Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.117exploits catalogados
38.374CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
phNNTP 1.3 - 'article-raw.php' Remote File Inclusion
CVE-2006-4103—webappsphp
PHP remote file inclusion vulnerability in article-raw.php in Jason Alexander phNNTP 1.3 and earlier allows remote attac
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Sphider 1.3 - 'configset.php' Remote File Inclusion
CVE-2006-1784—webappsphp
PHP remote file inclusion vulnerability in admin/configset.php in Sphider 1.3 and earlier, when register_globals is disa
23RIESGO
abrir ↗
Referência✓ VexDay Proof
NMDeluxe 1.0.1 - 'footer.php?template' Local File Inclusion
CVE-2007-2303—webappsphp
Directory traversal vulnerability in includes/footer.php in News Manager Deluxe (NMDeluxe) 1.0.1 allows remote attackers
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Acunetix WVS 4.0 20060717 - HTTP Sniffer Component Remote Denial of Service
CVE-2007-0120—doswindows
Acunetix Web Vulnerability Scanner (WVS) 4.0 Build 20060717 and earlier allows remote attackers to cause a denial of ser
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Fuju News 1.0 - Authentication Bypass / SQL Injection
CVE-2006-1837—webappsphp
SQL injection vulnerability in archiv2.php in Fuju News 1.0 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Blackorpheus ClanMemberSkript 1.0 - SQL Injection
CVE-2006-1917—webappsphp
SQL injection vulnerability in member.php in Blackorpheus ClanMemberSkript 1.0 allows remote attackers to execute arbitr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Michelles L2J Dropcalc 4 - SQL Injection
CVE-2007-0687—webappsphp
SQL injection vulnerability in i-search.php in Michelle's L2J Dropcalc 4 and earlier allows remote authenticated users t
23RIESGO
abrir ↗
Referência✓ VexDay Proof
YenerTurk Haber Script 1.0 - SQL Injection
CVE-2006-4064—webappsasp
SQL injection vulnerability in default.asp in YenerTurk Haber Script 1.0 and earlier allows remote attackers to execute
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SAPID Blog Beta 2 - 'ROOT_PATH' Remote File Inclusion
CVE-2006-4063—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Csaba Godor SAPID Blog Beta 2 and earlier allow remote attackers t
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Internet PhotoShow 1.3 - 'page' Remote File Inclusion
CVE-2006-1919—webappsphp
PHP remote file inclusion vulnerability in index.php in Internet Photoshow 1.3 allows remote attackers to execute arbitr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SAPID Shop 1.2 - 'ROOT_PATH' Remote File Inclusion
CVE-2006-4062—webappsphp
PHP remote file inclusion vulnerability in usr/extensions/get_tree.inc.php in Dmitry Sheiko SAPID Shop 1.2 and earlier a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
XnView 1.90.3 - '.xpm' Local Buffer Overflow
CVE-2007-2194—localwindows
Stack-based buffer overflow in XnView 1.90.3 allows user-assisted remote attackers to execute arbitrary code via a craft
28RIESGO
abrir ↗
Referência✓ VexDay Proof
ACDSee 9.0 - '.xpm' Local Buffer Overflow
CVE-2007-2193—localwindows
Stack-based buffer overflow in the ID_X.apl plugin in ACDSee 9.0 Build 108, Pro 8.1 Build 99, and Photo Editor 4.0 Build
50RIESGO
abrir ↗
Referência✓ VexDay Proof
nabopoll 1.2 - Remote Unprotected Admin Section
CVE-2007-0873—webappsphp
nabopoll 1.1.2 allows remote attackers to bypass authentication and access certain administrative functionality via a di
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ATutor 1.5.3.1 - 'links' Blind SQL Injection
CVE-2006-3996—webappsphp
SQL injection vulnerability in links/index.php in ATutor 1.5.3.1 and earlier allows remote authenticated users to execut
23RIESGO
abrir ↗
Referência✓ VexDay Proof
TSEP 0.942 - 'copyright.php' Remote File Inclusion
CVE-2006-3993—webappsphp
PHP remote file inclusion vulnerability in copyright.php in Olaf Noehring The Search Engine Project (TSEP) 0.942 allows
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Voodoo chat 1.0RC1b - 'file_path' Remote File Inclusion
CVE-2006-3991—webappsphp
PHP remote file inclusion vulnerability in index.php in Vlad Vostrykh Voodoo chat 1.0RC1b and earlier allows remote atta
23RIESGO
abrir ↗
Referência✓ VexDay Proof
k_fileManager 1.2 - 'dwl_include_path' Remote File Inclusion
CVE-2006-3987—webappsphp
Multiple PHP remote file inclusion vulnerabilities in index.php in Knusperleicht FileManager 1.2 and earlier allow remot
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Prozilla Reviews Script 1.0 - Arbitrary Delete User
CVE-2008-1783—webappsphp
Prozilla Reviews 1.0 allows remote attackers to delete arbitrary users via a modified UserID parameter in a direct reque
23RIESGO
abrir ↗
Referência✓ VexDay Proof
XOOPS Module WF-Section 1.01 - 'articleId' SQL Injection
CVE-2007-1974—webappsphp
SQL injection vulnerability in the getArticle function in class/wfsarticle.php in WF-Section (aka WF-Sections) 1.0.1, as
23RIESGO
abrir ↗
Referência✓ VexDay Proof
pafileDB 2.0.1 - 'mxBB'/'phpBB' Remote File Inclusion
CVE-2006-2361—webappsphp
PHP remote file inclusion vulnerability in pafiledb_constants.php in Download Manager (mxBB pafiledb) integration, as us
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Python 2.4.2 - 'realpath()' Local Stack Overflow
CVE-2006-1542—locallinux
Stack-based buffer overflow in Python 2.4.2 and earlier, running on Linux 2.6.12.5 under gcc 4.0.3 with libc 2.3.5, allo
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ScriptMagix Jokes 2.0 - 'index.php?catid' SQL Injection
CVE-2007-1615—webappsphp
SQL injection vulnerability in index.php in ScriptMagix Jokes 2.0 and earlier allows remote attackers to execute arbitra
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Flatchat 3.0 - 'pmscript.php' Local File Inclusion
CVE-2009-1486—webappsphp
Directory traversal vulnerability in pmscript.php in Flatchat 3.0 allows remote attackers to include and execute arbitra
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Studio Lounge Address Book 2.5 - 'profile' Arbitrary File Upload
CVE-2009-1483—webappsphp
Unrestricted file upload vulnerability in upload-file.php in Adam Patterson Studio Lounge Address Book 2.5, as reachable
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mambo Component Pearl 1.6 - Multiple Remote File Inclusions
CVE-2006-3340—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Pearl For Mambo module 1.6 for Mambo, when register_globals is ena
28RIESGO
abrir ↗
Referência✓ VexDay Proof
Cmaps v8.0 - SQL injection
CVE-2023-29809CRITICALwebappsphp
SQL injection vulnerability found in Maximilian Vogt companymaps (cmaps) v.8.0 allows a remote attacker to execute arbit
53RIESGO
abrir ↗
Referência✓ VexDay Proof
MyPHP CMS 0.3 - 'domain' Remote File Inclusion
CVE-2006-3478—webappsphp
PHP remote file inclusion vulnerability in styles/default/global_header.php in MyPHP CMS 0.3 and earlier, when register_
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WU-FTPD 2.6.2 - 'wuftpd-freezer.c' Remote Denial of Service
CVE-2003-0854—doslinux
ls in the fileutils or coreutils packages allows local users to consume a large amount of memory via a large -w value, w
23RIESGO
abrir ↗
Referência✓ VexDay Proof
LimeSurvey 4.1.11 - 'File Manager' Path Traversal
CVE-2020-11455—webappsphp
LimeSurvey before 4.1.12+200324 contains a path traversal vulnerability in application/controllers/admin/LimeSurveyFileM
60RIESGO
abrir ↗
← anteriorpágina 809 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.