Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
phpBB Links MOD 1.2.2 - SQL Injection
CVE-2007-4653webappsphp
SQL injection vulnerability in links.php in the Links MOD 1.2.2 and earlier for phpBB 2.0.22 and earlier allows remote a
23RIESGO
abrir
ReferênciaVexDay Proof
eNetman 20050830 - 'index.php' Remote File Inclusion
CVE-2007-4712webappsphp
PHP remote file inclusion vulnerability in index.php in eNetman 1 allows remote attackers to execute arbitrary PHP code
35RIESGO
abrir
ReferênciaVexDay Proof
Move Networks Quantum Streaming Player - Remote Overflow (SEH)
CVE-2007-4722remotewindows
Multiple stack-based buffer overflows in the Quantum Streaming Internet Explorer Player ActiveX control in qsp2ie0705100
28RIESGO
abrir
ReferênciaVexDay Proof
OtsTurntables 1.00 - '.m3u' Local Buffer Overflow
CVE-2007-4734localwindows
Buffer overflow in Ots Labs OTSTurntables 1.00 allows user-assisted remote attackers to execute arbitrary code via a lon
23RIESGO
abrir
ReferênciaVexDay Proof
phpRealty 0.02 - 'MGR' Multiple Remote File Inclusions
CVE-2007-4834webappsphp
Multiple PHP remote file inclusion vulnerabilities in phpRealty 0.02 allow remote attackers to execute arbitrary PHP cod
35RIESGO
abrir
ReferênciaVexDay Proof
RW::Download 2.0.3 lite - 'index.php?dlid' SQL Injection
CVE-2007-4845webappsphp
Multiple SQL injection vulnerabilities in UPLOAD/index.php in RW::Download 2.0.3 lite allow remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Visual Studio 6.0 - 'VBTOVSI.dll 1.0.0.0' File Overwrite
CVE-2007-4890remotewindows
Absolute directory traversal vulnerability in a certain ActiveX control in the VB To VSI Support Library (VBTOVSI.DLL) 1
28RIESGO
abrir
ReferênciaVexDay Proof
Streamline PHP Media Server 1.0-beta4 - Remote File Inclusion
CVE-2007-5015webappsphp
Multiple PHP remote file inclusion vulnerabilities in Streamline PHP Media Server 1.0-beta4 allow remote attackers to ex
35RIESGO
abrir
ReferênciaVexDay Proof
OneCMS 2.4 - 'abc' SQL Injection
CVE-2007-5016webappsphp
SQL injection vulnerability in userreviews.php in OneCMS 2.4 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
ReferênciaVexDay Proof
Airsensor M520 - HTTPd Remote Denial of Service / Buffer Overflow (PoC)
CVE-2007-5036doshardware
Multiple buffer overflows in the AirDefense Airsensor M520 with firmware 4.3.1.1 and 4.4.1.4 allow remote authenticated
23RIESGO
abrir
ReferênciaVexDay Proof
neuron news 1.0 - 'index.php?q' Local File Inclusion
CVE-2007-5050webappsphp
Directory traversal vulnerability in index.php in Neuron News 1.0 allows remote attackers to include and execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
PhFiTo 1.3.0 - 'SRC_PATH' Remote File Inclusion
CVE-2007-5157webappsphp
PHP remote file inclusion vulnerability in phfito-post.php in Alex Kocharin PHP Fidonet Tosser (PhFiTo) 1.3.0 in phpFido
23RIESGO
abrir
ReferênciaVexDay Proof
PHP Links 1.3 - 'id' SQL Injection
CVE-2008-0565webappsphp
SQL injection vulnerability in vote.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to execute arb
23RIESGO
abrir
ReferênciaVexDay Proof
FSFDT v3.000 d9 - 'HELP' Remote Buffer Overflow
CVE-2007-5256remotewindows
Multiple stack-based buffer overflows in FSD 2.052 d9 and earlier, and FSFDT FSD 3.000 d9 and earlier, allow (1) remote
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component com_Marketplace 1.1.1 - SQL Injection
CVE-2008-0689webappsphp
SQL injection vulnerability in index.php in the Marketplace (com_marketplace) 1.1.1 and 1.1.1-pl1 component for Joomla!
23RIESGO
abrir
ReferênciaVexDay Proof
BookmarkX script 2007 - 'topicid' SQL Injection
CVE-2008-0695webappsphp
SQL injection vulnerability in index.php in BookmarkX script 2007 allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir
ReferênciaVexDay Proof
ImageStation - 'SonyISUpload.cab 1.0.0.38' ActiveX Buffer Overflow (PoC)
CVE-2008-0748doswindows
Buffer overflow in the Sony AxRUploadServer.AxRUploadControl.1 ActiveX control in AxRUploadServer.dll 1.0.0.38 in SonyIS
28RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component MCQuiz 0.9 Final - 'tid' SQL Injection
CVE-2008-0800webappsphp
SQL injection vulnerability in index.php in the McQuiz (com_mcquiz) 0.9 Final component for Joomla! allows remote attack
23RIESGO
abrir
ReferênciaVexDay Proof
phpArcadeScript 3.0RC2 - 'userid' SQL Injection
CVE-2008-1163webappsphp
SQL injection vulnerability in index.php in phpArcadeScript 1.0 through 3.0 RC2 allows remote attackers to execute arbit
23RIESGO
abrir
ReferênciaVexDay Proof
1024 CMS 1.4.2 - Local File Inclusion / Blind SQL Injection
CVE-2008-1911webappsphp
SQL injection vulnerability in includes/system.php in 1024 CMS 1.4.2 beta and earlier, when magic_quotes_gpc is disabled
23RIESGO
abrir
ReferênciaVexDay Proof
Dream4 Koobi Pro 6.25 Poll - 'poll_id' SQL Injection
CVE-2008-2036webappsphp
SQL injection vulnerability in index.php in dream4 Koobi Pro 6.25 allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir
ReferênciaVexDay Proof
Smeego 1.0 - 'Cookie lang' Local File Inclusion
CVE-2008-2352webappsphp
Directory traversal vulnerability in index.php in Smeego 1.0, when magic_quotes_gpc is disabled, allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
Archangel Weblog 0.90.02 - 'post_id' SQL Injection
CVE-2008-2356webappsphp
SQL injection vulnerability in index.php in Archangel Weblog 0.90.02 and earlier allows remote attackers to execute arbi
23RIESGO
abrir
ReferênciaVexDay Proof
Flatnuke 3 - Remote Cookie Manipulation / Privilege Escalation
CVE-2007-5771webappsphp
Flatnuke 3 (aka FlatnuX) allows remote attackers to obtain administrative access via a myforum%00 cookie.
23RIESGO
abrir
ReferênciaVexDay Proof
Flatnuke 3 - Remote Command Execution / Privilege Escalation
CVE-2007-5773webappsphp
Cross-site request forgery (CSRF) vulnerability in index.php in the File Manager module in Flatnuke 3 allows remote atta
23RIESGO
abrir
ReferênciaVexDay Proof
ASPilot Pilot Cart 7.3 - 'article' SQL Injection
CVE-2008-2688webappsasp
SQL injection vulnerability in pilot.asp in ASPilot Pilot Cart 7.3 allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
ReferênciaVexDay Proof
Softbiz Link Directory Script - SQL Injection
CVE-2007-5996webappsphp
SQL injection vulnerability in searchresult.php in Softbiz Link Directory Script allows remote attackers to execute arbi
23RIESGO
abrir
ReferênciaVexDay Proof
ClipShare < 3.0.1 - 'tid' SQL Injection
CVE-2008-2793webappsphp
SQL injection vulnerability in group_posts.php in ClipShare before 3.0.1 allows remote attackers to execute arbitrary SQ
23RIESGO
abrir
ReferênciaVexDay Proof
doITlive CMS 2.50 - SQL Injection / Cross-Site Scripting
CVE-2008-2842webappsasp
Cross-site scripting (XSS) vulnerability in edit/showmedia.asp in doITLive CMS 2.50 and earlier allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
BoatScripts Classifieds - 'type' SQL Injection
CVE-2008-2846webappsphp
SQL injection vulnerability in index.php in BoatScripts Classifieds allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
anteriorpágina 177 / 188siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.