Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
YenerTurk Haber Script 1.0 - SQL Injection
CVE-2006-4064webappsasp
SQL injection vulnerability in default.asp in YenerTurk Haber Script 1.0 and earlier allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
CLUB-Nuke [XP] 2.0 LCID 2048 (Turkish Version) - SQL Injection
CVE-2006-4072webappsasp
Multiple SQL injection vulnerabilities in Club-Nuke [XP] 2.0 LCID 2048 allow remote attackers to execute arbitrary SQL c
23RIESGO
abrir
ReferênciaVexDay Proof
WebBiscuits Modules Controller 1.1 - Remote File Inclusion / Remote File Disclosure
CVE-2008-6138webappsphp
PHP remote file inclusion vulnerability in adminhead.php in WebBiscuits Modules Controller 1.1 and earlier allows remote
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component JD-Wiki 1.0.2 - Remote File Inclusion
CVE-2006-4074webappsphp
PHP remote file inclusion vulnerability in lib/tpl/default/main.php in the JD-Wiki Component (com_jd-wiki) 1.0.2 and ear
23RIESGO
abrir
ReferênciaVexDay Proof
SFS EZ BIZ PRO - SQL Injection
CVE-2008-6245webappsphp
SQL injection vulnerability in track.php in Scripts For Sites (SFS) EZ BIZ PRO allows remote attackers to execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
SFS EZ Webring - 'cat' SQL Injection
CVE-2008-6246webappsphp
SQL injection vulnerability in category.php in Scripts For Sites (SFS) EZ Webring allows remote attackers to execute arb
23RIESGO
abrir
ReferênciaVexDay Proof
PHPMyRing 4.2.0 - 'view_com.php' SQL Injection
CVE-2006-4114webappsphp
SQL injection vulnerability in view_com.php in Nicolas Grandjean PHPMyRing 4.2.0 and earlier allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
Sciurus Hosting Panel - Remote Code Injection
CVE-2007-6082webappsphp
Direct static code injection vulnerability in acp/savenews.php in Sciurus Hosting Panel, possibly 2.0.3, allows remote a
23RIESGO
abrir
ReferênciaVexDay Proof
Apple Safari / QuickTime 7.3 - RTSP Content-Type Remote Buffer Overflow
CVE-2007-6166remoteosx
Stack-based buffer overflow in Apple QuickTime before 7.3.1, as used in QuickTime Player on Windows XP and Safari on Mac
50RIESGO
abrir
ReferênciaVexDay Proof
6rbScript 3.3 - 'section.php' Local File Inclusion
CVE-2008-6453webappsphp
Directory traversal vulnerability in section.php in 6rbScript 3.3, when magic_quotes_gpc is disabled, allows remote atta
23RIESGO
abrir
ReferênciaVexDay Proof
6rbScript 3.3 - 'singerid' SQL Injection
CVE-2008-6454webappsphp
SQL injection vulnerability in section.php in 6rbScript 3.3 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir
ReferênciaVexDay Proof
e107 Plugin Image Gallery 0.9.6.2 - SQL Injection
CVE-2008-6466webappsphp
SQL injection vulnerability in image_gallery.php in the Akira Powered Image Gallery (image_gallery) plugin 0.9.6.2 for e
23RIESGO
abrir
ReferênciaVexDay Proof
Chaussette 080706 - '_BASE' Remote File Inclusion
CVE-2006-4159webappsphp
Multiple PHP remote file inclusion vulnerabilities in Chaussette 080706 and earlier allow remote attackers to execute ar
28RIESGO
abrir
ReferênciaVexDay Proof
phpPrintAnalyzer 1.2 - Remote File Inclusion
CVE-2006-4164webappsphp
PHP remote file inclusion vulnerability in inc/header.inc.php in phpPrintAnalyzer 1.2 and earlier allows remote attacker
23RIESGO
abrir
ReferênciaVexDay Proof
Seditio CMS 121 - SQL Injection
CVE-2007-6202webappsphp
SQL injection vulnerability in plugins/search/search.php in Neocrome Seditio CMS 121 and earlier allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
HP OpenView Network Node Manager 07.50 - CGI Remote Buffer Overflow
CVE-2007-6204remotewindows
Multiple stack-based buffer overflows in HP OpenView Network Node Manager (OV NNM) 6.41, 7.01, and 7.51 allow remote att
50RIESGO
abrir
ReferênciaVexDay Proof
KML share 1.1 - 'region.php?layer' Remote File Disclosure
CVE-2007-6212webappsphp
Directory traversal vulnerability in region.php in KML share 1.1 allows remote attackers to read arbitrary files via a .
23RIESGO
abrir
ReferênciaVexDay Proof
SFS EZ Hot or Not - 'phid' SQL Injection
CVE-2008-6776webappsphp
SQL injection vulnerability in viewcomments.php in Scripts For Sites (SFS) EZ Hot or Not allows remote attackers to exec
23RIESGO
abrir
ReferênciaVexDay Proof
MyPHP Forum 3.0 - Edit Topics / Blind SQL Injection
CVE-2008-6777webappsphp
Multiple SQL injection vulnerabilities in MyPHP Forum 3.0 and earlier allow remote attackers to execute arbitrary SQL co
23RIESGO
abrir
ReferênciaVexDay Proof
POWERGAP 2003 - 's0x.php' Remote File Inclusion
CVE-2006-4236webappsphp
Multiple PHP remote file inclusion vulnerabilities in POWERGAP allow remote attackers to execute arbitrary PHP code via
28RIESGO
abrir
ReferênciaVexDay Proof
Simple Machines Forum (SMF) 1.1.5 (Windows x86) - Admin Reset Password
CVE-2008-6971webappsphp
The password reset functionality in Simple Machines Forum (SMF) 1.0.x before 1.0.14, 1.1.x before 1.1.6, and 2.0 before
23RIESGO
abrir
ReferênciaVexDay Proof
Google Chrome 0.2.149.27 - Denial of Service
CVE-2008-6995doswindows
Integer underflow in net/base/escape.cc in chrome.dll in Google Chrome 0.2.149.27 allows remote attackers to cause a den
23RIESGO
abrir
ReferênciaVexDay Proof
phpBB Garage 1.2.0 Beta3 - SQL Injection
CVE-2007-6223webappsphp
SQL injection vulnerability in garage.php in phpBB Garage 1.2.0 Beta3 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
ReferênciaVexDay Proof
Rayzz Script 2.0 - Local/Remote File Inclusion
CVE-2007-6229webappsphp
PHP remote file inclusion vulnerability in common/classes/class_HeaderHandler.lib.php in Rayzz Script 2.0 allows remote
23RIESGO
abrir
ReferênciaVexDay Proof
Mambo Component mambelfish 1.1 - Remote File Inclusion
CVE-2006-4270webappsphp
PHP remote file inclusion vulnerability in mambelfish.class.php in the mambelfish component (com_mambelfish) 1.1 and ear
23RIESGO
abrir
ReferênciaVexDay Proof
Tutti Nova 1.6 - 'TNLIB_DIR' Remote File Inclusion
CVE-2006-4276webappsphp
PHP remote file inclusion vulnerability in Tutti Nova 1.6 and earlier allows remote attackers to execute arbitrary PHP c
23RIESGO
abrir
ReferênciaVexDay Proof
SimpleBlog 2.0 - 'comments.asp' SQL Injection (2)
CVE-2006-4300webappsphp
SQL injection vulnerability in comments.asp in SimpleBlog 2.0 and earlier allows remote attackers to execute arbitrary S
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Internet Explorer 6 - DirectX Media Remote Overflow Denial of Service
CVE-2006-4301doswindows
Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (crash) via a long Color attrib
35RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component Kochsuite 0.9.4 - Remote File Inclusion
CVE-2006-4348webappsphp
PHP remote file inclusion vulnerability in config.kochsuite.php in the Kochsuite (com_kochsuite) 0.9.4 component for Mam
23RIESGO
abrir
ReferênciaVexDay Proof
Apache Tomcat Connector jk2-2.0.2 mod_jk2 - Remote Overflow
CVE-2007-6258remotelinux
Multiple stack-based buffer overflows in the legacy mod_jk2 2.0.3-DEV and earlier Apache module allow remote attackers t
35RIESGO
abrir
anteriorpágina 168 / 188siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.