Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
Joomla! Component LMO 1.0b2 - Remote File Inclusion
CVE-2006-3970webappsphp
PHP remote file inclusion vulnerability in lmo.php in the LMO Component (com_lmo) 1.0b2 and earlier for Joomla! allows r
23RIESGO
abrir
ReferênciaVexDay Proof
WEBBDOMAIN Polls 1.01 - Authentication Bypass
CVE-2008-6625webappsphp
SQL injection vulnerability in getin.php in WEBBDOMAIN Polls (aka Poll) 1.0 and 1.01 allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
RoomPHPlanning 1.5 - Multiple SQL Injections
CVE-2008-6634webappsphp
SQL injection vulnerability in RoomPHPlanning 1.5 allows remote attackers to execute arbitrary SQL commands via the idro
23RIESGO
abrir
ReferênciaVexDay Proof
UNAK-CMS 1.5 - 'dirroot' Remote File Inclusion
CVE-2006-4890webappsphp
Multiple PHP remote file inclusion vulnerabilities in UNAK-CMS 1.5 and earlier allow remote attackers to execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
CWB PRO 1.5 - 'INCLUDE_PATH' Remote File Inclusion
CVE-2007-1809webappsphp
Multiple PHP remote file inclusion vulnerabilities in GraFX Company WebSite Builder (CWB) PRO 1.5 allow remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
XnView 1.92.1 - 'FontName' Slideshow Buffer Overflow
CVE-2008-0069localwindows
Stack-based buffer overflow in XnView 1.92 and 1.92.1 allows user-assisted remote attackers to execute arbitrary code vi
23RIESGO
abrir
ReferênciaVexDay Proof
OneCMS 2.5 - Blind SQL Injection
CVE-2008-6652webappsphp
SQL injection vulnerability in asd.php in OneCMS 2.5 allows remote attackers to execute arbitrary SQL commands via the s
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component Webhosting - 'catid' Blind SQL Injection
CVE-2008-6653webappsphp
SQL injection vulnerability in webhosting.php in the Webhosting Component (com_webhosting) module before 1.1 RC7 for Joo
23RIESGO
abrir
ReferênciaVexDay Proof
Foxit Reader 2.0 - 'PDF' Remote Denial of Service
CVE-2007-2186doswindows
Foxit Reader 2.0 allows remote attackers to cause a denial of service (application crash) via a crafted PDF document.
23RIESGO
abrir
ReferênciaVexDay Proof
Opera Web Browser 9.00 - 'iframe' Remote Denial of Service
CVE-2006-3353dosmultiple
Opera 9 allows remote attackers to cause a denial of service (crash) via a crafted web page that triggers an out-of-boun
23RIESGO
abrir
ReferênciaVexDay Proof
Opera 9.2 - '.torrent' Remote Denial of Service
CVE-2007-2274dosmultiple
The BitTorrent implementation in Opera 9.2 allows remote attackers to cause a denial of service (CPU consumption and app
23RIESGO
abrir
ReferênciaVexDay Proof
Data Dynamics ActiveBar (Actbar3.ocx 3.2) - Multiple Insecure Methods
CVE-2007-3883remotewindows
The Data Dynamics ActiveBar ActiveX control (actbar3.ocx) 3.2 and earlier allows remote attackers to create or overwrite
23RIESGO
abrir
ReferênciaVexDay Proof
PHP Live Helper 2.0 - 'abs_path' Remote File Inclusion
CVE-2006-4051webappsphp
PHP remote file inclusion vulnerability in global.php in Turnkey Web Tools PHP Live Helper 2.0 and earlier allows remote
23RIESGO
abrir
ReferênciaVexDay Proof
XLPortal 2.2.4 - 'Search' SQL Injection
CVE-2008-1509webappsphp
SQL injection vulnerability in index.php in XLPortal 2.2.4 and earlier allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
nweb2fax 0.2.7 - Multiple Vulnerabilities
CVE-2008-6669webappsphp
viewrq.php in nweb2fax 0.2.7 and earlier allows remote attackers to execute arbitrary code via shell metacharacters in t
23RIESGO
abrir
ReferênciaVexDay Proof
WebChat 0.77 - 'defines.php?WEBCHATPATH' Remote File Inclusion
CVE-2007-0485webappsphp
PHP remote file inclusion vulnerability in defines.php in WebChat 0.77 allows remote attackers to execute arbitrary PHP
23RIESGO
abrir
ReferênciaVexDay Proof
Apartment Search Script - Arbitrary File Upload / Cross-Site Scripting
CVE-2008-6683webappsphp
Cross-site scripting (XSS) vulnerability in listtest.php in Apartment Search Script allows remote attackers to inject ar
23RIESGO
abrir
ReferênciaVexDay Proof
TeamSpeak 2.0 (Windows Release) - Remote Denial of Service
CVE-2007-3956doswindows
TeamSpeak WebServer 2.0 for Windows does not validate parameter value lengths and does not expire TCP sessions, which al
23RIESGO
abrir
ReferênciaVexDay Proof
MiGCMS 2.0.5 - Multiple Remote File Inclusions
CVE-2008-2888webappsphp
Multiple PHP remote file inclusion vulnerabilities in MiGCMS 2.0.5, when register_globals is enabled, allow remote attac
23RIESGO
abrir
ReferênciaVexDay Proof
U&M Software Signup 1.1 - Authentication Bypass
CVE-2008-6717webappsphp
U&M Software Signup 1.0 and 1.1 does not require administrative authentication for all scripts in the admin/ directory,
23RIESGO
abrir
ReferênciaVexDay Proof
U&M Software Event Lister 1.0 - Authentication Bypass
CVE-2008-6719webappsphp
U&M Software Event Lister (aka JustListIt) 1.0 does not require administrative authentication for all scripts in the adm
23RIESGO
abrir
ReferênciaVexDay Proof
Durian Web Application Server 3.02 - Denial of Service
CVE-2006-6853doswindows
Buffer overflow in Durian Web Application Server 3.02 freeware on Windows allows remote attackers to execute arbitrary c
23RIESGO
abrir
ReferênciaVexDay Proof
RunCMS 1.5.2 - 'debug_show.php' SQL Injection
CVE-2007-2539webappsphp
The show_files function in RunCms 1.5.2 and earlier allows remote attackers to obtain sensitive information (file existe
23RIESGO
abrir
ReferênciaVexDay Proof
Mini Web Calendar 1.2 - File Disclosure / Cross-Site Scripting
CVE-2008-5062webappsphp
Directory traversal vulnerability in php/cal_pdf.php in Mini Web Calendar (mwcal) 1.2 allows remote attackers to read ar
23RIESGO
abrir
ReferênciaVexDay Proof
PHPmotion 2.1 - Cross-Site Request Forgery
CVE-2008-6729webappsphp
Multiple cross-site request forgery (CSRF) vulnerabilities in password.php in PHPmotion 2.1 and earlier allow remote att
23RIESGO
abrir
ReferênciaVexDay Proof
Flexphplink Pro - Arbitrary File Upload
CVE-2008-6731webappsphp
Unrestricted file upload vulnerability in submitlink.php in FlexPHPLink Pro 0.0.7 allows remote attackers to execute arb
23RIESGO
abrir
ReferênciaVexDay Proof
Downline Goldmine Builder - SQL Injection
CVE-2008-4178webappsphp
SQL injection vulnerability in tr.php in DownlineGoldmine Special Category Addon, Downline Builder Pro, New Addon, and D
23RIESGO
abrir
ReferênciaVexDay Proof
Shadows Rising RPG 0.0.5b - Remote File Inclusion
CVE-2006-4329webappsphp
Multiple PHP remote file inclusion vulnerabilities in Shadows Rising RPG (Pre-Alpha) 0.0.5b and earlier allow remote att
23RIESGO
abrir
ReferênciaVexDay Proof
Autodesk DWF Viewer Control / LiveUpdate Module - Remote Code Execution
CVE-2008-4472remotewindows
The UpdateEngine class in the LiveUpdate ActiveX control (LiveUpdate16.DLL 17.2.56), as used in Revit Architecture 2009
23RIESGO
abrir
ReferênciaVexDay Proof
BlogPHP 2.0 - Privilege Escalation / SQL Injection
CVE-2008-6745webappsphp
index.php in BlogPHP 2.0 allows remote attackers to gain administrator privileges via a crafted email parameter in a reg
23RIESGO
abrir
anteriorpágina 127 / 188siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.