Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.202exploits catalogados
38.443CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
blogme 3.0 - Cross-Site Scripting / Authentication Bypass
CVE-2006-5975—webappsasp
Multiple cross-site scripting (XSS) vulnerabilities in comments.asp in BlogMe 3.0 allow remote attackers to inject arbit
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Poll Pro 2.0 - Authentication Bypass
CVE-2008-5573—webappsasp
SQL injection vulnerability in the login feature in Poll Pro 2.0 allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ActiveVotes 2.2 - 'AccountID' Blind SQL Injection
CVE-2008-5365—webappsasp
SQL injection vulnerability in VoteHistory.asp in ActiveWebSoftwares ActiveVotes 2.2 allows remote attackers to execute
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PozScripts Classified Auctions - 'gotourl.php?id' SQL Injection
CVE-2008-4755—webappsphp
SQL injection vulnerability in gotourl.php in PozScripts Classified Auctions Script allows remote attackers to execute a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Adult Directory - 'cat_id' SQL Injection
CVE-2007-4056—webappsphp
SQL injection vulnerability in directory.php in Prozilla Adult Directory allows remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Google Chrome 0.2.149.27 - Denial of Service
CVE-2008-6995—doswindows
Integer underflow in net/base/escape.cc in chrome.dll in Google Chrome 0.2.149.27 allows remote attackers to cause a den
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP Auto Dealer 2.7 - 'v_cat' SQL Injection
CVE-2008-4495—webappsphp
SQL injection vulnerability in view_cat.php in PHP Auto Dealer 2.7 allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component com_jim 1.0.1 - Remote File Inclusion
CVE-2006-4242—webappsphp
PHP remote file inclusion vulnerability in install.jim.php in the JIM 1.0.1 component for Joomla or Mambo allows remote
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ITechBids 7.0 gold - Cross-Site Scripting / SQL Injection
CVE-2008-3238—webappsphp
Multiple SQL injection vulnerabilities in ITechBids 7.0 Gold allow remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Battle Blog 1.25 - 'comment.asp' SQL Injection
CVE-2008-2626—webappsphp
SQL injection vulnerability in comment.asp in Battle Blog 1.25 and earlier allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mambo Component Quran 1.1 - 'surano' SQL Injection
CVE-2008-0832—webappsphp
SQL injection vulnerability in index.php in the Kemas Antonius com_quran 1.1 and earlier component for Mambo and Joomla!
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHPMyRealty 1.0.x - 'search.php' SQL Injection
CVE-2007-6472—webappsphp
Multiple SQL injection vulnerabilities in phpMyRealty (PMR) 1.0.9 allow (1) remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CoolPlayer 2.17 - '.m3u' Local Stack Overflow
CVE-2006-6288—localwindows
Multiple buffer overflows in Niek Albers CoolPlayer 216 and earlier allow remote attackers to execute arbitrary code via
23RIESGO
abrir ↗
Referência✓ VexDay Proof
F-Prot AntiVirus 4.6.6 - CHM Heap Overflow (PoC)
CVE-2006-6293—doslinux
Heap-based buffer overflow in FRISK Software F-Prot Antivirus before 4.6.7 allows user-assisted remote attackers to exec
28RIESGO
abrir ↗
Referência✓ VexDay Proof
elvin bts 1.2.0 - Multiple Vulnerabilities
CVE-2009-2127—webappsphp
Cross-site scripting (XSS) vulnerability in show_activity.php in Elvin 1.2.0 allows remote attackers to inject arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP-Update 2.7 - Multiple Vulnerabilities
CVE-2006-6879—webappsphp
Unrestricted file upload vulnerability in admin/uploads.php in PHP-Update 2.7 and earlier allows remote authenticated us
23RIESGO
abrir ↗
Referência✓ VexDay Proof
RTWebalbum 1.0.462 - 'albumID' Blind SQL Injection
CVE-2009-1910—webappsphp
SQL injection vulnerability in index.php in RTWebalbum 1.0.462 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Click&Rank - SQL Injection / Cross-Site Scripting
CVE-2008-5889—webappsasp
Cross-site scripting (XSS) vulnerability in user.asp in Click&Rank allows remote attackers to inject arbitrary web scrip
23RIESGO
abrir ↗
Referência✓ VexDay Proof
vm Watermark for Gallery 0.4.1 - Remote File Inclusion
CVE-2007-2575—webappsphp
PHP remote file inclusion vulnerability in watermark.php in the vm (aka Jean-Francois Laflamme) watermark 0.4.1 mod for
23RIESGO
abrir ↗
Referência✓ VexDay Proof
AIDeX Mini-WebServer 1.1 - Remote Crash (Denial of Service)
CVE-2006-6855—doswindows
AIDeX Mini-WebServer 1.1 early release 3 allows remote attackers to cause a denial of service (daemon crash) via a flood
23RIESGO
abrir ↗
Referência✓ VexDay Proof
RiteCMS 2.2.1 - Authenticated Remote Code Execution
CVE-2020-23934—webappsphp
An issue was discovered in RiteCMS 2.2.1. An authenticated user can directly execute system commands by uploading a php
28RIESGO
abrir ↗
Referência✓ VexDay Proof
Squirrelcart 2.2.0 - 'cart_content.php' Remote File Inclusion
CVE-2006-2483—webappsphp
PHP remote file inclusion vulnerability in cart_content.php in Squirrelcart 2.2.2 and earlier allows remote attackers to
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Sugar Suite Open Source 4.2 - 'OptimisticLock' Command Execution
CVE-2006-2460—webappsphp
Sugar Suite Open Source (SugarCRM) 4.2 and earlier, when register_globals is enabled, does not protect critical variable
28RIESGO
abrir ↗
Referência✓ VexDay Proof
aForum 1.32 - 'CommonAbsDir' Remote File Inclusion
CVE-2007-2596—webappsphp
PHP remote file inclusion vulnerability in common/func.php in aForum 1.32 and earlier allows remote attackers to execute
23RIESGO
abrir ↗
Referência✓ VexDay Proof
AstonSoft DeepBurner 1.8.0 - '.dbr' File Parsing Buffer Overflow
CVE-2006-6665—localwindows
Buffer overflow in Astonsoft DeepBurner Pro and Free 1.8.0 and earlier allows user-assisted remote attackers to execute
50RIESGO
abrir ↗
Referência✓ VexDay Proof
MemHT Portal 3.9.0 - Remote Create Shell
CVE-2008-4457—webappsphp
SQL injection vulnerability in inc/inc_statistics.php in MemHT Portal 3.9.0 and earlier, when magic_quotes_gpc is disabl
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP-Update 2.7 - Multiple Vulnerabilities
CVE-2006-6880—webappsphp
Multiple SQL injection vulnerabilities in code/guestadd.php in PHP-Update 2.7 and earlier allow remote attackers to exec
23RIESGO
abrir ↗
Referência✓ VexDay Proof
HomePH Design 2.10 RC2 - Local File Inclusion / Remote File Inclusion / Cross-Site Scripting
CVE-2008-2980—webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in HomePH Design 2.10 RC2 allow remote attackers to inject arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Macromedia Shockwave 10 'SwDir.dll' Internet Explorer 7 - Denial of Service
CVE-2006-6885—doswindows
An ActiveX control in SwDir.dll in Macromedia Shockwave 10 allows remote attackers to cause a denial of service (Interne
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Voodoo chat 1.0RC1b - 'users.dat' Password Disclosure
CVE-2006-6890—webappsphp
Voodoo chat 1.0RC1b stores sensitive information under the web root with insufficient access control, which allows remot
23RIESGO
abrir ↗
← anteriorpágina 819 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.