Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.117exploits catalogados
38.374CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
PHP iCalendar 2.21 - 'publish.ical.php' Remote Code Execution
CVE-2006-1291—webappsphp
publish.ical.php in Jim Hu and Chad Little PHP iCalendar 2.21 and earlier does not require authentication for write acce
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SQuery 4.5 - 'libpath' Remote File Inclusion
CVE-2006-1610—webappsphp
PHP remote file inclusion vulnerability in lib/armygame.php in SQuery 4.5 and earlier, as used in products such as Auton
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Light Weight Calendar 1.x - 'date' Remote Code Execution
CVE-2006-1252—webappsphp
Eval injection vulnerability in cal.php in Light Weight Calendar (LWC) 1.0 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP iCalendar 2.21 - 'cookie' Remote Code Execution
CVE-2006-1292—webappsphp
Directory traversal vulnerability in Jim Hu and Chad Little PHP iCalendar 2.21 and earlier allows remote attackers to in
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Yahoo! Music Jukebox 2.2 - 'AddImage()' ActiveX Remote Buffer Overflow (1)
CVE-2008-0623—remotewindows
Stack-based buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! Music Jukebox 2.2.2.056 allows
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Yahoo! Music Jukebox 2.2 - 'AddImage()' ActiveX Remote Buffer Overflow (2)
CVE-2008-0623—remotewindows
Stack-based buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! Music Jukebox 2.2.2.056 allows
23RIESGO
abrir ↗
Referência✓ VexDay Proof
FreeWPS 2.11 - 'images.php' Remote Code Execution
CVE-2006-1363—webappsphp
images.php in Justin White (aka YTZ) Free Web Publishing System (FreeWPS) 2.11 allows remote attackers to execute arbitr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
XHP CMS 0.5 - 'upload' Remote Command Execution
CVE-2006-1371—webappsphp
Laurentiu Matei eXpandable Home Page (XHP) CMS 0.5 and earlier allows remote authenticated users to use the HTMLArea Fil
23RIESGO
abrir ↗
Referência✓ VexDay Proof
phpBB SpamBlocker Mod 1.0.2 - Remote File Inclusion
CVE-2006-5301—webappsphp
PHP remote file inclusion vulnerability in includes/antispam.php in the SpamBlockerMODv 1.0.2 and earlier module for php
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Transmit.app 3.5.5 - 'ftps://' URL Handler Heap Buffer Overflow (PoC)
CVE-2007-0020—dososx
Heap-based buffer overflow in the SFTP protocol handler for Panic Transmit (Transmit.app) up to 3.5.5 allows remote atta
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Fuju News 1.0 - Authentication Bypass / SQL Injection
CVE-2006-1837—webappsphp
SQL injection vulnerability in archiv2.php in Fuju News 1.0 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
vp-asp shopping cart 6.09 - SQL Injection / Cross-Site Scripting
CVE-2007-0225—webappsasp
Cross-site scripting (XSS) vulnerability in shopcustadmin.asp in VP-ASP Shopping Cart 6.09 and earlier allows remote att
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ImageStation - 'SonyISUpload.cab' 1.0.0.38 ActiveX Buffer Overflow
CVE-2008-0748—remotewindows
Buffer overflow in the Sony AxRUploadServer.AxRUploadControl.1 ActiveX control in AxRUploadServer.dll 1.0.0.38 in SonyIS
28RIESGO
abrir ↗
Referência✓ VexDay Proof
VP-ASP 6.00 - 'shopcurrency.asp' SQL Injection
CVE-2006-2263—webappsasp
SQL injection vulnerability in shopcurrency.asp in VP-ASP 6.00 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ITechBids 6.0 - 'item_id' SQL Injection
CVE-2008-0776—webappsphp
SQL injection vulnerability in detail.php in iTechBids Gold 6.0 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Back-End CMS 0.7.2.2 - 'BE_config.php' Remote File Inclusion
CVE-2006-2682—webappsphp
PHP remote file inclusion vulnerability in BE_config.php in Back-End CMS 0.7.2.1 and earlier allows remote attackers to
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MoinMoin 1.5.x - 'MOIND_ID' Cookie Login Bypass
CVE-2008-0782—webappsphp
Directory traversal vulnerability in MoinMoin 1.5.8 and earlier allows remote attackers to overwrite arbitrary files via
28RIESGO
abrir ↗
Referência✓ VexDay Proof
CaLogic Calendars 1.2.2 - 'CLPath' Remote File Inclusion
CVE-2006-2570—webappsphp
PHP remote file inclusion vulnerability in CaLogic Calendars 1.2.2 allows remote attackers to execute arbitrary PHP code
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Apple iOS 4.0.3 - DPAP Server Denial of Service
CVE-2008-0830—dosios
The Digital Photo Access Protocol (DPAP) server for iPhoto 4.0.3 allows remote attackers to cause a denial of service (c
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WebspotBlogging 3.0.1 - 'path' Remote File Inclusion
CVE-2006-2860—webappsphp
PHP remote file inclusion vulnerability in Webspotblogging 3.0.1 allows remote attackers to execute arbitrary PHP code v
28RIESGO
abrir ↗
Referência✓ VexDay Proof
CS-Cart 1.3.3 - 'classes_dir' Remote File Inclusion
CVE-2006-2863—webappsphp
PHP remote file inclusion vulnerability in class.cs_phpmailer.php in CS-Cart 1.3.3 allows remote attackers to execute ar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component Rapid Recipe 1.6.5 - SQL Injection
CVE-2008-0831—webappsphp
Multiple SQL injection vulnerabilities in the Rapid Recipe (com_rapidrecipe) 1.6.5 and earlier component for Joomla! all
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Quintessential Player 4.50.1.82 - Playlist Denial of Service (PoC)
CVE-2006-6261—doswindows
Buffer overflow in Quintessential Player 4.50.1.82 and earlier allows remote attackers to cause a denial of service (cra
23RIESGO
abrir ↗
Referência✓ VexDay Proof
THoRCMS 1.3.1 - 'phpbb_root_path' Remote File Inclusion
CVE-2006-3269—webappsphp
PHP remote file inclusion vulnerability in includes/functions_cms.php in THoRCMS 1.3.1 allows remote attackers to execut
23RIESGO
abrir ↗
Referência✓ VexDay Proof
LimeSurvey 4.1.11 - 'File Manager' Path Traversal
CVE-2020-11455—webappsphp
LimeSurvey before 4.1.12+200324 contains a path traversal vulnerability in application/controllers/admin/LimeSurveyFileM
60RIESGO
abrir ↗
Referência✓ VexDay Proof
gCards 1.45 - Multiple Vulnerabilities
CVE-2006-1347—webappsphp
SQL injection vulnerability in loginfunction.php in Greg Neustaetter gCards 1.45 and earlier allows remote attackers to
23RIESGO
abrir ↗
Referência✓ VexDay Proof
gCards 1.45 - Multiple Vulnerabilities
CVE-2006-1348—webappsphp
Cross-site scripting (XSS) vulnerability in index.php in Greg Neustaetter gCards 1.45 and earlier allows remote attacker
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Eskolar CMS 0.9.0.0 - Blind SQL Injection
CVE-2006-3727—webappsphp
Multiple SQL injection vulnerabilities in Eskolar CMS 0.9.0.0 allow remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mambo Module HTMLArea3 1.5 - Remote File Inclusion
CVE-2006-3751—webappsphp
PHP remote file inclusion vulnerability in popups/ImageManager/config.inc.php in the HTMLArea3 Addon Component (com_html
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mambo Component MoSpray 18RC1 - Remote File Inclusion
CVE-2006-3847—webappsphp
PHP remote file inclusion vulnerability in (1) admin.php, and possibly (2) details.php, (3) modify.php, (4) newgroup.php
23RIESGO
abrir ↗
← anteriorpágina 810 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.