Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.117exploits catalogados
38.374CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
ASP AutoDealer - SQL Injection / File Disclosure
CVE-2008-5608—webappsasp
ASP AutoDealer stores sensitive information under the web root with insufficient access control, which allows remote att
23RIESGO
abrir ↗
Referência✓ VexDay Proof
GuppY 4.5.16 - Remote Command Execution
CVE-2007-5845—webappsphp
Directory traversal vulnerability in error.php in GuppY 4.6.3, 4.5.16, and earlier allows remote attackers to include an
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ScozNews 1.2.1 - 'mainpath' Remote File Inclusion
CVE-2006-2487—webappsphp
Multiple PHP remote file inclusion vulnerabilities in ScozNews 1.2.1 and earlier allow remote attackers to execute arbit
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CodeAvalanche News 1.x - 'CAT_ID' SQL Injection
CVE-2007-1021—webappsasp
SQL injection vulnerability in inc_listnews.asp in CodeAvalanche News 1.x allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mapbender 2.4.4 - 'mapFiler.php' Remote Code Execution
CVE-2008-0300—webappsphp
mapFiler.php in Mapbender 2.4 to 2.4.4 allows remote attackers to execute arbitrary PHP code via PHP code sequences in t
23RIESGO
abrir ↗
Referência✓ VexDay Proof
phpShop 0.8.1 - SQL Injection / Filter Bypass
CVE-2008-0681—webappsphp
SQL injection vulnerability in index.php in PHPShop 0.8.1 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗
Referência✓ VexDay Proof
RunCMS Module MyArticles 0.6 Beta-1 - SQL Injection
CVE-2008-2084—webappsphp
SQL injection vulnerability in topics.php in the MyArticles 0.6 beta-1 module for RunCMS allows remote attackers to exec
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHPHoo3 < 5.2.6 - 'viewCat' SQL Injection
CVE-2008-3245—webappsphp
SQL injection vulnerability in phpHoo3.php in phpHoo3 4.3.9, 4.3.10, 4.4.8, and 5.2.6 allows remote attackers to execute
23RIESGO
abrir ↗
Referência✓ VexDay Proof
HiveMaker Directory 1.0.2 - 'cid' SQL Injection
CVE-2008-6427—webappsphp
SQL injection vulnerability in index.php in Hivemaker Professional 1.0.2 and earlier, when magic_quotes_gpc is disabled,
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP infoboard 7 plus - Multiple Vulnerabilities
CVE-2008-4332—webappsphp
SQL injection vulnerability in the showjavatopic function in func.php in PHP infoBoard V.7 Plus allows remote attackers
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ParsBlogger - 'blog.asp' SQL Injection
CVE-2008-5637—webappsphp
SQL injection vulnerability in blog.asp in ParsBlogger (Pb) allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
FaScript FaUpload - SQL Injection
CVE-2008-5766—webappsphp
SQL injection vulnerability in download.php in Farsi Script Faupload allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗
Referência✓ VexDay Proof
NICE FAQ Script - Authentication Bypass
CVE-2008-6525—webappsphp
SQL injection vulnerability in the Admin Panel in Nice PHP FAQ Script (Knowledge base Script) allows remote attackers to
23RIESGO
abrir ↗
Referência✓ VexDay Proof
StrawBerry 1.1.1 - Local File Inclusion / Remote Command Execution
CVE-2009-1774—webappsphp
Directory traversal vulnerability in plugins/ddb/foot.php in Strawberry 1.1.1 allows remote attackers to include and exe
28RIESGO
abrir ↗
Referência✓ VexDay Proof
Social Site Generator 2.0 - Multiple Remote File Disclosure Vulnerabilities
CVE-2008-6420—webappsphp
Social Site Generator (SSG) 2.0 allows remote attackers to read arbitrary files via the file parameter to (1) filedload.
23RIESGO
abrir ↗
Referência✓ VexDay Proof
XOOPS Module XFsection 1.07 - 'articleId' Blind SQL Injection
CVE-2007-1974—webappsphp
SQL injection vulnerability in the getArticle function in class/wfsarticle.php in WF-Section (aka WF-Sections) 1.0.1, as
23RIESGO
abrir ↗
Referência✓ VexDay Proof
OpenASP 3.0 - Blind SQL Injection
CVE-2008-6257—webappsasp
SQL injection vulnerability in default.asp in Openasp 3.0 and earlier allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Pluck CMS 4.5.3 - 'g_pcltar_lib_dir' Local File Inclusion
CVE-2008-6253—webappsphp
Directory traversal vulnerability in data/inc/lib/pcltar.lib.php in Pluck 4.5.3, when register_globals is enabled, allow
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Barracuda Spam Firewall 3.5.11.020 Model 600 - SQL Injection
CVE-2008-1094—remotehardware
SQL injection vulnerability in index.cgi in the Account View page in Barracuda Spam Firewall (BSF) before 3.5.12.007 all
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Angelo-Emlak 1.0 - Multiple SQL Injections
CVE-2008-2048—webappsasp
Cross-site scripting (XSS) vulnerability in hpz/admin/Default.asp in Angelo-Emlak 1.0 allows remote attackers to inject
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SourceForge 1.0.4 - 'database.php' Remote File Inclusion
CVE-2006-5562—webappsphp
PHP remote file inclusion vulnerability in include/database.php in SourceForge (aka alexandria) 1.0.4 allows remote atta
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Galatolo Web Manager 1.3a - Cross-Site Scripting / SQL Injection
CVE-2008-6249—webappsphp
SQL injection vulnerability in plugins/users/index.php in Galatolo WebManager 1.3a and earlier allows remote attackers t
23RIESGO
abrir ↗
Referência✓ VexDay Proof
W1L3D4 philboard 1.2 - Blind SQL Injection / Cross-Site Scripting
CVE-2008-5193—webappsphp
Cross-site scripting (XSS) vulnerability in search.asp in W1L3D4 Philboard 1.14 and 1.2 allows remote attackers to injec
23RIESGO
abrir ↗
Referência✓ VexDay Proof
phpcrs 2.06 - 'importFunction' Local File Inclusion
CVE-2008-6074—webappsphp
Directory traversal vulnerability in frame.php in phpcrs 2.06 and earlier, when magic_quotes_gpc is disabled, allows rem
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Yet Another NOCC 0.1.0 - Local File Inclusion
CVE-2009-0515—webappsphp
Directory traversal vulnerability in check_lang.php in Yet Another NOCC (YANOCC) 0.1.0 and earlier allows remote attacke
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP recommend 1.3 - Authentication Bypass / Remote File Inclusion / Code Injection
CVE-2009-1780—webappsphp
admin.php in Frax.dk Php Recommend 1.3 and earlier does not require authentication when the user password is changed, wh
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHPstore Wholesale - 'id' SQL Injection
CVE-2008-5493—webappsphp
SQL injection vulnerability in track.php in PHPStore Wholesales (aka Wholesale) allows remote attackers to execute arbit
23RIESGO
abrir ↗
Referência✓ VexDay Proof
actSite 1.991 Beta - 'base.php' Remote File Inclusion
CVE-2007-5175—webappsphp
PHP remote file inclusion vulnerability lib/base.php in actSite 1.991 Beta allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
unclassified NewsBoard 1.6.4 - Multiple Vulnerabilities
CVE-2009-1947—webappsphp
SQL injection vulnerability in the UnbDbEncode function in unb_lib/database.lib.php in Unclassified NewsBoard (UNB) 1.6.
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SFS EZ Webring - 'cat' SQL Injection
CVE-2008-6246—webappsphp
SQL injection vulnerability in category.php in Scripts For Sites (SFS) EZ Webring allows remote attackers to execute arb
23RIESGO
abrir ↗
← anteriorpágina 799 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.