Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.117exploits catalogados
38.374CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
Discuz! 6.0.1 - 'searchid' SQL Injection
CVE-2008-3554—webappsphp
SQL injection vulnerability in index.php in Discuz! 6.0.1 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗
Referência✓ VexDay Proof
txtshop 1.0b (Windows) - 'Language' Local File Inclusion
CVE-2008-6083—webappsphp
Directory traversal vulnerability in header.php in TXTshop beta 1.0 allows remote attackers to include and execute arbit
23RIESGO
abrir ↗
Referência✓ VexDay Proof
VMware 5.5.1 - 'ActiveX' Local Buffer Overflow
CVE-2006-6410—localwindows
Buffer overflow in an ActiveX control in VMWare 5.5.1 allows local users to execute arbitrary code via a long VmdbDb par
23RIESGO
abrir ↗
Referência✓ VexDay Proof
DigitalHive 2.0 RC2 - 'user_id' SQL Injection
CVE-2008-0290—webappsphp
Multiple SQL injection vulnerabilities in Digital Hive 2.0 RC2 and earlier allow (1) remote attackers to execute arbitra
23RIESGO
abrir ↗
Referência✓ VexDay Proof
living Local 1.1 - Cross-Site Scripting / Arbitrary File Upload
CVE-2008-6530—webappsphp
Unrestricted file upload vulnerability in editimage.php in eZoneScripts Living Local 1.1 allows remote authenticated adm
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Gretech GOM Encoder 1.0.0.11 - '.Subtitle' Buffer Overflow (PoC)
CVE-2009-1022—doswindows
Heap-based buffer overflow in the Preview/ Set Segment function in Gretech GOMlab GOM Encoder 1.0.0.11 and earlier allow
23RIESGO
abrir ↗
Referência✓ VexDay Proof
unclassified NewsBoard 1.6.4 - Multiple Vulnerabilities
CVE-2009-1949—webappsphp
import_wbb1.php in Unclassified NewsBoard (UNB) 1.6.4 allows remote attackers to obtain sensitive information via a dire
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CMS Faethon 2.0 - 'mainpath' Remote File Inclusion
CVE-2006-5588—webappsphp
Multiple PHP remote file inclusion vulnerabilities in CMS Faethon 2.0 Ultimate and earlier, when register_globals and ma
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Gravity GTD 0.4.5 - Local File Inclusion / Remote Code Execution
CVE-2008-5962—webappsphp
Directory traversal vulnerability in library/setup/rpc.php in Gravity Getting Things Done (GTD) 0.4.5 and earlier allows
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MangoBery CMS 0.5.5 - 'quotes.php' Remote File Inclusion
CVE-2007-1837—webappsphp
Multiple PHP remote file inclusion vulnerabilities in MangoBery CMS 0.5.5 allow remote attackers to execute arbitrary PH
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WFTPD Pro Server 3.25 - Site ADMN Remote Denial of Service
CVE-2007-0311—doswindows
Texas Imperial Software WFTPD and WFTPD Pro Server 3.25 and earlier allow remote attackers to cause a denial of service
23RIESGO
abrir ↗
Referência✓ VexDay Proof
E Annu 1.0 - Authentication Bypass / SQL Injection
CVE-2006-5666—webappsphp
SQL injection vulnerability in includes/menu.inc.php in E-Annu 1.0 allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mobius 1.4.4.1 - SQL Injection
CVE-2008-3420—webappsphp
Multiple SQL injection vulnerabilities in Mobius for Mimsy XG 1 1.4.4.1 and earlier allow remote attackers to execute ar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mozilla Firefox 3.0.10 - 'KEYGEN' Remote Denial of Service
CVE-2009-1828—dosmultiple
Mozilla Firefox 3.0.10 allows remote attackers to cause a denial of service (infinite loop, application hang, and memory
23RIESGO
abrir ↗
Referência✓ VexDay Proof
FileZilla FTP Server 0.9.21 - 'LIST/NLST' Denial of Service
CVE-2006-6565—doswindows
FileZilla Server before 0.9.22 allows remote attackers to cause a denial of service (crash) via a wildcard argument to t
60RIESGO
abrir ↗
Referência✓ VexDay Proof
XOOPS 2.3.1 - Multiple Local File Inclusions
CVE-2008-6884—webappsphp
Multiple directory traversal vulnerabilities in XOOPS 2.3.1, when register_globals is enabled, allow remote attackers to
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Easy-Clanpage 3.0b1 - 'section' Local File Inclusion
CVE-2008-2818—webappsphp
Directory traversal vulnerability in Easy-Clanpage 3.0 b1 allows remote attackers to include and execute arbitrary local
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SyndeoCMS 2.6.0 - Local File Inclusion / Cross-Site Scripting
CVE-2008-5272—webappsphp
Multiple directory traversal vulnerabilities in Fred Stuurman SyndeoCMS 2.6.0 allow remote authenticated users to read a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component JD-Wiki 1.0.2 - Remote File Inclusion
CVE-2006-4074—webappsphp
PHP remote file inclusion vulnerability in lib/tpl/default/main.php in the JD-Wiki Component (com_jd-wiki) 1.0.2 and ear
23RIESGO
abrir ↗
Referência✓ VexDay Proof
helplink 0.1.0 - 'show.php' Remote File Inclusion
CVE-2007-5099—webappsphp
PHP remote file inclusion vulnerability in show.php in David Watters Helplink 0.1.0 allows remote attackers to execute a
35RIESGO
abrir ↗
Referência✓ VexDay Proof
WebYep 1.1.9 - 'webyep_sIncludePath' File Inclusion
CVE-2006-5220—webappsphp
Multiple PHP remote file inclusion vulnerabilities in WebYep 1.1.9, when register_globals is enabled, allow remote attac
28RIESGO
abrir ↗
Referência✓ VexDay Proof
Youtuber Clone - SQL Injection
CVE-2008-3419—webappsphp
SQL injection vulnerability in ugroups.php in Youtuber Clone allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗
Referência✓ VexDay Proof
LeadTools Raster - Dialog File_D Object Remote Buffer Overflow (PoC)
CVE-2007-2946—doswindows
Buffer overflow in a certain ActiveX control in LeadTools Raster Dialog File_D Object (LTRDFD14e.DLL) 14.5.0.44 allows r
23RIESGO
abrir ↗
Referência✓ VexDay Proof
registroTL - 'main.php' Remote File Inclusion
CVE-2006-5316—webappsphp
registroTL stores sensitive information under the web root with insufficient access control, which allows remote attacke
23RIESGO
abrir ↗
Referência✓ VexDay Proof
DodosMail 2.0.1 - 'dodosmail.php' Remote File Inclusion
CVE-2006-5841—webappsphp
Multiple PHP remote file inclusion vulnerabilities in dodosmail.php in DodosMail 2.0.1 and earlier, and possibly 2.1, al
23RIESGO
abrir ↗
Referência✓ VexDay Proof
HP Digital Imaging 'hpqxml.dll 2.0.0.133' - Arbitrary Data Write
CVE-2007-3487—remotewindows
Absolute path traversal in a certain ActiveX control in hpqxml.dll 2.0.0.133 in Hewlett-Packard (HP) Photo Digital Imagi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Xitami Web Server 2.5 - 'If-Modified-Since' Remote Buffer Overflow
CVE-2007-5067—remotewindows
Multiple buffer overflows in iMatix Xitami Web Server 2.5c2 allow remote attackers to execute arbitrary code via a long
60RIESGO
abrir ↗
Referência✓ VexDay Proof
PacerCMS 0.6 - 'last_module' Remote Code Execution
CVE-2007-5056—webappsphp
Eval injection vulnerability in adodb-perf-module.inc.php in ADOdb Lite 1.42 and earlier, as used in products including
28RIESGO
abrir ↗
Referência✓ VexDay Proof
RSSonate - 'xml2rss.php' Remote File Inclusion
CVE-2006-5518—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Christopher Fowler (Rhode Island) RSSonate allow remote attackers
28RIESGO
abrir ↗
Referência✓ VexDay Proof
Google Chrome 0.2.149.27 - Automatic File Download
CVE-2008-6996—remotewindows
Google Chrome BETA (0.2.149.27) does not prompt the user before saving an executable file, which makes it easier for rem
23RIESGO
abrir ↗
← anteriorpágina 792 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.