Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.201exploits catalogados
38.442CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
FCRing 1.31 - 'fcring.php?s_fuss' Remote File Inclusion
CVE-2007-1133—webappsphp
PHP remote file inclusion vulnerability in fcring.php in FCRing 1.3 allows remote attackers to execute arbitrary PHP cod
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Novell eDirectory < 8.7.3 SP 10 / 8.8.2 - HTTP headers Denial of Service
CVE-2008-0927—doswindows
dhost.exe in Novell eDirectory 8.7.3 before sp10 and 8.8.2 allows remote attackers to cause a denial of service (CPU con
45RIESGO
abrir ↗
Referência✓ VexDay Proof
phpArcadeScript 4 - 'cat' SQL Injection
CVE-2008-3711—webappsphp
SQL injection vulnerability in index.php in PHPArcadeScript (PHP Arcade Script) 4.0 allows remote attackers to execute a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Essentia Web Server 2.15 - GET Remote Denial of Service
CVE-2006-5850—doswindows
Stack-based buffer overflow in Essentia Web Server 2.15 for Windows allows remote attackers to execute arbitrary code vi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Affiliate Directory - 'id' SQL Injection
CVE-2008-3719—webappsphp
SQL injection vulnerability in directory.php in SFS Affiliate Directory allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Microsoft Visual 6 - 'VDT70.dll NotSafe' Remote Stack Overflow
CVE-2007-4254—remotewindows
Stack-based buffer overflow in a certain ActiveX control in VDT70.DLL in Microsoft Visual Database Tools Database Design
28RIESGO
abrir ↗
Referência✓ VexDay Proof
eMeeting Online Dating Software 5.2 - SQL Injection
CVE-2007-3609—webappsphp
Multiple SQL injection vulnerabilities in eMeeting Online Dating Software 5.2 allow remote attackers to execute arbitrar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Falt4 CMS rc4 10.9.2007 - Multiple Vulnerabilities
CVE-2007-6311—webappsphp
SQL injection vulnerability in (1) index.php, and possibly (2) admin/index.php, in Falt4Extreme RC4 10.9.2007 allows rem
23RIESGO
abrir ↗
Referência✓ VexDay Proof
e107 Plugin ZoGo-Shop 1.15.4 - 'product' SQL Injection
CVE-2008-6114—webappsphp
SQL injection vulnerability in product_details.php in the Mytipper Zogo-shop 1.15.4 plugin for e107 allows remote attack
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Microsoft GDI Plugin - '.png' Infinite Loop Denial of Service (PoC)
CVE-2009-1511—doswindows
GDI+ in Microsoft Windows XP SP3 allows remote attackers to cause a denial of service (infinite loop) via a PNG file tha
28RIESGO
abrir ↗
Referência✓ VexDay Proof
TemaTres 1.0.3 - Blind SQL Injection
CVE-2009-1584—webappsphp
Multiple SQL injection vulnerabilities in TemaTres 1.0.3 and 1.031, when magic_quotes_gpc is disabled, allow remote atta
23RIESGO
abrir ↗
Referência✓ VexDay Proof
vbPortal 3.0.2 < 3.6.0 b1 - 'cookie' Remote Code Execution
CVE-2006-4004—webappsphp
Directory traversal vulnerability in index.php in vbPortal 3.0.2 through 3.6.0 Beta 1, when magic_quotes_gpc is disabled
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Oracle APEX 3.2 - Unprivileged DB users can see APEX Password hashes
CVE-2009-0981—localmultiple
Unspecified vulnerability in the Application Express component in Oracle Database 11.1.0.7 allows remote authenticated u
23RIESGO
abrir ↗
Referência✓ VexDay Proof
merlix educate servert - Authentication Bypass / File Disclosure
CVE-2008-6871—webappsasp
Merlix Educate Server stores db.mdb under the web root with insufficient access control, which allows remote attackers t
23RIESGO
abrir ↗
Referência✓ VexDay Proof
YourFreeWorld Viral Marketing - SQL Injection
CVE-2008-3756—webappsphp
SQL injection vulnerability in tr.php in YourFreeWorld Viral Marketing Script allows remote attackers to execute arbitra
23RIESGO
abrir ↗
Referência✓ VexDay Proof
phpAuction - 'profile.php' SQL Injection (1)
CVE-2008-6663—webappsphp
SQL injection vulnerability in profile.php in PHPAuctions.info PHPAuctions (aka PHPAuctionSystem) allows remote attacker
23RIESGO
abrir ↗
Referência✓ VexDay Proof
AJ Auction Pro Platinum - 'seller_id' SQL Injection
CVE-2008-6003—webappsphp
SQL injection vulnerability in sellers_othersitem.php in AJ Auction Pro Platinum 2 allows remote attackers to execute ar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP Live Helper 2.0.1 - Multiple Vulnerabilities
CVE-2008-3762—webappsphp
SQL injection vulnerability in onlinestatus_html.php in Turnkey PHP Live Helper 2.0.1 and earlier allows remote attacker
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component RSfiles 1.0.2 - 'path' File Download
CVE-2007-4504—webappsphp
Directory traversal vulnerability in index.php in the RSfiles component (com_rsfiles) 1.0.2 and earlier for Joomla! allo
38RIESGO
abrir ↗
Referência✓ VexDay Proof
Quick Poll Script - 'id' SQL Injection
CVE-2008-3765—webappsphp
SQL injection vulnerability in code.php in Quick Poll Script allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Social Site Generator 2.0 - 'path' Remote File Inclusion
CVE-2008-6421—webappsphp
PHP remote file inclusion vulnerability in social_game_play.php in Social Site Generator (SSG) 2.0 allows remote attacke
23RIESGO
abrir ↗
Referência✓ VexDay Proof
freeSSHd 1.2.1 - (Authenticated) SFTP 'rename' Remote Buffer Overflow (PoC)
CVE-2008-4762—doswindows
Stack-based buffer overflow in freeSSHd 1.2.1 allows remote authenticated users to cause a denial of service (service cr
28RIESGO
abrir ↗
Referência✓ VexDay Proof
2532/Gigs 1.2.1 - 'activateuser.php' Local File Inclusion
CVE-2007-4585—webappsphp
Directory traversal vulnerability in activateuser.php in 2532|Gigs 1.2.1 allows remote attackers to include and execute
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SFS EZ Pub Site - SQL Injection
CVE-2008-6794—webappsphp
SQL injection vulnerability in directory.php in Scripts For Sites (SFS) EZ Pub Site allows remote attackers to execute a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
FREEsimplePHPGuestbook - 'Guestbook.php' Remote Code Execution
CVE-2008-6934—webappsphp
Static code injection vulnerability in Sanus|artificium (aka Sanusart) Free simple guestbook PHP script, when downloaded
23RIESGO
abrir ↗
Referência✓ VexDay Proof
μTorrent (uTorrent) / BitTorrent WebIU HTTP 1.7.7/6.0.1 - Range header Denial of Service
CVE-2008-0071—doswindows
The Web UI interface in (1) BitTorrent before 6.0.3 build 8642 and (2) uTorrent before 1.8beta build 10524 allows remote
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MyPHP Forum 3.0 - 'Final' SQL Injection
CVE-2008-0099—webappsphp
Multiple SQL injection vulnerabilities in MyPHP Forum 3.0 and earlier allow remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Pre Classified Listings - Insecure Cookie Handling
CVE-2008-6231—webappsphp
Pre Classified Listing PHP allows remote attackers to bypass authentication and gain administrative access by setting th
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHPmyGallery Gold 1.51 - 'index.php' Directory Traversal
CVE-2008-5598—webappsphp
Directory traversal vulnerability in index.php in PHPmyGallery 1.51 gold allows remote attackers to list arbitrary direc
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Kasseler CMS 1.3.0 - Local File Inclusion / Cross-Site Scripting
CVE-2008-3087—webappsphp
Directory traversal vulnerability in Kasseler CMS 1.3.0 allows remote attackers to read arbitrary files via a .. (dot do
23RIESGO
abrir ↗
← anteriorpágina 814 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.