↗
Referência✓ VexDay Proof
BolinTech DreamFTP Server 1.0.2 - 'PORT' Remote Denial of Service
CVE-2006-6724—doswindows
BolinTech Dream FTP Server 1.02 allows remote authenticated users, including anonymous users, to cause a denial of servi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Microsoft Windows - 'NetrWkstaUserEnum()' Remote Denial of Service
CVE-2006-6723—doswindows
The Workstation service in Microsoft Windows 2000 SP4 and XP SP2 allows remote attackers to cause a denial of service (m
35RIESGO
abrir ↗
Referência✓ VexDay Proof
μTorrent (uTorrent) / BitTorrent WebIU HTTP 1.7.7/6.0.1 - Range header Denial of Service
CVE-2008-0071—doswindows
The Web UI interface in (1) BitTorrent before 6.0.3 build 8642 and (2) uTorrent before 1.8beta build 10524 allows remote
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MyPHP Forum 3.0 - 'Final' SQL Injection
CVE-2008-0099—webappsphp
Multiple SQL injection vulnerabilities in MyPHP Forum 3.0 and earlier allow remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PLE CMS 1.0 Beta 4.2 - Blind SQL Injection
CVE-2009-0394—webappsphp
SQL injection vulnerability in login.php in Pre Lecture Exercises (PLEs) CMS 1.0 beta 4.2 allows remote attackers to exe
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Motorola Wimax modem CPEi300 - File Disclosure / Cross-Site Scripting
CVE-2009-0393—remotehardware
Cross-site scripting (XSS) vulnerability in sysconf.cgi in Motorola Wimax modem CPEi300 allows remote authenticated user
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component ElearningForce Flash Magazine Deluxe - SQL Injection
CVE-2009-0373—webappsphp
SQL injection vulnerability in the ElearningForce Flash Magazine Deluxe (com_flashmagazinedeluxe) component for Joomla!
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Newxooper-PHP 0.9.1 - 'mapage.php' Remote File Inclusion
CVE-2006-6711—webappsphp
PHP remote file inclusion vulnerability in compteur/mapage.php in Newxooper 0.9.1 allows remote attackers to execute arb
23RIESGO
abrir ↗
Referência✓ VexDay Proof
BibCiter 1.4 - Multiple SQL Injections
CVE-2009-0324—webappsphp
Multiple SQL injection vulnerabilities in BibCiter 1.4 allow remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Wazzum Dating Software - 'userid' SQL Injection
CVE-2009-0293—webappsphp
SQL injection vulnerability in profile_view.php in Wazzum Dating Software, possibly 2.0, allows remote attackers to exec
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Flax Article Manager 1.1 - 'cat_id' SQL Injection
CVE-2009-0284—webappsphp
SQL injection vulnerability in category.php in Flax Article Manager 1.1 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ABC estore 3.0 - 'cat_id' Blind SQL Injection
CVE-2007-4627—webappsphp
SQL injection vulnerability in index.php in ABC eStore 3.0 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Microsoft Windows Wordpad - '.doc' File Local Denial of Service (PoC)
CVE-2009-0259—doswindows
The Word processor in OpenOffice.org 1.1.2 through 1.1.5 allows remote attackers to cause a denial of service (crash) an
23RIESGO
abrir ↗
Referência✓ VexDay Proof
VMware Inc 6.0.0 - CreateProcess Remote Code Execution
CVE-2007-4155—remotewindows
Absolute path traversal vulnerability in a certain ActiveX control in vielib.dll in EMC VMware 6.0.0 allows remote attac
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Hexamail Server 3.0.0.001 - 'pop3' Remote Overflow (PoC)
CVE-2007-4646—doswindows
Buffer overflow in the pop3 service in Hexamail Server 3.0.0.001 Lite allows remote attackers to cause a denial of servi
28RIESGO
abrir ↗
Referência✓ VexDay Proof
E-Uploader Pro 1.0 - Image Upload / Code Execution
CVE-2006-6694—webappsphp
Directory traversal vulnerability in include/config.php in E-Uploader Pro 1.0 and earlier allows remote attackers to exe
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MP3 TrackMaker 1.5 - '.mp3' Local Heap Overflow (PoC)
CVE-2009-0175—doswindows
Heap-based buffer overflow in Heathco Software MP3 TrackMaker 1.5 allows remote attackers to cause a denial of service (
23RIESGO
abrir ↗
Referência✓ VexDay Proof
the net guys aspired2blog - SQL Injection / File Disclosure
CVE-2008-5931—webappsasp
The Net Guys ASPired2Blog stores sensitive information under the web root with insufficient access control, which allows
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Jupiter CMS 1.1.5 - Arbitrary File Upload
CVE-2007-0972—webappsphp
Unrestricted file upload vulnerability in modules/emoticons.php in Jupiter CMS 1.1.5 allows remote attackers to upload a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Avant Browser 11.0 build 26 - Remote Stack Overflow Crash
CVE-2007-1501—doswindows
Stack-based buffer overflow in Avant Browser 11.0 build 26 allows remote attackers to cause a denial of service (crash)
23RIESGO
abrir ↗
← anteriorpágina 781 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.