Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
ClipShare < 3.0.1 - 'tid' SQL Injection
CVE-2008-2793webappsphp
SQL injection vulnerability in group_posts.php in ClipShare before 3.0.1 allows remote attackers to execute arbitrary SQ
23RIESGO
abrir
ReferênciaVexDay Proof
doITlive CMS 2.50 - SQL Injection / Cross-Site Scripting
CVE-2008-2842webappsasp
Cross-site scripting (XSS) vulnerability in edit/showmedia.asp in doITLive CMS 2.50 and earlier allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
BoatScripts Classifieds - 'type' SQL Injection
CVE-2008-2846webappsphp
SQL injection vulnerability in index.php in BoatScripts Classifieds allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
ReferênciaVexDay Proof
Debian OpenSSH - (Authenticated) Remote SELinux Privilege Escalation
CVE-2008-3234remotelinux
sshd in OpenSSH 4 on Debian GNU/Linux, and the 20070303 OpenSSH snapshot, allows remote authenticated users to obtain ac
23RIESGO
abrir
ReferênciaVexDay Proof
IAPR COMMENCE 1.3 - Multiple Remote File Inclusions
CVE-2007-6147webappsphp
Multiple PHP remote file inclusion vulnerabilities in IAPR COMMENCE 1.3 allow remote attackers to execute arbitrary PHP
23RIESGO
abrir
ReferênciaVexDay Proof
Arctic Issue Tracker 2.0.0 - 'filter' SQL Injection (2)
CVE-2008-3250webappsphp
SQL injection vulnerability in index.php in Arctic Issue Tracker 2.0.0 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
bilboblog 2.1 - Multiple Vulnerabilities
CVE-2008-3303webappsphp
admin/login.php in BilboBlog 0.2.1, when register_globals is enabled, allows remote attackers to bypass authentication a
23RIESGO
abrir
ReferênciaVexDay Proof
Eurologon CMS - Multiple SQL Injections
CVE-2007-6164webappsphp
Multiple SQL injection vulnerabilities in Eurologon CMS allow remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir
ReferênciaVexDay Proof
Apple QuickTime 7.2/7.3 - RTSP Response Remote Overwrite (SEH)
CVE-2007-6166dosmultiple
Stack-based buffer overflow in Apple QuickTime before 7.3.1, as used in QuickTime Player on Windows XP and Safari on Mac
50RIESGO
abrir
ReferênciaVexDay Proof
IP Reg 0.4 - Multiple SQL Injections
CVE-2008-4606webappsphp
Multiple SQL injection vulnerabilities in IP Reg 0.4 and earlier allow remote attackers to execute arbitrary SQL command
23RIESGO
abrir
ReferênciaVexDay Proof
Eurologon CMS - 'files.php' Arbitrary File Download
CVE-2007-6185webappsphp
Directory traversal vulnerability in users/files.php in Eurologon CMS allows remote attackers to read arbitrary files vi
23RIESGO
abrir
ReferênciaVexDay Proof
wPortfolio 0.3 - Admin Password Changing
CVE-2008-5221webappsphp
The account_save action in admin/userinfo.php in wPortfolio 0.3 and earlier does not require authentication and does not
23RIESGO
abrir
ReferênciaVexDay Proof
WebStudio eCatalogue - Blind SQL Injection
CVE-2008-5294webappsphp
SQL injection vulnerability in index.php in WebStudio eCatalogue allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
ReferênciaVexDay Proof
PG Real Estate - Authentication Bypass
CVE-2008-5306webappsphp
SQL injection vulnerability in admin/index.php in PG Real Estate Solution allows remote attackers to execute arbitrary S
23RIESGO
abrir
ReferênciaVexDay Proof
PHP-Fusion Mod TI - 'id' SQL Injection
CVE-2008-5733webappsphp
SQL injection vulnerability in blog.php in the Team Impact TI Blog System mod for PHP-Fusion allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
CzarNews 1.14 - 'tpath' Remote File Inclusion
CVE-2005-0859webappsphp
PHP remote file inclusion vulnerability in CzarNews 1.13b allows remote attackers to execute arbitrary PHP code via the
28RIESGO
abrir
ReferênciaVexDay Proof
CoolPlayer 2.19 - '.Skin' Local Buffer Overflow
CVE-2008-5735localwindows
Stack-based buffer overflow in skin.c in CoolPlayer 2.17 through 2.19 allows remote attackers to execute arbitrary code
23RIESGO
abrir
ReferênciaVexDay Proof
CoolPlayer 2.19 - '.Skin' Local Buffer Overflow
CVE-2008-5735localwindows
Stack-based buffer overflow in skin.c in CoolPlayer 2.17 through 2.19 allows remote attackers to execute arbitrary code
23RIESGO
abrir
ReferênciaVexDay Proof
TUTOS 1.3 - 'cmd.php' Remote Command Execution
CVE-2008-0149webappsphp
TUTOS 1.3 allows remote attackers to read system information via a direct request to php/admin/phpinfo.php, which calls
23RIESGO
abrir
ReferênciaVexDay Proof
FlexBB 0.6.3 - Cookies SQL Injection
CVE-2008-0157webappsphp
SQL injection vulnerability in FlexBB 0.6.3 and earlier allows remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir
ReferênciaVexDay Proof
Gateway Weblaunch - ActiveX Control Insecure Method
CVE-2008-0220remotewindows
Multiple stack-based buffer overflows in the WebLaunch.WeblaunchCtl.1 (aka CWebLaunchCtl) ActiveX control in weblaunch.o
28RIESGO
abrir
ReferênciaVexDay Proof
Gateway WebLaunch - ActiveX Remote Buffer Overflow
CVE-2008-0220remotewindows
Multiple stack-based buffer overflows in the WebLaunch.WeblaunchCtl.1 (aka CWebLaunchCtl) ActiveX control in weblaunch.o
28RIESGO
abrir
ReferênciaVexDay Proof
osData 2.08 Modules Php121 - Local File Inclusion
CVE-2008-0230webappsphp
PHP remote file inclusion vulnerability in php121db.php in osDate 2.0.8 and possibly earlier versions allows remote atta
23RIESGO
abrir
ReferênciaVexDay Proof
ZeroCMS 1.0 Alpha - Arbitrary File Upload / SQL Injection
CVE-2008-0232webappsphp
Multiple SQL injection vulnerabilities in Zero CMS 1.0 Alpha allow remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir
ReferênciaVexDay Proof
Agares phpAutoVideo 2.21 - 'articlecat' SQL Injection (2)
CVE-2008-0262webappsphp
SQL injection vulnerability in includes/articleblock.php in Agares PhpAutoVideo 2.21 allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
ImageAlbum 2.0.0b2 - 'id' SQL Injection
CVE-2008-0288webappsphp
Multiple SQL injection vulnerabilities in ImageAlbum 2.0.0b2 allow remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir
ReferênciaVexDay Proof
SCO UnixWare < 7.1.4 p534589 - 'pkgadd' Local Privilege Escalation
CVE-2008-0310localsco
Directory traversal vulnerability in pkgadd in SCO UnixWare 7.1.4 before p534589 allows local users to create or append
23RIESGO
abrir
ReferênciaVexDay Proof
Aria 0.99-6 - 'page' Local File Inclusion
CVE-2008-0332webappsphp
Directory traversal vulnerability in arias/help/effect.php in aria 0.99-6 allows remote attackers to include and execute
23RIESGO
abrir
ReferênciaVexDay Proof
PHPEcho CMS 2.0 - 'id' SQL Injection
CVE-2008-0355webappsphp
SQL injection vulnerability in index.php in the forum module in PHPEcho CMS, probably 2.0-rc3 and earlier, allows remote
23RIESGO
abrir
ReferênciaVexDay Proof
Small Axe 0.3.1 - 'cfile' Remote File Inclusion
CVE-2008-0376webappsphp
PHP remote file inclusion vulnerability in inc/linkbar.php in Small Axe Weblog 0.3.1 allows remote attackers to execute
35RIESGO
abrir
anteriorpágina 178 / 188siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.