Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.117exploits catalogados
38.374CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
forum livre 1.0 - SQL Injection / Cross-Site Scripting
CVE-2007-0590—webappsasp
Cross-site scripting (XSS) vulnerability in busca2.asp in Forum Livre 1.0 remote attackers to inject arbitrary web scrip
23RIESGO
abrir ↗
Referência✓ VexDay Proof
BbZL.php 0.92 - 'lien_2' Local Directory Traversal
CVE-2008-4707—webappsphp
Directory traversal vulnerability in index.php in BbZL.PhP 0.92 allows remote attackers to access unauthorized directori
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ComVironment 4.0 - 'grab_globals.lib.php' Remote File Inclusion
CVE-2007-0395—webappsphp
PHP remote file inclusion vulnerability in libraries/grab_globals.lib.php in ComVironment 4.0 allows remote attackers to
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Phaos R4000 Version - 'file' Remote File Disclosure
CVE-2008-1755—webappsphp
Directory traversal vulnerability in the showSource function in showSource.php in World of Phaos 4.0.1 allows remote att
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SG Real Estate Portal 2.0 - Blind SQL Injection / Local File Inclusion
CVE-2008-6010—webappsphp
Multiple directory traversal vulnerabilities in SG Real Estate Portal 2.0 allow remote attackers to read arbitrary files
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Minigal b13 - Remote File Disclosure
CVE-2008-6933—webappsphp
Directory traversal vulnerability in index.php in MiniGal b13 (aka MG2) allows remote attackers to read the source code
23RIESGO
abrir ↗
Referência✓ VexDay Proof
forum livre 1.0 - SQL Injection / Cross-Site Scripting
CVE-2007-0589—webappsasp
SQL injection vulnerability in Forum Livre 1.0 allows remote attackers to execute arbitrary SQL commands via the user pa
23RIESGO
abrir ↗
Referência✓ VexDay Proof
OneOrZero Helpdesk 1.6.5.7 - Local File Inclusion
CVE-2009-0886—webappsphp
Directory traversal vulnerability in login.php in OneOrZero Helpdesk 1.6.5.7 and earlier allows remote attackers to read
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Pakupaku CMS 0.4 - Arbitrary File Upload / Local File Inclusion
CVE-2007-4641—webappsphp
Directory traversal vulnerability in index.php in Pakupaku CMS 0.4 and earlier allows remote attackers to include and ex
23RIESGO
abrir ↗
Referência✓ VexDay Proof
asg-sentry 7.0.0 - Multiple Vulnerabilities
CVE-2008-1321—dosmultiple
The FxIAList service in ASG-Sentry Network Manager 7.0.0 and earlier does require authentication, which allows remote at
23RIESGO
abrir ↗
Referência✓ VexDay Proof
HP Compaq Notebooks - ActiveX Remote Code Execution
CVE-2007-6332—remotewindows
The HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 i
23RIESGO
abrir ↗
Referência✓ VexDay Proof
BBS E-Market - 'postscript.php?p_mode' Remote File Inclusion
CVE-2007-3934—webappsphp
PHP remote file inclusion vulnerability in postscript/postscript.php in BBS E-Market allows remote attackers to execute
23RIESGO
abrir ↗
Referência✓ VexDay Proof
chernobiLe Portal 1.0 - 'default.asp' SQL Injection
CVE-2007-0582—webappsasp
SQL injection vulnerability in default.asp in ChernobiLe 1.0 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗
Referência✓ VexDay Proof
falcon CMS 1.4.3 - Remote File Inclusion / Cross-Site Scripting
CVE-2007-6488—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Falcon Series One CMS 1.4.3 allow remote attackers to execute arbi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Basic-CMS - SQL Injection
CVE-2008-2789—webappsphp
SQL injection vulnerability in pages/index.php in BASIC-CMS allows remote attackers to execute arbitrary SQL commands vi
43RIESGO
abrir ↗
Referência✓ VexDay Proof
Comparison Engine Power 1.0 - Blind SQL Injection
CVE-2008-2791—webappsphp
SQL injection vulnerability in product.detail.php in Kalptaru Infotech Comparison Engine Power Script 1.0 allows remote
23RIESGO
abrir ↗
Referência✓ VexDay Proof
EclipseBB 0.5.0 Lite - 'phpbb_root_path' Remote File Inclusion
CVE-2007-0581—webappsphp
PHP remote file inclusion vulnerability in functions.php in EclipseBB 0.5.0 Lite allows remote attackers to execute arbi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
X7 Chat 2.0.1A1 - 'mini.php' Local File Inclusion
CVE-2008-4718—webappsphp
Directory traversal vulnerability in help/mini.php in X7 Chat 2.0.1 A1 and earlier allows remote attackers to include an
23RIESGO
abrir ↗
Referência✓ VexDay Proof
X7 Chat 2.0.1A1 - Local File Inclusion
CVE-2008-4718—webappsphp
Directory traversal vulnerability in help/mini.php in X7 Chat 2.0.1 A1 and earlier allows remote attackers to include an
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mozilla Firefox 3.0.5 - location.hash Remote Crash
CVE-2008-5715—doswindows
Mozilla Firefox 3.0.5 on Windows Vista allows remote attackers to cause a denial of service (application crash) via Java
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Apple iTunes 8.1.1 - 'ITMS' Multiple Protocol Handler Buffer Overflow (Metasploit)
CVE-2009-0950—remoteosx
Stack-based buffer overflow in Apple iTunes before 8.2 allows remote attackers to execute arbitrary code or cause a deni
43RIESGO
abrir ↗
Referência✓ VexDay Proof
AINS 0.02b - 'ains_main.php?ains_path' Remote File Inclusion
CVE-2007-0570—webappsphp
PHP remote file inclusion vulnerability in ains_main.php in Johannes Gijsbers (aka Taradino) Ad Fundum Integratable News
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PicoFlat CMS 0.5.9 (Windows) - Local File Inclusion
CVE-2008-6604—webappsphp
Directory traversal vulnerability in index.php in PicoFlat CMS 0.5.9 allows remote attackers to include and execute arbi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Bradabra 2.0.5 - '/include/includes.php' Remote File Inclusion
CVE-2007-0500—webappsphp
PHP remote file inclusion vulnerability in include/includes.php in Bradabra 2.0.5 and earlier allows remote attackers to
23RIESGO
abrir ↗
Referência✓ VexDay Proof
pl-PHP Beta 0.9 - Multiple Vulnerabilities
CVE-2007-2007—webappsphp
admin.php in pL-PHP beta 0.9 allows remote attackers to bypass authentication by setting the is_admin parameter to 1.
23RIESGO
abrir ↗
Referência✓ VexDay Proof
asg-sentry 7.0.0 - Multiple Vulnerabilities
CVE-2008-1322—dosmultiple
The File Check Utility (fcheck.exe) in ASG-Sentry Network Manager 7.0.0 and earlier allows remote attackers to cause a d
23RIESGO
abrir ↗
Referência✓ VexDay Proof
V-Webmail 1.6.4 - 'pear_dir' Remote File Inclusion
CVE-2006-2665—webappsphp
PHP remote file inclusion vulnerability in includes/mailaccess/pop3/core.php in V-Webmail 1.3 allows remote attackers to
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP-CON 1.3 - 'include.php' Remote File Inclusion
CVE-2007-6177—webappsphp
PHP remote file inclusion vulnerability in Exchange/include.php in PHP_CON 1.3 allows remote attackers to execute arbitr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PokerMax Poker League 0.13 - Insecure Cookie Handling
CVE-2008-4600—webappsphp
configure.php in PokerMax Poker League Tournament Script 0.13 allows remote attackers to bypass authentication and gain
23RIESGO
abrir ↗
Referência✓ VexDay Proof
mini-pub 0.3 - File Disclosure / Code Execution
CVE-2008-5579—webappsphp
Absolute path traversal vulnerability in mini-pub.php/front-end/cat.php in mini-pub 0.3 allows remote attackers to read
23RIESGO
abrir ↗
← anteriorpágina 801 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.