Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.116exploits catalogados
38.373CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
FireAnt 1.3 - 'index.php' Local File Inclusion
CVE-2008-2896—webappsphp
Directory traversal vulnerability in index.php in FireAnt 1.3 allows remote attackers to include and execute arbitrary l
23RIESGO
abrir ↗
Referência✓ VexDay Proof
LanSuite 3.3.2 - 'design' Local File Inclusion
CVE-2008-4330—webappsphp
Directory traversal vulnerability in index.php in LanSuite 3.3.2 allows remote attackers to include and execute arbitrar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Globsy 1.0 - Remote File Rewriting
CVE-2008-5966—webappsphp
globsy_edit.php in Globsy 1.0 and earlier allows remote attackers to create or overwrite arbitrary files via a filename
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Ol BookMarks Manager 0.7.5 - Local File Inclusion / Remote File Inclusion / SQL Injection
CVE-2008-6407—webappsphp
Directory traversal vulnerability in frame.php in ol'bookmarks manager 0.7.5 allows remote attackers to include and exec
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Xomol CMS 1.2 - Authentication Bypass / Local File Inclusion
CVE-2008-2484—webappsphp
SQL injection vulnerability in index.php in Xomol CMS 1.20071213, when magic_quotes_gpc is disabled, allows remote attac
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHPMyNews 1.4 - 'cfg_include_dir' Remote File Inclusion
CVE-2006-5261—webappsphp
Multiple PHP remote file inclusion vulnerabilities in PHPMyNews 1.4 and earlier allow remote attackers to execute arbitr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
HotScripts Clone - 'cid' SQL Injection
CVE-2008-6405—webappsphp
SQL injection vulnerability in showcategory.php in Hotscripts Clone allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component mydyngallery 1.4.2 - SQL Injection
CVE-2008-5957—webappsphp
SQL injection vulnerability in the Mydyngallery (com_mydyngallery) component 1.4.2 for Joomla! allows remote attackers t
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component live chat - SQL Injection / Open Proxy
CVE-2008-6882—webappsphp
Live Chat (com_livechat) component 1.0 for Joomla! allows remote attackers to use the xmlhttp.php script as an open HTTP
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PAD Site Scripts 3.6 - Arbitrary Database Backup
CVE-2009-1941—webappsphp
PAD Site Scripts 3.6 stores sensitive information under the web document root with insufficient access control, which al
23RIESGO
abrir ↗
Referência✓ VexDay Proof
VT-Auth 1.0 - 'zHk8dEes3.txt' File Disclosure
CVE-2009-2024—webappsasp
Vlad Titarenko ASP VT Auth 1.0 stores sensitive information under the web root with insufficient access control, which a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
compteur 2.0 - 'param_editor.php' Remote File Inclusion
CVE-2006-5259—webappsphp
PHP remote file inclusion vulnerability in param_editor.php in Compteur 2 allows remote attackers to execute arbitrary P
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Core Image Fun House 2.0 (OSX) - Arbitrary Code Execution (PoC)
CVE-2008-2304—dososx
Buffer overflow in Apple Core Image Fun House 2.0 and earlier in CoreImage Examples in Xcode tools before 3.1 allows use
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Internet PhotoShow (Special Edition) - Insecure Cookie Handling
CVE-2008-2282—webappsphp
admin.php in Internet Photoshow and Internet Photoshow Special Edition (SE) allows remote attackers to bypass authentica
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Kostenloses Linkmanagementscript - Remote File Inclusion
CVE-2008-2270—webappsphp
Multiple PHP remote file inclusion vulnerabilities in PHPWAY Kostenloses Linkmanagementscript allow remote attackers to
23RIESGO
abrir ↗
Referência✓ VexDay Proof
EMO Realty Manager - 'ida' SQL Injection
CVE-2008-2265—webappsphp
SQL injection vulnerability in news.php in EMO Realty Manager allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗
Referência✓ VexDay Proof
AdaptCMS Lite 1.4 - Cross-Site Scripting / Remote File Inclusion
CVE-2009-0526—webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in index.php in AdaptCMS Lite 1.4 allow remote attackers to inject a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Pritlog 0.4 - 'Filename' Remote File Disclosure
CVE-2008-6012—webappsphp
Directory traversal vulnerability in index.php in Pritlog 0.4 and earlier, when magic_quotes_gpc is disabled, allows rem
23RIESGO
abrir ↗
Referência✓ VexDay Proof
IPNPro3 < 1.44 - Admin Password Changing
CVE-2008-5568—webappsphp
Cross-site request forgery (CSRF) vulnerability in admin/settings.php in IPN Pro 3 1.44 and earlier allows remote attack
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Studio Lounge Address Book 2.5 - 'profile' Arbitrary File Upload
CVE-2009-1483—webappsphp
Unrestricted file upload vulnerability in upload-file.php in Adam Patterson Studio Lounge Address Book 2.5, as reachable
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Flatchat 3.0 - 'pmscript.php' Local File Inclusion
CVE-2009-1486—webappsphp
Directory traversal vulnerability in pmscript.php in Flatchat 3.0 allows remote attackers to include and execute arbitra
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MusicBox 2.3.7 - 'artistId' SQL Injection
CVE-2008-2125—webappsphp
SQL injection vulnerability in viewalbums.php in Musicbox 2.3.6 and 2.3.7 allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Pre Shopping Mall 1.1 - 'search.php' SQL Injection
CVE-2008-2114—webappsphp
SQL injection vulnerability in emall/search.php in Pre Shopping Mall 1.1 allows remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Freenews 1.1 - 'moteur.php' Remote File Inclusion
CVE-2006-5226—webappsphp
PHP remote file inclusion vulnerability in moteur/moteur.php in Prologin.fr Freenews 1.1 and earlier allows remote attac
23RIESGO
abrir ↗
Referência✓ VexDay Proof
DaZPHP 0.1 - 'prefixdir' Local File Inclusion
CVE-2008-1696—webappsphp
Directory traversal vulnerability in makepost.php in DaZPHPNews 0.1-1, when register_globals is enabled and magic_quotes
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Ocean12 Contact Manager Pro - SQL Injection / Cross-Site Scripting / File Disclosure
CVE-2008-6369—webappsphp
SQL injection vulnerability in default.asp in Ocean12 Contact Manager Pro 1.02 allows remote attackers to execute arbitr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Microsoft Windows Media Player - '.wav' Remote Crash (PoC)
CVE-2008-5745—doswindows
Integer overflow in quartz.dll in the DirectShow framework in Microsoft Windows Media Player (WMP) 9, 10, and 11, includ
28RIESGO
abrir ↗
Referência✓ VexDay Proof
VanGogh Web CMS 0.9 - 'article_ID' SQL Injection
CVE-2008-3027—webappsphp
SQL injection vulnerability in get_article.php in VanGogh Web CMS 0.9 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗
Referência✓ VexDay Proof
groone glinks 2.1 - Remote File Inclusion
CVE-2009-0463—webappsphp
PHP remote file inclusion vulnerability in includes/header.php in Groone GLinks 2.1 allows remote attackers to execute a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WebFileExplorer 3.1 - 'db.mdb' Database Disclosure
CVE-2009-1495—webappsphp
Web File Explorer 3.1 stores sensitive information under the web root with insufficient access control, which allows rem
23RIESGO
abrir ↗
← anteriorpágina 789 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.