Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.607exploits catalogados
34.986CVEs con explotación pública
24.695probados en laboratorio
21.899 exploits
Referência
CVE-2010-0380
install.php in JCE-Tech PHP Calendars, downloaded 20100121, allows remote attackers to bypass intended access restrictio
23RIESGO
abrir
ReferênciaVexDay Proof
LiveAlbum 0.9.0 - 'common.php' Remote File Inclusion
CVE-2007-5315webappsphp
PHP remote file inclusion vulnerability in common.php in LiveAlbum 0.9.0, when register_globals is enabled, allows remot
35RIESGO
abrir
ReferênciaVexDay Proof
Ubuntu 6.06 - DHCPd Remote Denial of Service
CVE-2007-5365dosmultiple
Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some othe
45RIESGO
abrir
ReferênciaVexDay Proof
LightBlog 8.4.1.1 - Remote Code Execution
CVE-2007-5374webappsphp
cp_memberedit.php in LightBlog 8.4.1.1 does not check for administrative credentials when processing an admin action, wh
23RIESGO
abrir
ReferênciaVexDay Proof
Pindorama 0.1 - 'client.php' Remote File Inclusion
CVE-2007-5387webappsphp
PHP remote file inclusion vulnerability in active/components/xmlrpc/client.php in Pindorama 0.1 allows remote attackers
28RIESGO
abrir
Referência
CVE-2022-35914
CVE-2022-35914CRITICALbajo ataque
/vendor/htmlawed/htmlawed/htmLawedTest.php in the htmlawed module for GLPI through 10.0.2 allows PHP code injection.
100RIESGO
abrir
Referência
CVE-2020-1472
CVE-2020-1472MEDIUMbajo ataqueransomware
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
Referência
CVE-2020-1472
CVE-2020-1472MEDIUMbajo ataqueransomware
Netlogon Elevation of Privilege Vulnerability
100RIESGO
abrir
ReferênciaVexDay Proof
phpBB Garage 1.2.0 Beta3 - SQL Injection
CVE-2007-6223webappsphp
SQL injection vulnerability in garage.php in phpBB Garage 1.2.0 Beta3 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
ReferênciaVexDay Proof
Rayzz Script 2.0 - Local/Remote File Inclusion
CVE-2007-6229webappsphp
PHP remote file inclusion vulnerability in common/classes/class_HeaderHandler.lib.php in Rayzz Script 2.0 allows remote
23RIESGO
abrir
ReferênciaVexDay Proof
tellmatic 1.0.7 - Multiple Remote File Inclusions
CVE-2007-6231webappsphp
Multiple PHP remote file inclusion vulnerabilities in tellmatic 1.0.7 allow remote attackers to execute arbitrary PHP co
23RIESGO
abrir
ReferênciaVexDay Proof
ftp Admin 0.1.0 - Local File Inclusion / Cross-Site Scripting / Authentication Bypass
CVE-2007-6232webappsphp
Cross-site scripting (XSS) vulnerability in index.php in FTP Admin 0.1.0 allows remote attackers to inject arbitrary web
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Windows Media Player - '.AIFF' Divide By Zero Exception Denial of Service (PoC)
CVE-2007-6236doswindows
Microsoft Windows Media Player (WMP) allows remote attackers to cause a denial of service (application crash) via a cert
28RIESGO
abrir
ReferênciaVexDay Proof
Snitz Forums 2000 - 'Active.asp' SQL Injection
CVE-2007-6240webappsasp
SQL injection vulnerability in active.asp in Snitz Forums 2000 3.4.06 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
ReferênciaVexDay Proof
HP Compaq Notebooks - ActiveX Remote Code Execution
CVE-2007-6333remotewindows
The HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 i
23RIESGO
abrir
ReferênciaVexDay Proof
SineCMS 2.3.4 - Calendar SQL Injection
CVE-2007-6366webappsphp
Multiple SQL injection vulnerabilities in SineCMS 2.3.4 and earlier allow remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
ReferênciaVexDay Proof
WordPress Plugin PictPress 0.91 - Remote File Disclosure
CVE-2007-6369webappsphp
Multiple directory traversal vulnerabilities in resize.php in the PictPress 0.91 and earlier plugin for WordPress allow
23RIESGO
abrir
ReferênciaVexDay Proof
BadBlue 2.72 - PassThru Remote Buffer Overflow
CVE-2007-6377remotewindows
Stack-based buffer overflow in the PassThru functionality in ext.dll in BadBlue 2.72b and earlier allows remote attacker
50RIESGO
abrir
ReferênciaVexDay Proof
Adult Script 1.6 - Unauthorized Administrative Access
CVE-2007-6414webappsphp
admin/administrator.php in Adult Script 1.6 and earlier sends a redirect to the web browser but does not exit, which all
23RIESGO
abrir
ReferênciaVexDay Proof
FreeWebShop 2.2.1 - Blind SQL Injection
CVE-2007-6466webappsphp
Multiple SQL injection vulnerabilities in index.php in FreeWebshop 2.2.1 allow remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
MOG-WebShop - 'index.php?group' SQL Injection
CVE-2007-6466webappsphp
Multiple SQL injection vulnerabilities in index.php in FreeWebshop 2.2.1 allow remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
gf-3xplorer 2.4 - Cross-Site Scripting / Local File Inclusion
CVE-2007-6476webappsphp
GF-3XPLORER 2.4 allows remote attackers to obtain configuration information via a direct request to explorer/phpinfo.php
23RIESGO
abrir
ReferênciaVexDay Proof
falcon CMS 1.4.3 - Remote File Inclusion / Cross-Site Scripting
CVE-2007-6490webappsphp
Cross-site request forgery (CSRF) vulnerability in Falcon Series One CMS 1.4.3 allows remote attackers to change a passw
23RIESGO
abrir
ReferênciaVexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
CVE-2007-6496webappsasp
Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote attackers to register arbitrary users via a request to host
23RIESGO
abrir
ReferênciaVexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
CVE-2007-6503webappsasp
Multiple unspecified vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and earlier allow remote authenticated users
23RIESGO
abrir
ReferênciaVexDay Proof
HP Software Update Client 3.0.8.4 - Multiple Vulnerabilities
CVE-2007-6506doswindows
The HPRulesEngine.ContentCollection.1 ActiveX Control in RulesEngine.dll for HP Software Update 4.000.005.007 and earlie
28RIESGO
abrir
Referência
CVE-2007-6515
support/dispatch.cgi in SiteScape Forum allows remote attackers to execute arbitrary TCL code via code separator charact
23RIESGO
abrir
ReferênciaVexDay Proof
RunCMS 1.6 - Multiple Vulnerabilities
CVE-2007-6547webappsphp
RunCMS before 1.6.1 does not require entry of the old password during a password change, which allows context-dependent
23RIESGO
abrir
ReferênciaVexDay Proof
LoudBlog 0.6.1 - 'parsedpage' Remote Code Execution
CVE-2008-0139webappsphp
Eval injection vulnerability in loudblog/inc/parse_old.php in Loudblog 0.8.0 and earlier allows remote attackers to exec
28RIESGO
abrir
Referência
CVE-2010-0607
Cross-site scripting (XSS) vulnerability in Forms/status_statistics_1 in the Sterlite SAM300 AX Router allows remote att
23RIESGO
abrir
anteriorpágina 368 / 730siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.