Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.117exploits catalogados
38.374CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
KB-Bestellsystem - 'kb_whois.cgi' Command Execution
CVE-2007-6176—webappscgi
kb_whois.cgi in K+B-Bestellsystem (aka KB-Bestellsystem) allows remote attackers to execute arbitrary commands via shell
23RIESGO
abrir ↗
Referência✓ VexDay Proof
TuMusika Evolution 1.7R5 - Remote File Disclosure
CVE-2007-6188—webappsphp
Multiple directory traversal vulnerabilities in TuMusika Evolution 1.7R5 allow remote attackers to include and execute a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ftp Admin 0.1.0 - Local File Inclusion / Cross-Site Scripting / Authentication Bypass
CVE-2007-6232—webappsphp
Cross-site scripting (XSS) vulnerability in index.php in FTP Admin 0.1.0 allows remote attackers to inject arbitrary web
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ftp Admin 0.1.0 - Local File Inclusion / Cross-Site Scripting / Authentication Bypass
CVE-2007-6234—webappsphp
index.php in FTP Admin 0.1.0 allows remote attackers to bypass authentication and obtain administrative access via a log
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Online Media Technologies 'AVSMJPEGFILE.DLL 1.1' - Remote Buffer Overflow (PoC)
CVE-2007-6327—doswindows
Buffer overflow in a certain ActiveX control in Online Media Technologies AVSMJPEGFILE.DLL 1.1.1.102 allows remote attac
28RIESGO
abrir ↗
Referência✓ VexDay Proof
CPCommerce 1.1.0 - Cross-Site Scripting / Local File Inclusion
CVE-2008-1906—webappsphp
Cross-site scripting (XSS) vulnerability in calendar.php in cpCommerce 1.1.0 allows remote attackers to inject arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
LaserNet CMS 1.5 - SQL Injection
CVE-2008-1913—webappsphp
SQL injection vulnerability in index.php in Lasernet CMS 1.5 and 1.11, when magic_quotes_gpc is disabled, allows remote
23RIESGO
abrir ↗
Referência✓ VexDay Proof
FreeWebShop 2.2.1 - Blind SQL Injection
CVE-2007-6466—webappsphp
Multiple SQL injection vulnerabilities in index.php in FreeWebshop 2.2.1 allow remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MOG-WebShop - 'index.php?group' SQL Injection
CVE-2007-6466—webappsphp
Multiple SQL injection vulnerabilities in index.php in FreeWebshop 2.2.1 allow remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Dream4 Koobi Pro 6.25 Poll - 'poll_id' SQL Injection
CVE-2008-2036—webappsphp
SQL injection vulnerability in index.php in dream4 Koobi Pro 6.25 allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir ↗
Referência✓ VexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
CVE-2007-6497—webappsasp
Hosting Controller 6.1 Hot fix 3.3 and earlier (1) allows remote attackers to change arbitrary user profiles via a reque
23RIESGO
abrir ↗
Referência✓ VexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
CVE-2007-6502—webappsasp
Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to obtain sensitive information via (1)
23RIESGO
abrir ↗
Referência✓ VexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
CVE-2007-6503—webappsasp
Multiple unspecified vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and earlier allow remote authenticated users
23RIESGO
abrir ↗
Referência✓ VexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
CVE-2007-6504—webappsasp
Unspecified vulnerability in IIS/iibind.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticate
23RIESGO
abrir ↗
Referência✓ VexDay Proof
TAGWORX.CMS 3.00.02 - Multiple SQL Injections
CVE-2008-2394—webappsphp
Multiple SQL injection vulnerabilities in TAGWORX.CMS 3.00.02 allow remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP Site Lock 2.0 - 'index.php' SQL Injection
CVE-2008-2865—webappsphp
SQL injection vulnerability in index.php in Kalptaru Infotech PHP Site Lock 2.0 allows remote attackers to execute arbit
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Link ADS 1 - 'linkid' SQL Injection
CVE-2008-2869—webappsphp
SQL injection vulnerability in out.php in E-topbiz Link ADS 1 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Lycos FileUploader Control - ActiveX Remote Buffer Overflow
CVE-2008-0443—remotewindows
Heap-based buffer overflow in the FileUploader.FUploadCtl.1 ActiveX control in FileUploader.dll 2.0.0.2 in Lycos FileUpl
28RIESGO
abrir ↗
Referência✓ VexDay Proof
Comodo AntiVirus 2.0 - 'ExecuteStr()' Remote Command Execution
CVE-2008-0470—remotewindows
A certain ActiveX control in Comodo AntiVirus 2.0 allows remote attackers to execute arbitrary commands via the ExecuteS
35RIESGO
abrir ↗
Referência✓ VexDay Proof
Web Wiz Forums 9.07 - 'sub' Directory Traversal
CVE-2008-0480—webappsasp
Multiple directory traversal vulnerabilities in Web Wiz Forums 9.07 and earlier allow remote attackers to list arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WordPress Plugin fGallery 2.4.1 - 'fimrss.php' SQL Injection
CVE-2008-0491—webappsphp
SQL injection vulnerability in fim_rss.php in the fGallery 2.4.1 plugin for WordPress allows remote attackers to execute
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WordPress Plugin Adserve 0.2 - 'adclick.php' SQL Injection
CVE-2008-0507—webappsphp
SQL injection vulnerability in adclick.php in the AdServe 0.2 plugin for WordPress allows remote attackers to execute ar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mambo Component 'com_fq' - 'listid' SQL Injection
CVE-2008-0512—webappsphp
SQL injection vulnerability in index.php in the fq (com_fq) component for Mambo and Joomla! allows remote attackers to e
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mambo Component 'com_glossary' 2.0 - 'catid' SQL Injection
CVE-2008-0514—webappsphp
SQL injection vulnerability in index.php in the Glossary (com_glossary) 2.0 component for Mambo and Joomla! allows remot
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mambo Component EstateAgent 0.1 - SQL Injection
CVE-2008-0517—webappsphp
SQL injection vulnerability in index.php in the Darko Selesi EstateAgent (com_estateagent) 0.1 component for Mambo 4.5.x
23RIESGO
abrir ↗
Referência✓ VexDay Proof
IntelliTamper 2.0.7 - HTML Parser Remote Buffer Overflow
CVE-2008-3360—remotewindows
Stack-based buffer overflow in the HTML parser in IntelliTamper 2.0.7 allows remote attackers to execute arbitrary code
23RIESGO
abrir ↗
Referência✓ VexDay Proof
IntelliTamper 2.0.7 - HTML Parser Remote Buffer Overflow
CVE-2008-3360—remotewindows
Stack-based buffer overflow in the HTML parser in IntelliTamper 2.0.7 allows remote attackers to execute arbitrary code
23RIESGO
abrir ↗
Referência✓ VexDay Proof
LoveCMS 1.6.2 Final - Update Settings
CVE-2008-3509—webappsphp
LoveCMS 1.6.2 does not require administrative authentication for (1) addblock.php, (2) blocks.php, and (3) themes.php in
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Xerox Phaser 8400 - Remote Reboot (Denial of Service)
CVE-2008-3571—doshardware
The Xerox Phaser 8400 allows remote attackers to cause a denial of service (reboot) via an empty UDP packet to port 1900
35RIESGO
abrir ↗
Referência✓ VexDay Proof
Yahoo! Music JukeBox 2.2 - 'AddButton()' ActiveX Remote Buffer Overflow
CVE-2008-0624—remotewindows
Buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! JukeBox 2.2.2.56 allows remote attackers to
23RIESGO
abrir ↗
← anteriorpágina 802 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.