Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
Joomla! Component custompages 1.1 - Remote File Inclusion
CVE-2008-1505webappsphp
PHP remote file inclusion vulnerability in the SSTREAMTV custompages (com_custompages) 1.1 and earlier component for Joo
35RIESGO
abrir
ReferênciaVexDay Proof
Danneo CMS 0.5.1 - Blind SQL Injection
CVE-2008-1513webappsphp
SQL injection vulnerability in index.php in Danneo CMS 0.5.1 and earlier, when the Referers statistics option is enabled
23RIESGO
abrir
ReferênciaVexDay Proof
PHP-Nuke Platinum 7.6.b.5 - 'dynamic_titles.php' SQL Injection
CVE-2008-1539webappsphp
SQL injection vulnerability in includes/dynamic_titles.php in PHP-Nuke Platinum 7.6.b.5 allows remote attackers to execu
23RIESGO
abrir
ReferênciaVexDay Proof
RunCMS Module Photo 3.02 - 'cid' SQL Injection
CVE-2008-1551webappsphp
SQL injection vulnerability in viewcat.php in the Photo 3.02 module for RunCMS allows remote attackers to execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
Uploader & Downloader 3.0 - 'id_user' SQL Injection
CVE-2006-6716webappsphp
SQL injection vulnerability in administration/administre2.php in Eric GUILLAUME uploader&downloader 3 allows remote atta
23RIESGO
abrir
ReferênciaVexDay Proof
Bandwebsite 1.5 - 'LOGIN' Remote Add Admin
CVE-2006-6722webappsphp
Bandwebsite (aka Bandsite portal system) 1.5 allows remote attackers to create administrative accounts via a direct requ
23RIESGO
abrir
ReferênciaVexDay Proof
TopperMod 2.0 - SQL Injection
CVE-2008-1554webappsphp
SQL injection vulnerability in account/index.php in TopperMod 2.0, when magic_quotes_gpc is disabled, allows remote atta
23RIESGO
abrir
ReferênciaVexDay Proof
MPlayer 1.0 rc2 - 'sdpplin_parse()' Array Indexing Buffer Overflow (PoC)
CVE-2008-1558doslinux
Uncontrolled array index in the sdpplin_parse function in stream/realrtsp/sdpplin.c in MPlayer 1.0 rc2 allows remote att
28RIESGO
abrir
ReferênciaVexDay Proof
Netartmedia Jobs Portal 1.3 - Multiple SQL Injections
CVE-2008-6030webappsphp
Multiple SQL injection vulnerabilities in NetArtMedia Jobs Portal 1.3 allow remote attackers to execute arbitrary SQL co
23RIESGO
abrir
ReferênciaVexDay Proof
WSN Links 2.22/2.23 - 'vote.php' SQL Injection
CVE-2008-6031webappsphp
SQL injection vulnerability in vote.php in WSN Links 2.22 and 2.23 allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component Alphacontent 2.5.8 - 'id' SQL Injection
CVE-2008-1559webappsphp
SQL injection vulnerability in the Bernard Gilly AlphaContent (com_alphacontent) 2.5.8 component for Joomla! allows remo
23RIESGO
abrir
ReferênciaVexDay Proof
PostNuke 0.764 - Blind SQL Injection
CVE-2008-1591webappsphp
The pnVarPrepForStore function in PostNuke 0.764 and earlier skips input sanitization when magic_quotes_runtime is enabl
23RIESGO
abrir
ReferênciaVexDay Proof
Quick TFTP Server Pro 2.1 - Remote Overflow (SEH)
CVE-2008-1610remotewindows
Stack-based buffer overflow in TallSoft Quick TFTP Server Pro 2.1 allows remote attackers to cause a denial of service o
50RIESGO
abrir
ReferênciaVexDay Proof
TFTP Server 1.4 - ST Buffer Overflow
CVE-2008-1611remotewindows
Stack-based buffer overflow in TFTP Server SP 1.4 for Windows allows remote attackers to cause a denial of service or ex
50RIESGO
abrir
ReferênciaVexDay Proof
Smoothflash - 'cid' SQL Injection
CVE-2008-1623webappsphp
SQL injection vulnerability in admin_view_image.php in Smoothflash allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
ReferênciaVexDay Proof
LoudBlog 0.8.0a - 'ajax.php' SQL Injection
CVE-2008-6077webappsphp
SQL injection vulnerability in loudblog/ajax.php in LoudBlog 0.8.0a and earlier allows remote authenticated users to exe
23RIESGO
abrir
ReferênciaVexDay Proof
KISGB (tmp_theme) 5.1.1 - Local File Inclusion
CVE-2008-1635webappsphp
Directory traversal vulnerability in view_private.php in Keep It Simple Guest Book (KISGB) 5.0.0 and earlier allows remo
23RIESGO
abrir
ReferênciaVexDay Proof
EasyNews 40tr - SQL Injection / Cross-Site Scripting / Local File Inclusion
CVE-2008-1650webappsphp
SQL injection vulnerability in dynamicpages/index.php in EasyNews 4.0 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
ReferênciaVexDay Proof
PHP-Nuke Platinum 7.6.b.5 - 'dynamic_titles.php' SQL Injection
CVE-2008-1680webappsphp
PHP-Nuke Platinum 7.6.b.5 allows remote attackers to obtain configuration information via a direct request to maintenanc
23RIESGO
abrir
ReferênciaVexDay Proof
Redaxo 3.2 - 'INCLUDE_PATH' Remote File Inclusion
CVE-2006-2844webappsphp
Multiple PHP remote file inclusion vulnerabilities in Redaxo 3.0 allow remote attackers to execute arbitrary PHP code vi
23RIESGO
abrir
ReferênciaVexDay Proof
HP OpenView Network Node Manager (OV NNM) 7.5.1 - 'OVAS.exe' Overflow (SEH)
CVE-2008-1697remotewindows
Stack-based buffer overflow in ovwparser.dll in HP OpenView Network Node Manager (OV NNM) 7.53, 7.51, and earlier allows
60RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Visual InterDev 6.0 SP6 - '.sln' Local Buffer Overflow (PoC)
CVE-2008-1709doswindows
Buffer overflow in Microsoft Visual InterDev 6.0 (SP6) allows user-assisted attackers to execute arbitrary code via a St
28RIESGO
abrir
ReferênciaVexDay Proof
FaScript FaPhoto 1.0 - 'show.php' SQL Injection
CVE-2008-1714webappsphp
SQL injection vulnerability in show.php in FaScript FaPhoto 1.0, when magic_quotes_gpc is disabled, allows remote attack
23RIESGO
abrir
ReferênciaVexDay Proof
KnowledgeQuest 2.6 - SQL Injection
CVE-2008-1726webappsphp
Multiple SQL injection vulnerabilities in KnowledgeQuest 2.6, when magic_quotes_gpc is disabled, allow remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
Titan FTP Server 6.26 build 630 - Remote Denial of Service
CVE-2008-6082doswindows
Titan FTP Server 6.26 build 630 allows remote attackers to cause a denial of service (CPU consumption) via the SITE WHO
50RIESGO
abrir
ReferênciaVexDay Proof
Limbo CMS Module event 1.0 - Remote File Inclusion
CVE-2006-6800webappsphp
PHP remote file inclusion in eventcal/mod_eventcal.php in the event module 1.0 for Limbo CMS allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
Back-End CMS 0.7.2.2 - 'BE_config.php' Remote File Inclusion
CVE-2006-2682webappsphp
PHP remote file inclusion vulnerability in BE_config.php in Back-End CMS 0.7.2.1 and earlier allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
Informium 0.12.0 - 'common-menu.php' Remote File Inclusion
CVE-2006-2818webappsphp
PHP remote file inclusion vulnerability in common-menu.php in Cameron McKay Informium 0.12.0 allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
Prediction Football 1.x - 'matchid' SQL Injection
CVE-2008-1732webappsphp
SQL injection vulnerability in showpredictionsformatch.php in Prediction Football 1.x allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
LiveCart 1.1.1 - 'id' Blind SQL Injection
CVE-2008-1750webappsphp
SQL injection vulnerability in Integry Systems LiveCart 1.1.1 and earlier allows remote attackers to execute arbitrary S
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.