Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
X-Forum 0.6.2 - Remote Command Execution
CVE-2009-1512webappsphp
Static code injection vulnerability in X-Forum 0.6.2 allows remote authenticated administrators to inject arbitrary PHP
23RIESGO
abrir
ReferênciaVexDay Proof
MiniBB 2.0.5 - 'Language' Local File Inclusion
CVE-2007-3272webappsphp
Directory traversal vulnerability in index.php in MiniBB 2.0.5 allows remote attackers to read arbitrary files via a ..
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Internet Explorer - 'MDAC' Remote Code Execution (MS06-014) (Metasploit) (2)
CVE-2006-0003remotewindows
Unspecified vulnerability in the RDS.Dataspace ActiveX control, which is contained in ActiveX Data Objects (ADO) and dis
60RIESGO
abrir
ReferênciaVexDay Proof
Technote 7.2 - Remote File Inclusion
CVE-2009-0441webappsphp
PHP remote file inclusion vulnerability in skin_shop/standard/2_view_body/body_default.php in TECHNOTE 7.2, when registe
23RIESGO
abrir
ReferênciaVexDay Proof
wget 1.10.2 - Unchecked Boundary Condition Denial of Service
CVE-2006-6719dosmultiple
The ftp_syst function in ftp-basic.c in Free Software Foundation (FSF) GNU wget 1.10.2 allows remote attackers to cause
23RIESGO
abrir
ReferênciaVexDay Proof
IP Reg 0.3 - Multiple SQL Injections
CVE-2007-6579webappsphp
Multiple SQL injection vulnerabilities in Ip Reg 0.3 allow remote attackers to execute arbitrary SQL commands via the vl
23RIESGO
abrir
ReferênciaVexDay Proof
ravennuke 2.3.0 - Multiple Vulnerabilities
CVE-2009-0678webappsphp
images/captcha.php in RavenNuke 2.30 allows remote attackers to obtain sensitive information via an aFonts array paramet
23RIESGO
abrir
ReferênciaVexDay Proof
Mozilla Firefox - unclamped loop Denial of Service
CVE-2009-1827dosmultiple
The SVG component in Mozilla Firefox 3.0.4 allows remote attackers to cause a denial of service (application hang) via a
23RIESGO
abrir
ReferênciaVexDay Proof
Exhibit Engine 1.22 - 'styles.php' Remote File Inclusion
CVE-2006-7183webappsphp
PHP remote file inclusion vulnerability in styles.php in Exhibit Engine (EE) 1.22 and earlier allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
DZCP (deV!L_z Clanportal) 1.4.5 - Remote File Disclosure
CVE-2007-1167webappsphp
inc/filebrowser/browser.php in deV!L`z Clanportal (DZCP) 1.4.5 and earlier allows remote attackers to obtain MySQL data
23RIESGO
abrir
ReferênciaVexDay Proof
Freelance Auction Script 1.0 - 'browseproject.php' SQL Injection
CVE-2008-2278webappsphp
SQL injection vulnerability in browseproject.php in Freelance Auction Script 1.0 allows remote attackers to execute arbi
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Internet Explorer - MDAC Remote Code Execution (MS06-014)
CVE-2006-0003remotewindows
Unspecified vulnerability in the RDS.Dataspace ActiveX control, which is contained in ActiveX Data Objects (ADO) and dis
60RIESGO
abrir
ReferênciaVexDay Proof
Etomite CMS 0.6.1 - 'rfiles.php' Remote Command Execution
CVE-2006-7070webappsphp
Unrestricted file upload vulnerability in manager/media/ibrowser/scripts/rfiles.php in Etomite CMS 0.6.1 and earlier all
23RIESGO
abrir
ReferênciaVexDay Proof
PHP-Stats 0.1.9.2 - Multiple Vulnerabilities
CVE-2007-5453webappsphp
Multiple eval injection vulnerabilities in Php-Stats 0.1.9.2 allow remote authenticated administrators to execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
rgboard 3.0.12 - Remote File Inclusioni / Cross-Site Scripting
CVE-2008-2295webappsphp
Cross-site scripting (XSS) vulnerability in rg_search.php in Rgboard 3.0.12, and possibly earlier versions, allows remot
23RIESGO
abrir
ReferênciaVexDay Proof
SoftBB 0.1 - 'cmd' Remote Command Execution
CVE-2006-4632webappsphp
Multiple SQL injection vulnerabilities in SoftBB 0.1, and possibly earlier, allow remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
W3Filer 2.1.3 - Remote Stack Overflow (PoC)
CVE-2007-3548doswindows
Stack-based buffer overflow in W3Filer 2.1.3 allows remote FTP servers to cause a denial of service (application hang or
23RIESGO
abrir
ReferênciaVexDay Proof
Live for Speed S1/S2/Demo - '.mpr replay' Local Buffer Overflow
CVE-2007-4140localwindows
Buffer overflow in Live for Speed (LFS) S2 ALPHA PATCH 0.5x allows user-assisted remote attackers to execute arbitrary c
23RIESGO
abrir
ReferênciaVexDay Proof
Web Wiz NewsPad 1.02 - 'sub' Directory Traversal
CVE-2008-0479webappsasp
Directory traversal vulnerability in RTE_file_browser.asp in Web Wiz NewsPad 1.02 allows remote attackers to list arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
AllMyGuests 0.4.1 - 'cfg_serverpath' Remote File Inclusion
CVE-2006-4993webappsphp
Multiple PHP remote file inclusion vulnerabilities in AllMyGuests 0.4.1 and earlier allow remote attackers to execute ar
23RIESGO
abrir
ReferênciaVexDay Proof
68 Classifieds 4.0 - 'category.php' SQL Injection
CVE-2008-2336webappsphp
SQL injection vulnerability in category.php in 68 Classifieds 4.0.1 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
ReferênciaVexDay Proof
plusphp url shortening software 1.6 - Remote File Inclusion
CVE-2008-2480webappsphp
PHP remote file inclusion vulnerability in plus.php in plusPHP Short URL Multi-User Script 1.6 allows remote attackers t
23RIESGO
abrir
ReferênciaVexDay Proof
Webfwlog 0.92 - 'debug.php' Remote File Disclosure
CVE-2007-0585webappsphp
include/debug.php in Webfwlog 0.92 and earlier, when register_globals is enabled, allows remote attackers to obtain sour
23RIESGO
abrir
ReferênciaVexDay Proof
PHP recommend 1.3 - Authentication Bypass / Remote File Inclusion / Code Injection
CVE-2009-1779webappsphp
PHP remote file inclusion vulnerability in admin.php in Frax.dk Php Recommend 1.3 and earlier allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
phpMyProfiler 0.9.6 - Remote File Inclusion
CVE-2006-5186webappsphp
PHP remote file inclusion vulnerability in functions.php in phpMyProfiler 0.9.6 and earlier, when register_globals is en
23RIESGO
abrir
ReferênciaVexDay Proof
PHP-Stats 0.1.9.1b - 'PHP-stats-options.php' Command Execution
CVE-2006-7173webappsphp
Direct static code injection vulnerability in admin.php in PHP-Stats 0.1.9.1b and earlier allows remote attackers to exe
23RIESGO
abrir
ReferênciaVexDay Proof
CrystalPlayer 1.98 - '.mls' Local Buffer Overflow
CVE-2007-4032localwindows
Buffer overflow in CrystalPlayer Pro 1.98 allows user-assisted remote attackers to execute arbitrary code via a long str
23RIESGO
abrir
ReferênciaVexDay Proof
Flatnuke 3 - Remote Cookie Manipulation / Privilege Escalation
CVE-2007-5772webappsphp
Direct static code injection vulnerability in the download module in Flatnuke 3 allows remote authenticated administrato
23RIESGO
abrir
ReferênciaVexDay Proof
newsmanager 2.0 - Remote File Inclusion / File Disclosure / SQL Injection
CVE-2008-2341webappsphp
PHP remote file inclusion vulnerability in ch_readalso.php in News Manager 2.0 allows remote attackers to execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
MeltingIce File System 1.0 - Arbitrary Add User
CVE-2008-2348webappsphp
MeltingIce File System 1.0 allows remote attackers to bypass application authentication, create new user accounts, and e
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.