Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
Check Point Firewall-1 - PKI Web Service HTTP Header Remote Overflow
CVE-2009-1227doshardware
NOTE: this issue has been disputed by the vendor. Buffer overflow in the PKI Web Service in Check Point Firewall-1 PKI
23RIESGO
abrir
ReferênciaVexDay Proof
Arcadwy Arcade Script - 'Username' Static Cross-Site Scripting
CVE-2009-1228webappsphp
Cross-site scripting (XSS) vulnerability in register.php in Arcadwy Arcade Script CMS allows remote attackers to inject
23RIESGO
abrir
ReferênciaVexDay Proof
Ventrilo 3.0.2 - Null Pointer Remote Denial of Service
CVE-2008-3680dosmultiple
The decryption function in Flagship Industries Ventrilo 3.0.2 and earlier allows remote attackers to cause a denial of s
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Visual Studio - 'Msmask32.ocx' ActiveX Remote Buffer Overflow (PoC)
CVE-2008-3704doswindows
Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions befo
50RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Visual Studio - 'Msmask32.ocx' ActiveX Remote Buffer Overflow
CVE-2008-3704remotewindows
Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions befo
50RIESGO
abrir
ReferênciaVexDay Proof
isiAJAX 1 - 'praises.php?id' SQL Injection
CVE-2009-0881webappsphp
SQL injection vulnerability in ejemplo/paises.php in isiAJAX 1 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
Mozilla Firefox 3.0.x - XML Parser Memory Corruption / Denial of Service (PoC)
CVE-2009-1232doswindows
Mozilla Firefox 3.0.8 and earlier 3.0.x versions allows remote attackers to cause a denial of service (memory corruption
23RIESGO
abrir
ReferênciaVexDay Proof
Zeeways ZeeJobsite 2.0 - 'adid' SQL Injection
CVE-2008-3706webappsphp
SQL injection vulnerability in bannerclick.php in ZEEJOBSITE 2.0 allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
ReferênciaVexDay Proof
phpTrafficA 1.4.2 - 'pageid' SQL Injection
CVE-2007-3426webappsphp
Cross-site scripting (XSS) vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to inject
23RIESGO
abrir
ReferênciaVexDay Proof
phpArcadeScript 4 - 'cat' SQL Injection
CVE-2008-3711webappsphp
SQL injection vulnerability in index.php in PHPArcadeScript (PHP Arcade Script) 4.0 allows remote attackers to execute a
23RIESGO
abrir
ReferênciaVexDay Proof
cyberBB 0.6 - Multiple SQL Injections
CVE-2008-3718webappsphp
Multiple SQL injection vulnerabilities in cyberBB 0.6 allow remote authenticated users to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
Gravity GTD 0.4.5 - Local File Inclusion / Remote Code Execution
CVE-2008-5962webappsphp
Directory traversal vulnerability in library/setup/rpc.php in Gravity Getting Things Done (GTD) 0.4.5 and earlier allows
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component com_bookJoomlas 0.1 - SQL Injection
CVE-2009-1263webappsphp
SQL injection vulnerability in sub_commententry.php in the BookJoomlas (com_bookjoomlas) component 0.1 for Joomla! allow
23RIESGO
abrir
ReferênciaVexDay Proof
Affiliate Directory - 'id' SQL Injection
CVE-2008-3719webappsphp
SQL injection vulnerability in directory.php in SFS Affiliate Directory allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
EternalMart Guestbook 1.10 - '/admin/auth.php' Remote File Inclusion
CVE-2003-1314webappsphp
PHP remote file inclusion vulnerability in admin/auth.php in EternalMart Guestbook (EMGB) 1.1 allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
Ad Board - 'id' SQL Injection
CVE-2008-3725webappsphp
SQL injection vulnerability in trr.php in YourFreeWorld Ad Board Script allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
phpTrafficA 1.4.2 - 'pageid' SQL Injection
CVE-2007-3427webappsphp
SQL injection vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to execute arbitrary S
23RIESGO
abrir
ReferênciaVexDay Proof
Gravity Board X 2.0 Beta - SQL Injection / (Authenticated) Code Execution
CVE-2009-1277webappsphp
SQL injection vulnerability in index.php in Gravity Board X (GBX) 2.0 BETA allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
Active PHP BookMarks 1.1.02 - SQL Injection
CVE-2008-3748webappsphp
SQL injection vulnerability in view_group.php in Active PHP Bookmarks (APB) 1.1.02 and 1.2.06 allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
YourFreeWorld Classifieds - 'category' SQL Injection
CVE-2008-3755webappsphp
SQL injection vulnerability in view.php in YourFreeWorld Classifieds Script allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
YourFreeWorld Viral Marketing - SQL Injection
CVE-2008-3756webappsphp
SQL injection vulnerability in tr.php in YourFreeWorld Viral Marketing Script allows remote attackers to execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
VMware Workstation 6.5.1 - 'hcmon.sys 6.0.0.45731' Local Denial of Service
CVE-2008-3761doswindows
hcmon.sys in VMware Workstation 6.5.1 and earlier, VMware Player 2.5.1 and earlier, VMware ACE 2.5.1 and earlier, and VM
23RIESGO
abrir
ReferênciaVexDay Proof
PHP Live Helper 2.0.1 - Multiple Vulnerabilities
CVE-2008-3762webappsphp
SQL injection vulnerability in onlinestatus_html.php in Turnkey PHP Live Helper 2.0.1 and earlier allows remote attacker
23RIESGO
abrir
ReferênciaVexDay Proof
Quick Poll Script - 'id' SQL Injection
CVE-2008-3765webappsphp
SQL injection vulnerability in code.php in Quick Poll Script allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
ReferênciaVexDay Proof
SunShop Shopping Cart 4.1.4 - 'id' SQL Injection
CVE-2008-3768webappsphp
Multiple SQL injection vulnerabilities in class.ajax.php in Turnkey Web Tools SunShop Shopping Cart before 4.1.5 allow r
23RIESGO
abrir
ReferênciaVexDay Proof
Pars4U Videosharing 1.0 - Cross-Site Scripting / Blind SQL Injection
CVE-2008-3772webappsphp
SQL injection vulnerability in categories_portal.php in Pars4u Videosharing 1 allows remote attackers to execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
SuperCali PHP Event Calendar 0.4.0 - SQL Injection
CVE-2007-3582webappsphp
SQL injection vulnerability in index.php in SuperCali PHP Event Calendar 0.4.0 allows remote attackers to execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
Easy RM to MP3 Converter - Universal Stack Overflow
CVE-2009-1330localwindows
Stack-based buffer overflow in Easy RM to MP3 Converter allows remote attackers to execute arbitrary code via a long fil
28RIESGO
abrir
ReferênciaVexDay Proof
5 star review - Cross-Site Scripting / SQL Injection
CVE-2008-3780webappsphp
SQL injection vulnerability in recommend.php in Five Star Review Script allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
Matterdaddy Market 1.1 - 'index.php' Multiple SQL Injections
CVE-2008-3783webappsphp
Multiple SQL injection vulnerabilities in index.php in Matterdaddy Market 1.1, when magic_quotes_gpc is disabled, allow
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.