Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.202exploits catalogados
38.443CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
SH-News 3.1 - 'scriptpath' Remote File Inclusion
CVE-2006-5282—webappsphp
Multiple PHP remote file inclusion vulnerabilities in SH-News 3.1 and earlier allow remote attackers to execute arbitrar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Tucows Client Code Suite (CSS) 1.2.1015 - Remote File Inclusion
CVE-2006-6551—webappsphp
PHP remote file inclusion vulnerability in libs/tucows/api/cartridges/crt_TUCOWS_domains/lib/domainutils.inc.php in Tuco
23RIESGO
abrir ↗
Referência✓ VexDay Proof
n@board 3.1.9e - 'naboard_pnr.php' Remote File Inclusion
CVE-2006-5281—webappsphp
PHP remote file inclusion vulnerability in naboard_pnr.php in n@board 3.1.9e and earlier allows remote attackers to exec
23RIESGO
abrir ↗
Referência✓ VexDay Proof
AR Memberscript - 'usercp_menu.php' Remote File Inclusion
CVE-2006-6590—webappsphp
PHP remote file inclusion vulnerability in usercp_menu.php in AR Memberscript allows remote attackers to execute arbitra
23RIESGO
abrir ↗
Referência✓ VexDay Proof
phpMyAgenda 3.1 - '/templates/header.php3' Local File Inclusion
CVE-2006-5263—webappsphp
Directory traversal vulnerability in templates/header.php3 in phpMyAgenda 3.1 and earlier allows remote attackers to inc
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHPMyCMS 0.3 - 'basic.inc.php' Remote File Inclusion
CVE-2006-6612—webappsphp
PHP remote file inclusion vulnerability in basic.inc.php in PhpMyCms 0.3 allows remote attackers to execute arbitrary PH
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Millewin 13.39.146.1 - Local Privilege Escalation
CVE-2021-3394—localwindows
Millennium Millewin (also known as "Cartella clinica") 13.39.028, 13.39.28.3342, and 13.39.146.1 has insecure folder per
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Sambar FTP Server 6.4 - 'SIZE' Remote Denial of Service
CVE-2006-6624—doswindows
The FTP Server in Sambar Server 6.4 allows remote authenticated users to cause a denial of service (application crash) v
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Genepi 1.6 - 'genepi.php' Remote File Inclusion
CVE-2006-6632—webappsphp
PHP remote file inclusion vulnerability in genepi.php in Genepi 1.6 and earlier allows remote attackers to execute arbit
23RIESGO
abrir ↗
Referência✓ VexDay Proof
JumbaCMS 0.0.1 - '/includes/functions.php' Remote File Inclusion
CVE-2006-6635—webappsphp
PHP remote file inclusion vulnerability in includes/functions.php in JumbaCMS 0.0.1 allows remote attackers to execute a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
faceStones personal 2.0.42 - 'fs_form_links.php' File Inclusion
CVE-2006-5070—webappsphp
PHP remote file inclusion vulnerability in fsl2/objects/fs_form_links.php in faceStones Personal 2.0.42 and earlier allo
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component Joomlaboard 1.1.1 - 'sbp' Remote File Inclusion
CVE-2006-5043—webappsphp
Multiple PHP remote file inclusion vulnerabilities in the Joomlaboard Forum Component (com_joomlaboard) before 1.1.2 for
23RIESGO
abrir ↗
Referência✓ VexDay Proof
mxBB Module Meeting 1.1.2 - Remote File Inclusion
CVE-2006-6644—webappsphp
PHP remote file inclusion vulnerability in pages/meeting_constants.php in the Meeting (mx_meeting) 1.1.2 and earlier mod
23RIESGO
abrir ↗
Referência✓ VexDay Proof
VerliAdmin 0.3 - 'index.php' Remote File Inclusion
CVE-2006-6666—webappsphp
PHP remote file inclusion vulnerability in index.php in VerliAdmin 0.3 and earlier allows remote authenticated users to
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PBLang 4.66z - 'temppath' Remote File Inclusion
CVE-2006-5062—webappsphp
PHP remote file inclusion vulnerability in templates/pb/language/lang_nl.php in PBLang (PBL) 4.66z and earlier allows re
23RIESGO
abrir ↗
Referência✓ VexDay Proof
mxBB Module MX Shotcast 1.0 RC2 - 'getinfo1.php' Remote File Inclusion
CVE-2007-2313—webappsphp
PHP remote file inclusion vulnerability in getinfo1.php in the Shotcast 1.0 RC2 module for mxBB allows remote attackers
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Quick and Dirty Blog (qdblog) 0.4 - SQL Injection / Local File Inclusion
CVE-2007-2304—webappsphp
Multiple directory traversal vulnerabilities in Quick and Dirty Blog (QDBlog) 0.4, and possibly earlier, allow remote at
23RIESGO
abrir ↗
Referência✓ VexDay Proof
AirMore 1.6.1 - Denial of Service (PoC)
CVE-2019-9831—dosandroid
The AirMore application through 1.6.1 for Android allows remote attackers to cause a denial of service (system hang) via
28RIESGO
abrir ↗
Referência✓ VexDay Proof
Scorp Book 1.0 - 'smilies.php?config' Remote File Inclusion
CVE-2007-1937—webappsphp
PHP remote file inclusion vulnerability in smilies.php in Scorp Book 1.0 allows remote attackers to execute arbitrary PH
23RIESGO
abrir ↗
Referência✓ VexDay Proof
gtcatalog 0.9.1 - 'index.php' Remote File Inclusion
CVE-2006-5923—webappsphp
PHP remote file inclusion vulnerability in index.php in Chris Mac gtcatalog (aka GimeScripts Shopping Catalog) 0.9.1 and
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Enrollment System Project v1.0 - SQL Injection Authentication Bypass (SQLI)
CVE-2023-33584CRITICALwebappsphp
Sourcecodester Enrollment System Project V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to
53RIESGO
abrir ↗
Referência✓ VexDay Proof
WU-FTPD 2.6.2 - 'wuftpd-freezer.c' Remote Denial of Service
CVE-2003-0854—doslinux
ls in the fileutils or coreutils packages allows local users to consume a large amount of memory via a large -w value, w
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP < 4.4.5/5.2.1 - 'shmop' SSL RSA Private-Key Disclosure
CVE-2007-1376—locallinux
The shmop functions in PHP before 4.4.5, and before 5.2.1 in the 5.x series, do not verify that their arguments correspo
28RIESGO
abrir ↗
Referência✓ VexDay Proof
XM Easy Personal FTP Server 5.30 - 'ABOR' Format String Denial of Service
CVE-2007-1195—doswindows
Multiple buffer overflows in XM Easy Personal FTP Server 5.3.0 allow remote attackers to execute arbitrary code via unsp
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP-Nuke Module Emporium 2.3.0 - SQL Injection
CVE-2007-1034—webappsphp
SQL injection vulnerability in the category file in modules.php in the Emporium 2.3.0 and earlier module for PHP-Nuke al
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ashNews 0.83 - 'pathtoashnews' Remote File Inclusion
CVE-2003-1292—webappsphp
PHP remote file include vulnerability in Derek Ashauer ashNews 0.83 allows remote attackers to include and execute arbit
23RIESGO
abrir ↗
Referência✓ VexDay Proof
uniForum 4 - 'wbsearch.aspx' SQL Injection
CVE-2007-0226—webappsphp
SQL injection vulnerability in wbsearch.aspx in uniForum 4 and earlier allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Referência✓ VexDay Proof
AutoDealer 2.0 - 'detail.asp?iPro' SQL Injection
CVE-2007-0053—webappsasp
SQL injection vulnerability in detail.asp in ASP SiteWare autoDealer 2.0 and earlier allows remote attackers to execute
23RIESGO
abrir ↗
Referência✓ VexDay Proof
TaskTracker 1.5 - 'Customize.asp' Remote Add Administrator
CVE-2007-0049—webappsasp
Geckovich TaskTracker Pro 1.5 and earlier allows remote attackers to add administrative or other accounts via an Add act
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Voodoo chat 1.0RC1b - 'users.dat' Password Disclosure
CVE-2006-6890—webappsphp
Voodoo chat 1.0RC1b stores sensitive information under the web root with insufficient access control, which allows remot
23RIESGO
abrir ↗
← anteriorpágina 822 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.