Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
CMS NetCat 3.0/3.12 - Blind SQL Injection
CVE-2008-6853webappsphp
SQL injection vulnerability in modules/poll/index.php in AIST NetCat 3.0 and 3.12 allows remote attackers to execute arb
23RIESGO
abrir
ReferênciaVexDay Proof
WordPress Core 2.2 - 'xmlrpc.php' SQL Injection
CVE-2007-3140webappsphp
SQL injection vulnerability in xmlrpc.php in WordPress 2.2 allows remote authenticated users to execute arbitrary SQL co
23RIESGO
abrir
ReferênciaVexDay Proof
Jasmine CMS 1.0 - SQL Injection / Remote Code Execution
CVE-2007-3312webappsphp
Directory traversal vulnerability in admin/plugin_manager.php in Jasmine CMS 1.0 allows remote authenticated administrat
23RIESGO
abrir
ReferênciaVexDay Proof
ChartDirector 4.1 - 'viewsource.php' File Disclosure
CVE-2008-1782webappsphp
phpdemo/viewsource.php in Advanced Software Engineering ChartDirector 4.1 allows remote attackers to read sensitive file
23RIESGO
abrir
ReferênciaVexDay Proof
Ourgame GLWorld 2.x - 'hgs_startNotify()' ActiveX Buffer Overflow
CVE-2008-0647remotewindows
Multiple stack-based buffer overflows in the HanGamePluginCn18.HanGamePluginCn18.1 ActiveX control in HanGamePluginCn18.
23RIESGO
abrir
ReferênciaVexDay Proof
Absolute News Feed 1.0 - Remote Insecure Cookie Handling
CVE-2008-6855webappsphp
Xigla Software Absolute News Feed 1.0 and possibly 1.5 allows remote attackers to bypass authentication and gain adminis
23RIESGO
abrir
ReferênciaVexDay Proof
DS-IPN.NET Digital Sales IPN - Database Disclosure
CVE-2009-0328webappsasp
ROBS-PROJECTS Digital Sales IPN (aka DS-IPN.NET or DS-IPN Paypal Shop) stores sensitive information under the web root w
23RIESGO
abrir
ReferênciaVexDay Proof
Faq Administrator 2.1 - 'faq_reply.php' Remote File Inclusion
CVE-2006-5637webappsphp
PHP remote file inclusion vulnerability in faq_reply.php in Faq Administrator 2.1b allows remote attackers to execute ar
23RIESGO
abrir
ReferênciaVexDay Proof
Prozilla Top 100 1.2 - Arbitrary Delete Stats
CVE-2008-1785webappsphp
delete.php in Prozilla Top 100 1.2 allows remote authenticated users to delete statistics and accounts of arbitrary user
23RIESGO
abrir
ReferênciaVexDay Proof
Entertainment Directory 1.1 - SQL Injection
CVE-2008-1788webappsphp
SQL injection vulnerability in directory.php in Prozilla Entertainers 1.1 and earlier allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
Absolute News Manager 5.1 - Insecure Cookie Handling
CVE-2008-6856webappsphp
Xigla Software Absolute News Manager.NET 5.1 allows remote attackers to bypass authentication and gain administrative ac
23RIESGO
abrir
ReferênciaVexDay Proof
Absolute Podcast 1.0 - Remote Insecure Cookie Handling
CVE-2008-6857webappsphp
Absolute Podcast .NET 1.0 allows remote attackers to bypass authentication and gain administrative access by setting a c
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component Restaurante - Arbitrary File Upload
CVE-2007-4817webappsphp
Unrestricted file upload vulnerability in the Restaurante (com_restaurante) component for Joomla! allows remote attacker
23RIESGO
abrir
ReferênciaVexDay Proof
JBC Explorer 7.20 RC 1 - Remote Code Execution
CVE-2007-5913webappsphp
dirsys/modules/auth.php in JBC Explorer 7.20 RC1 and earlier does not require authentication, which allows remote attack
23RIESGO
abrir
ReferênciaVexDay Proof
My Gaming Ladder 7.5 - 'ladderid' SQL Injection
CVE-2008-1791webappsphp
SQL injection vulnerability in ladder.php in My Gaming Ladder 7.5 and earlier allows remote attackers to execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
Absolute Poll Manager XE 4.1 - Insecure Cookie Handling
CVE-2008-6860webappsphp
Xigla Software Absolute Poll Manager XE 4.1 allows remote attackers to bypass authentication and gain administrative acc
23RIESGO
abrir
ReferênciaVexDay Proof
VMware 'IntraProcessLogging.dll' 5.5.3.42958 - Arbitrary Data Write
CVE-2007-4059remotewindows
Absolute path traversal vulnerability in a certain ActiveX control in IntraProcessLogging.dll 5.5.3.42958 in EMC VMware
23RIESGO
abrir
ReferênciaVexDay Proof
Simple HTTPd 1.41 - '/aux' Remote Denial of Service
CVE-2007-6326doswindows
Sergey Lyubka Simple HTTPD (shttpd) 1.3 on Windows allows remote attackers to cause a denial of service via a request th
23RIESGO
abrir
ReferênciaVexDay Proof
Absolute NewsLetter 6.1 - Insecure Cookie Handling
CVE-2008-6861webappsphp
Xigla Software Absolute Newsletter 6.0 and 6.1 allows remote attackers to bypass authentication and gain administrative
23RIESGO
abrir
ReferênciaVexDay Proof
PPStream - 'PowerPlayer.dll 2.0.1.3829' ActiveX Remote Overflow
CVE-2007-4748remotewindows
Buffer overflow in the PowerPlayer.dll ActiveX control in PPStream 2.0.1.3829 allows remote attackers to execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
Dragoon 0.1 - 'lng' Local File Inclusion
CVE-2008-1798webappsphp
Directory traversal vulnerability in forum/kietu/libs/calendrier.php in Dragoon 0.1 allows remote attackers to include a
23RIESGO
abrir
ReferênciaVexDay Proof
Absolute Content Rotator 6.0 - Insecure Cookie Handling
CVE-2008-6862webappsphp
Absolute Content Rotator 6.0 allows remote attackers to bypass authentication and gain administrative access by setting
23RIESGO
abrir
ReferênciaVexDay Proof
rdesktop 1.5.0 - 'iso_recv_msg()' Integer Underflow (PoC)
CVE-2008-1801doslinux
Integer underflow in the iso_recv_msg function (iso.c) in rdesktop 1.5.0 allows remote attackers to cause a denial of se
28RIESGO
abrir
ReferênciaVexDay Proof
ASPReferral 5.3 - 'AccountID' Blind SQL Injection
CVE-2008-6889webappsasp
SQL injection vulnerability in Merchantsadd.asp in ASPReferral 5.3 allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
ReferênciaVexDay Proof
μTorrent (uTorrent) / BitTorrent WebIU HTTP 1.7.7/6.0.1 - Range header Denial of Service
CVE-2008-0071doswindows
The Web UI interface in (1) BitTorrent before 6.0.3 build 8642 and (2) uTorrent before 1.8beta build 10524 allows remote
23RIESGO
abrir
ReferênciaVexDay Proof
SasCam WebCam Server 2.6.5 - ActiveX Remote Buffer Overflow
CVE-2008-6898remotewindows
Buffer overflow in the XHTTP Module 4.1.0.0 in the ActiveX control for SaschArt SasCam Webcam Server 2.6.5 allows remote
50RIESGO
abrir
ReferênciaVexDay Proof
WordPress Core 2.1.2 - 'xmlrpc' SQL Injection
CVE-2007-1897webappsphp
SQL injection vulnerability in xmlrpc (xmlrpc.php) in WordPress 2.1.2, and probably earlier, allows remote authenticated
23RIESGO
abrir
ReferênciaVexDay Proof
AvailScript Article Script - Arbitrary File Upload
CVE-2008-6900webappsphp
Unrestricted file upload vulnerability in "Add Pen/Author Name" feature in addpen.php in AvailScript Article Script allo
23RIESGO
abrir
ReferênciaVexDay Proof
2532/Gigs 1.2.2 Stable - Multiple Vulnerabilities
CVE-2008-6902webappsphp
Unrestricted file upload vulnerability in upload_flyer.php in 2532designs 2532|Gigs 1.2.2 Stable allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
WengoPhone 2.x - SIP Phone Remote Denial of Service
CVE-2007-4366doswindows
WengoPhone 2.1 allows remote attackers to cause a denial of service (device crash) via a SIP INVITE message without a Co
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.