Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
mini-pub 0.3 - File Disclosure / Code Execution
CVE-2008-5579webappsphp
Absolute path traversal vulnerability in mini-pub.php/front-end/cat.php in mini-pub 0.3 allows remote attackers to read
23RIESGO
abrir
ReferênciaVexDay Proof
pl-PHP Beta 0.9 - Multiple Vulnerabilities
CVE-2007-2007webappsphp
admin.php in pL-PHP beta 0.9 allows remote attackers to bypass authentication by setting the is_admin parameter to 1.
23RIESGO
abrir
ReferênciaVexDay Proof
txtshop 1.0b (Windows) - 'Language' Local File Inclusion
CVE-2008-6083webappsphp
Directory traversal vulnerability in header.php in TXTshop beta 1.0 allows remote attackers to include and execute arbit
23RIESGO
abrir
ReferênciaVexDay Proof
PHP-CON 1.3 - 'include.php' Remote File Inclusion
CVE-2007-6177webappsphp
PHP remote file inclusion vulnerability in Exchange/include.php in PHP_CON 1.3 allows remote attackers to execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
unclassified NewsBoard 1.6.4 - Multiple Vulnerabilities
CVE-2009-1949webappsphp
import_wbb1.php in Unclassified NewsBoard (UNB) 1.6.4 allows remote attackers to obtain sensitive information via a dire
23RIESGO
abrir
ReferênciaVexDay Proof
CcMail 1.0.1 - 'functions_dir' Remote File Inclusion
CVE-2007-1516webappsphp
PHP remote file inclusion vulnerability in functions/update.php in Cicoandcico CcMail 1.0 allows remote attackers to exe
23RIESGO
abrir
ReferênciaVexDay Proof
OWL Intranet Engine 0.82 - 'xrms_file_root' Code Execution
CVE-2006-1149webappsphp
PHP remote file inclusion vulnerability in lib/OWL_API.php in OWL Intranet Engine 0.82, when register_globals is enabled
23RIESGO
abrir
ReferênciaVexDay Proof
FreeCMS.us 0.2 - 'index.php' SQL Injection
CVE-2008-2796webappsphp
SQL injection vulnerability in index.php in FreeCMS 0.2 allows remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir
ReferênciaVexDay Proof
mystats - 'hits.php' Multiple Vulnerabilities
CVE-2008-4644webappsphp
hits.php in myWebland myStats allows remote attackers to bypass IP address restrictions via a modified X-Forwarded-For H
23RIESGO
abrir
ReferênciaVexDay Proof
Yerba SACphp 6.3 - Multiple Vulnerabilities
CVE-2008-5873webappsphp
Yerba SACphp 6.3 and earlier allows remote attackers to bypass authentication and gain administrative access via a galle
23RIESGO
abrir
ReferênciaVexDay Proof
ravennuke 2.3.0 - Multiple Vulnerabilities
CVE-2009-0673webappsphp
Eval injection vulnerability in the Custom Fields feature in the Your Account module in Raven Web Services RavenNuke 2.3
23RIESGO
abrir
ReferênciaVexDay Proof
Easy-Clanpage 3.0b1 - 'section' Local File Inclusion
CVE-2008-2818webappsphp
Directory traversal vulnerability in Easy-Clanpage 3.0 b1 allows remote attackers to include and execute arbitrary local
23RIESGO
abrir
ReferênciaVexDay Proof
registroTL - 'main.php' Remote File Inclusion
CVE-2006-5316webappsphp
registroTL stores sensitive information under the web root with insufficient access control, which allows remote attacke
23RIESGO
abrir
ReferênciaVexDay Proof
DodosMail 2.0.1 - 'dodosmail.php' Remote File Inclusion
CVE-2006-5841webappsphp
Multiple PHP remote file inclusion vulnerabilities in dodosmail.php in DodosMail 2.0.1 and earlier, and possibly 2.1, al
23RIESGO
abrir
ReferênciaVexDay Proof
PHPEasyNews 1.13 RC2 - 'POST' SQL Injection
CVE-2008-2823webappsphp
SQL injection vulnerability in newsarchive.php in PHPeasyblog (formerly phpeasynews) 1.13 RC2 and earlier allows remote
23RIESGO
abrir
ReferênciaVexDay Proof
gCards 1.45 - Multiple Vulnerabilities
CVE-2006-1347webappsphp
SQL injection vulnerability in loginfunction.php in Greg Neustaetter gCards 1.45 and earlier allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
APC ActionApps CMS 2.8.1 - Remote File Inclusion
CVE-2006-2686webappsphp
PHP remote file inclusion vulnerabilities in ActionApps 2.8.1 allow remote attackers to execute arbitrary PHP code via a
28RIESGO
abrir
ReferênciaVexDay Proof
Socketwiz BookMarks 2.0 - 'root_dir' Remote File Inclusion
CVE-2006-7069webappsphp
PHP remote file inclusion vulnerability in smarty_config.php in Socketwiz Bookmarks 2.0 and earlier allows remote attack
23RIESGO
abrir
ReferênciaVexDay Proof
NetProxy 4.03 - Web Filter Evasion / Bypass Logging
CVE-2007-1224remotewindows
Grok Developments NetProxy 4.03 allows remote attackers to bypass URL filtering via a request that omits "http://" from
23RIESGO
abrir
ReferênciaVexDay Proof
Blog PixelMotion - 'sauvBase.php' Arbitrary Database Backup
CVE-2008-1868webappsphp
admin/sauvBase.php in Blog Pixel Motion (aka Blog PixelMotion) does not require authentication, which allows remote atta
23RIESGO
abrir
ReferênciaVexDay Proof
SimpleBlog 2.0 - 'comments.asp' SQL Injection (1)
CVE-2006-4300webappsasp
SQL injection vulnerability in comments.asp in SimpleBlog 2.0 and earlier allows remote attackers to execute arbitrary S
23RIESGO
abrir
ReferênciaVexDay Proof
Barman 0.0.1r3 - 'Interface.php' Remote File Inclusion
CVE-2006-6611webappsphp
PHP remote file inclusion vulnerability in interface.php in Barman 0.0.1r3 allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
realm CMS 2.3 - Multiple Vulnerabilities
CVE-2008-2681webappsphp
Realm CMS 2.3 and earlier allows remote attackers to obtain sensitive information via a direct request to _db/compact.as
23RIESGO
abrir
ReferênciaVexDay Proof
Thickbox Gallery 2.0 - 'Admins.php' Admin Data Disclosure
CVE-2008-3859webappsphp
Davlin Thickbox Gallery 2 allows remote attackers to obtain the administrative username and MD5 password hash via a dire
23RIESGO
abrir
ReferênciaVexDay Proof
nightfall personal diary 1.0 - Cross-Site Scripting / File Disclosure
CVE-2008-5592webappsphp
Nightfall Personal Diary 1.0 stores sensitive information under the web root with insufficient access control, which all
23RIESGO
abrir
ReferênciaVexDay Proof
PHP Site Lock 2.0 - Insecure Cookie Handling
CVE-2009-1587webappsphp
index.php in PHP Site Lock 2.0 allows remote attackers to bypass authentication and obtain administrative access by sett
23RIESGO
abrir
ReferênciaVexDay Proof
DM FileManager 3.9.2 - Insecure Cookie Handling
CVE-2009-2025webappsphp
admin/login.php in DM FileManager 3.9.2 allows remote attackers to bypass authentication and gain administrative access
23RIESGO
abrir
ReferênciaVexDay Proof
OwnRS blog beta3 - SQL Injection / Cross-Site Scripting
CVE-2008-2856webappsphp
SQL injection vulnerability in clanek.php in OwnRS Beta 3 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
ReferênciaVexDay Proof
Techno Dreams Articles & Papers 2.0 - SQL Injection
CVE-2006-4891webappsasp
SQL injection vulnerability in ArticlesTableview.asp in Techno Dreams Articles & Papers Package 2.0 and earlier allows r
23RIESGO
abrir
ReferênciaVexDay Proof
Flatnuke 3 - Remote Command Execution / Privilege Escalation
CVE-2007-5774webappsphp
index.php in the File Manager module in Flatnuke 3 allows remote attackers to obtain sensitive information via an invali
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.