Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
webid 0.5.4 - Multiple Vulnerabilities
CVE-2008-7118webappsphp
WeBid auction script 0.5.4 stores sensitive information under the web root with insufficient access control, which allow
23RIESGO
abrir
ReferênciaVexDay Proof
PHP Photo Gallery 1.0 - 'photo_id' SQL Injection
CVE-2008-1711webappsphp
Terong PHP Photo Gallery (aka Advanced Web Photo Gallery) 1.0 stores passwords in cleartext in a MySQL database, which a
23RIESGO
abrir
ReferênciaVexDay Proof
WebAlbum 2.02pl - COOKIE[skin2] Remote Code Execution
CVE-2006-1480webappsphp
Directory traversal vulnerability in start.php in WebAlbum 2.02 allows remote attackers to include arbitrary files and e
23RIESGO
abrir
ReferênciaVexDay Proof
Cartweaver 3 - 'prodId' Blind SQL Injection
CVE-2008-2918webappsphp
SQL injection vulnerability in details.php in Application Dynamics Cartweaver 3.0 allows remote attackers to execute arb
23RIESGO
abrir
ReferênciaVexDay Proof
iWare Pro 5.0.4 - 'chat_panel.php' Remote Code Execution
CVE-2006-5837webappsphp
Static code injection vulnerability in chat_panel.php in the SimpleChat 1.0.0 module for iWare Professional CMS allows r
23RIESGO
abrir
ReferênciaVexDay Proof
TorrentFlux 2.2 - 'downloaddetails.php' Local File Disclosure
CVE-2006-6598webappsphp
Directory traversal vulnerability in viewnfo.php in (1) TorrentFlux before 2.2 and (2) torrentflux-b4rt before 2.1-b4rt-
23RIESGO
abrir
ReferênciaVexDay Proof
NewsCMSLite - 'newsCMS.mdb' Remote Password Disclosure
CVE-2007-0091webappsasp
newsCMSlite stores sensitive information under the web root with insufficient access control, which allows remote attack
23RIESGO
abrir
ReferênciaVexDay Proof
Pakupaku CMS 0.4 - Arbitrary File Upload / Local File Inclusion
CVE-2007-4640webappsphp
Unrestricted file upload vulnerability in index.php in Pakupaku CMS 0.4 and earlier allows remote attackers to upload an
23RIESGO
abrir
ReferênciaVexDay Proof
Postfix 2.6-20080814 - 'symlink' Local Privilege Escalation
CVE-2008-2936locallinux
Postfix before 2.3.15, 2.4 before 2.4.8, 2.5 before 2.5.4, and 2.6 before 2.6-20080814, when the operating system suppor
23RIESGO
abrir
ReferênciaVexDay Proof
GGCMS 1.1.0 RC1 - Remote Code Execution
CVE-2007-0804webappsphp
Directory traversal vulnerability in admin/subpages.php in GGCMS 1.1.0 RC1 and earlier allows remote attackers to inject
23RIESGO
abrir
ReferênciaVexDay Proof
Garennes 0.6.1 - 'repertoire_config' Remote File Inclusion
CVE-2007-2298webappsphp
Multiple PHP remote file inclusion vulnerabilities in Garennes 0.6.1 and earlier allow remote attackers to execute arbit
23RIESGO
abrir
ReferênciaVexDay Proof
iyzi Forum 1.0b3 - Database Disclosure
CVE-2008-5901webappsphp
iyzi Forum 1.0 beta 3 stores sensitive information under the web root with insufficient access control, which allows rem
23RIESGO
abrir
ReferênciaVexDay Proof
GoSamba 1.0.1 - 'INCLUDE_PATH' Multiple Remote File Inclusions
CVE-2007-5786webappsphp
Multiple PHP remote file inclusion vulnerabilities in GoSamba 1.0.1 allow remote attackers to execute arbitrary PHP code
23RIESGO
abrir
ReferênciaVexDay Proof
Apache Tomcat < 6.0.18 - 'utf8' Directory Traversal (PoC)
CVE-2008-2938remotemultiple
Directory traversal vulnerability in Apache Tomcat 4.1.0 through 4.1.37, 5.5.0 through 5.5.26, and 6.0.0 through 6.0.16,
60RIESGO
abrir
ReferênciaVexDay Proof
Cahier de texte 2.2 - Bypass General Access Protection
CVE-2006-6849webappsphp
administration/index.php in Cahier de texte (CDT) 2.2 does not properly exit when authentication fails, which allows rem
23RIESGO
abrir
ReferênciaVexDay Proof
Shop-Script FREE 2.0 - Remote Command Execution
CVE-2007-4933webappsphp
Direct static code injection vulnerability in includes/admin/sub/conf_appearence.php in Shop-Script FREE 2.0 and earlier
23RIESGO
abrir
ReferênciaVexDay Proof
iziContents rc6 - Local/Remote File Inclusion
CVE-2007-5055webappsphp
Multiple directory traversal vulnerabilities in iziContents 1 RC6 and earlier allow remote attackers to include and exec
23RIESGO
abrir
ReferênciaVexDay Proof
Flat PHP Board 1.2 - Multiple Vulnerabilities
CVE-2007-6396webappsphp
Direct static code injection vulnerability in index.php in Flat PHP Board 1.2 and earlier allows remote attackers to inj
23RIESGO
abrir
ReferênciaVexDay Proof
X7 Chat 2.0.5 - 'day' SQL Injection
CVE-2008-0278webappsphp
SQL injection vulnerability in index.php in X7 Chat 2.0.5 and possibly earlier allows remote attackers to execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
MyBlog: PHP and MySQL Blog/CMS software - SQL Injection / Cross-Site Scripting
CVE-2008-2962webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in MyBlog allow remote attackers to inject arbitrary web script or H
23RIESGO
abrir
ReferênciaVexDay Proof
Google Chrome 1.0.154.43 - Clickjacking
CVE-2009-0374remotewindows
Google Chrome 1.0.154.43 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action th
23RIESGO
abrir
ReferênciaVexDay Proof
snetworks PHP Classifieds 5.0 - Remote File Inclusion
CVE-2008-0137webappsphp
PHP remote file inclusion vulnerability in config.inc.php in SNETWORKS PHP CLASSIFIEDS 5.0 allows remote attackers to ex
23RIESGO
abrir
ReferênciaVexDay Proof
Contenido 4.8.4 - Remote File Inclusion / Cross-Site Scripting
CVE-2008-2912webappsphp
Multiple PHP remote file inclusion vulnerabilities in Contenido CMS 4.8.4 allow remote attackers to execute arbitrary PH
23RIESGO
abrir
ReferênciaVexDay Proof
PHP Multiple Newsletters 2.7 - Local File Inclusion / Cross-Site Scripting
CVE-2008-5570webappsphp
Directory traversal vulnerability in index.php in PHP Multiple Newsletters 2.7, when magic_quotes_gpc is disabled, allow
23RIESGO
abrir
ReferênciaVexDay Proof
Apache Tomcat - 'WebDAV' Remote File Disclosure
CVE-2007-5461remotemultiple
Absolute path traversal vulnerability in Apache Tomcat 4.0.0 through 4.0.6, 4.1.0, 5.0.0, 5.5.0 through 5.5.25, and 6.0.
35RIESGO
abrir
ReferênciaVexDay Proof
Mafia Scum Tools 2.0.0 - 'index.php?gen' Remote File Inclusion
CVE-2007-0501webappsphp
PHP remote file inclusion vulnerability in index.php in Mafia Scum Tools 2.0.0 in Matthew Wardrop Advanced Random Genera
23RIESGO
abrir
ReferênciaVexDay Proof
GNU/Gallery 1.1.1.0 - 'admin.php' Local File Inclusion
CVE-2008-2353webappsphp
Directory traversal vulnerability in admin.php in GNU/Gallery 1.1.1.0 and earlier allows remote attackers to include and
23RIESGO
abrir
ReferênciaVexDay Proof
PHP 4.4.6 - 'ibase_connect()' Local Buffer Overflow
CVE-2007-1475localwindows
Multiple buffer overflows in the (1) ibase_connect and (2) ibase_pconnect functions in the interbase extension in PHP 4.
23RIESGO
abrir
ReferênciaVexDay Proof
MyBlog: PHP and MySQL Blog/CMS software - SQL Injection / Cross-Site Scripting
CVE-2008-2963webappsphp
Multiple SQL injection vulnerabilities in MyBlog allow remote attackers to execute arbitrary SQL commands via the (1) vi
23RIESGO
abrir
ReferênciaVexDay Proof
Integramod Nederland 1.4.2 - Remote File Inclusion
CVE-2007-5140webappsphp
PHP remote file inclusion vulnerability in includes/archive/archive_topic.php in IntegraMOD Nederland 1.4.2 allows remot
23RIESGO
abrir
anteriorpágina 154 / 188siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.