Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
mxBB Module ErrorDocs 1.0 - 'common.php' Remote File Inclusion
CVE-2006-6545webappsphp
PHP remote file inclusion vulnerability in includes/common.php in the ErrorDocs 1.0.0 and earlier module for mxBB (mx_er
23RIESGO
abrir
ReferênciaVexDay Proof
CuteNews aj-fork 167f - 'cutepath' Remote File Inclusion
CVE-2006-6546webappsphp
PHP remote file inclusion vulnerability in inc/shows.inc.php in cutenews aj-fork (CN:AJ) 167f and earlier allows remote
23RIESGO
abrir
ReferênciaVexDay Proof
Phorum 3.2.11 - 'common.php' Remote File Inclusion
CVE-2006-6550webappsphp
PHP remote file inclusion vulnerability in common.php in Phorum 3.2.11 and earlier allows remote attackers to execute ar
23RIESGO
abrir
ReferênciaVexDay Proof
mxBB Module mx_modsdb 1.0 - Remote File Inclusion
CVE-2006-6560webappsphp
PHP remote file inclusion vulnerability in includes/common.php in the mx_modsdb 1.0.0 module for MxBB (aka MX-System) Po
23RIESGO
abrir
ReferênciaVexDay Proof
mxBB Module WebLinks 2.05 - Remote File Inclusion
CVE-2006-6645webappsphp
PHP remote file inclusion vulnerability in language/lang_english/lang_admin.php in the Web Links (mx_links) 2.05 and ear
23RIESGO
abrir
ReferênciaVexDay Proof
PHP-Update 2.7 - 'extract()' Authentication Bypass / Shell Injection
CVE-2006-6661webappsphp
Variable overwrite vulnerability in blog.php in PHP-Update 2.7 and earlier allows remote attackers to overwrite arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
AstonSoft DeepBurner 1.8.0 - '.dbr' File Parsing Buffer Overflow
CVE-2006-6665localwindows
Buffer overflow in Astonsoft DeepBurner Pro and Free 1.8.0 and earlier allows user-assisted remote attackers to execute
50RIESGO
abrir
ReferênciaVexDay Proof
VerliAdmin 0.3 - 'index.php' Remote File Inclusion
CVE-2006-6666webappsphp
PHP remote file inclusion vulnerability in index.php in VerliAdmin 0.3 and earlier allows remote authenticated users to
23RIESGO
abrir
ReferênciaVexDay Proof
TextSend 1.5 - '/config/sender.php' Remote File Inclusion
CVE-2006-6686webappsphp
PHP remote file inclusion vulnerability in sender.php in Carsen Klock TextSend 1.5 allows remote attackers to execute ar
23RIESGO
abrir
ReferênciaVexDay Proof
Valdersoft Shopping Cart 3.0 - Multiple Remote File Inclusions
CVE-2006-6691webappsphp
Multiple PHP remote file inclusion vulnerabilities in Valdersoft Shopping Cart 3.0 and earlier allow remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
E-Uploader Pro 1.0 - Image Upload / Code Execution
CVE-2006-6694webappsphp
Directory traversal vulnerability in include/config.php in E-Uploader Pro 1.0 and earlier allows remote attackers to exe
23RIESGO
abrir
ReferênciaVexDay Proof
Aqua CMS - 'Username' SQL Injection
CVE-2009-1317webappsphp
Multiple SQL injection vulnerabilities in Aqua CMS 1.1, when magic_quotes_gpc is disabled, allow remote attackers to exe
23RIESGO
abrir
ReferênciaVexDay Proof
Jamroom 4.0.2 - 't' Local File Inclusion
CVE-2009-1318webappsphp
Directory traversal vulnerability in index.php in Jamroom 3.1.2, 3.2.3 through 3.2.6, 4.0.2, and possibly other versions
23RIESGO
abrir
ReferênciaVexDay Proof
ASX to MP3 Converter - '.m3u' Local Stack Overflow (PoC)
CVE-2009-1324doswindows
Stack-based buffer overflow in Mini-stream ASX to MP3 Converter 3.0.0.7 allows remote attackers to execute arbitrary cod
28RIESGO
abrir
ReferênciaVexDay Proof
ASX to MP3 Converter 3.0.0.7 - '.m3u' Universal Stack Overflow
CVE-2009-1324localwindows
Stack-based buffer overflow in Mini-stream ASX to MP3 Converter 3.0.0.7 allows remote attackers to execute arbitrary cod
28RIESGO
abrir
ReferênciaVexDay Proof
Mini-stream Ripper 3.0.1.1 - '.m3u' Universal Stack Overflow
CVE-2009-1325localwindows
Stack-based buffer overflow in Mini-stream Ripper 3.0.1.1 allows remote attackers to execute arbitrary code via a long U
23RIESGO
abrir
ReferênciaVexDay Proof
RM Downloader - '.m3u' Local Stack Overflow (PoC)
CVE-2009-1326doswindows
Stack-based buffer overflow in Mini-stream RM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a
23RIESGO
abrir
ReferênciaVexDay Proof
WM Downloader 3.0.0.9 - '.m3u' Universal Stack Overflow
CVE-2009-1327localwindows
Stack-based buffer overflow in Mini-stream WM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a
23RIESGO
abrir
ReferênciaVexDay Proof
Mini-stream RM-MP3 Converter 3.0.0.7 - '.m3u' Local Stack Overflow (PoC)
CVE-2009-1328doswindows
Stack-based buffer overflow in Mini-stream RM-MP3 Converter 3.0.0.7 allows remote attackers to execute arbitrary code vi
23RIESGO
abrir
ReferênciaVexDay Proof
Mini-stream RM-MP3 Converter 3.0.0.7 - '.m3u' Local Stack Overflow
CVE-2009-1328localwindows
Stack-based buffer overflow in Mini-stream RM-MP3 Converter 3.0.0.7 allows remote attackers to execute arbitrary code vi
23RIESGO
abrir
ReferênciaVexDay Proof
Zervit Web Server 0.02 - Remote Buffer Overflow (PoC)
CVE-2009-1353doswindows
Buffer overflow in the http_parse_hex function in libz/misc.c in Zervit Webserver 0.02 allows remote attackers to cause
23RIESGO
abrir
ReferênciaVexDay Proof
Elecard AVC HD Player - '.XPL' Stack Buffer Overflow (SEH) (PoC)
CVE-2009-1356doswindows
Stack-based buffer overflow in Elecard AVC HD Player allows remote attackers to execute arbitrary code via a long MP3 fi
23RIESGO
abrir
ReferênciaVexDay Proof
OpenSSL < 0.9.8i - DTLS ChangeCipherSpec Remote Denial of Service
CVE-2009-1386dosmultiple
ssl/s3_pkt.c in OpenSSL before 0.9.8i allows remote attackers to cause a denial of service (NULL pointer dereference and
60RIESGO
abrir
ReferênciaVexDay Proof
CRE Loaded 6.2 - 'products_id' SQL Injection
CVE-2009-1403webappsphp
SQL injection vulnerability in product_info.php in CRE Loaded 6.2 allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir
ReferênciaVexDay Proof
pastelcms 0.8.0 - Local File Inclusion / SQL Injection
CVE-2009-1404webappsphp
SQL injection vulnerability in admin.php in PastelCMS 0.8.0, when magic_quotes_gpc is disabled, allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
TotalCalendar 2.4 - 'Include' Local File Inclusion
CVE-2009-1406webappsphp
Directory traversal vulnerability in cms_detect.php in TotalCalendar 2.4 allows remote attackers to include and execute
23RIESGO
abrir
ReferênciaVexDay Proof
e107 < 0.7.15 - 'extended_user_fields' Blind SQL Injection
CVE-2009-1409webappsphp
SQL injection vulnerability in usersettings.php in e107 0.7.15 and earlier, when "Extended User Fields" is enabled and m
23RIESGO
abrir
ReferênciaVexDay Proof
Quick.CMS.Lite 0.5 - 'id' SQL Injection
CVE-2009-1410webappsphp
SQL injection vulnerability in index.php in Quick.Cms.Lite 0.5 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
Enthrallweb eNews 1.0 - Remote User Pass Change
CVE-2006-6821webappsasp
myprofile.asp in Enthrallweb eNews does not properly validate the MM_recordId parameter during profile updates, which al
23RIESGO
abrir
ReferênciaVexDay Proof
Yrch 1.0 - 'plug.inc.phppath' Remote File Inclusion
CVE-2006-6823webappsphp
PHP remote file inclusion vulnerability in plugins/metasearch/plug.inc.php in Yrch! 1.0 allows remote attackers to execu
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.