Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
UltraISO 9.3.3.2685 - CCD/IMG Universal Buffer Overflow
CVE-2009-1260localwindows
Multiple stack-based buffer overflows in UltraISO 9.3.3.2685 and earlier allow remote attackers to cause a denial of ser
50RIESGO
abrir
ReferênciaVexDay Proof
Crysis 1.1.1.5879 - Remote Format String Denial of Service (PoC)
CVE-2008-1127doswindows
Format string vulnerability in the cryactio function in Crysis 1.1.1.5879 allows remote authenticated users to execute a
23RIESGO
abrir
ReferênciaVexDay Proof
WebSVN 2.0 - Cross-Site Scripting / File Handling / Code Execution
CVE-2008-5920webappsphp
The create_anchors function in utils.inc in WebSVN 1.x allows remote attackers to execute arbitrary PHP code via a craft
23RIESGO
abrir
ReferênciaVexDay Proof
LiteNews 0.1 - Insecure Cookie Handling
CVE-2008-3508webappsphp
LiteNews 0.1 (aka 01), and possibly 1.2 and earlier, allows remote attackers to bypass authentication and gain administr
23RIESGO
abrir
ReferênciaVexDay Proof
Mosaic Commerce - 'cid' SQL Injection
CVE-2008-4599webappsphp
SQL injection vulnerability in category.php in Mosaic Commerce allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
Jamroom 4.0.2 - 't' Local File Inclusion
CVE-2009-1318webappsphp
Directory traversal vulnerability in index.php in Jamroom 3.1.2, 3.2.3 through 3.2.6, 4.0.2, and possibly other versions
23RIESGO
abrir
ReferênciaVexDay Proof
CafeEngine - Multiple SQL Injections
CVE-2008-4604webappsphp
SQL injection vulnerability in index.php in Easy CafeEngine 1.1 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
ReferênciaVexDay Proof
Dart Communications PowerTCP FTP module - Remote Buffer Overflow
CVE-2008-4652remotewindows
Buffer overflow in the ActiveX control (DartFtp.dll) in Dart Communications PowerTCP FTP for ActiveX 2.0.2 0 allows remo
28RIESGO
abrir
ReferênciaVexDay Proof
PowerTCP FTP Module - Multiple Techniques (SEH HeapSpray)
CVE-2008-4652remotewindows
Buffer overflow in the ActiveX control (DartFtp.dll) in Dart Communications PowerTCP FTP for ActiveX 2.0.2 0 allows remo
28RIESGO
abrir
ReferênciaVexDay Proof
ASX to MP3 Converter - '.m3u' Local Stack Overflow (PoC)
CVE-2009-1324doswindows
Stack-based buffer overflow in Mini-stream ASX to MP3 Converter 3.0.0.7 allows remote attackers to execute arbitrary cod
28RIESGO
abrir
ReferênciaVexDay Proof
ASX to MP3 Converter 3.0.0.7 - '.m3u' Universal Stack Overflow
CVE-2009-1324localwindows
Stack-based buffer overflow in Mini-stream ASX to MP3 Converter 3.0.0.7 allows remote attackers to execute arbitrary cod
28RIESGO
abrir
ReferênciaVexDay Proof
Mini-stream Ripper - '.m3u' Local Stack Overflow (PoC)
CVE-2009-1325doswindows
Stack-based buffer overflow in Mini-stream Ripper 3.0.1.1 allows remote attackers to execute arbitrary code via a long U
23RIESGO
abrir
ReferênciaVexDay Proof
eLineStudio Site Composer (ESC) 2.6 - Multiple Vulnerabilities
CVE-2008-2861webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in eLineStudio Site Composer (ESC) 2.6 and earlier allow remote atta
23RIESGO
abrir
ReferênciaVexDay Proof
MODx CMS 0.9.2.1 - 'FCKeditor' Remote File Inclusion
CVE-2006-5730webappsphp
PHP remote file inclusion vulnerability in manager/media/browser/mcpuk/connectors/php/Commands/Thumbnail.php in Modx CMS
23RIESGO
abrir
ReferênciaVexDay Proof
pPIM 1.0 - Arbitrary File Delete / Cross-Site Scripting
CVE-2008-4425webappsphp
Directory traversal vulnerability in upload.php in Phlatline's Personal Information Manager (pPIM) 1.0 allows remote att
23RIESGO
abrir
ReferênciaVexDay Proof
ClaSS 0.8.60 - 'export.php' Local File Inclusion
CVE-2008-5856webappsphp
Directory traversal vulnerability in scripts/export.php in ClaSS before 0.8.61 allows remote attackers to read arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
Durian Web Application Server 3.02 - Remote Buffer Overflow
CVE-2006-6853remotewindows
Buffer overflow in Durian Web Application Server 3.02 freeware on Windows allows remote attackers to execute arbitrary c
23RIESGO
abrir
ReferênciaVexDay Proof
Lanius CMS 1.2.16 - 'FCKeditor' Arbitrary File Upload
CVE-2007-5156webappsphp
Incomplete blacklist vulnerability in editor/filemanager/upload/php/upload.php in FCKeditor, as used in SiteX CMS 0.7.3.
23RIESGO
abrir
ReferênciaVexDay Proof
Ax Developer CMS 0.1.1 - 'index.php?module' Local File Inclusion
CVE-2007-5820webappsphp
Directory traversal vulnerability in index.php in Ax Developer CMS (AxDCMS) 0.1.1 allows remote attackers to include and
23RIESGO
abrir
ReferênciaVexDay Proof
Acidcat CMS 3.4.1 - Multiple Vulnerabilities
CVE-2008-1992webappsphp
Acidcat CMS 3.4.1 does not properly restrict access to (1) default_mail_aspemail.asp, (2) default_mail_cdosys.asp or (3)
23RIESGO
abrir
ReferênciaVexDay Proof
Aardvark Topsites PHP 4.2.2 - 'path' Remote File Inclusion
CVE-2006-7026webappsphp
PHP remote file inclusion vulnerability in sources/join.php in Aardvark Topsites PHP 4.2.2 and earlier, when register_gl
23RIESGO
abrir
ReferênciaVexDay Proof
QuickTalk forum 1.3 - 'lang' Local File Inclusion
CVE-2007-3505webappsphp
Multiple directory traversal vulnerabilities in QuickTalk forum 1.3 allow remote attackers to include and execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
RPG.Board 0.0.8Beta2 - 'showtopic' SQL Injection
CVE-2008-4736webappsphp
SQL injection vulnerability in index.php in RPG.Board 0.8 Beta2 and earlier allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
EZ Publish < 3.9.5/3.10.1/4.0.1 - Privilege Escalation
CVE-2008-6844webappsphp
The registration view (/user/register) in eZ Publish 3.5.6 and earlier, and possibly other versions before 3.9.5, 3.10.1
23RIESGO
abrir
ReferênciaVexDay Proof
Mini-stream Ripper 3.0.1.1 - '.m3u' Universal Stack Overflow
CVE-2009-1325localwindows
Stack-based buffer overflow in Mini-stream Ripper 3.0.1.1 allows remote attackers to execute arbitrary code via a long U
23RIESGO
abrir
ReferênciaVexDay Proof
Mambo Component MMP 1.2 - Remote File Inclusion
CVE-2006-4203webappsphp
PHP remote file inclusion vulnerability in help.mmp.php in the MMP Component (com_mmp) 1.2 and earlier for Mambo allows
23RIESGO
abrir
ReferênciaVexDay Proof
Pluck CMS 4.5.2 - Multiple Local File Inclusions
CVE-2008-3851webappsphp
Multiple directory traversal vulnerabilities in Pluck CMS 4.5.2 on Windows allow remote attackers to include and execute
23RIESGO
abrir
ReferênciaVexDay Proof
AEP SmartGate 4.3b - 'GET' Arbitrary File Download
CVE-2006-5596remotewindows
Directory traversal vulnerability in the SSL server in AEP Smartgate 4.3b allows remote attackers to download arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
Keller Web Admin CMS 0.94 Pro - Local File Inclusion (1)
CVE-2008-6734webappsphp
Directory traversal vulnerability in Public/index.php in Keller Web Admin CMS 0.94 Pro allows remote attackers to includ
23RIESGO
abrir
ReferênciaVexDay Proof
Max.Blog 1.0.6 - Arbitrary Delete Post
CVE-2009-0383webappsphp
delete.php in Max.Blog 1.0.6 does not properly restrict access, which allows remote attackers to delete arbitrary blog p
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.