Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
eFiction 3.1.1 - 'path_to_smf' Remote File Inclusion
CVE-2007-1118webappsphp
Multiple PHP remote file inclusion vulnerabilities in eFiction 3.1.1 and earlier allow remote attackers to execute arbit
23RIESGO
abrir
ReferênciaVexDay Proof
XChat 2.6.7 (Windows) - Remote Denial of Service
CVE-2006-4455doswindows
Unspecified vulnerability in Xchat 2.6.7 and earlier allows remote attackers to cause a denial of service (crash) via un
23RIESGO
abrir
ReferênciaVexDay Proof
ItCMS 2.1a - Authentication Bypass
CVE-2009-0493webappsphp
SQL injection vulnerability in login.php in IT!CMS 2.1a and earlier allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
ReferênciaVexDay Proof
Mambo Module MambWeather 1.8.1 - Remote File Inclusion
CVE-2006-5519webappsphp
PHP remote file inclusion vulnerability in Savant2/Savant2_Plugin_options.php in the MambWeather 1.8.1 and earlier compo
23RIESGO
abrir
ReferênciaVexDay Proof
Enigma 2 Coppermine Bridge - 'boarddir' Remote File Inclusion
CVE-2006-6864webappsphp
PHP remote file inclusion vulnerability in E2_header.inc.php in Enigma2 Coppermine Bridge 1.0 allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
GNU/Linux mbse-bbs 0.70.0 - Local Buffer Overflow
CVE-2007-0368locallinux
Stack-based buffer overflow in mbse-bbs 0.70 and earlier allows local users to execute arbitrary code via a long string
23RIESGO
abrir
ReferênciaVexDay Proof
Pictures Rating - 'index.php?msgid' SQL Injection
CVE-2007-3881webappsphp
SQL injection vulnerability in index.php in Pictures Rating (Picture Rating) allows remote attackers to execute arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
Demo4 CMS - 'id' SQL Injection
CVE-2008-2983webappsphp
SQL injection vulnerability in index.php in Demo4 CMS 01 Beta allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
phpProfiles 3.1.2b - Multiple Remote File Inclusions
CVE-2006-6740webappsphp
Multiple PHP remote file inclusion vulnerabilities in phpProfiles 3.1.2b and earlier allow remote attackers to execute a
23RIESGO
abrir
ReferênciaVexDay Proof
ViRC 2.0 - JOIN Response Remote Overwrite (SEH)
CVE-2007-3612remotewindows
Stack-based buffer overflow in Visual IRC (ViRC) 2.0 allows remote IRC servers to execute arbitrary code via a long resp
23RIESGO
abrir
ReferênciaVexDay Proof
Virtual Guestbook 2.1 - Remote Database Disclosure
CVE-2009-0498webappsasp
Virtual GuestBook (vgbook) 2.1 stores sensitive information under the web root with insufficient access control, which a
23RIESGO
abrir
ReferênciaVexDay Proof
Web Wiz Rich Text Editor 4.0 - Multiple Vulnerabilities
CVE-2008-0466webappsasp
Web Wiz RTE_file_browser.asp in, as used in Web Wiz Rich Text Editor 4.0, Web Wiz Forums 9.07, and Web Wiz Newspad 1.02,
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component beamospetition - SQL Injection
CVE-2008-3132webappsphp
SQL injection vulnerability in the beamospetition (com_beamospetition) component for Joomla! allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
Foxmail 5.0 - 'PunyLib.dll' Remote Stack Overflow
CVE-2004-2719remotewindows
Buffer overflow in the UrlToLocal function in PunyLib.dll of Foxmail 5.0.300 allows remote attackers to execute arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
East Wind Software - 'advdaudio.ocx 1.5.1.1' Local Buffer Overflow
CVE-2007-2576localwindows
Buffer overflow in the East Wind Software advdaudio.ocx 1.5.1.1 ActiveX control allows user-assisted remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
FlexCMS 2.5 - 'catId' SQL Injection
CVE-2009-0534webappsphp
SQL injection vulnerability in FlexCMS allows remote attackers to execute arbitrary SQL commands via the catId parameter
23RIESGO
abrir
ReferênciaVexDay Proof
March Networks DVR 3204 - Logfile Information Disclosure
CVE-2007-6638remotehardware
March Networks DVR 3204 stores sensitive information under the web root with insufficient access control, which allows r
28RIESGO
abrir
ReferênciaVexDay Proof
Move Networks Quantum Streaming Player Control - Remote Buffer Overflow
CVE-2008-1044remotewindows
Stack-based buffer overflow in the Quantum Streaming Player (Quantum Streaming IE Player) ActiveX control (aka QSP2IE.QS
23RIESGO
abrir
ReferênciaVexDay Proof
Panda Security ActiveScan 2.0 (Update) - Remote Buffer Overflow
CVE-2008-3155remotewindows
Stack-based buffer overflow in the ActiveX control (as2guiie.dll) in Panda ActiveScan before 1.02.00 allows remote attac
23RIESGO
abrir
ReferênciaVexDay Proof
CMS Made Simple 1.2.4 Module FileManager - Arbitrary File Upload
CVE-2008-2267webappsphp
Incomplete blacklist vulnerability in javaUpload.php in Postlet in the FileManager module in CMS Made Simple 1.2.4 and e
23RIESGO
abrir
ReferênciaVexDay Proof
mxCamArchive 2.2 - Bypass Configuration Download
CVE-2008-6956webappsphp
Static code injection vulnerability in admin/admin.php in mxCamArchive 2.2 allows remote authenticated administrators to
23RIESGO
abrir
ReferênciaVexDay Proof
dBpowerAMP Audio Player 2 - '.m3u' Remote Buffer Overflow
CVE-2008-0661remotewindows
Buffer overflow in dBpowerAMP Audio Player Release 2 allows remote attackers to execute arbitrary code via a .M3U file w
23RIESGO
abrir
ReferênciaVexDay Proof
PNPHPBB2 < 1.2i - 'ModName' Multiple Local File Inclusions
CVE-2009-0592webappsphp
Multiple directory traversal vulnerabilities in PNphpBB2 1.2i and earlier allow remote attackers to include and execute
28RIESGO
abrir
ReferênciaVexDay Proof
phpskelsite 1.4 - Local File Inclusion / Remote File Inclusion / Cross-Site Scripting
CVE-2009-0596webappsphp
Directory traversal vulnerability in skysilver/login.tpl.php in phpSkelSite 1.4, when register_globals is enabled, allow
23RIESGO
abrir
ReferênciaVexDay Proof
w3blabor CMS 3.3.0 - Authentication Bypass
CVE-2009-0597webappsphp
SQL injection vulnerability in admin/index.php in w3b>cms (aka w3blabor CMS) before 3.4.0, when magic_quotes_gpc is disa
23RIESGO
abrir
ReferênciaVexDay Proof
Omegaboard 1.0beta4 - 'functions.php' Remote File Inclusion
CVE-2007-0683webappsphp
PHP remote file inclusion vulnerability in includes/functions.php in Omegaboard 1.0beta4 and earlier allows remote attac
23RIESGO
abrir
ReferênciaVexDay Proof
Scripteen Free Image Hosting Script 1.2 - 'cookie' Pass Grabber
CVE-2008-3211webappsphp
Scripteen Free Image Hosting Script 1.2 and 1.2.1 allows remote attackers to bypass authentication and gain administrati
23RIESGO
abrir
ReferênciaVexDay Proof
Jaws 0.8.8 - Multiple Local File Inclusions
CVE-2009-0645webappsphp
Directory traversal vulnerability in index.php in Jaws 0.8.8 allows remote authenticated users to read arbitrary files v
23RIESGO
abrir
ReferênciaVexDay Proof
4Site CMS 2.6 - Multiple SQL Injections
CVE-2009-0646webappsphp
Multiple SQL injection vulnerabilities in 4Site CMS 2.6 and earlier allow remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
ReferênciaVexDay Proof
Nokia N95-8 browser - 'setAttributeNode' Method Crash
CVE-2009-0649doshardware
The web browser in Symbian OS on the Nokia N95 cell phone allows remote attackers to cause a denial of service (crash) v
23RIESGO
abrir
anteriorpágina 137 / 188siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.