Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.117exploits catalogados
38.374CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
postecards - SQL Injection / File Disclosure
CVE-2008-5560—webappsasp
PostEcards stores sensitive information under the web root with insufficient access control, which allows remote attacke
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Apache Geronimo 2.1.3 - Multiple Directory Traversal Vulnerabilities
CVE-2008-5518—remotemultiple
Multiple directory traversal vulnerabilities in the web administration console in Apache Geronimo Application Server 2.1
35RIESGO
abrir ↗
Referência✓ VexDay Proof
Simple Machines Forum (SMF) 1.1.3 - Blind SQL Injection
CVE-2007-5646—webappsphp
SQL injection vulnerability in Sources/Search.php in Simple Machines Forum (SMF) 1.1.3, when MySQL 5 is used, allows rem
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Discloser 0.0.4 - 'fileloc' Remote File Inclusion
CVE-2006-4207—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Bob Jewell Discloser 0.0.4 and earlier allow remote attackers to e
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PozScripts Business Directory Script - 'cid' SQL Injection
CVE-2008-5496—webappsphp
SQL injection vulnerability in showcategory.php in PozScripts Business Directory Script allows remote attackers to execu
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WebSVN 2.0 - Cross-Site Scripting / File Handling / Code Execution
CVE-2008-5920—webappsphp
The create_anchors function in utils.inc in WebSVN 1.x allows remote attackers to execute arbitrary PHP code via a craft
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Musoo 0.21 - Remote File Inclusion
CVE-2007-3297—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Musoo 0.21 allow remote attackers to execute arbitrary PHP code vi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Fuzzylime CMS 3.03a - Local Inclusion / Arbitrary File Corruption
CVE-2009-2177—webappsphp
code/display.php in fuzzylime (cms) 3.03a and earlier, when magic_quotes_gpc is disabled, allows remote attackers to con
23RIESGO
abrir ↗
Referência✓ VexDay Proof
phpDatingClub 3.7 - SQL Injection / Cross-Site Scripting Injection
CVE-2009-2179—webappsphp
SQL injection vulnerability in search.php in phpDatingClub 3.7 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mini-stream ASX to MP3 Converter 3.0.0.7 - '.RAM' Local Buffer Overflow
CVE-2009-1642—localwindows
Multiple stack-based buffer overflows in Mini-stream ASX to MP3 Converter 3.0.0.7 allow remote attackers to execute arbi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
icblogger 2.0 - 'YID' SQL Injection
CVE-2006-4597—webappsasp
SQL injection vulnerability in devam.asp in ICBlogger 2.0 and earlier allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗
Referência✓ VexDay Proof
tbdev 01-01-2008 - Multiple Vulnerabilities
CVE-2009-2141—webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in TBDev.NET 01-01-08 allow remote attackers to inject arbitrary web
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WM Downloader - '.m3u' Local Stack Overflow (PoC)
CVE-2009-1327—doswindows
Stack-based buffer overflow in Mini-stream WM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
JW Player - 'playerready' Cross-Site Scripting
CVE-2012-3351—webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in LongTail Video JW Player through 5.10.2295 allow remote attackers
23RIESGO
abrir ↗
Referência✓ VexDay Proof
VeryPDF PDFView - OCX ActiveX OpenPDF Heap Overflow (PoC)
CVE-2008-5492—doswindows
Heap-based buffer overflow in the PDFVIEW.PdfviewCtrl.1 ActiveX control in pdfview.ocx 2.0.0.1 in VeryDOC PDF Viewer OCX
50RIESGO
abrir ↗
Referência✓ VexDay Proof
Adobe Shockwave - 'ShockwaveVersion()' Stack Overflow (PoC)
CVE-2007-5941—doswindows
Stack-based buffer overflow in the SWCtl.SWCtl ActiveX control in Adobe Shockwave allows remote attackers to cause a den
35RIESGO
abrir ↗
Referência✓ VexDay Proof
SlimCMS 1.0.0 - 'edit.php' SQL Injection
CVE-2008-5491—webappsphp
SQL injection vulnerability in edit.php in SlimCMS 1.0.0 and earlier allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗
Referência✓ VexDay Proof
RX Maxsoft - 'fotoID' SQL Injection
CVE-2008-4912—webappsphp
SQL injection vulnerability in popup_img.php in the fotogalerie module in RS MAXSOFT allows remote attackers to execute
23RIESGO
abrir ↗
Referência✓ VexDay Proof
X.Org xorg-server 1.1.1-48.13 - Probe for Files (PoC)
CVE-2007-5958—dosmultiple
X.Org Xserver before 1.4.1 allows local users to determine the existence of arbitrary files via a filename argument in t
23RIESGO
abrir ↗
Referência✓ VexDay Proof
jPORTAL 2.3.1 - 'articles.php' SQL Injection
CVE-2007-5973—webappsphp
SQL injection vulnerability in articles.php in JPortal 2.3.1 and earlier allows remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗
Referência✓ VexDay Proof
UltraISO 9.3.3.2685 - CCD/IMG Universal Buffer Overflow
CVE-2009-1257—localwindows
Heap-based buffer overflow in Magic ISO Maker 5.5 build 0274 allows remote attackers to cause a denial of service (crash
28RIESGO
abrir ↗
Referência✓ VexDay Proof
phpMyNewsletter 0.8b5 - 'msg_id' SQL Injection
CVE-2008-1295—webappsphp
SQL injection vulnerability in archives.php in Gregory Kokanosky (aka Greg's Place) phpMyNewsletter 0.8 beta 5 and earli
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Nero ShowTime 5.0.15.0 - '.m3u' Playlist File Remote Buffer Overflow (PoC)
CVE-2008-7079—doswindows
Buffer overflow in Nero ShowTime 5.0.15.0 allows remote attackers to cause a denial of service (crash) and possibly exec
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SoftArtisans SAFileUp 5.0.14 - 'viewsrc.asp' Script Source Disclosure
CVE-2006-6865—webappsasp
Directory traversal vulnerability in SAFileUpSamples/util/viewsrc.asp in SoftArtisans FileUp (SAFileUp) 5.0.14 allows re
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Shop Script Pro 2.12 - SQL Injection
CVE-2009-2023—webappsphp
SQL injection vulnerability in index.php in Shop-Script Pro 2.12, when magic_quotes_gpc is disabled, allows remote attac
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Arab Portal 2.1 (Windows) - Remote File Disclosure
CVE-2008-5787—webappsphp
Directory traversal vulnerability in mod.php in Arab Portal 2.1 on Windows allows remote attackers to read arbitrary fil
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SFS EZ Gaming Directory - 'directory.php' SQL Injection
CVE-2008-6781—webappsphp
SQL injection vulnerability in directory.php in Sites for Scripts (SFS) Gaming Directory allows remote attackers to exec
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Simplog 0.9.2 - 's' Remote Command Execution
CVE-2006-0147—webappsphp
Dynamic code evaluation vulnerability in tests/tmssql.php test script in ADOdb for PHP before 4.70, as used in multiple
28RIESGO
abrir ↗
Referência✓ VexDay Proof
PPA Gallery 1.0 - 'functions.inc.php' Remote File Inclusion
CVE-2006-5165—webappsphp
PHP remote file inclusion vulnerability in inc/functions.inc.php in Skrypty PPA Gallery 1.0 and earlier allows remote at
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Symantec BackupExec Calendar Control - 'PVCalendar.ocx' Remote Buffer Overflow
CVE-2007-6016—remotewindows
Multiple stack-based buffer overflows in the PVATLCalendar.PVCalendar.1 ActiveX control in pvcalendar.ocx in the schedul
50RIESGO
abrir ↗
← anteriorpágina 805 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.