Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
OpenH323 Opal SIP Protocol - Remote Denial of Service
CVE-2007-4924doswindows
The Open Phone Abstraction Library (opal), as used by (1) Ekiga before 2.0.10 and (2) OpenH323 before 2.2.4, allows remo
28RIESGO
abrir
ReferênciaVexDay Proof
Shop-Script FREE 2.0 - Remote Command Execution
CVE-2007-4932webappsphp
admin.php in Shop-Script FREE 2.0 and earlier sends a redirect to the web browser but does not exit when administrative
23RIESGO
abrir
ReferênciaVexDay Proof
phpFFL 1.24 - 'PHPFFL_FILE_ROOT' Remote File Inclusion
CVE-2007-4934webappsphp
Multiple PHP remote file inclusion vulnerabilities in phpFFL 1.24 allow remote attackers to execute arbitrary PHP code v
28RIESGO
abrir
ReferênciaVexDay Proof
Omnistar Article Manager Software - 'article.php' SQL Injection
CVE-2007-4952webappsphp
SQL injection vulnerability in article.php in OmniStar Article Manager allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
SimpCMS - 'keyword' SQL Injection
CVE-2007-4953webappsphp
SQL injection vulnerability in index.php in SimpCMS allows remote attackers to execute arbitrary SQL commands via the ke
23RIESGO
abrir
ReferênciaVexDay Proof
KwsPHP 1.0 sondages Module - SQL Injection
CVE-2007-4979webappsphp
SQL injection vulnerability in index.php in the sondages module in KwsPHP 1.0 allows remote attackers to execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
MW6 Technologies QRCode ActiveX 3.0 - Remote File Overwrite
CVE-2007-4982remotewindows
Multiple absolute path traversal vulnerabilities in the MW6QRCode.QRCode.1 ActiveX control in MW6QRCode.dll in MW6 Techn
28RIESGO
abrir
ReferênciaVexDay Proof
Aqua CMS - 'Username' SQL Injection
CVE-2009-1317webappsphp
Multiple SQL injection vulnerabilities in Aqua CMS 1.1, when magic_quotes_gpc is disabled, allow remote attackers to exe
23RIESGO
abrir
ReferênciaVexDay Proof
Teraway LiveHelp 2.0 - Insecure Cookie Handling
CVE-2009-1618webappsphp
Teraway LiveHelp 2.0 allows remote attackers to bypass authentication and gain administrative access via a pwd=&lvl=1&us
23RIESGO
abrir
ReferênciaVexDay Proof
PHPWebThings 1.5.2 - 'help.php?module' Local File Inclusion
CVE-2009-2081webappsphp
Directory traversal vulnerability in help.php in phpWebThings 1.5.2 and earlier, when magic_quotes_gpc is disabled, allo
23RIESGO
abrir
ReferênciaVexDay Proof
Mundi Mail 0.8.2 - 'top' Remote File Inclusion
CVE-2009-2095webappsphp
PHP remote file inclusion vulnerability in template/simpledefault/admin/_masterlayout.php in Mundi Mail 0.8.2, when regi
23RIESGO
abrir
ReferênciaVexDay Proof
LushiNews 1.01 - 'comments.php' SQL Injection
CVE-2007-0865webappsphp
SQL injection vulnerability in comments.php in LushiNews 1.01 and earlier allows remote authenticated users to inject ar
23RIESGO
abrir
ReferênciaVexDay Proof
Connectix Boards 0.7 - 'p_skin' Multiple Vulnerabilities
CVE-2007-1254webappsphp
SQL injection vulnerability in part.userprofile.php in Connectix Boards 0.7 and earlier allows remote authenticated user
23RIESGO
abrir
ReferênciaVexDay Proof
Mambo Module Calendar (Agenda) 1.5.5 - Remote File Inclusion
CVE-2007-2049webappsphp
Multiple PHP remote file inclusion vulnerabilities in the Calendar Module (com_calendar) 1.5.5 for Mambo allow remote at
23RIESGO
abrir
ReferênciaVexDay Proof
RicarGBooK 1.2.1 - 'lang' Local File Inclusion
CVE-2007-2050webappsphp
Multiple directory traversal vulnerabilities in header.php in RicarGBooK 1.2.1 allow remote attackers to include and exe
23RIESGO
abrir
ReferênciaVexDay Proof
Flip 3.0 - Remote Password Hash Disclosure
CVE-2007-5063webappsphp
Adam Scheinberg Flip 3.0 and earlier stores sensitive information under the web root with insufficient access control, w
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component com_slideshow - Remote File Inclusion
CVE-2007-5065webappsphp
PHP remote file inclusion vulnerability in admin.slideshow1.php in the Flash Slide Show (com_slideshow) component for Jo
35RIESGO
abrir
ReferênciaVexDay Proof
PHP-Nuke addon Nuke Mobile Entartainment 1.0 - Local File Inclusion
CVE-2007-5069webappsphp
Directory traversal vulnerability in data/compatible.php in the Nuke Mobile Entertainment 1 addon for PHP-Nuke allows re
23RIESGO
abrir
ReferênciaVexDay Proof
Zomplog 3.8.1 - Arbitrary File Upload
CVE-2007-5230webappsphp
admin/upload_files.php in Zomplog 3.8.1 and earlier does not check for administrative credentials, which allows remote a
23RIESGO
abrir
ReferênciaVexDay Proof
Zomplog 3.8.1 - Arbitrary File Upload
CVE-2007-5231webappsphp
Unrestricted file upload vulnerability in admin/upload_files.php in Zomplog 3.8.1 and earlier allows remote authenticate
23RIESGO
abrir
ReferênciaVexDay Proof
Web Template Management System 1.3 - SQL Injection
CVE-2007-5233webappsphp
SQL injection vulnerability in index.php in Web Template Management System 1.3 allows remote attackers to execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
Scout Portal Toolkit 1.4.0 - 'ParentId' SQL Injection
CVE-2005-4195webappsphp
Multiple SQL injection vulnerabilities in Scout Portal Toolkit (SPT) 1.3.1 and earlier allow remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
VS-News-System 1.2.1 - 'newsordner' Remote File Inclusion
CVE-2007-1017webappsphp
PHP remote file inclusion vulnerability in show_news_inc.php in VirtualSystem VS-News-System 1.2.1 and earlier allows re
23RIESGO
abrir
ReferênciaVexDay Proof
EZContents CMS 2.0.0 - Multiple SQL Injections
CVE-2008-2135webappsphp
Multiple SQL injection vulnerabilities in VisualShapers ezContents 2.0.0 allow remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
Studio Lounge Address Book 2.5 - 'profile' Arbitrary File Upload
CVE-2009-1483webappsphp
Unrestricted file upload vulnerability in upload-file.php in Adam Patterson Studio Lounge Address Book 2.5, as reachable
23RIESGO
abrir
ReferênciaVexDay Proof
PrecisionID Barcode ActiveX 1.3 - Denial of Service
CVE-2007-2657doswindows
Unspecified vulnerability in the PrecisionID Barcode 1.3 ActiveX control in PrecisionID_DataMatrix.DLL allows remote att
23RIESGO
abrir
ReferênciaVexDay Proof
DFF PHP Framework API - 'Data Feed File' Remote File Inclusion
CVE-2008-4502webappsphp
Multiple PHP remote file inclusion vulnerabilities in DataFeedFile (DFF) PHP Framework API allow remote attackers to exe
23RIESGO
abrir
ReferênciaVexDay Proof
PHP-Fusion Mod Classifieds - 'lid' SQL Injection
CVE-2008-5197webappsphp
SQL injection vulnerability in classifieds.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
ReferênciaVexDay Proof
TurnkeyForms Web Hosting Directory - Multiple Vulnerabilities
CVE-2008-6940webappsphp
TurnkeyForms Web Hosting Directory stores sensitive information under the web root with insufficient access control, whi
23RIESGO
abrir
ReferênciaVexDay Proof
pivot 1.40.4-7 - Multiple Vulnerabilities
CVE-2009-2133webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in Pivot 1.40.4 and 1.40.7 allow remote attackers to inject arbitrar
23RIESGO
abrir
anteriorpágina 149 / 188siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.