Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
Aperto Blog 0.1.1 - Local File Inclusion / SQL Injection
CVE-2008-5776webappsphp
Multiple directory traversal vulnerabilities in Aperto Blog 0.1.1 allow remote attackers to include and execute arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
ravennuke 2.3.0 - Multiple Vulnerabilities
CVE-2009-0674webappsphp
images/captcha.php in Raven Web Services RavenNuke 2.30, when register_globals and display_errors are enabled, allows re
23RIESGO
abrir
ReferênciaVexDay Proof
ASP Product Catalog 1.0 - Cross-Site Scripting / File Disclosure
CVE-2009-1322webappsphp
ASP Product Catalog 1.0 stores sensitive information under the web root with insufficient access control, which allows r
23RIESGO
abrir
ReferênciaVexDay Proof
LearnLoop 2.0beta7 - 'sFilePath' Remote File Disclosure
CVE-2007-6214webappsphp
Directory traversal vulnerability in include/file_download.php in LearnLoop 2.0 beta7 allows remote attackers to read ar
23RIESGO
abrir
ReferênciaVexDay Proof
PHPortal 1.2 - Multiple Remote File Inclusions
CVE-2008-3022webappsphp
Multiple PHP remote file inclusion vulnerabilities in sablonlar/gunaysoft/gunaysoft.php in PHPortal 1.2 Beta allow remot
23RIESGO
abrir
ReferênciaVexDay Proof
Pritlog 0.4 - 'Filename' Remote File Disclosure
CVE-2008-6012webappsphp
Directory traversal vulnerability in index.php in Pritlog 0.4 and earlier, when magic_quotes_gpc is disabled, allows rem
23RIESGO
abrir
ReferênciaVexDay Proof
ScriptMagix Jokes 2.0 - 'index.php?catid' SQL Injection
CVE-2007-1615webappsphp
SQL injection vulnerability in index.php in ScriptMagix Jokes 2.0 and earlier allows remote attackers to execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
Prozilla Reviews Script 1.0 - Arbitrary Delete User
CVE-2008-1783webappsphp
Prozilla Reviews 1.0 allows remote attackers to delete arbitrary users via a modified UserID parameter in a direct reque
23RIESGO
abrir
ReferênciaVexDay Proof
Meto Forum 1.1 - Multiple SQL Injections
CVE-2008-2448webappsasp
Multiple SQL injection vulnerabilities in Meto Forum 1.1 allow remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir
ReferênciaVexDay Proof
Sisplet CMS 2008-01-24 - 'id' SQL Injection
CVE-2008-3026webappsphp
SQL injection vulnerability in index.php in OneClick CMS (aka Sisplet CMS) 2008-01-24 allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
CMS MAXSITE Component Guestbook - Remote Command Execution
CVE-2008-6446webappsphp
Static code injection vulnerability in the Guestbook component in CMS MAXSITE allows remote attackers to inject arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
MauryCMS 0.53.2 - Arbitrary File Upload
CVE-2008-6952webappsphp
SQL injection vulnerability in Rss.php in MauryCMS 0.53.2 and earlier allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
ReferênciaVexDay Proof
DaZPHP 0.1 - 'prefixdir' Local File Inclusion
CVE-2008-1696webappsphp
Directory traversal vulnerability in makepost.php in DaZPHPNews 0.1-1, when register_globals is enabled and magic_quotes
23RIESGO
abrir
ReferênciaVexDay Proof
VanGogh Web CMS 0.9 - 'article_ID' SQL Injection
CVE-2008-3027webappsphp
SQL injection vulnerability in get_article.php in VanGogh Web CMS 0.9 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
ReferênciaVexDay Proof
PHP-Agenda 2.2.4 - 'index.php' Local File Inclusion
CVE-2008-3031webappsphp
Directory traversal vulnerability in index.php in Simple PHP Agenda 2.2.4 and earlier allows remote attackers to include
23RIESGO
abrir
ReferênciaVexDay Proof
groone glinks 2.1 - Remote File Inclusion
CVE-2009-0463webappsphp
PHP remote file inclusion vulnerability in includes/header.php in Groone GLinks 2.1 allows remote attackers to execute a
23RIESGO
abrir
ReferênciaVexDay Proof
FlexPHPNews 0.0.5 - 'newsid' SQL Injection
CVE-2005-1237webappsphp
SQL injection vulnerability in news.php in FlexPHPNews 0.0.3 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
ReferênciaVexDay Proof
myPHPCalendar 10192000b - 'cal_dir' Remote File Inclusion
CVE-2006-6812webappsphp
Multiple PHP remote file inclusion vulnerabilities in myPHPCalendar 10.1 allow remote attackers to execute arbitrary PHP
23RIESGO
abrir
ReferênciaVexDay Proof
MeGaCheatZ 1.1 - Multiple SQL Injections
CVE-2007-6557webappsphp
Multiple SQL injection vulnerabilities in MeGaCheatZ 1.1 allow remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir
ReferênciaVexDay Proof
minimal Gallery 0.8 - Remote File Disclosure
CVE-2008-0259webappsphp
Multiple directory traversal vulnerabilities in _mg/php/mg_thumbs.php in minimal Gallery 0.8 allow remote attackers to r
23RIESGO
abrir
ReferênciaVexDay Proof
DomPHP 0.82 - 'index.php' Local File Inclusion
CVE-2008-0745webappsphp
Directory traversal vulnerability in aides/index.php in DomPHP 0.82 allows remote attackers to include and execute arbit
23RIESGO
abrir
ReferênciaVexDay Proof
XchangeBoard 1.70 - 'boardID' SQL Injection
CVE-2008-3035webappsphp
SQL injection vulnerability in newThread.php in XchangeBoard 1.70 Final and earlier allows remote authenticated users to
23RIESGO
abrir
ReferênciaVexDay Proof
Netartmedia Cars Portal 2.0 - SQL Injection
CVE-2008-5310webappsphp
SQL injection vulnerability in image.php in NetArt Media Car Portal 2.0 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
ASP Download 1.03 - Arbitrary Change Administrator Account
CVE-2008-6739webappsasp
Todd Woolums ASP Download management script 1.03 does not require authentication for setupdownload.asp, which allows rem
23RIESGO
abrir
ReferênciaVexDay Proof
Koschtit Image Gallery 1.82 - Multiple Local File Inclusions
CVE-2009-1510webappsphp
Multiple directory traversal vulnerabilities in KoschtIT Image Gallery 1.82 allow remote attackers to include and execut
23RIESGO
abrir
ReferênciaVexDay Proof
Destar 0.2.2-5 - Arbitrary Add Admin
CVE-2008-6539webappsphp
Static code injection vulnerability in user/settings/ in DeStar 0.2.2-5 allows remote authenticated users to add arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
PHP-Nuke NukeAI Module 3b - 'util.php' Remote File Inclusion
CVE-2006-6255webappsphp
Direct static code injection vulnerability in util.php in the NukeAI 0.0.3 Beta module for PHP-Nuke, aka Program E is an
23RIESGO
abrir
ReferênciaVexDay Proof
P-News 1.16/1.17 - 'user.dat' Remote Password Disclosure
CVE-2006-6888webappsphp
P-News 1.16 and 1.17 store sensitive information under the web root with insufficient access control, which allows remot
23RIESGO
abrir
ReferênciaVexDay Proof
MiniBB 2.2 - Cross-Site Scripting / SQL Injection / Full Path Disclosure
CVE-2008-2028webappsphp
miniBB 2.2, and possibly earlier, when register_globals is enabled, allows remote attackers to obtain the full path via
23RIESGO
abrir
ReferênciaVexDay Proof
XPOZE Pro 3.06 - 'uid' SQL Injection
CVE-2008-3089webappsphp
SQL injection vulnerability in user.html in Xpoze Pro 3.06 (aka Xpoze Pro CMS 2008) allows remote attackers to execute a
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.