Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.188exploits catalogados
38.439CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
MyBlog 0.9.8 - Insecure Cookie Handling
CVE-2008-4341—webappsphp
add.php in MyBlog 0.9.8 and earlier allows remote attackers to bypass authentication and gain administrative access by s
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Open Auto Classifieds 1.4.3b - SQL Injection
CVE-2008-6656—webappsphp
Multiple SQL injection vulnerabilities in Open Auto Classifieds 1.4.3b allow remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Virtual CD 9.0.0.2 - 'vc9api.DLL' Remote Shell Commands Execution
CVE-2007-2853—remotewindows
The VCDAPILibApi ActiveX control in vc9api.DLL 9.0.0.57 in Virtual CD 9.0.0.2 allows remote attackers to execute arbitra
23RIESGO
abrir ↗
Referência✓ VexDay Proof
LeadTools Raster Variant - 'LTRVR14e.dll' Remote File Overwrite
CVE-2007-2851—remotewindows
A certain ActiveX control in LeadTools Raster Variant Object Library (LTRVR14e.dll) 14.5.0.44 allows remote attackers to
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Web3news 0.95 - 'PHPSECURITYADMIN_PATH' Remote File Inclusion
CVE-2006-4452—webappsphp
PHP remote file inclusion vulnerability in security/include/_class.security.php in Web3news 0.95 and earlier, when regis
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Interact 2.2 - 'CONFIG[base_path]' Remote File Inclusion
CVE-2006-4448—webappsphp
Multiple PHP remote file inclusion vulnerabilities in interact 2.2, when register_globals is enabled, allow remote attac
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CMS Buzz - 'id' SQL Injection
CVE-2008-4374—webappsphp
SQL injection vulnerability in index.php in CMS Buzz allows remote attackers to execute arbitrary SQL commands via the i
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Creator CMS 5.0 - 'sideid' SQL Injection
CVE-2008-4377—webappsasp
SQL injection vulnerability in index.asp in Creative Mind Creator CMS 5.0 allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Hot Links SQL-PHP 3 - 'report.php' Multiple Vulnerabilities
CVE-2008-4378—webappsphp
SQL injection vulnerability in report.php in Mr. CGI Guy Hot Links SQL-PHP 3.0 and earlier allows remote attackers to ex
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Masir Camp E-Shop Module 3.0 - 'ordercode' SQL Injection
CVE-2008-3955—webappsphp
SQL injection vulnerability in index.php in Masir Camp E-Shop Module 3.0 and earlier allows remote attackers to execute
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mambo Component musepoes - 'aid' SQL Injection
CVE-2008-0579—webappsphp
SQL injection vulnerability in index.php in the buslicense (com_buslicense) component for Joomla! allows remote attacker
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP Autos 2.9.1 - 'catid' SQL Injection
CVE-2008-4498—webappsphp
SQL injection vulnerability in searchresults.php in PHP Autos 2.9.1 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Konqueror 3.5.9 - 'font color' Remote Crash
CVE-2008-4514—doslinux
The HTML parser in KDE Konqueror 3.5.9 allows remote attackers to cause a denial of service (application crash) via a fo
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Fastpublish CMS 1.9999 - Local File Inclusion / SQL Injection
CVE-2008-4518—webappsphp
Multiple SQL injection vulnerabilities in Fastpublish CMS 1.9.9.9.9 d (1.9999 d) allow remote attackers to execute arbit
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mambo Component com_yanc 1.4 Beta - 'id' SQL Injection
CVE-2007-2792—webappsphp
SQL injection vulnerability in the Yet another Newsletter Component (aka YaNC or com_yanc) component before 1.5 beta 3 f
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component Highwood Design hwdVideoShare - SQL Injection
CVE-2008-0916—webappsphp
SQL injection vulnerability in the Highwood Design hwdVideoShare (com_hwdvideoshare) 1.1.3 Alpha component for Joomla!
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CafeEngine - Multiple SQL Injections
CVE-2008-4605—webappsphp
SQL injection vulnerability in CafeEngine allows remote attackers to execute arbitrary SQL commands via the id parameter
23RIESGO
abrir ↗
Referência✓ VexDay Proof
DELTAScripts PHP Classifieds 7.5 - Authentication Bypass
CVE-2008-5806—webappsphp
SQL injection vulnerability in login.php in DeltaScripts PHP Classifieds 7.5 and earlier allows remote attackers to exec
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component actualite 1.0 - 'id' SQL Injection
CVE-2008-4617—webappsphp
SQL injection vulnerability in the actualite module 1.0 for Joomla! allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Ultimate WebBoard 3.00 - 'Category' SQL Injection
CVE-2008-4666—webappsphp
SQL injection vulnerability in webboard.php in Ultimate Webboard 3.00 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ArabCMS - 'rss.php' Local File Inclusion
CVE-2008-4667—webappsphp
Directory traversal vulnerability in rss.php in ArabCMS 2.0 beta 1 allows remote attackers to include and execute arbitr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
more.groupware 0.74 - 'new_calendarid' SQL Injection
CVE-2006-4906—webappsphp
SQL injection vulnerability in modules/calendar/week.php in More.groupware 0.74 allows remote attackers to execute arbit
23RIESGO
abrir ↗
Referência✓ VexDay Proof
InoutMailingListManager 3.1 - Remote Command Execution
CVE-2007-2004—webappsphp
Multiple SQL injection vulnerabilities in InoutMailingListManager 3.1 and earlier allow remote attackers to execute arbi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Bloggie Lite 0.0.2 Beta - Insecure Cookie Handling / SQL Injection
CVE-2008-5004—webappsphp
SQL injection vulnerability in genscode.php in myWebland Bloggie Lite 0.0.2 beta allows remote attackers to execute arbi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mole Group Pizza - 'manufacturers_id' SQL Injection
CVE-2008-5046—webappsphp
SQL injection vulnerability in index.php in Mole Group Pizza Script allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mole Group Rental Script - Authentication Bypass
CVE-2008-5047—webappsphp
SQL injection vulnerability in admin/index.php in Mole Group Rental Script allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
minimal ablog 0.4 - SQL Injection / Arbitrary File Upload / Authentication Bypass
CVE-2008-6611—webappsphp
SQL injection vulnerability in index.php in Minimal ABlog 0.4 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WordPress Plugin Enigma 2 Bridge - 'boarddir' Remote File Inclusion
CVE-2006-6863CRITICALwebappsphp
PHP remote file inclusion vulnerability in the Enigma2 plugin (Enigma2.php) in Enigma WordPress Bridge allows remote att
53RIESGO
abrir ↗
Referência✓ VexDay Proof
eFiction < 2.0.7 - Remote Admin Authentication Bypass
CVE-2006-4427—webappsphp
index.php in eFiction before 2.0.7 allows remote attackers to bypass authentication and gain privileges by setting the (
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Nitrotech 0.0.3a - Remote Code Execution
CVE-2006-6938—webappsphp
Directory traversal vulnerability in includes/common.php in NitroTech 0.0.3a, as distributed before 2006, allows remote
23RIESGO
abrir ↗
← anteriorpágina 813 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.