Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.386exploits catalogados
36.533CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
IMGallery 2.5 - Create Uploader Script
CVE-2007-0082webappsphp
users_adm/start1.php in IMGallery 2.5 and earlier does not properly handle files with multiple extensions, which allows
23RIESGO
abrir
ReferênciaVexDay Proof
VerliAdmin 0.3 - 'language.php' Local File Inclusion
CVE-2007-0098webappsphp
Directory traversal vulnerability in language.php in VerliAdmin 0.3 and earlier, when magic_quotes_gpc is disabled, allo
23RIESGO
abrir
ReferênciaVexDay Proof
OmniWeb 5.5.1 - JavaScript alert() Remote Format String (PoC)
CVE-2007-0148dososx
Format string vulnerability in OmniGroup OmniWeb 5.5.1 allows remote attackers to cause a denial of service (application
23RIESGO
abrir
ReferênciaVexDay Proof
AllMyVisitors 0.4.0 - 'index.php' Remote File Inclusion
CVE-2007-0170webappsphp
PHP remote file inclusion vulnerability in index.php in AllMyVisitors 0.4.0 allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
Mint Haber Sistemi 2.7 - 'duyuru.asp?id' SQL Injection
CVE-2007-0304webappsphp
SQL injection vulnerability in duyuru.asp in MiNT Haber Sistemi 2.7 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
ReferênciaVexDay Proof
Article System 0.1 - 'INCLUDE_DIR' Remote File Inclusion
CVE-2007-0314webappsphp
Multiple PHP remote file inclusion vulnerabilities in Article System 1.0 allow remote attackers to execute arbitrary PHP
23RIESGO
abrir
ReferênciaVexDay Proof
JV2 Folder Gallery 3.0 - 'download.php' Remote File Disclosure
CVE-2007-0329webappsphp
download.php in Joonas Viljanen JV2 Folder Gallery allows remote attackers to read sensitive files via a relative pathna
23RIESGO
abrir
ReferênciaVexDay Proof
BolinTech DreamFTP Server - 'USER' Remote Buffer Overflow (PoC)
CVE-2007-0338doswindows
Heap-based buffer overflow in Dream FTP Server allows remote attackers to execute arbitrary code via a USER command with
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Help Workshop 4.03.0002 - '.cnt' Local Buffer Overflow
CVE-2007-0352localwindows
Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitr
35RIESGO
abrir
ReferênciaVexDay Proof
Apple Mac OSX 10.4.8 - SLP Daemon Service Registration Buffer Overflow (PoC)
CVE-2007-0355dososx
Buffer overflow in the Apple Minimal SLP v2 Service Agent (slpd) in Mac OS X 10.4.11 and earlier, including 10.4.8, allo
23RIESGO
abrir
ReferênciaVexDay Proof
phpBP RC3 (2.204) - SQL Injection / Remote Code Execution
CVE-2007-0369webappsphp
SQL injection vulnerability in phpBP RC3 (2.204) and earlier allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
ReferênciaVexDay Proof
CascadianFAQ 4.1 - 'index.php' SQL Injection
CVE-2007-0631webappsphp
SQL injection vulnerability in index.php in Eclectic Designs CascadianFAQ 4.1 and earlier allows remote attackers to exe
23RIESGO
abrir
ReferênciaVexDay Proof
Galeria Zdjec 3.0 - 'zd_numer.php' Local File Inclusion
CVE-2007-0637webappsphp
Directory traversal vulnerability in zd_numer.php in Galeria Zdjec 3.0 and earlier allows remote attackers to include an
23RIESGO
abrir
ReferênciaVexDay Proof
GuppY 4.5.16 - Remote Command Execution
CVE-2007-0639webappsphp
Multiple static code injection vulnerabilities in error.php in GuppY 4.5.16 and earlier allow remote attackers to inject
23RIESGO
abrir
ReferênciaVexDay Proof
Dev-C++ 4.9.9.2 - '.CPP' File Parsing Local Stack Overflow (PoC)
CVE-2007-0643doswindows
Stack-based buffer overflow in Bloodshed Dev-C++ 4.9.9.2 allows user-assisted remote attackers to cause a denial of serv
23RIESGO
abrir
ReferênciaVexDay Proof
Hailboards 1.2.0 - 'phpbb_root_path' Remote File Inclusion
CVE-2007-0662webappsphp
PHP remote file inclusion vulnerability in includes/usercp_viewprofile.php in Hailboards 1.2.0 allows remote attackers t
23RIESGO
abrir
ReferênciaVexDay Proof
ExoPHPDesk 1.2.1 - 'faq.php' SQL Injection
CVE-2007-0676webappsphp
SQL injection vulnerability in faq.php in ExoPHPDesk 1.2.1 and earlier allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
Cadre PHP Framework - Remote File Inclusion
CVE-2007-0677webappsphp
PHP remote file inclusion vulnerability in fw/class.Quick_Config_Browser.php in Cadre PHP Framework 20020724 allows remo
23RIESGO
abrir
ReferênciaVexDay Proof
Fullaspsite Asp Hosting Sitesi - 'tr' SQL Injection
CVE-2007-0678webappsasp
SQL injection vulnerability in windows.asp in Fullaspsite Asp Hosting Sitesi allows remote attackers to execute arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
PHPMyRing 4.1.3b - 'fichier' Remote File Inclusion
CVE-2007-0679webappsphp
PHP remote file inclusion vulnerability in lang/leslangues.php in Nicolas Grandjean PHPMyRing 4.1.3b and earlier allows
23RIESGO
abrir
ReferênciaVexDay Proof
Chicken of the VNC 2.0 - 'NULL-pointer' Remote Denial of Service
CVE-2007-0756dososx
Chicken of the VNC (cotv) 2.0 allows remote attackers to cause a denial of service (application crash) via a large compu
23RIESGO
abrir
ReferênciaVexDay Proof
CoD2: DreamStats 4.2 - 'index.php' Remote File Inclusion
CVE-2007-0757webappsphp
PHP remote file inclusion vulnerability in index.php in Miguel Nunes Call of Duty 2 (CoD2) DreamStats System 4.2 and ear
23RIESGO
abrir
ReferênciaVexDay Proof
Flip 2.01 final - 'previewtheme.php?inc_path' Remote File Inclusion
CVE-2007-0785webappsphp
PHP remote file inclusion vulnerability in previewtheme.php in Flipsource Flip 2.01-final 1.0 and earlier allows remote
35RIESGO
abrir
ReferênciaVexDay Proof
Photo Galerie Standard 1.1 - 'view.php' SQL Injection
CVE-2007-0786webappsphp
SQL injection vulnerability in view.php in Noname Media Photo Galerie Standard 1.1.1 and earlier allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
SmartFTP Client 2.0.1002 - Remote Heap Overflow Denial of Service
CVE-2007-0790doswindows
Heap-based buffer overflow in SmartFTP 2.0.1002 allows remote FTP servers to execute arbitrary code via a large banner.
23RIESGO
abrir
ReferênciaVexDay Proof
SMA-DB 0.3.9 - 'settings.php' Remote File Inclusion
CVE-2007-0797webappsphp
PHP remote file inclusion vulnerability in theme/settings.php in bluevirus-design SMA-DB 0.3.9 and earlier allows remote
23RIESGO
abrir
ReferênciaVexDay Proof
Categories hierarchy phpBB Mod 2.1.2 - 'phpbb_root_path' Remote File Inclusion
CVE-2007-0809webappsphp
PHP remote file inclusion vulnerability in includes/class_template.php in Categories hierarchy (aka CH or mod-CH) 2.1.2
23RIESGO
abrir
ReferênciaVexDay Proof
LightRO CMS 1.0 - 'inhalt.php' Remote File Inclusion
CVE-2007-0824webappsphp
PHP remote file inclusion vulnerability in inhalt.php in LightRO CMS 1.0 allows remote attackers to execute arbitrary PH
23RIESGO
abrir
ReferênciaVexDay Proof
Kisisel Site 2007 - 'tr' SQL Injection
CVE-2007-0826webappsphp
SQL injection vulnerability in forum.asp in Kisisel Site 2007 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
Alibaba Alipay - Remove ActiveX Remote Code Execution
CVE-2007-0827remotewindows
The Alibaba Alipay PTA Module ActiveX control (PTA.DLL) allows remote attackers to execute arbitrary code via a JavaScri
23RIESGO
abrir
anteriorpágina 185 / 188siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.