Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
DM Guestbook 0.4.1 - Multiple Local File Inclusions
CVE-2007-5821webappsphp
Multiple directory traversal vulnerabilities in DM Guestbook 0.4.1 and earlier allow remote attackers to include and exe
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component com_school 1.4 - 'classid' SQL Injection
CVE-2009-2014webappsphp
SQL injection vulnerability in the ComSchool (com_school) component 1.4 for Joomla! allows remote attackers to execute a
23RIESGO
abrir
ReferênciaVexDay Proof
nuBoard 0.5 - 'site' Remote File Inclusion
CVE-2007-5841webappsphp
PHP remote file inclusion vulnerability in admin/index.php in nuBoard 0.5 allows remote attackers to execute arbitrary P
35RIESGO
abrir
ReferênciaVexDay Proof
Cold BBS - Remote Database Disclosure
CVE-2008-5597webappsasp
Cold BBS stores sensitive information under the web root with insufficient access control, which allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
NCTAudioStudio2 - ActiveX DLL 2.6.1.148 'CreateFile()'/ Insecure Method
CVE-2007-3493remotewindows
A certain ActiveX control in NCTWavChunksEditor2.dll 2.6.1.148 in NCTAudioStudio (NCTAudioStudio2) 2.7, as used by Sienz
35RIESGO
abrir
ReferênciaVexDay Proof
ASPTicker 1.0 - Remote Database Disclosure
CVE-2008-5603webappsasp
ASPTicker 1.0 stores sensitive information under the web root with insufficient access control, which allows remote atta
23RIESGO
abrir
ReferênciaVexDay Proof
My Simple Forum 3.0 - Local File Inclusion
CVE-2008-5604webappsphp
Directory traversal vulnerability in index.php in My Simple Forum 3.0 and 4.1, when magic_quotes_gpc is disabled, allows
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component com_colorlab 1.0 - Remote File Inclusion
CVE-2007-5451webappsphp
PHP remote file inclusion vulnerability in admin.color.php in the com_colorlab (aka com_color) 1.0 component for Joomla!
35RIESGO
abrir
ReferênciaVexDay Proof
MyCars Automotive - Authentication Bypass
CVE-2009-2018webappsphp
SQL injection vulnerability in admin/index.php in Jared Eckersley MyCars, when magic_quotes_gpc is disabled, allows remo
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component JMovies 1.1 - 'id' SQL Injection
CVE-2008-5607webappsphp
SQL injection vulnerability in the JMovies (aka JM or com_jmovies) component 1.1 for Joomla! allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
ASP AutoDealer - Remote Database Disclosure
CVE-2008-5608webappsasp
ASP AutoDealer stores sensitive information under the web root with insufficient access control, which allows remote att
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Visual Studio 6.0 - 'PDWizard.ocx' Remote Command Execution
CVE-2007-4891remotewindows
A certain ActiveX control in PDWizard.ocx 6.0.0.9782 and earlier in Microsoft Visual Studio 6.0 exposes dangerous (1) St
35RIESGO
abrir
ReferênciaVexDay Proof
GuppY 4.6.3 - 'index.php?selskin' Remote File Inclusion
CVE-2007-5844webappsphp
Directory traversal vulnerability in inc/includes.inc in GuppY 4.6.3 allows remote attackers to include and execute arbi
23RIESGO
abrir
ReferênciaVexDay Proof
ASP AutoDealer - SQL Injection / File Disclosure
CVE-2008-5608webappsasp
ASP AutoDealer stores sensitive information under the web root with insufficient access control, which allows remote att
23RIESGO
abrir
ReferênciaVexDay Proof
XOOPS Module XT-Conteudo - 'spaw_root' Remote File Inclusion
CVE-2007-3221webappsphp
PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the XT-Conteudo module for XOOPS allows
35RIESGO
abrir
ReferênciaVexDay Proof
WholeHogSoftware Ware Support - Insecure Cookie Handling
CVE-2009-0460webappsphp
Whole Hog Ware Support 1.x allows remote attackers to bypass authentication and obtain administrative access via an inte
23RIESGO
abrir
ReferênciaVexDay Proof
PHP::HTML 0.6.4 - 'PHPhtml.php' Remote File Inclusion
CVE-2007-3230webappsphp
PHP remote file inclusion vulnerability in phphtml.php in Idan Sofer PHP::HTML 0.6.4 allows remote attackers to execute
35RIESGO
abrir
ReferênciaVexDay Proof
virtue news - SQL Injection / Cross-Site Scripting
CVE-2009-2020webappsphp
Cross-site scripting (XSS) vulnerability in news_detail.php in Virtue News Manager allows remote attackers to inject arb
23RIESGO
abrir
ReferênciaVexDay Proof
GuppY 4.5.16 - Remote Command Execution
CVE-2007-5845webappsphp
Directory traversal vulnerability in error.php in GuppY 4.6.3, 4.5.16, and earlier allows remote attackers to include an
23RIESGO
abrir
ReferênciaVexDay Proof
Fuzzylime Forum 1.0 - 'low.php?topic' SQL Injection
CVE-2007-3235webappsphp
Cross-site scripting (XSS) vulnerability in low.php in Fuzzylime Forum 1.0 allows remote attackers to inject arbitrary w
23RIESGO
abrir
ReferênciaVexDay Proof
XOOPS Module horoscope 2.0 - Remote File Inclusion
CVE-2007-3236webappsphp
PHP remote file inclusion vulnerability in footer.php in the Horoscope 1.0 module for XOOPS allows remote attackers to e
45RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Windows Mobile 6.0 - Device Long Name Remote Reboot (Denial of Service)
CVE-2008-4295doshardware
Microsoft Windows Mobile 6.0 on HTC Wiza 200 and HTC MDA 8125 devices does not properly handle the first attempt to esta
35RIESGO
abrir
ReferênciaVexDay Proof
Profense Web Application Firewall 2.6.2 - Cross-Site Request Forgery / Cross-Site Scripting
CVE-2009-0467remotewindows
Cross-site scripting (XSS) vulnerability in proxy.html in Profense Web Application Firewall 2.6.2 and 2.6.3 allows remot
23RIESGO
abrir
ReferênciaVexDay Proof
xoops module tinycontent 1.5 - Remote File Inclusion
CVE-2007-3237webappsphp
PHP remote file inclusion vulnerability in admin/spaw/spaw_control.class.php in the TinyContent 1.5 module for XOOPS all
35RIESGO
abrir
ReferênciaVexDay Proof
tbdev 01-01-2008 - Multiple Vulnerabilities
CVE-2009-2138webappsphp
Multiple open redirect vulnerabilities in TBDev.NET 01-01-08 allow remote attackers to redirect users to arbitrary web s
23RIESGO
abrir
ReferênciaVexDay Proof
Roundcube Webmail 0.2-3 Beta - Code Execution
CVE-2008-5619webappsphp
html2text.php in Chuggnutt HTML to Text Converter, as used in PHPMailer before 5.2.10, RoundCube Webmail (roundcubemail)
35RIESGO
abrir
ReferênciaVexDay Proof
XM Easy Personal FTP Server 5.6.0 - Remote Denial of Service
CVE-2008-5626doswindows
XM Easy Personal FTP Server 5.6.0 allows remote authenticated users to cause a denial of service via a crafted argument
50RIESGO
abrir
ReferênciaVexDay Proof
PHPMyInventory 2.8 - 'global.inc.php' Remote File Inclusion
CVE-2007-3270webappsphp
PHP remote file inclusion vulnerability in Includes/global.inc.php in phpMyInventory 2.8 allows remote attackers to exec
23RIESGO
abrir
ReferênciaVexDay Proof
campus virtual-lms - Cross-Site Scripting / SQL Injection
CVE-2009-2150webappsphp
Multiple cross-site request forgery (CSRF) vulnerabilities in Campus Virtual-LMS allow (1) remote attackers to hijack th
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component flash fun! 1.0 - Remote File Inclusion
CVE-2007-4955webappsphp
PHP remote file inclusion vulnerability in admin.joomlaflashfun.php in the Flash Fun! (com_joomlaflashfun) 1.0 component
28RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.