Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
phpPrintAnalyzer 1.2 - Remote File Inclusion
CVE-2006-4164webappsphp
PHP remote file inclusion vulnerability in inc/header.inc.php in phpPrintAnalyzer 1.2 and earlier allows remote attacker
23RIESGO
abrir
ReferênciaVexDay Proof
HP OpenView Network Node Manager 07.50 - CGI Remote Buffer Overflow
CVE-2007-6204remotewindows
Multiple stack-based buffer overflows in HP OpenView Network Node Manager (OV NNM) 6.41, 7.01, and 7.51 allow remote att
50RIESGO
abrir
ReferênciaVexDay Proof
KML share 1.1 - 'region.php?layer' Remote File Disclosure
CVE-2007-6212webappsphp
Directory traversal vulnerability in region.php in KML share 1.1 allows remote attackers to read arbitrary files via a .
23RIESGO
abrir
ReferênciaVexDay Proof
SFS EZ Hot or Not - 'phid' SQL Injection
CVE-2008-6776webappsphp
SQL injection vulnerability in viewcomments.php in Scripts For Sites (SFS) EZ Hot or Not allows remote attackers to exec
23RIESGO
abrir
ReferênciaVexDay Proof
MyPHP Forum 3.0 - Edit Topics / Blind SQL Injection
CVE-2008-6777webappsphp
Multiple SQL injection vulnerabilities in MyPHP Forum 3.0 and earlier allow remote attackers to execute arbitrary SQL co
23RIESGO
abrir
ReferênciaVexDay Proof
ProjectButler 0.8.4 - 'rootdir' Remote File Inclusion
CVE-2006-4205webappsphp
Multiple PHP remote file inclusion vulnerabilities in WebDynamite ProjectButler 0.8.4 allow remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
ExoPHPDesk 1.2 Final - Authentication Bypass
CVE-2008-6917webappsphp
SQL injection vulnerability in admin.php in Exocrew ExoPHPDesk 1.2 Final allows remote attackers to execute arbitrary SQ
23RIESGO
abrir
ReferênciaVexDay Proof
ThePortal 2.2 - Arbitrary File Upload
CVE-2008-6918webappsphp
Unrestricted file upload vulnerability in admin/galeria.php in ThePortal2 2.2 allows remote attackers to execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
TaskDriver 1.3 - Remote Change Admin Password
CVE-2008-6919webappsphp
profileedit.php TaskDriver 1.3 and earlier allows remote attackers to bypass authentication and gain administrative acce
23RIESGO
abrir
ReferênciaVexDay Proof
dotProject 2.0.4 - 'baseDir' Remote File Inclusion
CVE-2006-4234webappsphp
PHP remote file inclusion vulnerability in classes/query.class.php in dotProject 2.0.4 and earlier allows remote attacke
23RIESGO
abrir
ReferênciaVexDay Proof
PHPAdBoard - PHP uploads Arbitrary File Upload
CVE-2008-6921webappsphp
Unrestricted file upload vulnerability in index.php in phpAdBoard 1.8 allows remote attackers to execute arbitrary code
23RIESGO
abrir
ReferênciaVexDay Proof
Mambo Component mambelfish 1.1 - Remote File Inclusion
CVE-2006-4270webappsphp
PHP remote file inclusion vulnerability in mambelfish.class.php in the mambelfish component (com_mambelfish) 1.1 and ear
23RIESGO
abrir
ReferênciaVexDay Proof
Tutti Nova 1.6 - 'TNLIB_DIR' Remote File Inclusion
CVE-2006-4276webappsphp
PHP remote file inclusion vulnerability in Tutti Nova 1.6 and earlier allows remote attackers to execute arbitrary PHP c
23RIESGO
abrir
ReferênciaVexDay Proof
Mambo Component bigAPE-Backup 1.1 - Remote File Inclusion
CVE-2006-4296webappsphp
PHP remote file inclusion vulnerability in classes/Tar.php in bigAPE-Backup component (com_babackup) for Mambo 1.1 allow
23RIESGO
abrir
ReferênciaVexDay Proof
Texas Imperial Software WFTPD 3.23 - 'SIZE' Remote Buffer Overflow
CVE-2006-4318remotewindows
Buffer overflow in WFTPD Server 3.23 allows remote attackers to execute arbitrary code via long SIZE commands.
50RIESGO
abrir
ReferênciaVexDay Proof
OpenSSL < 0.9.7l/0.9.8d - SSLv2 Client Crash
CVE-2006-4343dosmultiple
The get_server_hello function in the SSLv2 client code in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier
28RIESGO
abrir
ReferênciaVexDay Proof
Empire CMS 3.7 - 'checklevel.php' Remote File Inclusion
CVE-2006-4354webappsphp
PHP remote file inclusion vulnerability in e/class/CheckLevel.php in Phome Empire CMS 3.7 and earlier allows remote atta
23RIESGO
abrir
ReferênciaVexDay Proof
SerWeb 2.0.0 dev1 2007-02-20 - Multiple Local/Remote File Inclusion Vulnerabilities
CVE-2007-6289webappsphp
Multiple PHP remote file inclusion vulnerabilities in SerWeb 2.0.0 dev1 and earlier allow remote attackers to execute ar
23RIESGO
abrir
ReferênciaVexDay Proof
HP Compaq Notebooks - ActiveX Remote Code Execution
CVE-2007-6333remotewindows
The HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 i
23RIESGO
abrir
ReferênciaVexDay Proof
XChat 2.6.7 (Windows) - Remote Denial of Service
CVE-2006-4455doswindows
Unspecified vulnerability in Xchat 2.6.7 and earlier allows remote attackers to cause a denial of service (crash) via un
23RIESGO
abrir
ReferênciaVexDay Proof
Web3news 0.95 - 'PHPSECURITYADMIN_PATH' Remote File Inclusion
CVE-2006-4452webappsphp
PHP remote file inclusion vulnerability in security/include/_class.security.php in Web3news 0.95 and earlier, when regis
23RIESGO
abrir
ReferênciaVexDay Proof
ClamAV 0.91.2 - libclamav MEW PE Buffer Overflow
CVE-2007-6335remotelinux
Integer overflow in libclamav in ClamAV before 0.92 allows remote attackers to execute arbitrary code via a crafted MEW
28RIESGO
abrir
ReferênciaVexDay Proof
Joomla! / Mambo Component rsgallery 2.0b5 - 'catid' SQL Injection
CVE-2007-6362webappsphp
SQL injection vulnerability in index.php in the RSGallery (com_rsgallery) 2.0 beta 5 and earlier component for Mambo and
23RIESGO
abrir
ReferênciaVexDay Proof
SineCMS 2.3.4 - Calendar SQL Injection
CVE-2007-6366webappsphp
Multiple SQL injection vulnerabilities in SineCMS 2.3.4 and earlier allow remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
ReferênciaVexDay Proof
BadBlue 2.72 - PassThru Remote Buffer Overflow
CVE-2007-6377remotewindows
Stack-based buffer overflow in the PassThru functionality in ext.dll in BadBlue 2.72b and earlier allows remote attacker
50RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Plugin tinybrowser 1.5.12 - Arbitrary File Upload / Execution
CVE-2011-4908webappsphp
TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php.
50RIESGO
abrir
ReferênciaVexDay Proof
GrapAgenda 0.1 - 'page' Remote File Inclusion
CVE-2006-4610webappsphp
PHP remote file inclusion vulnerability in index.php in GrapAgenda 0.11 and earlier, when register_globals is enabled, a
23RIESGO
abrir
ReferênciaVexDay Proof
BinGo News 3.01 - 'bnrep' Remote File Inclusion
CVE-2006-4648webappsphp
PHP remote file inclusion vulnerability in bp_ncom.php in BinGo News (BP News) 3.01 and earlier allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
webSPELL 4.01.01 - Database Backup Download
CVE-2006-4782webappsphp
src/index.php in WebSPELL 4.01.01 and earlier, when register_globals is enabled, allows remote attackers to bypass authe
23RIESGO
abrir
ReferênciaVexDay Proof
Anon Proxy Server 0.1000 - Remote Command Execution
CVE-2007-6459webappsphp
Anon Proxy Server 0.100, and probably 0.101, allows remote attackers to execute arbitrary commands via shell metacharact
23RIESGO
abrir
anteriorpágina 167 / 188siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.