Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.117exploits catalogados
38.374CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
IntelliTamper 2.07/2.08 Beta 4 - A HREF Remote Buffer Overflow
CVE-2008-3360—remotewindows
Stack-based buffer overflow in the HTML parser in IntelliTamper 2.0.7 allows remote attackers to execute arbitrary code
23RIESGO
abrir ↗
Referência✓ VexDay Proof
webSPELL 4.2.0c - Bypass BBCode Cross-Site Scripting Cookie Stealing
CVE-2009-1408—webappsphp
Cross-site scripting (XSS) vulnerability in webSPELL 4.2.0c allows remote attackers to inject arbitrary web script or HT
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ATutor 1.6.1-pl1 - 'import.php' Remote File Inclusion
CVE-2008-3368—webappsphp
PHP remote file inclusion vulnerability in tools/packages/import.php in ATutor 1.6.1 pl1 and earlier allows remote authe
23RIESGO
abrir ↗
Referência✓ VexDay Proof
KISGB 5.1.1 - 'Authenticate.php' Remote File Inclusion
CVE-2006-6764—webappsphp
PHP remote file inclusion vulnerability in authenticate.php in Keep It Simple Guest Book (KISGB), when executing PHP thr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Openfire Server 3.6.0a - Authentication Bypass / SQL Injection / Cross-Site Scripting
CVE-2008-6509—webappsjsp
SQL injection vulnerability in CallLogDAO in SIP Plugin in Openfire 3.6.0a and earlier allows remote attackers to execut
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Particle Blogger 1.2.0 - 'post.php?postid' SQL Injection
CVE-2007-1510—webappsphp
SQL injection vulnerability in post.php in Particle Blogger 1.0.0 through 1.2.0 allows remote attackers to execute arbit
23RIESGO
abrir ↗
Referência✓ VexDay Proof
InoutMailingListManager 3.1 - Remote Command Execution
CVE-2007-2002—webappsphp
InoutMailingListManager 3.1 and earlier allows remote attackers to access certain restricted functionality, and upload a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP-Nuke 8.0 Final - 'sid' SQL Injection
CVE-2008-0461—webappsphp
SQL injection vulnerability in index.php in the Search module in PHP-Nuke 8.0 FINAL and earlier, when magic_quotes_gpc i
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Apartment Search Script - 'listtest.php' SQL Injection
CVE-2008-1919—webappsphp
SQL injection vulnerability in listtest.php in YourFreeWorld Apartment Search Script allows remote attackers to execute
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Getacoder clone - 'sb_protype' SQL Injection
CVE-2008-3372—webappsphp
SQL injection vulnerability in search_form.php in Getacoder Clone allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component Datsogallery 1.6 - Blind SQL Injection
CVE-2008-5208—webappsphp
SQL injection vulnerability in sub_votepic.php in the Datsogallery (com_datsogallery) module 1.6 for Joomla! allows remo
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Ocean12 Membership Manager Pro - Authentication Bypass
CVE-2008-6371—webappsphp
SQL injection vulnerability in login.asp in Ocean12 Membership Manager Pro allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
BrewBlogger 2.1.0.1 - Arbitrary Add Admin
CVE-2008-6911—webappsphp
SQL injection vulnerability in the authenticateUser function in includes/authentication.inc.php in BrewBlogger (BB) 2.1.
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PAD Site Scripts 3.6 - Insecure Cookie Handling
CVE-2009-1739—webappsphp
PAD Site Scripts 3.6 allows remote attackers to bypass authentication and gain privileges as other users, including admi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
RunCMS Newbb_plus 0.92 - Client IP SQL Injection
CVE-2008-0224—webappsphp
SQL injection vulnerability in index.php in the Newbb_plus 0.92 and earlier module in RunCMS 1.6.1 allows remote attacke
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component joovideo 1.2.2 - 'id' SQL Injection
CVE-2008-1460—webappsphp
SQL injection vulnerability in the Joovideo (com_joovideo) 1.0 and 1.2.2 component for Mambo and Joomla! allows remote a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP Classifieds Script 05122008 - SQL Injection
CVE-2008-2453—webappsphp
Multiple SQL injection vulnerabilities in PHP Classifieds Script allow remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗
Referência✓ VexDay Proof
FizzMedia 1.51.2 - SQL Injection
CVE-2008-3378—webappsphp
SQL injection vulnerability in comment.php in Fizzmedia 1.51.2 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component Ignite Gallery 0.8.3 - SQL Injection
CVE-2008-6182—webappsphp
SQL injection vulnerability in the Ignite Gallery (com_ignitegallery) component 0.8.0 through 0.8.3 for Joomla! allows r
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Peel Shopping 3.1 - 'rubid' SQL Injection
CVE-2008-6892—webappsphp
SQL injection vulnerability in lire/index.php in Peel 3.1 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗
Referência✓ VexDay Proof
VidShare Pro - Arbitrary File Upload
CVE-2009-1750—webappsphp
Unrestricted file upload vulnerability in VidSharePro allows remote authenticated users to execute arbitrary code by upl
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MultiCart 1.0 - Blind SQL Injection
CVE-2007-5261—webappsphp
Multiple SQL injection vulnerabilities in MultiCart 1.0 allow remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Softbiz Freelancers Script 1 - SQL Injection
CVE-2007-6124—webappsphp
Cross-site scripting (XSS) vulnerability in signin.php in Softbiz Freelancers Script 1 allows remote attackers to inject
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP Help Agent 1.1 - 'content' Local File Inclusion
CVE-2008-3385—webappsphp
Directory traversal vulnerability in include/head_chat.inc.php in php Help Agent 1.0 and 1.1 Full allows remote attacker
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Tribiq CMS 5.0.10a (Windows) - Local File Inclusion
CVE-2008-4894—webappsphp
Directory traversal vulnerability in templates/mytribiqsite/tribal-GPL-1066/includes/header.inc.php in Tribiq CMS 5.0.10
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CMS NetCat 3.12 - Multiple Vulnerabilities
CVE-2008-5728—webappsphp
Multiple directory traversal vulnerabilities in AIST NetCat 3.12 and earlier, when magic_quotes_gpc is disabled and regi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Flyspeck CMS 6.8 - Local/Remote File Inclusion / Change Add Admin
CVE-2009-1771—webappsphp
index.php in Flyspeck CMS 6.8 does not require administrative authentication for the updateExistingContent action, which
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Osprey 1.0 - 'GetRecord.php' Remote File Inclusion
CVE-2006-6631—webappsphp
PHP remote file inclusion vulnerability in lib/xml/oai/GetRecord.php in osprey 1.0 and earlier allows remote attackers t
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ScozNews 1.2.1 - 'mainpath' Remote File Inclusion
CVE-2006-2487—webappsphp
Multiple PHP remote file inclusion vulnerabilities in ScozNews 1.2.1 and earlier allow remote attackers to execute arbit
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CodeAvalanche News 1.x - 'CAT_ID' SQL Injection
CVE-2007-1021—webappsasp
SQL injection vulnerability in inc_listnews.asp in CodeAvalanche News 1.x allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗
← anteriorpágina 795 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.