Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
Micro CMS 0.3.5 - Remote Add/Delete/Password Change
CVE-2008-6553webappsphp
microcms-admin-home.php in Implied by Design Micro CMS (Micro-CMS) 3.5 (aka 0.3.5) does not require authentication as an
23RIESGO
abrir
ReferênciaVexDay Proof
xml2owl 0.1.1 - 'showcode.php' Remote Command Execution
CVE-2007-6632webappsphp
showCode.php in xml2owl 0.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the path
23RIESGO
abrir
ReferênciaVexDay Proof
Cuteflow Bin 1.5.0 - 'login.php' Local File Inclusion
CVE-2008-1493webappsphp
Directory traversal vulnerability in login.php in Cuteflow Bin 1.5.0 allows remote attackers to include and execute arbi
23RIESGO
abrir
ReferênciaVexDay Proof
Dayfox Blog 4 - Multiple Local File Inclusions
CVE-2008-3564webappsphp
Multiple directory traversal vulnerabilities in index.php in Dayfox Blog 4 allow remote attackers to include and execute
23RIESGO
abrir
ReferênciaVexDay Proof
OTManager CMS 24a - Local File Inclusion / Cross-Site Scripting
CVE-2008-5201webappsphp
Directory traversal vulnerability in index.php in OTManager CMS 24a allows remote attackers to include and execute arbit
23RIESGO
abrir
ReferênciaVexDay Proof
team 1.x - File Disclosure / Cross-Site Scripting
CVE-2009-0760webappsasp
Team Board 1.x and 2.x stores sensitive information under the web root with insufficient access control, which allows re
23RIESGO
abrir
ReferênciaVexDay Proof
Flyspeck CMS 6.8 - Local/Remote File Inclusion / Change Add Admin
CVE-2009-1771webappsphp
index.php in Flyspeck CMS 6.8 does not require administrative authentication for the updateExistingContent action, which
23RIESGO
abrir
ReferênciaVexDay Proof
ADN Forum 1.0b - Insecure Cookie Handling
CVE-2008-6001webappsphp
index.php in ADN Forum 1.0b and earlier allows remote attackers to bypass authentication and gain sysop access via a fpu
23RIESGO
abrir
ReferênciaVexDay Proof
Flat PHP Board 1.2 - Multiple Vulnerabilities
CVE-2007-6398webappsphp
Flat PHP Board 1.2 and earlier allows remote attackers to bypass authentication and obtain limited access to an arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
RantX 1.0 - Insecure Admin Authentication
CVE-2008-2297webappsphp
The admin.php file in Rantx allows remote attackers to bypass authentication and gain privileges by setting the logininf
23RIESGO
abrir
ReferênciaVexDay Proof
Acc PHP eMail 1.1 - Insecure Cookie Handling
CVE-2008-6291webappsphp
Acc PHP eMail 1.1 allows remote attackers to bypass authentication and gain administrative access by setting the NEWSLET
23RIESGO
abrir
ReferênciaVexDay Proof
minimal ablog 0.4 - SQL Injection / Arbitrary File Upload / Authentication Bypass
CVE-2008-6613webappsphp
uploader.php in minimal-ablog 0.4 does not properly restrict access, which allows remote attackers to gain administrativ
23RIESGO
abrir
ReferênciaVexDay Proof
TurnkeyForms - Text Link Sales Authentication Bypass
CVE-2008-6963webappsphp
admin.php in TurnkeyForms Text Link Sales allows remote attackers to bypass authentication and gain administrative privi
23RIESGO
abrir
ReferênciaVexDay Proof
Exjune Officer Message System 1 - Multiple Vulnerabilities
CVE-2009-1752webappsphp
exJune Office Message System 1 does not properly restrict access to (1) configure.asp and (2) addmessage2.asp, which all
23RIESGO
abrir
ReferênciaVexDay Proof
PEEL CMS 3.x - Admin Hash Extraction / Arbitrary File Upload
CVE-2008-1506webappsphp
PEEL, possibly 3.x and earlier, allows remote attackers to obtain configuration information via a direct request to phpi
23RIESGO
abrir
ReferênciaVexDay Proof
vhostadmin 0.1 - 'MODULES_DIR' Remote File Inclusion
CVE-2007-0558webappsphp
PHP remote file inclusion vulnerability in modules/mail/main.php in Inter7 vHostAdmin 1.0 allows remote attackers to exe
23RIESGO
abrir
ReferênciaVexDay Proof
jGallery 1.3 - 'index.php' Remote File Inclusion
CVE-2007-2158webappsphp
PHP remote file inclusion vulnerability in index.php in jGallery 1.3 allows remote attackers to execute arbitrary PHP co
23RIESGO
abrir
ReferênciaVexDay Proof
Zomplog 3.8.2 - 'newuser.php' Arbitrary Add Admin
CVE-2008-2349webappsphp
Zomplog 3.8.2 and earlier allows remote attackers to gain administrative access by creating an admin account via a direc
23RIESGO
abrir
ReferênciaVexDay Proof
Squirrelcart 1.x - 'cart.php' Remote File Inclusion
CVE-2007-4439webappsphp
PHP remote file inclusion vulnerability in popup_window.php in Squirrelcart 1.x.x and earlier allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
PacPoll 4.0 - Database Disclosure
CVE-2008-5981webappsphp
PacPoll 4.0 stores sensitive information under the web root with insufficient access control, which allows remote attack
23RIESGO
abrir
ReferênciaVexDay Proof
webid 0.5.4 - Multiple Vulnerabilities
CVE-2008-7118webappsphp
WeBid auction script 0.5.4 stores sensitive information under the web root with insufficient access control, which allow
23RIESGO
abrir
ReferênciaVexDay Proof
PHP Photo Gallery 1.0 - 'photo_id' SQL Injection
CVE-2008-1711webappsphp
Terong PHP Photo Gallery (aka Advanced Web Photo Gallery) 1.0 stores passwords in cleartext in a MySQL database, which a
23RIESGO
abrir
ReferênciaVexDay Proof
WebAlbum 2.02pl - COOKIE[skin2] Remote Code Execution
CVE-2006-1480webappsphp
Directory traversal vulnerability in start.php in WebAlbum 2.02 allows remote attackers to include arbitrary files and e
23RIESGO
abrir
ReferênciaVexDay Proof
Cartweaver 3 - 'prodId' Blind SQL Injection
CVE-2008-2918webappsphp
SQL injection vulnerability in details.php in Application Dynamics Cartweaver 3.0 allows remote attackers to execute arb
23RIESGO
abrir
ReferênciaVexDay Proof
iWare Pro 5.0.4 - 'chat_panel.php' Remote Code Execution
CVE-2006-5837webappsphp
Static code injection vulnerability in chat_panel.php in the SimpleChat 1.0.0 module for iWare Professional CMS allows r
23RIESGO
abrir
ReferênciaVexDay Proof
TorrentFlux 2.2 - 'downloaddetails.php' Local File Disclosure
CVE-2006-6598webappsphp
Directory traversal vulnerability in viewnfo.php in (1) TorrentFlux before 2.2 and (2) torrentflux-b4rt before 2.1-b4rt-
23RIESGO
abrir
ReferênciaVexDay Proof
NewsCMSLite - 'newsCMS.mdb' Remote Password Disclosure
CVE-2007-0091webappsasp
newsCMSlite stores sensitive information under the web root with insufficient access control, which allows remote attack
23RIESGO
abrir
ReferênciaVexDay Proof
Pakupaku CMS 0.4 - Arbitrary File Upload / Local File Inclusion
CVE-2007-4640webappsphp
Unrestricted file upload vulnerability in index.php in Pakupaku CMS 0.4 and earlier allows remote attackers to upload an
23RIESGO
abrir
ReferênciaVexDay Proof
Webace-Linkscript 1.3 SE - 'start.php' SQL Injection
CVE-2007-4846webappsphp
SQL injection vulnerability in start.php in Webace-Linkscript (wls) 1.3 Special Edition (SE) allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
rgboard 3.0.12 - Remote File Inclusioni / Cross-Site Scripting
CVE-2008-2296webappsphp
PHP remote file inclusion vulnerability in include/bbs.lib.inc.php in Rgboard 3.0.12 allows remote attackers to execute
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.