Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
Envolution 1.1.0 - 'topic' SQL Injection
CVE-2007-4253webappsphp
SQL injection vulnerability in the News module in modules.php in Envolution 1.1.0 and earlier allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
PHP Blue Dragon CMS 3.0.0 - SQL Injection
CVE-2007-4312webappsphp
SQL injection vulnerability in index.php in Php Blue Dragon CMS 3.0.0 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
ReferênciaVexDay Proof
PHP blue dragon CMS 3.0.0 - Remote File Inclusion
CVE-2007-4313webappsphp
PHP remote file inclusion vulnerability in public_includes/pub_blocks/activecontent.php in Php Blue Dragon CMS 3.0.0 all
35RIESGO
abrir
ReferênciaVexDay Proof
Pixlie 1.7 - 'pixlie.php?root' Remote File Disclosure
CVE-2007-4314webappsphp
pixlie.php in Pixlie 1.7 allows remote attackers to trigger the reading and JPEG image processing of files in a remote d
23RIESGO
abrir
ReferênciaVexDay Proof
Ncaster 1.7.2 - 'archive.php' Remote File Inclusion
CVE-2007-4320webappsphp
PHP remote file inclusion vulnerability in admin/addons/archive/archive.php in Ncaster 1.7.2 allows remote attackers to
45RIESGO
abrir
ReferênciaVexDay Proof
Prozilla Webring Website Script - 'category.php?cat' SQL Injection
CVE-2007-4362webappsphp
SQL injection vulnerability in category.php in Prozilla Webring allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
ReferênciaVexDay Proof
IBM Rational ClearQuest - Web Authentication Bypass / SQL Injection
CVE-2007-4368webappscgi
SQL injection vulnerability in /main in IBM Rational ClearQuest (CQ) Web 7.0.0.0-IFIX02 and 7.0.0.1 allows remote attack
23RIESGO
abrir
ReferênciaVexDay Proof
DL PayCart 1.01 - 'viewitem.php?ItemID' Blind SQL Injection
CVE-2007-4604webappsphp
SQL injection vulnerability in viewitem.php in DL PayCart 1.01 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
PHPNuke-Clan 4.2.0 - 'mvcw_conver.php' Remote File Inclusion
CVE-2007-4606webappsphp
PHP remote file inclusion vulnerability in convert/mvcw_conver.php in the Virtual War (VWar) module for PHPNuke-Clan (PN
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Visual Basic 6.0 - VBP_Open OLE Local CodeExec
CVE-2007-4776localwindows
Buffer overflow in Microsoft Visual Basic 6.0 and Enterprise Edition 6.0 SP6 allows user-assisted remote attackers to ex
50RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Visual Basic Enterprise 6.0 SP6 - Code Execution
CVE-2007-4776localwindows
Buffer overflow in Microsoft Visual Basic 6.0 and Enterprise Edition 6.0 SP6 allows user-assisted remote attackers to ex
50RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Visual FoxPro 6.0 - FPOLE.OCX 6.0.8450.0 Remote (PoC)
CVE-2007-4790doswindows
Stack-based buffer overflow in certain ActiveX controls in (1) FPOLE.OCX 6.0.8450.0 and (2) Foxtlib.ocx, as used in the
35RIESGO
abrir
ReferênciaVexDay Proof
Microsoft SQL Server - Distributed Management Objects Buffer Overflow
CVE-2007-4814remotewindows
Buffer overflow in the SQLServer ActiveX control in the Distributed Management Objects OLE DLL (sqldmo.dll) 2000.085.200
35RIESGO
abrir
ReferênciaVexDay Proof
Vantage Linguistics AnswerWorks 4 - API ActiveX Control Buffer Overflow
CVE-2007-6387remotewindows
Multiple stack-based buffer overflows in the awApi4.AnswerWorks.1 ActiveX control in awApi4.dll 4.0.0.42, as used by Van
35RIESGO
abrir
ReferênciaVexDay Proof
WebED 0.8999a - Multiple Remote File Inclusions
CVE-2007-4815webappsphp
Multiple PHP remote file inclusion vulnerabilities in WebED in Markus Iser ED Engine 0.8999 alpha allow remote attackers
35RIESGO
abrir
ReferênciaVexDay Proof
BaoFeng2 - 'mps.dll' ActiveX Multiple Remote Buffer Overflows (PoC)
CVE-2007-4816doswindows
Multiple buffer overflows in the BaoFeng2 storm ActiveX control in Mps.dll allow remote attackers to have an unknown imp
23RIESGO
abrir
ReferênciaVexDay Proof
X-Cart - Multiple Remote File Inclusions
CVE-2007-4907webappsphp
Multiple PHP remote file inclusion vulnerabilities in X-Cart allow remote attackers to execute arbitrary PHP code via a
23RIESGO
abrir
ReferênciaVexDay Proof
JetCast Server 2.0.0.4308 - Remote Denial of Service
CVE-2007-4911doswindows
JSMP3OGGWt.dll in JetCast Server 2.0.0.4308 allows remote attackers to cause a denial of service (daemon crash) via a lo
23RIESGO
abrir
ReferênciaVexDay Proof
Streamline PHP Media Server 1.0-beta4 - Remote File Inclusion
CVE-2007-5015webappsphp
Multiple PHP remote file inclusion vulnerabilities in Streamline PHP Media Server 1.0-beta4 allow remote attackers to ex
35RIESGO
abrir
ReferênciaVexDay Proof
OneCMS 2.4 - 'abc' SQL Injection
CVE-2007-5016webappsphp
SQL injection vulnerability in userreviews.php in OneCMS 2.4 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
ReferênciaVexDay Proof
Airsensor M520 - HTTPd Remote Denial of Service / Buffer Overflow (PoC)
CVE-2007-5036doshardware
Multiple buffer overflows in the AirDefense Airsensor M520 with firmware 4.3.1.1 and 4.4.1.4 allow remote authenticated
23RIESGO
abrir
ReferênciaVexDay Proof
neuron news 1.0 - 'index.php?q' Local File Inclusion
CVE-2007-5050webappsphp
Directory traversal vulnerability in index.php in Neuron News 1.0 allows remote attackers to include and execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
PhFiTo 1.3.0 - 'SRC_PATH' Remote File Inclusion
CVE-2007-5157webappsphp
PHP remote file inclusion vulnerability in phfito-post.php in Alex Kocharin PHP Fidonet Tosser (PhFiTo) 1.3.0 in phpFido
23RIESGO
abrir
ReferênciaVexDay Proof
PHP Links 1.3 - 'id' SQL Injection
CVE-2008-0565webappsphp
SQL injection vulnerability in vote.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to execute arb
23RIESGO
abrir
ReferênciaVexDay Proof
Mambo Component com_downloads - SQL Injection
CVE-2008-0652webappsphp
SQL injection vulnerability in index.php in the Downloads (com_downloads) component for Mambo and Joomla! allows remote
23RIESGO
abrir
ReferênciaVexDay Proof
FaceBook PhotoUploader - 'ImageUploader4.ocx 4.5.57.0' Remote Buffer Overflow
CVE-2008-0660remotewindows
Multiple stack-based buffer overflows in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.6.17.0, 4.5.70.0,
35RIESGO
abrir
ReferênciaVexDay Proof
The Everything Development System Pre-1.0 - SQL Injection
CVE-2008-0675webappsphp
SQL injection vulnerability in cms/index.pl in The Everything Development Engine in The Everything Development System Pr
23RIESGO
abrir
ReferênciaVexDay Proof
FSFDT v3.000 d9 - 'HELP' Remote Buffer Overflow
CVE-2007-5256remotewindows
Multiple stack-based buffer overflows in FSD 2.052 d9 and earlier, and FSFDT FSD 3.000 d9 and earlier, allow (1) remote
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component com_Marketplace 1.1.1 - SQL Injection
CVE-2008-0689webappsphp
SQL injection vulnerability in index.php in the Marketplace (com_marketplace) 1.1.1 and 1.1.1-pl1 component for Joomla!
23RIESGO
abrir
ReferênciaVexDay Proof
BookmarkX script 2007 - 'topicid' SQL Injection
CVE-2008-0695webappsphp
SQL injection vulnerability in index.php in BookmarkX script 2007 allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir
anteriorpágina 176 / 188siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.