Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.122exploits catalogados
38.377CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
Centreon 1.4.2.3 - 'get_image.php' Remote File Disclosure
CVE-2008-1119—webappsphp
Directory traversal vulnerability in include/doc/get_image.php in Centreon 1.4.2.3 and earlier allows remote attackers t
23RIESGO
abrir ↗
Referência✓ VexDay Proof
FlashBB 1.1.8 - 'phpbb_root_path' Remote File Inclusion
CVE-2006-7032—webappsphp
PHP remote file inclusion vulnerability in phpbb/getmsg.php in FlashBB 1.1.5 and earlier allows remote attackers to exec
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Linux Kernel 2.6.x - 'sys_timer_create()' Local Denial of Service
CVE-2006-7051—doslinux
The sys_timer_create function in posix-timers.c for Linux kernel 2.6.x allows local users to cause a denial of service (
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Cheats Complete Website 1.1.1 - 'itemID' SQL Injection
CVE-2008-5170—webappsphp
SQL injection vulnerability in item.php in Cheats Complete Website 1.1.1 allows remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Easysitenetwork Jokes Complete Website 2.1.3 - 'jokeid' SQL Injection
CVE-2008-5174—webappsphp
SQL injection vulnerability in joke.php in Jokes Complete Website 2.1.3 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Referência✓ VexDay Proof
myEvent 1.6 - 'eventdate' SQL Injection
CVE-2008-4650—webappsphp
SQL injection vulnerability in viewevent.php in myEvent 1.6 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Absolute Control Panel XE 1.5 - Insecure Cookie Handling
CVE-2008-6859—webappsphp
Xigla Software Absolute Control Panel XE 1.5 allows remote attackers to bypass authentication and gain administrative ac
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Absolute Live Support 5.1 - Insecure Cookie Handling
CVE-2008-6864—webappsphp
Xigla Software Absolute Live Support .NET 5.1 allows remote attackers to bypass authentication and gain administrative a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
merlix educate servert - Authentication Bypass / File Disclosure
CVE-2008-6870—webappsasp
Merlix Educate Server allows remote attackers to bypass intended security restrictions and obtain sensitive information
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Calendar MX BASIC 1.0.2 - 'ID' SQL Injection
CVE-2006-6792—webappsasp
SQL injection vulnerability in calendar_detail.asp in Calendar MX BASIC 1.0.2 and earlier allows remote attackers to exe
23RIESGO
abrir ↗
Referência✓ VexDay Proof
geccBBlite 2.0 - 'id' SQL Injection
CVE-2008-4517—webappsphp
SQL injection vulnerability in leggi.php in geccBBlite 2.0 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Enthrallweb eNews 1.0 - Remote User Pass Change
CVE-2006-6821—webappsasp
myprofile.asp in Enthrallweb eNews does not properly validate the MM_recordId parameter during profile updates, which al
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Shadowed Portal Module Character Roster - 'mod_root' Remote File Inclusion
CVE-2006-6850—webappsphp
PHP remote file inclusion vulnerability in include.php in the Roster Module (character_roster) in Shadowed Portal 5.7 al
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ExoPHPDesk 1.2 Final - Authentication Bypass
CVE-2008-6917—webappsphp
SQL injection vulnerability in admin.php in Exocrew ExoPHPDesk 1.2 Final allows remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ClipShare Pro 2006-2007 - 'chid' SQL Injection
CVE-2008-5489—webappsphp
SQL injection vulnerability in channel_detail.php in ClipShare Pro 4, and 2006 through 2007, allows remote attackers to
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Really Simple PHP and Ajax (RSPA) 2007-03-23 - Remote File Inclusion
CVE-2007-1851—webappsphp
Multiple directory traversal vulnerabilities in Really Simple PHP and Ajax (RSPA) 2007-03-23 allow remote attackers to i
23RIESGO
abrir ↗
Referência✓ VexDay Proof
XOOPS Module MyAds Bug Fix 2.04jp - 'index.php' SQL Injection
CVE-2007-1846—webappsphp
SQL injection vulnerability in index.php in the MyAds 2.04jp and earlier module for Xoops allows remote attackers to exe
23RIESGO
abrir ↗
Referência✓ VexDay Proof
eXchange POP3 5.0.050203 - RPCT TO Remote Buffer Overflow
CVE-2006-0537—remotewindows
Buffer overflow in the POP3 server in Kinesphere Corporation eXchange before 5.0.060125 allows remote attackers to execu
35RIESGO
abrir ↗
Referência✓ VexDay Proof
jspwiki 2.4.104/2.5.139 - Multiple Vulnerabilities
CVE-2008-1229—webappsjsp
Cross-site scripting (XSS) vulnerability in Edit.jsp in JSPWiki 2.4.104 and 2.5.139 allows remote attackers to inject ar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
BM Classifieds 20080409 - Multiple SQL Injections
CVE-2008-1272—webappsphp
Multiple SQL injection vulnerabilities in BM Classifieds 20080309 and earlier allow remote attackers to execute arbitrar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Butterfly ORGanizer 2.0.0 - SQL Injection / Cross-Site Scripting
CVE-2008-6328—webappsphp
SQL injection vulnerability in view.php in Butterfly Organizer 2.0.0 and 2.0.1 allows remote attackers to execute arbitr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Linkarity - 'link.php' SQL Injection
CVE-2008-4353—webappsphp
SQL injection vulnerability in link.php in Linkarity allows remote attackers to execute arbitrary SQL commands via the c
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Active Time Billing 3.2 - Authentication Bypass
CVE-2008-5632—webappsphp
SQL injection vulnerability in Account.asp in Active Time Billing 3.2 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Lito Lite CMS - 'cid' SQL Injection
CVE-2008-5636—webappsphp
SQL injection vulnerability in cate.php in Lito Lite CMS, when magic_quotes_gpc is disabled, allows remote attackers to
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CMS Made Simple 1.4.1 - Local File Inclusion
CVE-2008-5642—webappsphp
Directory traversal vulnerability in admin/login.php in CMS Made Simple 1.4.1 allows remote attackers to read arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component live chat - SQL Injection / Open Proxy
CVE-2008-6881—webappsphp
Multiple SQL injection vulnerabilities in the Live Chat (com_livechat) component 1.0 for Joomla! allow remote attackers
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Injader CMS 2.1.1 - 'id' SQL Injection
CVE-2008-5890—webappsphp
SQL injection vulnerability in feeds.php in Injader before 2.1.2 allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WebPortal CMS 0.7.4 - 'download.php' SQL Injection
CVE-2008-4345—webappsphp
SQL injection vulnerability in download.php in WebPortal CMS 0.7.4 and earlier allows remote attackers to execute arbitr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Autodealers CMS AutOnline - 'id' SQL Injection
CVE-2008-4074—webappsphp
SQL injection vulnerability in index.php in Zanfi Autodealers CMS AutOnline allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mambo Component Remository - 'cat' SQL Injection
CVE-2007-4505—webappsphp
SQL injection vulnerability in index.php in the RemoSitory component (com_remository) for Mambo allows remote attackers
23RIESGO
abrir ↗
← anteriorpágina 812 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.