Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
PHP-Nuke Module splattforum 4.0 RC1 - Local File Inclusion
CVE-2007-1633webappsphp
Directory traversal vulnerability in bbcode_ref.php in the Giorgio Ciranni Splatt Forum 4.0 RC1 module for PHP-Nuke allo
23RIESGO
abrir
ReferênciaVexDay Proof
PHPGlossar 0.8 - 'format_menue' Remote File Inclusion
CVE-2007-2751webappsphp
Multiple PHP remote file inclusion vulnerabilities in PHPGlossar 0.8 allow remote attackers to execute arbitrary PHP cod
23RIESGO
abrir
ReferênciaVexDay Proof
CA BrightStor Backup 11.5.2.0 - 'caloggderd.exe' Denial of Service
CVE-2007-2772doswindows
(1) caloggerd.exe (camt70.dll) and (2) mediasvr.exe (catirpc.dll and rwxdr.dll) in CA BrightStor Backup 11.5.2.0 SP2 all
28RIESGO
abrir
ReferênciaVexDay Proof
CA BrightStor Backup 11.5.2.0 - 'Mediasvr.exe' Denial of Service
CVE-2007-2772doswindows
(1) caloggerd.exe (camt70.dll) and (2) mediasvr.exe (catirpc.dll and rwxdr.dll) in CA BrightStor Backup 11.5.2.0 SP2 all
28RIESGO
abrir
ReferênciaVexDay Proof
Battle.net Clan Script for PHP 1.5.1 - SQL Injection
CVE-2007-1909webappsphp
SQL injection vulnerability in login.php in Ryan Haudenschilt Battle.net Clan Script for PHP 1.5.1 and earlier allows re
23RIESGO
abrir
ReferênciaVexDay Proof
InoutMailingListManager 3.1 - Remote Command Execution
CVE-2007-2004webappsphp
Multiple SQL injection vulnerabilities in InoutMailingListManager 3.1 and earlier allow remote attackers to execute arbi
23RIESGO
abrir
ReferênciaVexDay Proof
pl-PHP Beta 0.9 - Multiple Vulnerabilities
CVE-2007-2006webappsphp
Multiple SQL injection vulnerabilities in login.php in pL-PHP beta 0.9 allow remote attackers to execute arbitrary SQL c
23RIESGO
abrir
ReferênciaVexDay Proof
Mambo Component com_yanc 1.4 Beta - 'id' SQL Injection
CVE-2007-2792webappsphp
SQL injection vulnerability in the Yet another Newsletter Component (aka YaNC or com_yanc) component before 1.5 beta 3 f
23RIESGO
abrir
ReferênciaVexDay Proof
GeekLog 2.x - 'ImageImageMagick.php' Remote File Inclusion
CVE-2007-2793webappsphp
PHP remote file inclusion vulnerability in ImageImageMagick.php in Geeklog 2.x allows remote attackers to execute arbitr
35RIESGO
abrir
ReferênciaVexDay Proof
Vizayn Urun Tanitim Sistemi 0.2 - 'tr' SQL Injection
CVE-2007-2803webappsasp
SQL injection vulnerability in default.asp in Vizayn Urun Tanitim Sitesi 0.2 allows remote attackers to execute arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
Ol BookMarks Manager 0.7.4 - 'root' Remote File Inclusion
CVE-2007-2816webappsphp
Multiple PHP remote file inclusion vulnerabilities in ol'bookmarks 0.7.4 allow remote attackers to execute arbitrary PHP
28RIESGO
abrir
ReferênciaVexDay Proof
LeadTools Raster Variant - 'LTRVR14e.dll' Remote File Overwrite
CVE-2007-2851remotewindows
A certain ActiveX control in LeadTools Raster Variant Object Library (LTRVR14e.dll) 14.5.0.44 allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
Virtual CD 9.0.0.2 - 'vc9api.DLL' Remote Shell Commands Execution
CVE-2007-2853remotewindows
The VCDAPILibApi ActiveX control in vc9api.DLL 9.0.0.57 in Virtual CD 9.0.0.2 allows remote attackers to execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
BtiTracker 1.4.1 - Become Admin SQL Injection
CVE-2007-2854webappsphp
Multiple SQL injection vulnerabilities in account_change.php in BtiTracker 1.4.1 and earlier allow remote attackers to e
23RIESGO
abrir
ReferênciaVexDay Proof
PHPOracleView - 'include_all.inc.php?page_dir' Remote File Inclusion
CVE-2007-2340webappsphp
Multiple PHP remote file inclusion vulnerabilities in inc/include_all.inc.php in phporacleview allow remote attackers to
35RIESGO
abrir
ReferênciaVexDay Proof
CreaDirectory 1.2 - 'error.asp?id' SQL Injection
CVE-2007-2342webappsasp
SQL injection vulnerability in error.asp in CreaScripts CreaDirectory 1.2 allows remote attackers to execute arbitrary S
23RIESGO
abrir
ReferênciaVexDay Proof
CodeWand phpBrowse - 'site_path' Remote File Inclusion
CVE-2007-2345webappsphp
PHP remote file inclusion vulnerability in include/include_stream.inc.php in CodeWand phpBrowse allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
DESlock+ < 3.2.6 - 'DLMFENC.sys' Local Kernel Ring0 link list zero (PoC)
CVE-2008-1138doswindows
DLMFENC.sys 1.0.0.26 in DESlock+ 3.2.6 and earlier allows local users to cause a denial of service (system crash) via a
23RIESGO
abrir
ReferênciaVexDay Proof
burnCMS 0.2 - 'root' Remote File Inclusion
CVE-2007-2364webappsphp
Multiple PHP remote file inclusion vulnerabilities in burnCMS 0.2 and earlier allow remote attackers to execute arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
WordPress Plugin Sniplets 1.1.2 - Remote File Inclusion / Cross-Site Scripting / Remote Code Execution
CVE-2008-1059webappsphp
PHP remote file inclusion vulnerability in modules/syntax_highlight.php in the Sniplets 1.1.2 and 1.2.2 plugin for WordP
50RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Windows - GDI (EMR_COLORMATCHTOTARGETW) (MS08-021)
CVE-2008-1087remotewindows
Stack-based buffer overflow in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 200
35RIESGO
abrir
ReferênciaVexDay Proof
Motorola Timbuktu Pro 8.6.5 - File Deletion/Creation
CVE-2008-1117remotewindows
Directory traversal vulnerability in the Notes (aka Flash Notes or instant messages) feature in tb2ftp.dll in Timbuktu P
50RIESGO
abrir
ReferênciaVexDay Proof
Motorola Timbuktu Pro 8.6.5/8.7 - Directory Traversal / Log Injection
CVE-2008-1117remotewindows
Directory traversal vulnerability in the Notes (aka Flash Notes or instant messages) feature in tb2ftp.dll in Timbuktu P
50RIESGO
abrir
ReferênciaVexDay Proof
Barryvan Compo Manager 0.3 - Remote File Inclusion
CVE-2008-1126webappsphp
PHP remote file inclusion vulnerability in main.php in Barryvan Compo Manager 0.3 allows remote attackers to execute arb
28RIESGO
abrir
ReferênciaVexDay Proof
Mambo Component garyscookbook 1.1.1 - SQL Injection
CVE-2008-1137webappsphp
SQL injection vulnerability in the Garys Cookbook (com_garyscookbook) 1.1.1 and earlier component for Mambo and Joomla!
23RIESGO
abrir
ReferênciaVexDay Proof
DESlock+ < 3.2.6 - Local Kernel Ring0 link list zero SYSTEM
CVE-2008-1139localwindows
DESlock+ 3.2.6 and earlier, when DLMFENC.sys 1.0.0.26 and DLMFDISK.sys 1.2.0.27 are present, allows local users to gain
23RIESGO
abrir
ReferênciaVexDay Proof
DESlock+ < 3.2.6 - 'DLMFDISK.sy's Local kernel Ring0 SYSTEM
CVE-2008-1140localwindows
DLMFDISK.sys 1.2.0.27 in DESlock+ 3.2.6 and earlier allows local users to gain privileges via a certain DLKFDISK_IOCTL r
23RIESGO
abrir
ReferênciaVexDay Proof
DESlock+ < 3.2.6 - 'LIST' Local Kernel Memory Leak
CVE-2008-1141localwindows
Memory leak in DLMFENC.sys 1.0.0.26 in DESlock+ 3.2.6 and earlier allows local users to cause a denial of service (kerne
23RIESGO
abrir
ReferênciaVexDay Proof
Pheap 2.0 - Authentication Bypass / Remote Code Execution
CVE-2007-2985webappsphp
Pheap 2.0 allows remote attackers to bypass authentication by setting a pheap_login cookie value to the administrator's
23RIESGO
abrir
ReferênciaVexDay Proof
ZYXEL ZyWALL Quagga/Zebra - 'Default Password' Remote Code Execution
CVE-2008-1160remotehardware
ZyXEL ZyWALL 1050 has a hard-coded password for the Quagga and Zebra processes that is not changed when it is set by a u
28RIESGO
abrir
anteriorpágina 118 / 188siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.