Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
PHP-Fusion Mod Members CV (job) 1.0 - SQL Injection
CVE-2009-0831webappsphp
SQL injection vulnerability in members.php in the Members CV (job) module 1.0 for PHP-Fusion, when magic_quotes_gpc is d
23RIESGO
abrir
ReferênciaVexDay Proof
PHP-Fusion Mod E-Cart 1.3 - 'items.php' SQL Injection
CVE-2009-0832webappsphp
SQL injection vulnerability in items.php in the E-Cart module 1.3 for PHP-Fusion allows remote attackers to execute arbi
23RIESGO
abrir
ReferênciaVexDay Proof
K&S Shopsysteme - Arbitrary File Upload
CVE-2008-6768webappsphp
Unrestricted file upload vulnerability in admin/editor/images.php in K&S Shopsoftware allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
Ext 1.0 - 'feed-proxy.php?feed' Remote File Disclosure
CVE-2007-2285webappsphp
Directory traversal vulnerability in examples/layout/feed-proxy.php in Jack Slocum Ext 1.0 alpha1 (Ext JS) allows remote
28RIESGO
abrir
ReferênciaVexDay Proof
SyndeoCMS 2.5.01 - 'cmsdir' Remote File Inclusion
CVE-2007-5840webappsphp
PHP remote file inclusion vulnerability in starnet/themes/c-sky/main.inc.php in Fred Stuurman SyndeoCMS 2.5.01 allows re
23RIESGO
abrir
ReferênciaVexDay Proof
jspwiki 2.4.104/2.5.139 - Multiple Vulnerabilities
CVE-2008-1230webappsjsp
Unrestricted file upload vulnerability in JSPWiki 2.4.104 and 2.5.139 allows remote attackers to upload and execute arbi
23RIESGO
abrir
ReferênciaVexDay Proof
Maran PHP Forum - 'forum_write.php' Remote Code Execution
CVE-2007-2182webappsphp
Unrestricted file upload vulnerability in forum_write.php in Maran PHP Forum allows remote attackers to upload and execu
23RIESGO
abrir
ReferênciaVexDay Proof
ACG-PTP 1.0.6 - 'adid' SQL Injection
CVE-2008-3944webappsphp
SQL injection vulnerability in index.php in ACG-PTP 1.0.6 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
ReferênciaVexDay Proof
Zenturi NixonMyPrograms Class 'sasatl.dll 1.5.0.531' - Remote Buffer Overflow
CVE-2007-3984remotewindows
Buffer overflow in a certain ActiveX control in the NixonMyPrograms class in sasatl.dll 1.5.0.531 in Zenturi ProgramChec
23RIESGO
abrir
ReferênciaVexDay Proof
Drupal 5.2 - PHP Zend Hash ation Vector
CVE-2007-5416webappsphp
Drupal 5.2 and earlier does not properly unset variables when the input data includes a numeric parameter with a value m
23RIESGO
abrir
ReferênciaVexDay Proof
S-CMS 1.1 Stable - Insecure Cookie Handling / Mass Page Delete
CVE-2009-0864webappsphp
S-Cms 1.1 Stable allows remote attackers to bypass authentication and obtain administrative access via an OK value for t
23RIESGO
abrir
ReferênciaVexDay Proof
GeoVision LiveX 8200 - ActiveX 'LIVEX_~1.OCX' File Corruption
CVE-2009-0865remotewindows
Directory traversal vulnerability in the SnapShotToFile method in the GeoVision LiveX (aka LiveX_v8200) ActiveX control
23RIESGO
abrir
ReferênciaVexDay Proof
pHNews Alpha 1 - 'genbackup.php' Database Disclosure
CVE-2009-0866webappsphp
pHNews Alpha 1 stores sensitive information under the web root with insufficient access control, which allows remote att
23RIESGO
abrir
ReferênciaVexDay Proof
Trawler Web CMS 1.8.1 - Multiple Remote File Inclusions
CVE-2006-5495webappsphp
Multiple PHP remote file inclusion vulnerabilities in Trawler Web CMS 1.8.1 and earlier allow remote attackers to execut
23RIESGO
abrir
ReferênciaVexDay Proof
ID Automation Linear Barcode - ActiveX Denial of Service
CVE-2007-2658doswindows
Unspecified vulnerability in the ID Automation Linear Barcode 1.6.0.5 ActiveX control in IDAutomationLinear6.dll allows
23RIESGO
abrir
ReferênciaVexDay Proof
Musoo 0.21 - Remote File Inclusion
CVE-2007-3297webappsphp
Multiple PHP remote file inclusion vulnerabilities in Musoo 0.21 allow remote attackers to execute arbitrary PHP code vi
23RIESGO
abrir
ReferênciaVexDay Proof
IBM Director 5.20.3su2 CIM Server - Remote Denial of Service
CVE-2009-0879doswindows
The CIM server in IBM Director before 5.20.3 Service Update 2 on Windows allows remote attackers to cause a denial of se
23RIESGO
abrir
ReferênciaVexDay Proof
PrecisionID Barcode ActiveX 1.9 - Arbitrary File Overwrite
CVE-2007-2755remotewindows
The PrecisionID Barcode 1.9 ActiveX control in PrecisionID_Barcode.dll, when Internet Explorer 6 is used, allows remote
23RIESGO
abrir
ReferênciaVexDay Proof
NEPT Image Uploader 1.0 - Arbitrary File Upload
CVE-2008-6822webappsphp
Unrestricted file upload vulnerability in uploadp.php in New Earth Programming Team (NEPT) imgupload (aka Image Uploader
23RIESGO
abrir
ReferênciaVexDay Proof
PA168 Chipset IP Phones - Weak Session Management
CVE-2007-0528remotehardware
The admin web console implemented by the Centrality Communications (aka Aredfox) PA168 chipset and firmware 1.54 and ear
23RIESGO
abrir
ReferênciaVexDay Proof
Remote Display Dev kit 1.2.1.0 - 'RControl.dll' Denial of Service
CVE-2007-2623doswindows
Multiple buffer overflows in RControl.dll in Remote Display Dev kit 1.2.1.0 allow remote attackers to cause a denial of
23RIESGO
abrir
ReferênciaVexDay Proof
Blue Eye CMS 1.0.0 - Remote Cookie SQL Injection
CVE-2009-0883webappsphp
SQL injection vulnerability in Blue Eye CMS 1.0.0 and earlier, when magic_quotes_gpc is disabled, allows remote attacker
23RIESGO
abrir
ReferênciaVexDay Proof
PHP recommend 1.3 - Authentication Bypass / Remote File Inclusion / Code Injection
CVE-2009-1781webappsphp
Static code injection vulnerability in admin.php in Frax.dk Php Recommend 1.3 and earlier allows remote attackers to inj
23RIESGO
abrir
ReferênciaVexDay Proof
Ocean FTP Server 1.00 - Denial of Service
CVE-2005-0847doswindows
Code Ocean FTP server 1.0 allows remote attackers to cause a denial of service via a large number of connections.
23RIESGO
abrir
ReferênciaVexDay Proof
MG-SOFT Net Inspector 6.5.0.828 - Multiple Vulnerabilities
CVE-2008-1401remotewindows
Format string vulnerability in the Net Inspector HTTP server (mghttpd) in MG-SOFT Net Inspector 6.5.0.828 and earlier fo
23RIESGO
abrir
ReferênciaVexDay Proof
WordPress Plugin Spreadsheet 0.6 - SQL Injection
CVE-2008-1982webappsphp
SQL injection vulnerability in ss_load.php in the Spreadsheet (wpSS) 0.6 and earlier plugin for WordPress allows remote
23RIESGO
abrir
ReferênciaVexDay Proof
RSS-aggregator - 'path' Remote File Inclusion
CVE-2008-2884webappsphp
PHP remote file inclusion vulnerability in display.php in RSS-aggregator allows remote attackers to execute arbitrary PH
23RIESGO
abrir
ReferênciaVexDay Proof
phpCC 4.2 Beta - 'base_dir' Remote File Inclusion
CVE-2006-4073webappsphp
Multiple PHP remote file inclusion vulnerabilities in Fabian Hainz phpCC Beta 4.2 allow remote attackers to execute arbi
23RIESGO
abrir
ReferênciaVexDay Proof
Cisco Router - HTTP Administration Cross-Site Request Forgery / Command Execution (1)
CVE-2008-4128MEDIUMbajo ataqueremotehardware
Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the
75RIESGO
abrir
ReferênciaVexDay Proof
MyPHPcommander 2.0 - 'package.php' Remote File Inclusion
CVE-2007-0568webappsphp
PHP remote file inclusion vulnerability in system/lib/package.php in MyPHPCommander 2.0 allows remote attackers to execu
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.