Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
Imageview 5.3 - 'fileview.php?album' Local File Inclusion
CVE-2007-2425webappsphp
Directory traversal vulnerability in fileview.php in Imageview 5.3 allows remote attackers to read arbitrary files via a
23RIESGO
abrir
ReferênciaVexDay Proof
CGX 20050314 - 'pathCGX' Remote File Inclusion
CVE-2007-2611webappsphp
Multiple PHP remote file inclusion vulnerabilities in CGX 20050314 allow remote attackers to execute arbitrary PHP code
23RIESGO
abrir
ReferênciaVexDay Proof
Woltlab Burning Board Addon JGS-Treffen 2.0.2 - SQL Injection
CVE-2008-1640webappsphp
SQL injection vulnerability in jgs_treffen.php in the JGS-XA JGS-Treffen 2.0.2 and earlier addon for Woltlab Burning Boa
23RIESGO
abrir
ReferênciaVexDay Proof
SFS EZ Gaming Directory - 'cat_id' SQL Injection
CVE-2008-6781webappsphp
SQL injection vulnerability in directory.php in Sites for Scripts (SFS) Gaming Directory allows remote attackers to exec
23RIESGO
abrir
ReferênciaVexDay Proof
Oracle 10g - MDSYS.SDO_TOPO_DROP_FTBL SQL Injection (Metasploit)
CVE-2008-3979localmultiple
Unspecified vulnerability in the Oracle Spatial component in Oracle Database 10.1.0.5 and 10.2.0.2 allows remote authent
50RIESGO
abrir
ReferênciaVexDay Proof
SFS EZ Home Business Directory - 'cat_id' SQL Injection
CVE-2008-6783webappsphp
SQL injection vulnerability in directory.php in Sites for Scripts (SFS) EZ Home Business Directory allows remote attacke
23RIESGO
abrir
ReferênciaVexDay Proof
MindDezign Photo Gallery 2.2 - SQL Injection
CVE-2008-6788webappsphp
SQL injection vulnerability in MindDezign Photo Gallery 2.2, when magic_quotes_gpc is disabled, allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
EnjoySAP ActiveX rfcguisink.rfcguisink.1 - Remote Heap Overflow (PoC)
CVE-2007-3606doswindows
Heap-based buffer overflow in the rfcguisink.rfcguisink.1 ActiveX control in the EnjoySAP SAP GUI, on systems using ASCI
23RIESGO
abrir
ReferênciaVexDay Proof
jspwiki 2.4.104/2.5.139 - Multiple Vulnerabilities
CVE-2008-1231webappsjsp
Directory traversal vulnerability in Edit.jsp in JSPWiki 2.4.104 and 2.5.139 allows remote attackers to include and exec
23RIESGO
abrir
ReferênciaVexDay Proof
AuraCMS 2.x - '/user.php' Security Code Bypass / Arbitrary Add Administrator
CVE-2008-1715webappsphp
SQL injection vulnerability in content/user.php in AuraCMS 2.2.1 and earlier, when magic_quotes_gpc is disabled, allows
23RIESGO
abrir
ReferênciaVexDay Proof
Vibro-School-CMS - 'nID' SQL Injection
CVE-2008-6795webappsphp
SQL injection vulnerability in view_news.php in nicLOR Vibro-School-CMS allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
Pre Real Estate Listings - Authentication Bypass
CVE-2008-6796webappsphp
SQL injection vulnerability in manager/login.php in Pre Projects Pre Real Estate Listings allows remote attackers to exe
23RIESGO
abrir
ReferênciaVexDay Proof
PHPwebnews 0.2 MySQL Edition - 'det' SQL Injection
CVE-2008-6812webappsphp
SQL injection vulnerability in bukutamu.php in phpWebNews 0.2 MySQL Edition allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
PHPwebnews 0.2 MySQL Edition - 'id_kat' SQL Injection
CVE-2008-6813webappsphp
SQL injection vulnerability in index.php in phpWebNews 0.2 MySQL Edition allows remote attackers to execute arbitrary SQ
23RIESGO
abrir
ReferênciaVexDay Proof
Mambo Component SimpleBoard 1.0.1 - Arbitrary File Upload
CVE-2008-6814webappsphp
Unrestricted file upload vulnerability in image_upload.php in the SimpleBoard (com_simpleboard) component 1.0.1 and earl
23RIESGO
abrir
ReferênciaVexDay Proof
KwsPHP Module jeuxflash 1.0 - 'cat' SQL Injection
CVE-2008-1759webappsphp
SQL injection vulnerability in the jeuxflash module for KwsPHP allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
Fuzzylime CMS 3.01a - 'file' Local File Inclusion
CVE-2008-6834webappsphp
Multiple directory traversal vulnerabilities in fuzzylime (cms) 3.01 and 3.01a allow remote attackers to include and exe
23RIESGO
abrir
ReferênciaVexDay Proof
Pie Cart Pro - 'Inc_Dir' Remote File Inclusion
CVE-2006-4969webappsphp
Multiple PHP remote file inclusion vulnerabilities in WAHM E-Commerce Pie Cart Pro allow remote attackers to execute arb
28RIESGO
abrir
ReferênciaVexDay Proof
JSBoard 2.0.10 - 'login.php?table' Local File Inclusion
CVE-2007-1842webappsphp
Directory traversal vulnerability in login.php in JSBoard before 2.0.12 allows remote attackers to include and execute a
23RIESGO
abrir
ReferênciaVexDay Proof
XOOPS Module XFsection - 'modify.php' Remote File Inclusion
CVE-2007-3222webappsphp
PHP remote file inclusion vulnerability in modify.php in the XFsection 1.07 module for XOOPS allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
MicroTik RouterOS 3.2 - SNMPd snmp-set Denial of Service
CVE-2008-0680doshardware
SNMPd in MikroTik RouterOS 3.2 and earlier allows remote attackers to cause a denial of service (daemon crash) via a cra
23RIESGO
abrir
ReferênciaVexDay Proof
Dragoon 0.1 - 'root' Remote File Inclusion
CVE-2008-1773webappsphp
PHP remote file inclusion vulnerability in includes/header.inc.php in Dragoon 0.1 allows remote attackers to execute arb
28RIESGO
abrir
ReferênciaVexDay Proof
V3 Chat Live Support 3.0.4 - Insecure Cookie Handling
CVE-2008-5783webappsphp
admin/index.php in V3 Chat Live Support 3.0.4 allows remote attackers to bypass authentication and gain administrative a
23RIESGO
abrir
ReferênciaVexDay Proof
phpGreetCards - Cross-Site Scripting / Arbitrary File Upload
CVE-2008-6849webappsphp
Unrestricted file upload vulnerability in index.php in phpGreetCards 3.7 allows remote attackers to execute arbitrary PH
23RIESGO
abrir
ReferênciaVexDay Proof
ChartDirector 4.1 - 'viewsource.php' File Disclosure
CVE-2008-1782webappsphp
phpdemo/viewsource.php in Advanced Software Engineering ChartDirector 4.1 allows remote attackers to read sensitive file
23RIESGO
abrir
ReferênciaVexDay Proof
Ourgame GLWorld 2.x - 'hgs_startNotify()' ActiveX Buffer Overflow
CVE-2008-0647remotewindows
Multiple stack-based buffer overflows in the HanGamePluginCn18.HanGamePluginCn18.1 ActiveX control in HanGamePluginCn18.
23RIESGO
abrir
ReferênciaVexDay Proof
Absolute News Feed 1.0 - Remote Insecure Cookie Handling
CVE-2008-6855webappsphp
Xigla Software Absolute News Feed 1.0 and possibly 1.5 allows remote attackers to bypass authentication and gain adminis
23RIESGO
abrir
ReferênciaVexDay Proof
DS-IPN.NET Digital Sales IPN - Database Disclosure
CVE-2009-0328webappsasp
ROBS-PROJECTS Digital Sales IPN (aka DS-IPN.NET or DS-IPN Paypal Shop) stores sensitive information under the web root w
23RIESGO
abrir
ReferênciaVexDay Proof
Faq Administrator 2.1 - 'faq_reply.php' Remote File Inclusion
CVE-2006-5637webappsphp
PHP remote file inclusion vulnerability in faq_reply.php in Faq Administrator 2.1b allows remote attackers to execute ar
23RIESGO
abrir
ReferênciaVexDay Proof
Prozilla Top 100 1.2 - Arbitrary Delete Stats
CVE-2008-1785webappsphp
delete.php in Prozilla Top 100 1.2 allows remote authenticated users to delete statistics and accounts of arbitrary user
23RIESGO
abrir
anteriorpágina 131 / 188siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.