Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
GeoVision LiveAudio - ActiveX Remote Freed-Memory Access
CVE-2009-1092remotewindows
Use-after-free vulnerability in the LIVEAUDIO.LiveAudioCtrl.1 ActiveX control in LIVEAU~1.OCX 7.0 for GeoVision DVR syst
23RIESGO
abrir
ReferênciaVexDay Proof
BBClone 0.31 - 'selectlang.php' Remote File Inclusion
CVE-2007-0508webappsphp
PHP remote file inclusion vulnerability in lib/selectlang.php in BBClone 0.31 allows remote attackers to execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
cPanel 11.x - 'Fantastico' Local File Inclusion
CVE-2008-4181webappsphp
Directory traversal vulnerability in includes/xml.php in the Netenberg Fantastico De Luxe module before 2.10.4 r19 for c
23RIESGO
abrir
ReferênciaVexDay Proof
AT Contenator 1.0 - 'Root_To_Script' Remote File Inclusion
CVE-2007-0983webappsphp
PHP remote file inclusion vulnerability in _admin/nav.php in AT Contenator 1.0 and earlier allows remote attackers to ex
23RIESGO
abrir
ReferênciaVexDay Proof
Hot Links SQL-PHP 3 - 'report.php' Multiple Vulnerabilities
CVE-2008-4379webappsphp
Cross-site scripting (XSS) vulnerability in report.php in Mr. CGI Guy Hot Links SQL-PHP 3.0 and earlier allows remote at
23RIESGO
abrir
ReferênciaVexDay Proof
OWLLib 1.0 - 'OWLMemoryProperty.php' Remote File Inclusion
CVE-2006-6150webappsphp
PHP remote file inclusion vulnerability in memory/OWLMemoryProperty.php in OWLLib 1.0 allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
BrowseDialog Class - 'ccrpbds6.dll' Multiple Denial of Service Vulnerabilities
CVE-2007-1162doswindows
A certain ActiveX control in the Common Controls Replacement Project (CCRP) CCRP BrowseDialog Server (ccrpbds6.dll) allo
23RIESGO
abrir
ReferênciaVexDay Proof
Mozilla Firefox XSL - Parsing Remote Memory Corruption (PoC) (1)
CVE-2009-1169dosmultiple
The txMozillaXSLTProcessor::TransformToDoc function in Mozilla Firefox before 3.0.8 and SeaMonkey before 1.1.16 allows r
28RIESGO
abrir
ReferênciaVexDay Proof
PHP-Nuke - 'iframe.php' Remote File Inclusion
CVE-2007-1626webappsphp
PHP remote file inclusion vulnerability in iframe.php in the iFrame Module for PHP-NUKE allows remote attackers to execu
23RIESGO
abrir
ReferênciaVexDay Proof
Moodle < 1.6.9/1.7.7/1.8.9/1.9.5 - File Disclosure
CVE-2009-1171webappsphp
The TeX filter in Moodle 1.6 before 1.6.9+, 1.7 before 1.7.7+, 1.8 before 1.8.9, and 1.9 before 1.9.5 allows user-assist
23RIESGO
abrir
ReferênciaVexDay Proof
PrecisionID Datamatrix - ActiveX Arbitrary File Overwrite
CVE-2009-1212remotewindows
Multiple insecure method vulnerabilities in PRECIS~2.DLL in the PrecisionID Datamatrix ActiveX control (DMATRIXLib.Datam
23RIESGO
abrir
ReferênciaVexDay Proof
FOSS Gallery Admin 1.0 - Arbitrary File Upload
CVE-2008-4509webappsphp
Unrestricted file upload vulnerability in processFiles.php in FOSS Gallery Admin and FOSS Gallery Public 1.0 beta allows
23RIESGO
abrir
ReferênciaVexDay Proof
FOSS Gallery Public 1.0 - Arbitrary File Upload
CVE-2008-4509webappsphp
Unrestricted file upload vulnerability in processFiles.php in FOSS Gallery Admin and FOSS Gallery Public 1.0 beta allows
23RIESGO
abrir
ReferênciaVexDay Proof
Apple Mac OSX xnu 1228.3.13 - 'zip-notify' Remote Kernel Overflow (PoC)
CVE-2009-1236dososx
Heap-based buffer overflow in the AppleTalk networking stack in XNU 1228.3.13 and earlier on Apple Mac OS X 10.5.6 and e
23RIESGO
abrir
ReferênciaVexDay Proof
Chilkat Mail ActiveX 7.8 - 'ChilkatCert.dll' Insecure Method
CVE-2008-4584remotewindows
Insecure method vulnerability in Chilkat Mail 7.8 ActiveX control (ChilkatCert.dll) allows remote attackers to overwrite
23RIESGO
abrir
ReferênciaVexDay Proof
Macrovision FlexNet - 'isusweb.dll' DownloadAndExecute Method
CVE-2008-4586remotewindows
Insecure method vulnerability in the MVSNCLientWebAgent61.WebAgent.1 ActiveX control (isusweb.dll 6.1.100.61372) in Macr
23RIESGO
abrir
ReferênciaVexDay Proof
Apple Mac OSX xnu 1228.x - 'vfssysctl' Local Kernel Denial of Service (PoC)
CVE-2009-1238dososx
Race condition in the HFS vfs sysctl interface in XNU 1228.8.20 and earlier on Apple Mac OS X 10.5.6 and earlier allows
23RIESGO
abrir
ReferênciaVexDay Proof
Hitweb 4.2.1 - 'REP_INC' Remote File Inclusion
CVE-2006-4113webappsphp
PHP remote file inclusion vulnerability in genpage-cgi.php in Brian Fraval hitweb 4.2 and possibly earlier versions allo
23RIESGO
abrir
ReferênciaVexDay Proof
phpBB Journals System Mod 1.0.2 RC2 - Remote File Inclusion
CVE-2006-5306webappsphp
Multiple PHP remote file inclusion vulnerabilities in the Journals System module 1.0.2 (RC2) and earlier for phpBB allow
23RIESGO
abrir
ReferênciaVexDay Proof
acute control panel 1.0.0 - SQL Injection / Remote File Inclusion
CVE-2009-1247webappsphp
SQL injection vulnerability in login.php in Acute Control Panel 1.0.0 allows remote attackers to execute arbitrary SQL c
28RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component com_Projectfork 2.0.10 - Local File Inclusion
CVE-2009-2100webappsphp
Directory traversal vulnerability in the JoomlaPraise Projectfork (com_projectfork) component 2.0.10 for Joomla! allows
38RIESGO
abrir
ReferênciaVexDay Proof
PHP 5.2.3 - 'bz2 com_print_typeinfo()' Denial of Service
CVE-2007-3790dosmultiple
The com_print_typeinfo function in the bz2 extension in PHP 5.2.3 allows context-dependent attackers to cause a denial o
23RIESGO
abrir
ReferênciaVexDay Proof
Eserv 3.x - FTP Server (ABOR) Remote Stack Overflow (PoC)
CVE-2008-4588doswindows
Stack-based buffer overflow in the FTP server in Etype Eserv 3.x, possibly 3.26, allows remote attackers to cause a deni
23RIESGO
abrir
ReferênciaVexDay Proof
Stash 1.0.3 - SQL Injection User Credentials Disclosure
CVE-2008-4590webappsphp
Multiple SQL injection vulnerabilities in Stash 1.0.3 allow remote attackers to execute arbitrary SQL commands via (1) t
23RIESGO
abrir
ReferênciaVexDay Proof
Cartweaver 2.16.11 - 'ProdID' SQL Injection
CVE-2006-2046webappscgi
Multiple SQL injection vulnerabilities in Application Dynamics Cartweaver ColdFusion 2.16.11 and earlier allow remote at
23RIESGO
abrir
ReferênciaVexDay Proof
FlexCMS Calendar - 'itemID' Blind SQL Injection
CVE-2009-1256webappsphp
SQL injection vulnerability in FlexCMS 2.5 allows remote attackers to execute arbitrary SQL commands via the ItemId para
23RIESGO
abrir
ReferênciaVexDay Proof
OPENi-CMS 1.0.1beta - 'config' Remote File Inclusion
CVE-2006-4750webappsphp
PHP remote file inclusion vulnerability in openi-admin/base/fileloader.php in OPENi-CMS 1.0.1, and possibly earlier, all
23RIESGO
abrir
ReferênciaVexDay Proof
KGB 1.9 - 'sesskglogadmin.php' Local File Inclusion
CVE-2007-0337webappsphp
Directory traversal vulnerability in sesskglogadmin.php in KGB 1.9 and earlier allows remote attackers to include and ex
23RIESGO
abrir
ReferênciaVexDay Proof
Campsite 3.3.0 RC1 - Multiple Remote File Inclusions
CVE-2009-2182webappsphp
Multiple PHP remote file inclusion vulnerabilities in Campsite 3.3.0 RC1 allow remote attackers to execute arbitrary PHP
23RIESGO
abrir
ReferênciaVexDay Proof
Aktueldownload Haber scripti - 'id' SQL Injection
CVE-2007-1015webappsasp
SQL injection vulnerability in HaberDetay.asp in Aktueldownload Haber script allows remote attackers to execute arbitrar
23RIESGO
abrir
anteriorpágina 129 / 188siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.