Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
Boonex Dolphin 6.1.2 - Multiple Remote File Inclusions
CVE-2008-3167webappsphp
Multiple PHP remote file inclusion vulnerabilities in BoonEx Dolphin 6.1.2, when register_globals is enabled, allow remo
23RIESGO
abrir
ReferênciaVexDay Proof
ContentNow 1.4.1 - Arbitrary File Upload / Cross-Site Scripting
CVE-2008-3180webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in upload/file/language_menu.php in ContentNow CMS 1.4.1 allow remot
23RIESGO
abrir
ReferênciaVexDay Proof
phpdaily - SQL Injection / Cross-Site Scripting / Local File Download
CVE-2008-4758webappsphp
Directory traversal vulnerability in download_file.php in PHP-Daily allows remote attackers to read arbitrary local file
23RIESGO
abrir
ReferênciaVexDay Proof
freeSSHd 1.2.1 - (Authenticated) SFTP 'realpath' Remote Buffer Overflow (PoC)
CVE-2008-4762doswindows
Stack-based buffer overflow in freeSSHd 1.2.1 allows remote authenticated users to cause a denial of service (service cr
28RIESGO
abrir
ReferênciaVexDay Proof
ITLPoll 2.7 Stable2 - Blind SQL Injection
CVE-2009-0295webappsphp
SQL injection vulnerability in index.php in Information Technology Light Poll Information (ITLPoll) 2.7 Stable 2, when m
23RIESGO
abrir
ReferênciaVexDay Proof
AuraCMS 2.2.2 - '/pages_data.php' Arbitrary Edit/Add/Delete
CVE-2008-3203webappsphp
js/pages/pages_data.php in AuraCMS 2.2 through 2.2.2 does not perform authentication, which allows remote attackers to a
23RIESGO
abrir
ReferênciaVexDay Proof
Million Pixels 3 - 'id_cat' SQL Injection
CVE-2008-3204webappsphp
SQL injection vulnerability in tops_top.php in E-topbiz Million Pixels 3 allows remote attackers to execute arbitrary SQ
23RIESGO
abrir
ReferênciaVexDay Proof
Pragyan CMS 2.6.2 - 'sourceFolder' Remote File Inclusion
CVE-2008-3207webappsphp
PHP remote file inclusion vulnerability in cms/modules/form.lib.php in Pragyan CMS 2.6.2, when register_globals is enabl
23RIESGO
abrir
ReferênciaVexDay Proof
Amaya Web Editor 11.0 - XML / HTML Parser
CVE-2009-0323doswindows
Multiple stack-based buffer overflows in W3C Amaya Web Browser 10.0 and 11.0 allow remote attackers to execute arbitrary
50RIESGO
abrir
ReferênciaVexDay Proof
PPMate PPMedia Class - ActiveX Control Buffer Overflow (PoC)
CVE-2008-3242doswindows
Heap-based buffer overflow in the PPMedia Class ActiveX control in PPMPlayer.dll in PPMate 2.3.1.93 allows remote attack
28RIESGO
abrir
ReferênciaVexDay Proof
Arctic Issue Tracker 2.0.0 - 'filter' SQL Injection (1)
CVE-2008-3250webappsphp
SQL injection vulnerability in index.php in Arctic Issue Tracker 2.0.0 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
preCMS 1 - 'index.php' SQL Injection
CVE-2008-3254webappsphp
SQL injection vulnerability in index.php in preCMS 1 allows remote attackers to execute arbitrary SQL commands via the i
23RIESGO
abrir
ReferênciaVexDay Proof
MW6 Datamatrix - ActiveX 'Datamatrix.dll' Insecure Method
CVE-2008-4925remotewindows
Multiple insecure method vulnerabilities in MW6 Technologies DataMatrix ActiveX control (DATAMATRIXLib.MW6DataMatrix, Da
23RIESGO
abrir
ReferênciaVexDay Proof
Simple PHP NewsLetter 1.5 - Local File Inclusion
CVE-2009-0340webappsphp
Multiple directory traversal vulnerabilities in Simple PHP Newsletter 1.5 allow remote attackers to read arbitrary files
23RIESGO
abrir
ReferênciaVexDay Proof
HRS Multi - 'key' Blind SQL Injection
CVE-2008-3266webappsasp
SQL injection vulnerability in picture_pic_bv.asp in SoftAcid Hotel Reservation System (HRS) Multi allows remote attacke
23RIESGO
abrir
ReferênciaVexDay Proof
WinRemotePC Full+Lite 2008 r.2server - Denial of Service
CVE-2008-3269doswindows
WRPCServer.exe in WinSoftMagic WinRemotePC (WRPC) Lite 2008 and Full 2008 allows remote attackers to cause a denial of s
28RIESGO
abrir
ReferênciaVexDay Proof
PHP TopTree BBS 2.0.1a - 'right_file' Remote File Inclusion
CVE-2007-2544webappsphp
PHP remote file inclusion vulnerability in templates/default/tpl_message.php in PHP TopTree BBS 2.0.1a and earlier allow
23RIESGO
abrir
ReferênciaVexDay Proof
OpenSSL 0.9.8c-1 < 0.9.8g-9 (Debian and Derivatives) - Predictable PRNG Brute Force SSH
CVE-2008-3280remotelinux
It was found that various OpenID Providers (OPs) had TLS Server Certificates that used weak keys, as a result of the Deb
23RIESGO
abrir
ReferênciaVexDay Proof
DeluxeBB 1.07 - Remote Create Admin
CVE-2006-3304webappsphp
SQL injection vulnerability in cp.php in DeluxeBB 1.07 and earlier allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
ReferênciaVexDay Proof
bilboblog 2.1 - Multiple Vulnerabilities
CVE-2008-3302webappsphp
SQL injection vulnerability in admin/delete.php in BilboBlog 0.2.1, when magic_quotes_gpc is disabled, allows remote aut
23RIESGO
abrir
ReferênciaVexDay Proof
bilboblog 2.1 - Multiple Vulnerabilities
CVE-2008-3304webappsphp
BilboBlog 0.2.1 allows remote attackers to obtain sensitive information via (1) an enable_cache=false query string to fo
23RIESGO
abrir
ReferênciaVexDay Proof
Pre Survey Poll - 'catid' SQL Injection
CVE-2008-3310webappsasp
SQL injection vulnerability in default.asp in Pre Survey Poll allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
feedDemon 2.7 - OPML Outline Tag Buffer Overflow
CVE-2009-0546localwindows
Stack-based buffer overflow in NewsGator FeedDemon 2.7 and earlier allows user-assisted remote attackers to execute arbi
50RIESGO
abrir
ReferênciaVexDay Proof
PHP FirstPost 0.1 - 'block.php?Include' Remote File Inclusion
CVE-2007-2665webappsphp
PHP remote file inclusion vulnerability in block.php in PhpFirstPost 0.1 allows remote attackers to execute arbitrary PH
23RIESGO
abrir
ReferênciaVexDay Proof
IntelliTamper 2.0.7 - HTML Parser Remote Buffer Overflow
CVE-2008-3360remotewindows
Stack-based buffer overflow in the HTML parser in IntelliTamper 2.0.7 allows remote attackers to execute arbitrary code
23RIESGO
abrir
ReferênciaVexDay Proof
IntelliTamper 2.0.7 - HTML Parser Remote Buffer Overflow
CVE-2008-3360remotewindows
Stack-based buffer overflow in the HTML parser in IntelliTamper 2.0.7 allows remote attackers to execute arbitrary code
23RIESGO
abrir
ReferênciaVexDay Proof
XOOPS Module GesGaleri - SQL Injection
CVE-2008-5321webappsphp
SQL injection vulnerability in index.php in GesGaleri, a module for XOOPS, allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
DMXReady Secure Document Library 1.1 - SQL Injection
CVE-2009-0428webappsphp
SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Secure Document Library 1.1 and ear
23RIESGO
abrir
ReferênciaVexDay Proof
IntelliTamper 2.07 - server header Remote Code Execution
CVE-2008-3361remotewindows
Stack-based buffer overflow in IntelliTamper 2.07 allows remote web sites to execute arbitrary code via a long HTTP Serv
23RIESGO
abrir
ReferênciaVexDay Proof
PixelPost 1.7.1 - 'language_full' Local File Inclusion
CVE-2008-3365webappsphp
Directory traversal vulnerability in index.php in Pixelpost 1.7.1 on Windows, when register_globals is enabled, allows r
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.