Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.117exploits catalogados
38.374CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
Web Oddity Web Server 0.09b - Directory Traversal
CVE-2007-4726—remotelinux
Directory traversal vulnerability in Web Oddity 0.09b allows remote attackers to read arbitrary files via a .. (dot dot)
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SiteBuilderElite 1.2 - Multiple Remote File Inclusions
CVE-2008-1123—webappsphp
Multiple PHP remote file inclusion vulnerabilities in SiteBuilder Elite 1.2 allow remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component GameQ 4.0 - SQL Injection
CVE-2008-2701—webappsphp
SQL injection vulnerability in the GameQ (com_gameq) component 4.0 and earlier for Joomla! allows remote attackers to ex
23RIESGO
abrir ↗
Referência✓ VexDay Proof
RoomPHPlanning 1.5 - 'idresa' SQL Injection
CVE-2008-6633—webappsphp
SQL injection vulnerability in RoomPHPlanning 1.5 allows remote attackers to execute arbitrary SQL commands via the idre
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Free Arcade Script 1.0 - Local File Inclusion Command Execution
CVE-2009-0731—webappsphp
Directory traversal vulnerability in pages/play.php in Free Arcade Script 1.0 allows remote attackers to include and exe
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Phoenician Casino FlashAX - ActiveX Remote Code Execution
CVE-2008-5691—remotewindows
Heap-based buffer overflow in the Phoenician Casino FlashAX ActiveX control 1.0.0.7 allows remote attackers to execute a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Campsite 3.3.0 RC1 - Multiple Remote File Inclusions
CVE-2009-2181—webappsphp
Cross-site scripting (XSS) vulnerability in admin-files/templates/list_dir.php in Campsite 3.3.0 RC1 allows remote attac
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Poppawid 2.7 - 'form' Remote File Inclusion
CVE-2007-5221—webappsphp
PHP remote file inclusion vulnerability in mail/childwindow.inc.php in Poppawid 2.7 allows remote attackers to execute a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Destar 0.2.2-5 - Arbitrary Add New User
CVE-2008-6538—webappsphp
DeStar 0.2.2-5 allows remote attackers to add arbitrary users via a direct request to config/add/CfgOptUser.
23RIESGO
abrir ↗
Referência✓ VexDay Proof
living Local 1.1 - Cross-Site Scripting / Arbitrary File Upload
CVE-2008-6529—webappsphp
Cross-site scripting (XSS) vulnerability in listtest.php in eZoneScripts Living Local 1.1 allows remote attackers to inj
23RIESGO
abrir ↗
Referência✓ VexDay Proof
RunCMS 1.6 - Multiple Vulnerabilities
CVE-2007-6546—webappsphp
RunCMS before 1.6.1 uses a predictable session id, which makes it easier for remote attackers to hijack sessions via a m
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Active Membership 2 - Authentication Bypass
CVE-2008-5635—webappsasp
SQL injection vulnerability in account.asp in Active Membership 2.0 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗
Referência✓ VexDay Proof
AlkalinePHP 0.77.35 - 'adduser.php' Arbitrary Add Admin
CVE-2008-2346—webappsphp
AlkalinePHP 0.77.35 and earlier allows remote attackers to bypass authentication and gain administrative access by creat
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Tlnews 2.2 - Insecure Cookie Handling
CVE-2008-4752—webappsphp
TlNews 2.2 allows remote attackers to bypass authentication and gain administrative access by setting the tlNews_login c
23RIESGO
abrir ↗
Referência✓ VexDay Proof
team 1.x - File Disclosure / Cross-Site Scripting
CVE-2009-0760—webappsasp
Team Board 1.x and 2.x stores sensitive information under the web root with insufficient access control, which allows re
23RIESGO
abrir ↗
Referência✓ VexDay Proof
FLABER 1.1 RC1 - Remote Command Execution
CVE-2008-6490—webappsphp
function/update_xml.php in FLABER 1.1 and earlier allows remote attackers to overwrite arbitrary files by specifying the
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Pharmacy System 2.0 - 'index.php?ID' SQL Injection
CVE-2007-3434—webappsphp
index.php in Pharmacy System 2 and earlier allows remote attackers to obtain sensitive information via a ' (quote) chara
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component MyAlbum 1.0 - 'album' SQL Injection
CVE-2008-6489—webappsphp
SQL injection vulnerability in MyAlbum component (com_myalbum) 1.0 for Joomla! allows remote attackers to execute arbitr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
EncapsCMS 0.3.6 - '/core/core.php' Remote File Inclusion
CVE-2006-5895—webappsphp
PHP remote file inclusion vulnerability in core/core.php in EncapsCMS 0.3.6 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
LinPHA 1.3.3 Plugin Maps - Remote Command Execution
CVE-2008-1856—webappsphp
plugins/maps/db_handler.php in LinPHA 1.3.3 and earlier does not require authentication for a settings action that modif
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WoW Roster 1.5.1 - 'subdir' Remote File Inclusion
CVE-2006-3998—webappsphp
PHP remote file inclusion vulnerability in conf.php in WoWRoster (aka World of Warcraft Roster) 1.5.1 and earlier allows
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Pet Grooming Management System 2.0 - Arbitrary Add Admin
CVE-2008-2294—webappsphp
Pet Grooming Management System 2.0 allows remote attackers to gain privileges via a direct request to useradded.php with
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Pooya Site Builder (PSB) 6.0 - Multiple SQL Injections
CVE-2008-2753—webappsphp
Multiple SQL injection vulnerabilities in Pooya Site Builder (PSB) 6.0 allow remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Microsoft Office - MSODataSourceControl COM-object Buffer Overflow (PoC)
CVE-2007-3282—doswindows
Buffer overflow in the Microsoft Office MSODataSourceControl ActiveX object allows remote attackers to cause a denial of
35RIESGO
abrir ↗
Referência✓ VexDay Proof
virtue news - SQL Injection / Cross-Site Scripting
CVE-2009-2020—webappsphp
Cross-site scripting (XSS) vulnerability in news_detail.php in Virtue News Manager allows remote attackers to inject arb
23RIESGO
abrir ↗
Referência✓ VexDay Proof
HLStats 1.34 - 'hlstats.php' SQL Injection
CVE-2006-6781—webappsphp
HLstats 1.20 through 1.34 allows remote attackers to obtain sensitive information via playinfo mode, with certain values
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Poplar Gedcom Viewer 2.0 - 'common.php' Remote File Inclusion
CVE-2007-0307—webappsphp
PHP remote file inclusion vulnerability in include/common.php in Poplar Gedcom Viewer 2.0 and earlier allows remote atta
23RIESGO
abrir ↗
Referência✓ VexDay Proof
LokiCMS 0.3.3 - Arbitrary File Delete
CVE-2008-4913—webappsphp
Directory traversal vulnerability in admin.php in LokiCMS 0.3.3 and earlier allows remote attackers to delete arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
IrayoBlog 0.2.4 - '/inc/irayofuncs.php' Remote File Inclusion
CVE-2006-5849—webappsphp
PHP remote file inclusion vulnerability in inc/irayofuncs.php in IrayoBlog alpha-0.2.4 allows remote attackers to execut
23RIESGO
abrir ↗
Referência✓ VexDay Proof
celerbb 0.0.2 - Multiple Vulnerabilities
CVE-2009-0852—webappsphp
showme.php in CelerBB 0.0.2 allows remote attackers to obtain "reserved information" via the user parameter.
23RIESGO
abrir ↗
← anteriorpágina 811 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.