Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
HydraIrc 0.3.164 - Remote Denial of Service
CVE-2008-3578doswindows
HydraIRC 0.3.164 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and applicat
23RIESGO
abrir
ReferênciaVexDay Proof
BabbleBoard 1.1.6 - Cross-Site Request Forgery/Cookie Grabber
CVE-2008-6905webappsphp
Cross-site request forgery (CSRF) vulnerability in index.php in BabbleBoard 1.1.6 allows remote authenticated users to h
23RIESGO
abrir
ReferênciaVexDay Proof
Quantum Game Library 0.7.2c - Remote File Inclusion
CVE-2008-1069webappsphp
Multiple PHP remote file inclusion vulnerabilities in Quantum Game Library 0.7.2c allow remote attackers to execute arbi
28RIESGO
abrir
ReferênciaVexDay Proof
zeeproperty 1.0 - Arbitrary File Upload / Cross-Site Scripting
CVE-2008-6915webappsphp
Cross-site scripting (XSS) vulnerability in view_prop_details.php in Zeeways ZEEPROPERTY 1.0 allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
SpeedStream 5200 - Authentication Bypass Configuration Download
CVE-2008-6916remotehardware
Siemens SpeedStream 5200 with NetPort Software 1.1 allows remote attackers to bypass authentication via an invalid Host
23RIESGO
abrir
ReferênciaVexDay Proof
cPanel 11.x - Cross-Site Scripting / Local File Inclusion
CVE-2008-6927webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in autoinstall4imagesgalleryupgrade.php in the Fantastico De Luxe Mo
23RIESGO
abrir
ReferênciaVexDay Proof
Service Provider Management System v1.0 - SQL Injection
CVE-2023-34581webappsphp
Sourcecodester Service Provider Management System v1.0 is vulnerable to SQL Injection via the ID parameter in /php-spms/
23RIESGO
abrir
ReferênciaVexDay Proof
PHPStore Car Dealers - Arbitrary File Upload
CVE-2008-6929webappsphp
Unrestricted file upload vulnerability in PHPStore Auto Classifieds allows remote authenticated users to execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
PHPStore Real Estate - Arbitrary File Upload
CVE-2008-6930webappsphp
Unrestricted file upload vulnerability in PHPStore Real Estate allows remote authenticated users to execute arbitrary co
23RIESGO
abrir
ReferênciaVexDay Proof
PHPStore PHP Job Search Script - Arbitrary File Upload
CVE-2008-6931webappsphp
Unrestricted file upload vulnerability in PHPStore Job Search (aka PHPCareers) allows remote authenticated users to exec
23RIESGO
abrir
ReferênciaVexDay Proof
PHPAddressBook 2.11 - 'view.php' SQL Injection
CVE-2008-1847webappsphp
SQL injection vulnerability in view.php in CoronaMatrix phpAddressBook 2.11 allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
RealPlayer 10 - '.ra' Remote Denial of Service
CVE-2007-2497doswindows
RealNetworks RealPlayer 10 Gold allows remote attackers to cause a denial of service (memory consumption) via a certain
23RIESGO
abrir
ReferênciaVexDay Proof
PHP Multiple Newsletters 2.7 - Local File Inclusion / Cross-Site Scripting
CVE-2008-5566webappsphp
Cross-site scripting (XSS) vulnerability in index.php in Triangle Solutions PHP Multiple Newsletters 2.7 allows remote a
23RIESGO
abrir
ReferênciaVexDay Proof
WordPress Plugin E-Commerce 3.4 - Arbitrary File Upload
CVE-2008-6811webappsphp
Unrestricted file upload vulnerability in image_processing.php in the e-Commerce Plugin 3.4 and earlier for Wordpress al
23RIESGO
abrir
ReferênciaVexDay Proof
Alstrasoft SendIt Pro - Arbitrary File Upload
CVE-2008-6932webappsphp
Unrestricted file upload vulnerability in submit_file.php in AlstraSoft SendIt Pro allows remote attackers to execute ar
23RIESGO
abrir
ReferênciaVexDay Proof
eZip Wizard 3.0 - Local Stack Buffer Overflow (PoC) (SEH)
CVE-2009-1057doswindows
MicroSmarts Enterprise ZipItFast! 3.0 allows remote attackers to execute arbitrary code via a crafted .zip file that tri
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component JoomlaXplorer 1.6.2 - Remote s
CVE-2008-1849webappsphp
Directory traversal vulnerability in index.php in the joomlaXplorer (com_joomlaxplorer) Mambo/Joomla! component 1.6.2 an
23RIESGO
abrir
ReferênciaVexDay Proof
Exodus 0.10 - URI Handler Arbitrary Parameter Injection (1)
CVE-2008-6935remotewindows
Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, over
23RIESGO
abrir
ReferênciaVexDay Proof
ASPPortal 3.1.1 - 'downloadid' SQL Injection
CVE-2006-1353webappsasp
Multiple SQL injection vulnerabilities in ASPPortal 3.1.1 and earlier allow remote attackers to execute arbitrary SQL co
23RIESGO
abrir
ReferênciaVexDay Proof
Exodus 0.10 - URI Handler Arbitrary Parameter Injection (2)
CVE-2008-6935remotewindows
Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, over
23RIESGO
abrir
ReferênciaVexDay Proof
ViArt CMS/Shop/Helpdesk 3.3.2 - Remote File Inclusion
CVE-2007-6347webappsphp
PHP remote file inclusion vulnerability in blocks/block_site_map.php in ViArt (1) CMS 3.3.2, (2) HelpDesk 3.3.2, (3) Sho
23RIESGO
abrir
ReferênciaVexDay Proof
Mcafee EPO 4.0 - 'FrameworkService.exe' Remote Denial of Service
CVE-2008-1855doswindows
FrameworkService.exe in McAfee Common Management Agent (CMA) 3.6.0.574 Patch 3 and earlier, as used by ePolicy Orchestra
23RIESGO
abrir
ReferênciaVexDay Proof
BS.Player 2.27 Build 959 - '.srt' File Buffer Overflow (PoC)
CVE-2008-6583doswindows
Buffer overflow in BS.player 2.27 build 959 allows remote attackers to cause a denial of service (crash) and possibly ex
23RIESGO
abrir
ReferênciaVexDay Proof
RGameScript Pro - 'page.php?id' Remote File Inclusion
CVE-2007-3980webappsphp
PHP remote file inclusion vulnerability in page.php in RCMS Pro RGameScript Pro allows remote attackers to execute arbit
23RIESGO
abrir
ReferênciaVexDay Proof
Pi3Web 2.0.3 - 'ISAPI' Remote Denial of Service
CVE-2008-6938doswindows
Pi3Web 2.0.3 before PL2, when installed on Windows as a desktop application and without using the Pi3Web/Conf/Intenet.pi
43RIESGO
abrir
ReferênciaVexDay Proof
EasyMail MessagePrinter Object - 'emprint.dll 6.0.1.0' Remote Buffer Overflow
CVE-2007-5070remotewindows
Heap-based buffer overflow in the EasyMailMessagePrinter ActiveX control in emprint.DLL 6.0.1.0 in the Quiksoft EasyMail
23RIESGO
abrir
ReferênciaVexDay Proof
ChilkatHttp ActiveX 2.3 - Arbitrary Files Overwrite
CVE-2008-1647remotewindows
The ChilkatHttp.ChilkatHttp.1 and ChilkatHttp.ChilkatHttpRequest.1 ActiveX controls in ChilkatHttp.dll 2.4.0.0, 2.3.0.0,
23RIESGO
abrir
ReferênciaVexDay Proof
UeberProject 1.0 - '/login/secure.php' Remote File Inclusion
CVE-2006-5539webappsphp
PHP remote file inclusion vulnerability in login/secure.php in UeberProject Management System 1.0 and earlier allows rem
23RIESGO
abrir
ReferênciaVexDay Proof
ScriptsFeed (SF) Real Estate Classifieds Software - Arbitrary File Upload
CVE-2008-6942webappsphp
Unrestricted file upload vulnerability in ScriptsFeed Realtor Classifieds System (aka Real Estate Classifieds) allows re
23RIESGO
abrir
ReferênciaVexDay Proof
ScriptsFeed (SF) Auto Classifieds Software - Arbitrary File Upload
CVE-2008-6944webappsphp
Unrestricted file upload vulnerability in ScriptsFeed Auto Classifieds allows remote authenticated users to execute arbi
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.