Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
Evilsentinel 1.0.9 - Multiple Vulnerabilities Disable
CVE-2008-0351webappsphp
admin/config.php in Evilsentinel 1.0.9 and earlier allows remote attackers to bypass the CAPTCHA test by omitting the es
23RIESGO
abrir
ReferênciaVexDay Proof
yourplace 1.0.2 - Multiple Vulnerabilities / Remote Code Execution
CVE-2008-6772webappsphp
login/register_form.php in YourPlace 1.0.2 and earlier does not check that a username already exists when a new account
23RIESGO
abrir
ReferênciaVexDay Proof
A-shop 0.70 - Remote File Deletion
CVE-2007-3936webappsasp
Directory traversal vulnerability in admin/filebrowser.asp in A-shop 0.70 and earlier, and possibly 0.71, allows remote
23RIESGO
abrir
ReferênciaVexDay Proof
AuraCMS 1.62 - 'stat.php' Remote Code Execution
CVE-2008-0390webappsphp
stat.php in AuraCMS 1.62, and Mod Block Statistik for AuraCMS, allows remote attackers to inject arbitrary PHP code into
23RIESGO
abrir
ReferênciaVexDay Proof
Adobe Reader - 'util.printf()' JavaScript Function Stack Overflow (1)
CVE-2008-2992HIGHbajo ataqueransomwarelocalwindows
Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary c
100RIESGO
abrir
ReferênciaVexDay Proof
Thyme 1.3 - 'export_to' Local File Inclusion
CVE-2009-0535webappsphp
Directory traversal vulnerability in export.php in Thyme 1.3 and earlier, when register_globals is disabled, allows remo
23RIESGO
abrir
ReferênciaVexDay Proof
Seditio CMS Events Plugin - 'c' SQL Injection
CVE-2009-1411webappsphp
SQL injection vulnerability in events/inc/events.inc.php in the Events plugin for Seditio CMS 1.0 allows remote attacker
23RIESGO
abrir
ReferênciaVexDay Proof
Submitter Script - Authentication Bypass
CVE-2009-1813webappsphp
Multiple SQL injection vulnerabilities in admin/index.php in Submitter Script 2 allow remote attackers to execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
Minerva 2.0.8a Build 237 - 'phpbb_root_path' File Inclusion
CVE-2006-3028webappsphp
PHP remote file inclusion vulnerability in stat_modules/users_age/module.php in Minerva 2.0.8a Build 237 and earlier all
23RIESGO
abrir
ReferênciaVexDay Proof
PHP-Update 2.7 - '/admin/uploads.php' Remote Code Execution
CVE-2006-6878webappsphp
admin/uploads.php in PHP-Update 2.7 and earlier allows remote attackers to gain privileges by setting the rights[7] para
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component module autostand 1.0 - Remote File Inclusion
CVE-2007-2319webappsphp
PHP remote file inclusion vulnerability in the AutoStand 1.1 and earlier module for Joomla! allows remote attackers to e
23RIESGO
abrir
ReferênciaVexDay Proof
Blakord Portal Beta 1.3.A (All Modules) - SQL Injection
CVE-2007-6565webappsphp
Multiple SQL injection vulnerabilities in Blakord Portal 1.3.A Beta and earlier allow remote attackers to execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
Adobe Reader - 'util.printf()' JavaScript Function Stack Overflow (2)
CVE-2008-2992HIGHbajo ataqueransomwarelocalwindows
Stack-based buffer overflow in Adobe Acrobat and Reader 8.1.2 and earlier allows remote attackers to execute arbitrary c
100RIESGO
abrir
ReferênciaVexDay Proof
FOG Forum 0.8.1 - Multiple Local File Inclusions
CVE-2008-2993webappsphp
Multiple directory traversal vulnerabilities in index.php in FOG Forum 0.8.1 allow remote attackers to include and execu
23RIESGO
abrir
ReferênciaVexDay Proof
Libra PHP File Manager 1.18/2.0 - Local File Inclusion
CVE-2008-4319webappsphp
fileadmin.php in Libra File Manager (aka Libra PHP File Manager) 1.18 and earlier allows remote attackers to bypass auth
23RIESGO
abrir
ReferênciaVexDay Proof
Gelato - 'index.php?post' SQL Injection
CVE-2007-4918webappsphp
SQL injection vulnerability in classes/gelato.class.php in Gelato allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir
ReferênciaVexDay Proof
Xcode OpenBase 10.0.0 (OSX) - Unsafe System Call Privilege Escalation
CVE-2006-5852localosx
Untrusted search path vulnerability in openexec in OpenBase SQL before 10.0.1 allows local users to gain privileges via
23RIESGO
abrir
ReferênciaVexDay Proof
Uebimiau Web-Mail 2.7.10/2.7.2 - Remote File Disclosure
CVE-2008-0140webappsphp
Directory traversal vulnerability in error.php in Uebimiau Webmail 2.7.10 and 2.7.2 allows remote authenticated users to
23RIESGO
abrir
ReferênciaVexDay Proof
Xcode OpenBase 10.0.0 (OSX) - Symlink Privilege Escalation
CVE-2006-5851localosx
openexec in OpenBase SQL before 10.0.1 allows local users to create arbitrary files via a symlink attack on the /tmp/out
23RIESGO
abrir
ReferênciaVexDay Proof
phpBB Module XS-Mod 2.3.1 - Local File Inclusion
CVE-2008-1512webappsphp
Directory traversal vulnerability in admin/admin_xs.php in eXtreme Styles module (XS-Mod) 2.3.1 and 2.4.0 for phpBB allo
23RIESGO
abrir
ReferênciaVexDay Proof
Aprox CMS Engine 5.1.0.4 - Local File Inclusion
CVE-2008-2895webappsphp
Directory traversal vulnerability in index.php in AproxEngine 5.1.0.4 allows remote attackers to include and execute arb
23RIESGO
abrir
ReferênciaVexDay Proof
PHP weather 2.2.2 - Local File Inclusion / Cross-Site Scripting
CVE-2008-5771webappsphp
Directory traversal vulnerability in test.php in PHP Weather 2.2.2 allows remote attackers to include and execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
BNCwi 1.04 - Local File Inclusion
CVE-2008-5948webappsphp
Directory traversal vulnerability in index.php in BNCwi 1.04 and earlier allows remote attackers to include and execute
23RIESGO
abrir
ReferênciaVexDay Proof
wotw 5.0 - Local/Remote File Inclusion
CVE-2008-6224webappsphp
Directory traversal vulnerability in visualizza.php in Way Of The Warrior (WOTW) 5.0 and earlier allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
Telephone Directory 2008 - Arbitrary Delete Contact
CVE-2008-7180webappsphp
del_query1.php in Telephone Directory 2008 allows remote attackers to delete arbitrary contacts via a direct request wit
23RIESGO
abrir
ReferênciaVexDay Proof
ClipShare 2.6 - Remote User Password Change
CVE-2008-7188webappsphp
ClipShare 2.6 does not properly restrict access to certain functionality, which allows remote attackers to change the pr
23RIESGO
abrir
ReferênciaVexDay Proof
Harpia CMS 1.0.5 - Remote File Inclusion
CVE-2006-7024webappsphp
Multiple PHP remote file inclusion vulnerabilities in Harpia CMS 1.0.5 and earlier allow remote attackers to execute arb
23RIESGO
abrir
ReferênciaVexDay Proof
PHP-Nuke platinum 7.6.b.5 - Remote File Inclusion
CVE-2007-5676webappsphp
PHP remote file inclusion vulnerability in modules/Forums/favorites.php in PHP-Nuke Platinum 7.6.b.5 allows remote attac
23RIESGO
abrir
ReferênciaVexDay Proof
Bubbling Library 1.32 - Multiple Local File Inclusions
CVE-2008-0545webappsphp
Multiple directory traversal vulnerabilities in Bubbling Library 1.32 allow remote attackers to include and execute arbi
23RIESGO
abrir
ReferênciaVexDay Proof
PEEL CMS 3.x - Admin Hash Extraction / Arbitrary File Upload
CVE-2008-1507webappsphp
PEEL, possibly 3.x and earlier, has (1) a default info@peel.fr account with password admin, and (2) a default contact@pe
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.