Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
IDM-OS 1.0 - 'Filename' File Disclosure
CVE-2008-0431webappsphp
Directory traversal vulnerability in administrator/download.php in IDMOS (aka Phoenix) 1.0 allows remote attackers to re
23RIESGO
abrir
ReferênciaVexDay Proof
Wysi Wiki Wyg 1.0 - Local File Inclusion / Cross-Site Scripting / PHPInfo
CVE-2008-3205webappsphp
Directory traversal vulnerability in index.php in Easy-Script Wysi Wiki Wyg 1.0 allows remote attackers to read arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
BbZL.php 0.92 - Insecure Cookie Handling
CVE-2008-4708webappsphp
BbZL.PhP 0.92 allows remote attackers to bypass authentication and gain administrative access by setting the phorum_admi
23RIESGO
abrir
ReferênciaVexDay Proof
sCssBoard (Multiple Versions) - 'pwnpack' Remote s
CVE-2008-5576webappsphp
admin/forums.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allows remote attackers to bypass authentication and gain adminis
23RIESGO
abrir
ReferênciaVexDay Proof
asp-project 1.0 - Insecure Cookie Method
CVE-2009-0280webappsasp
Asp Project Management 1.0 allows remote attackers to bypass authentication and gain administrative access by setting th
23RIESGO
abrir
ReferênciaVexDay Proof
WinFTP Server 2.0.2 - 'PASV' Remote Denial of Service
CVE-2006-6673doswindows
WinFtp Server 2.0.2 allows remote attackers to cause a denial of service (crash) via long (1) PASV, (2) LIST, (3) USER,
23RIESGO
abrir
ReferênciaVexDay Proof
TLM CMS 1.1 - 'i-accueil.php?chemin' Remote File Inclusion
CVE-2007-0300webappsphp
PHP remote file inclusion vulnerability in i-accueil.php in TLM CMS 1.1 and earlier allows remote attackers to execute a
23RIESGO
abrir
ReferênciaVexDay Proof
CS-Gallery 2.0 - 'index.php?album' Remote File Inclusion
CVE-2007-1108webappsphp
PHP remote file inclusion vulnerability in index.php in Christian Schneider CS-Gallery 2.0 and earlier allows remote att
23RIESGO
abrir
ReferênciaVexDay Proof
JChit counter 1.0.0 - 'imgsrv.php?ac' Remote File Disclosure
CVE-2007-2184webappsphp
Directory traversal vulnerability in imgsrv.php in jchit counter 1.0.0 allows remote attackers to read arbitrary files v
23RIESGO
abrir
ReferênciaVexDay Proof
MiniWeb HTTP Server 0.8.x - Remote Denial of Service
CVE-2007-3159doswindows
http.c in MiniWeb Http Server 0.8.x allows remote attackers to cause a denial of service (application crash) via a negat
23RIESGO
abrir
ReferênciaVexDay Proof
Picturesolution 2.1 - 'config.php?path' Remote File Inclusion
CVE-2007-5313webappsphp
PHP remote file inclusion vulnerability in install/config.php in Picturesolution 2.1 and earlier allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
kontakt formular 1.4 - Remote File Inclusion
CVE-2007-6655webappsphp
PHP remote file inclusion vulnerability in includes/function.php in Kontakt Formular 1.4 allows remote attackers to exec
23RIESGO
abrir
ReferênciaVexDay Proof
Admidio 1.4.8 - 'getfile.php' Remote File Disclosure
CVE-2008-5209webappsphp
Directory traversal vulnerability in modules/download/get_file.php in Admidio 1.4.8 allows remote attackers to read arbi
23RIESGO
abrir
ReferênciaVexDay Proof
ibase 2.03 - Remote File Disclosure
CVE-2008-6288webappsphp
Directory traversal vulnerability in download.php in Interface Medien ibase 2.03 and earlier allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
Quick 'n Easy Mail Server 3.3 (Demo) - Remote Denial of Service (PoC)
CVE-2009-1602doswindows
Pablo Software Solutions Quick 'n Easy Mail Server 3.3 allows remote attackers to cause a denial of service (daemon outa
23RIESGO
abrir
ReferênciaVexDay Proof
vidshare pro - SQL Injection / Cross-Site Scripting
CVE-2009-1735webappsphp
Cross-site scripting (XSS) vulnerability in search.php in VidSharePro allows remote attackers to inject arbitrary web sc
23RIESGO
abrir
ReferênciaVexDay Proof
WebCreator 0.2.6-rc3 - 'moddir' Remote File Inclusion
CVE-2007-1459webappsphp
Multiple PHP remote file inclusion vulnerabilities in WebCreator 0.2.6-rc3 and earlier allow remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
CVE-2007-6502webappsasp
Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to obtain sensitive information via (1)
23RIESGO
abrir
ReferênciaVexDay Proof
phpMyDirectory 10.4.4 - 'ROOT_PATH' Remote File Inclusion
CVE-2006-2521webappsphp
PHP remote file inclusion vulnerability in cron.php in phpMyDirectory 10.4.4 and earlier allows remote attackers to exec
23RIESGO
abrir
ReferênciaVexDay Proof
PowerBook 1.21 - 'index.php' Local File Inclusion
CVE-2008-1537webappsphp
Directory traversal vulnerability in pb_inc/admincenter/index.php in PowerScripts PowerBook 1.21 allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
Multi-Page Comment System 1.1.0 - Insecure Cookie Handling
CVE-2008-2293webappsphp
admin.php in Multi-Page Comment System (MPCS) 1.0 and 1.1 allows remote attackers to bypass authentication and gain priv
23RIESGO
abrir
ReferênciaVexDay Proof
Galatolo Web Manager 1.0 - SQL Injection
CVE-2008-2700webappsphp
SQL injection vulnerability in view.php in Galatolo WebManager 1.0 and earlier allows remote attackers to execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
AyeView 2.20 - Invalid Bitmap Header Parsing Crash
CVE-2008-5937doswindows
AyeView 2.20 allows user-assisted attackers to cause a denial of service (memory consumption or application crash) via a
23RIESGO
abrir
ReferênciaVexDay Proof
Gravy Media Photo Host 1.0.8 - Local File Disclosure
CVE-2009-2184webappsphp
Absolute path traversal vulnerability in forcedownload.php in Gravy Media Photo Host 1.0.8 allows remote attackers to re
23RIESGO
abrir
ReferênciaVexDay Proof
ACGVAnnu 1.3 - 'acgv.php?rubrik' Local File Inclusion
CVE-2007-2560webappsphp
Directory traversal vulnerability in theme/acgv.php in ACGVannu 1.3 and earlier allows remote attackers to read arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
Simple HTTPd 1.38 - Multiple Vulnerabilities
CVE-2007-6404remotewindows
Directory traversal vulnerability in Sergey Lyubka Simple HTTPD (shttpd) 1.38 and earlier on Windows allows remote attac
23RIESGO
abrir
ReferênciaVexDay Proof
WordPress Plugin WP-Cal 0.3 - 'editevent.php' SQL Injection
CVE-2008-0490webappsphp
SQL injection vulnerability in functions/editevent.php in the WP-Cal 0.3 plugin for WordPress allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
WordPress Plugin Download - 'dl_id' SQL Injection
CVE-2008-1646webappsphp
SQL injection vulnerability in wp-download.php in the WP-Download 1.2 plugin for WordPress allows remote attackers to ex
23RIESGO
abrir
ReferênciaVexDay Proof
HomePH Design 2.10 RC2 - Local File Inclusion / Remote File Inclusion / Cross-Site Scripting
CVE-2008-2981webappsphp
PHP remote file inclusion vulnerability in admin/templates/template_thumbnail.php in HomePH Design 2.10 RC2, when regist
23RIESGO
abrir
ReferênciaVexDay Proof
Acc Autos 4.0 - Insecure Cookie Handling
CVE-2008-6292webappsphp
Acc Autos 4.0 allows remote attackers to bypass authentication and gain administrative access by setting the (1) usernam
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.