Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
Joomla! Component ongumatimesheet20 4b - Remote File Inclusion
CVE-2008-6347webappsphp
PHP remote file inclusion vulnerability in lib/onguma.class.php in the Onguma Time Sheet (com_ongumatimesheet20) 2.0 4b
28RIESGO
abrir
ReferênciaVexDay Proof
DevelopItEasy Photo Gallery 1.2 - SQL Injection
CVE-2008-6348webappsphp
Multiple SQL injection vulnerabilities in DevelopItEasy Photo Gallery 1.2 allow remote attackers to execute arbitrary SQ
23RIESGO
abrir
ReferênciaVexDay Proof
BlogPHP 2 - 'id' Cross-Site Scripting / SQL Injection
CVE-2008-0678webappsphp
SQL injection vulnerability in index.php in BlogPHP 2.0 allows remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir
ReferênciaVexDay Proof
Black Ice Software Annotation Plugin - 'BiAnno.ocx' Remote Buffer Overflow
CVE-2008-2745remotewindows
Stack-based buffer overflow in BiAnno ActiveX Control (BiAnno.ocx) in Black Ice Software Annotation Plugin 10.95 allows
28RIESGO
abrir
ReferênciaVexDay Proof
BXCP 0.2.9.9 - 'tid' SQL Injection
CVE-2006-0821webappsphp
SQL injection vulnerability in index.php in BXCP 0.299 allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir
ReferênciaVexDay Proof
TurnkeyForms Business Survey Pro 1.0 - 'id' SQL Injection
CVE-2008-6349webappsphp
SQL injection vulnerability in survey_results_text.php in TurnkeyForms Business Survey Pro 1.0 allows remote attackers t
23RIESGO
abrir
ReferênciaVexDay Proof
Online Media Technologies 'AVSMJPEGFILE.DLL 1.1' - Remote Buffer Overflow (PoC)
CVE-2007-6327doswindows
Buffer overflow in a certain ActiveX control in Online Media Technologies AVSMJPEGFILE.DLL 1.1.1.102 allows remote attac
28RIESGO
abrir
ReferênciaVexDay Proof
ASP-CMS 1.0 - 'cha' SQL Injection
CVE-2008-6353webappsasp
SQL injection vulnerability in index.asp in ASP-CMS 1.0 allows remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir
ReferênciaVexDay Proof
MyCal Personal Events Calendar - Database Disclosure
CVE-2008-6357webappsasp
MyCal Personal Events Calendar stores sensitive information under the web root with insufficient access control, which a
23RIESGO
abrir
ReferênciaVexDay Proof
Social Groupie - 'id' SQL Injection
CVE-2008-6358webappsphp
SQL injection vulnerability in group_index.php in Social Groupie allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
ReferênciaVexDay Proof
Bytehoard 2.1 - 'server.php' Remote File Inclusion
CVE-2006-2849webappsphp
PHP remote file inclusion vulnerability in includes/webdav/server.php in Bytehoard 2.1 Epsilon/Delta allows remote attac
28RIESGO
abrir
ReferênciaVexDay Proof
DesignWorks Professional 4.3.1 - '.CCT' File Local Stack Buffer Overflow (PoC)
CVE-2008-6363doswindows
Stack-based buffer overflow in DesignWorks Professional 4.3.1 and 5.0.7 allows remote attackers to execute arbitrary cod
23RIESGO
abrir
ReferênciaVexDay Proof
Site@School 2.4.02 - Arbitrary File Upload
CVE-2006-4920webappsphp
Multiple PHP remote file inclusion vulnerabilities in Site@School (S@S) 2.4.02 and earlier allow remote attackers to exe
28RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component NeoReferences 1.3.1 - 'catid' SQL Injection
CVE-2008-0686webappsphp
SQL injection vulnerability in index.php in the NeoReferences (com_neoreferences) 1.3.1 and 1.3.3 component for Joomla!
23RIESGO
abrir
ReferênciaVexDay Proof
Ad Management Java - Authentication Bypass
CVE-2008-6365webappsasp
SQL injection vulnerability in logon.jsp in Ad Server Solutions Ad Management Software Java allows remote attackers to e
23RIESGO
abrir
ReferênciaVexDay Proof
ITechBids 5.0 - 'item_id' SQL Injection
CVE-2008-0692webappsphp
SQL injection vulnerability in bidhistory.php in iTechBids 3 Gold and 5.0 allows remote attackers to execute arbitrary S
23RIESGO
abrir
ReferênciaVexDay Proof
Affiliate Software Java 4.0 - Authentication Bypass
CVE-2008-6366webappsasp
SQL injection vulnerability in logon.jsp in Ad Server Solutions Affiliate Software Java 4.0 allows remote attackers to e
23RIESGO
abrir
ReferênciaVexDay Proof
Ocean12 Contact Manager Pro - SQL Injection / Cross-Site Scripting / File Disclosure
CVE-2008-6369webappsphp
SQL injection vulnerability in default.asp in Ocean12 Contact Manager Pro 1.02 allows remote attackers to execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
Codefixer MailingListPro - Database Disclosure
CVE-2008-6374webappsasp
CodefixerSoftware MailingListPro Free Edition stores sensitive information under the web root with insufficient access c
23RIESGO
abrir
ReferênciaVexDay Proof
Calendar MX Professional 2.0.0 - Blind SQL Injection
CVE-2008-6378webappsasp
SQL injection vulnerability in calendar_Eventupdate.asp in Calendar Mx Professional 2.0.0 allows remote attackers to exe
23RIESGO
abrir
ReferênciaVexDay Proof
CA BrightStor ARCserve 11.5.2.0 - 'catirpc.dll' RPC Server Denial of Service
CVE-2007-0816doswindows
The RPC Server service (catirpc.exe) in CA (formerly Computer Associates) BrightStor ARCserve Backup 11.5 SP2 and earlie
28RIESGO
abrir
ReferênciaVexDay Proof
Active Web Helpdesk 2 - 'categoryId' Blind SQL Injection
CVE-2008-6380webappsphp
SQL injection vulnerability in default.aspx in Active Web Helpdesk 2.0 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
CandyPress eCommerce suite 4.1.1.26 - Multiple Vulnerabilities
CVE-2008-0736webappsasp
admin/SA_shipFedExMeter.asp in CandyPress (CP) 4.1.1.26, and possibly other 4.x and 3.x versions, allows remote attacker
23RIESGO
abrir
ReferênciaVexDay Proof
Visual Events Calendar 1.1 - 'cfg_dir' Remote File Inclusion
CVE-2006-4060webappsphp
PHP remote file inclusion vulnerability in calendar.php in Visual Events Calendar 1.1 allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
Serv-U FTP Server 7.3 - (Authenticated) Remote FTP File Replacement
CVE-2008-4501remotewindows
Directory traversal vulnerability in the FTP server in Serv-U 7.0.0.1 through 7.3, including 7.2.0.1, allows remote auth
28RIESGO
abrir
ReferênciaVexDay Proof
CS-Cart 1.3.5 - Authentication Bypass
CVE-2008-6394webappsphp
SQL injection vulnerability in core/user.php in CS-Cart 1.3.5 and earlier allows remote attackers to execute arbitrary S
23RIESGO
abrir
ReferênciaVexDay Proof
Oreon 1.4 / Centreon 1.4.1 - Multiple Remote File Inclusion Vulnerabilities
CVE-2007-6485webappsphp
Multiple PHP remote file inclusion vulnerabilities in Centreon 1.4.1 (aka Oreon 1.4) allow remote attackers to execute a
28RIESGO
abrir
ReferênciaVexDay Proof
PowerNews 2.5.6 - Local File Inclusion
CVE-2008-0742webappsphp
Multiple directory traversal vulnerabilities in PowerScripts PowerNews 2.5.6 allow remote attackers to read and include
23RIESGO
abrir
ReferênciaVexDay Proof
Mambo Component com_gallery - SQL Injection
CVE-2008-0746webappsphp
SQL injection vulnerability in index.php in the Gallery (com_gallery) component for Mambo and Joomla! allows remote atta
23RIESGO
abrir
ReferênciaVexDay Proof
HotScripts Clone - 'cid' SQL Injection
CVE-2008-6405webappsphp
SQL injection vulnerability in showcategory.php in Hotscripts Clone allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.