Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
Free Arcade Script 1.0 - Local File Inclusion Command Execution
CVE-2009-0731webappsphp
Directory traversal vulnerability in pages/play.php in Free Arcade Script 1.0 allows remote attackers to include and exe
23RIESGO
abrir
ReferênciaVexDay Proof
Article Directory - 'index.php' Remote File Inclusion
CVE-2007-4007webappsphp
PHP remote file inclusion vulnerability in index.php in Article Directory (Article Site Directory) allows remote attacke
23RIESGO
abrir
ReferênciaVexDay Proof
Axigen 5.0.2 - AXIMilter Remote Format String
CVE-2008-0434remotelinux
Format string vulnerability in the AXIMilter module in AXIGEN Mail Server 5.0.2 allows remote attackers to execute arbit
28RIESGO
abrir
ReferênciaVexDay Proof
AuthPhp 1.0 - Authentication Bypass
CVE-2009-0738webappsphp
SQL injection vulnerability in login.php in Auth Php 1.0 allows remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir
ReferênciaVexDay Proof
Yaws < 1.80 - Multiple Headers Remote Denial of Service Vulnerabilities
CVE-2009-0751dosmultiple
Yaws before 1.80 allows remote attackers to cause a denial of service (memory consumption and crash) via a request with
28RIESGO
abrir
ReferênciaVexDay Proof
TR Forum 2.0 - SQL Injection / Bypass Security Restriction
CVE-2006-4584webappsphp
Tr Forum 2.0 allows remote attackers to bypass authentication and add an administrative account via the login and passwo
23RIESGO
abrir
ReferênciaVexDay Proof
IntelliTamper 2.07 - 'imgsrc' Remote Buffer Overflow
CVE-2008-3583remotewindows
Buffer overflow in the HTML parser in IntelliTamper 2.07 allows remote attackers to execute arbitrary code via a long UR
23RIESGO
abrir
ReferênciaVexDay Proof
WikkiTikkiTavi 1.11 - Arbitrary '.PHP' File Upload
CVE-2009-0602webappsphp
Unrestricted file upload vulnerability in upload.php in WikkiTikkiTavi 1.11 allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
MLdonkey 2.9.7 - Arbitrary File Disclosure
CVE-2009-0753remotemultiple
Absolute path traversal vulnerability in MLDonkey 2.8.4 through 2.9.7 allows remote attackers to read arbitrary files vi
23RIESGO
abrir
ReferênciaVexDay Proof
YapBB 1.2 - 'forumID' Blind SQL Injection
CVE-2009-0768webappsphp
SQL injection vulnerability in forumhop.php in YapBB 1.2 and earlier allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir
ReferênciaVexDay Proof
webSPELL 4.2.0e - 'page' Blind SQL Injection
CVE-2009-1912webappsphp
Directory traversal vulnerability in src/func/language.php in webSPELL 4.2.0e and earlier allows remote attackers to inc
23RIESGO
abrir
ReferênciaVexDay Proof
PHPBasket - 'pro_id' SQL Injection
CVE-2008-3713webappsphp
SQL injection vulnerability in product.php in PHPBasket allows remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir
ReferênciaVexDay Proof
Dyncms Release 6 - 'x_admindir' Remote File Inclusion
CVE-2006-4589webappsphp
PHP remote file inclusion vulnerability in 0_admin/modules/Wochenkarte/frontend/index.php in DynCMS 6 and earlier allows
23RIESGO
abrir
ReferênciaVexDay Proof
Hex Workshop 6.0 - '.hex' Local Code Execution
CVE-2009-0812localwindows
Stack-based buffer overflow in BreakPoint Software Hex Workshop 4.23, 6.0.1.4603, and other 6.x and earlier versions all
23RIESGO
abrir
ReferênciaVexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
CVE-2007-6500webappsasp
Unspecified vulnerability in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to delete
23RIESGO
abrir
ReferênciaVexDay Proof
5 star review - Cross-Site Scripting / SQL Injection
CVE-2008-3779webappsphp
Cross-site scripting (XSS) vulnerability in search/index.php in Five Star Review Script allows remote attackers to injec
23RIESGO
abrir
ReferênciaVexDay Proof
Sponge News 2.2 - 'sndir' Remote File Inclusion
CVE-2006-4647webappsphp
PHP remote file inclusion vulnerability in news.php in Sponge News 2.2 and earlier allows remote attackers to execute ar
23RIESGO
abrir
ReferênciaVexDay Proof
K&S Shopsysteme - Arbitrary File Upload
CVE-2008-6768webappsphp
Unrestricted file upload vulnerability in admin/editor/images.php in K&S Shopsoftware allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
Ext 1.0 - 'feed-proxy.php?feed' Remote File Disclosure
CVE-2007-2285webappsphp
Directory traversal vulnerability in examples/layout/feed-proxy.php in Jack Slocum Ext 1.0 alpha1 (Ext JS) allows remote
28RIESGO
abrir
ReferênciaVexDay Proof
SyndeoCMS 2.5.01 - 'cmsdir' Remote File Inclusion
CVE-2007-5840webappsphp
PHP remote file inclusion vulnerability in starnet/themes/c-sky/main.inc.php in Fred Stuurman SyndeoCMS 2.5.01 allows re
23RIESGO
abrir
ReferênciaVexDay Proof
jspwiki 2.4.104/2.5.139 - Multiple Vulnerabilities
CVE-2008-1230webappsjsp
Unrestricted file upload vulnerability in JSPWiki 2.4.104 and 2.5.139 allows remote attackers to upload and execute arbi
23RIESGO
abrir
ReferênciaVexDay Proof
Maran PHP Forum - 'forum_write.php' Remote Code Execution
CVE-2007-2182webappsphp
Unrestricted file upload vulnerability in forum_write.php in Maran PHP Forum allows remote attackers to upload and execu
23RIESGO
abrir
ReferênciaVexDay Proof
ACG-PTP 1.0.6 - 'adid' SQL Injection
CVE-2008-3944webappsphp
SQL injection vulnerability in index.php in ACG-PTP 1.0.6 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
ReferênciaVexDay Proof
Zenturi NixonMyPrograms Class 'sasatl.dll 1.5.0.531' - Remote Buffer Overflow
CVE-2007-3984remotewindows
Buffer overflow in a certain ActiveX control in the NixonMyPrograms class in sasatl.dll 1.5.0.531 in Zenturi ProgramChec
23RIESGO
abrir
ReferênciaVexDay Proof
Drupal 5.2 - PHP Zend Hash ation Vector
CVE-2007-5416webappsphp
Drupal 5.2 and earlier does not properly unset variables when the input data includes a numeric parameter with a value m
23RIESGO
abrir
ReferênciaVexDay Proof
Musoo 0.21 - Remote File Inclusion
CVE-2007-3297webappsphp
Multiple PHP remote file inclusion vulnerabilities in Musoo 0.21 allow remote attackers to execute arbitrary PHP code vi
23RIESGO
abrir
ReferênciaVexDay Proof
IBM Director 5.20.3su2 CIM Server - Remote Denial of Service
CVE-2009-0879doswindows
The CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows remote attackers to cause a denial of se
23RIESGO
abrir
ReferênciaVexDay Proof
PrecisionID Barcode ActiveX 1.9 - Arbitrary File Overwrite
CVE-2007-2755remotewindows
The PrecisionID Barcode 1.9 ActiveX control in PrecisionID_Barcode.dll, when Internet Explorer 6 is used, allows remote
23RIESGO
abrir
ReferênciaVexDay Proof
Ocean FTP Server 1.00 - Denial of Service
CVE-2005-0847doswindows
Code Ocean FTP server 1.0 allows remote attackers to cause a denial of service via a large number of connections.
23RIESGO
abrir
ReferênciaVexDay Proof
MG-SOFT Net Inspector 6.5.0.828 - Multiple Vulnerabilities
CVE-2008-1401remotewindows
Format string vulnerability in the Net Inspector HTTP server (mghttpd) in MG-SOFT Net Inspector 6.5.0.828 and earlier fo
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.