Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
Ipswitch WS_FTP Server with SSH 6.1.0.0 - Remote Buffer Overflow (PoC)
CVE-2008-0590doswindows
Buffer overflow in Ipswitch WS_FTP Server with SSH 6.1.0.0 allows remote authenticated users to cause a denial of servic
28RIESGO
abrir
ReferênciaVexDay Proof
Linux Kernel 2.6.17 < 2.6.24.1 - 'vmsplice' Local Privilege Escalation (2)
CVE-2008-0600locallinux
The vmsplice_to_pipe function in Linux kernel 2.6.17 through 2.6.24.1 does not validate a certain userspace pointer befo
23RIESGO
abrir
ReferênciaVexDay Proof
All Club CMS 0.0.2 - 'index.php' SQL Injection
CVE-2008-0601webappsphp
SQL injection vulnerability in index.php in All Club CMS (ACCMS) 0.0.1f and earlier allows remote attackers to execute a
23RIESGO
abrir
ReferênciaVexDay Proof
All Club CMS 0.0.1f - 'index.php' Local File Inclusion
CVE-2008-0602webappsphp
Directory traversal vulnerability in index.php in All Club CMS (ACCMS) 0.0.1f and earlier allows remote attackers to inc
23RIESGO
abrir
ReferênciaVexDay Proof
Mambo Component 'com_awesom' 0.3.2 - 'listid' SQL Injection
CVE-2008-0603webappsphp
SQL injection vulnerability in index.php in the amazOOP Awesom! (com_awesom) 0.3.2component for Mambo and Joomla! allows
23RIESGO
abrir
ReferênciaVexDay Proof
RMSOFT Gallery System 2.0 - 'id' SQL Injection
CVE-2008-0611webappsphp
SQL injection vulnerability in rmgs/images.php in the RMSOFT Gallery System 2.0 module for XOOPS allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
phpunity.postcard - 'gallery_path' Remote File Inclusion
CVE-2006-4869webappsphp
PHP remote file inclusion vulnerability in phpunity-postcard.php in phpunity.postcard allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
Linux Kernel 2.6.x - 'sys_timer_create()' Local Denial of Service
CVE-2006-7051doslinux
The sys_timer_create function in posix-timers.c for Linux kernel 2.6.x allows local users to cause a denial of service (
23RIESGO
abrir
ReferênciaVexDay Proof
Ipswitch WS_FTP LE 5.08 - PASV Response Remote Buffer Overflow
CVE-2006-4974remotewindows
Buffer overflow in Ipswitch WS_FTP Limited Edition (LE) 5.08 allows remote FTP servers to execute arbitrary code via a l
23RIESGO
abrir
ReferênciaVexDay Proof
phpQuiz 0.1.2 - SQL Injection / Code Execution
CVE-2006-4977webappsphp
Multiple unrestricted file upload vulnerabilities in (1) back/upload_img.php and (2) admin/upload_img.php in Walter Besc
23RIESGO
abrir
ReferênciaVexDay Proof
phpBB SpamBlocker Mod 1.0.2 - Remote File Inclusion
CVE-2006-5301webappsphp
PHP remote file inclusion vulnerability in includes/antispam.php in the SpamBlockerMODv 1.0.2 and earlier module for php
23RIESGO
abrir
ReferênciaVexDay Proof
Redaction System 1.0 - 'lang_prefix' Remote File Inclusion
CVE-2006-5302webappsphp
Multiple PHP remote file inclusion vulnerabilities in Redaction System 1.0000 allow remote attackers to execute arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
Transmit.app 3.5.5 - 'ftps://' URL Handler Heap Buffer Overflow (PoC)
CVE-2007-0020dososx
Heap-based buffer overflow in the SFTP protocol handler for Panic Transmit (Transmit.app) up to 3.5.5 allows remote atta
23RIESGO
abrir
ReferênciaVexDay Proof
Yahoo! Music Jukebox 2.2 - 'AddImage()' ActiveX Remote Buffer Overflow (1)
CVE-2008-0623remotewindows
Stack-based buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! Music Jukebox 2.2.2.056 allows
23RIESGO
abrir
ReferênciaVexDay Proof
Yahoo! Music Jukebox 2.2 - 'AddImage()' ActiveX Remote Buffer Overflow (2)
CVE-2008-0623remotewindows
Stack-based buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! Music Jukebox 2.2.2.056 allows
23RIESGO
abrir
ReferênciaVexDay Proof
Yahoo! Music JukeBox 2.2 - 'AddButton()' ActiveX Remote Buffer Overflow
CVE-2008-0624remotewindows
Buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! JukeBox 2.2.2.56 allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
EPNadmin 0.7 - 'constantes.inc.php' Remote File Inclusion
CVE-2006-5555webappsphp
PHP remote file inclusion vulnerability in constantes.inc.php in EPNadmin 0.7 and 0.7.1 allows remote attackers to execu
23RIESGO
abrir
ReferênciaVexDay Proof
HP-UX 11i - 'swmodify' Local Stack Overflow / Local Privilege Escalation
CVE-2006-5557localhp-ux
Stack-based buffer overflow in the (1) swpackage and (2) swmodify commands in HP-UX B.11.11 and possibly other versions
23RIESGO
abrir
ReferênciaVexDay Proof
HP-UX 11i - 'swpackage' Local Stack Overflow / Local Privilege Escalation
CVE-2006-5557localhp-ux
Stack-based buffer overflow in the (1) swpackage and (2) swmodify commands in HP-UX B.11.11 and possibly other versions
23RIESGO
abrir
ReferênciaVexDay Proof
phpProfiles 2.1 Beta - Multiple Remote File Inclusions
CVE-2006-5634webappsphp
Multiple PHP remote file inclusion vulnerabilities in phpProfiles 2.1 Beta allow remote attackers to execute arbitrary P
23RIESGO
abrir
ReferênciaVexDay Proof
Easy File Sharing Web Server 4 - Remote Information Stealer
CVE-2006-5714remotewindows
Easy File Sharing (EFS) Web Server 4.0, when running on an NTFS file system, allows remote attackers to read arbitrary f
23RIESGO
abrir
ReferênciaVexDay Proof
EFS Easy Address Book Web Server 1.2 - Remote File Stream
CVE-2006-5715remotewindows
Easy File Sharing (EFS) Easy Address Book 1.2, when run on an NTFS file system, allows remote attackers to read arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
ig shop 1.0 - Code Execution / SQL Injection
CVE-2007-0134webappsphp
Multiple eval injection vulnerabilities in iGeneric iG Shop 1.0 allow remote attackers to execute arbitrary code via the
28RIESGO
abrir
ReferênciaVexDay Proof
Aratix 0.2.2b11 - '/inc/init.inc.php' Remote File Inclusion
CVE-2007-0135webappsphp
PHP remote file inclusion vulnerability in inc/init.inc.php in Aratix 0.2.2 beta 11 and earlier, when register_globals i
23RIESGO
abrir
ReferênciaVexDay Proof
L2J Statistik Script 0.09 - 'index.php' Local File Inclusion
CVE-2007-0173webappsphp
Directory traversal vulnerability in index.php in L2J Statistik Script 0.09 and earlier, when register_globals is enable
23RIESGO
abrir
ReferênciaVexDay Proof
ImageStation - 'SonyISUpload.cab' 1.0.0.38 ActiveX Buffer Overflow
CVE-2008-0748remotewindows
Buffer overflow in the Sony AxRUploadServer.AxRUploadControl.1 ActiveX control in AxRUploadServer.dll 1.0.0.38 in SonyIS
28RIESGO
abrir
ReferênciaVexDay Proof
nabopoll 1.2 - Remote Unprotected Admin Section
CVE-2007-0873webappsphp
nabopoll 1.1.2 allows remote attackers to bypass authentication and access certain administrative functionality via a di
23RIESGO
abrir
ReferênciaVexDay Proof
OPENi-CMS Site Protection Plugin - Remote File Inclusion
CVE-2007-0881webappsphp
PHP remote file inclusion vulnerability in the Seitenschutz plugin for OPENi-CMS 1.0 allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
Hpecs Shopping Cart - Remote Authentication Bypass
CVE-2006-5962webappsasp
Multiple SQL injection vulnerabilities in Hpecs Shopping Cart allow remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
ReferênciaVexDay Proof
ITechBids 6.0 - 'item_id' SQL Injection
CVE-2008-0776webappsphp
SQL injection vulnerability in detail.php in iTechBids Gold 6.0 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
anteriorpágina 173 / 188siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.