Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
XOOPS Module WF-Snippets 1.02 (c) - Blind SQL Injection
CVE-2007-1962webappsphp
SQL injection vulnerability in index.php in the WF-Snippets 1.02 and earlier module for XOOPS allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
QuickEStore 8.2 - 'insertorder.cfm' SQL Injection
CVE-2007-3933webappsphp
SQL injection vulnerability in insertorder.cfm in QuickEStore 8.2 and earlier allows remote attackers to execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
PHP Real Estate - 'fullnews.php?id' SQL Injection
CVE-2007-6462webappsphp
SQL injection vulnerability in fullnews.php in PHP Real Estate Classifieds allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
Limbo CMS 1.0.4.2 - 'Cuid' cookie Blind SQL Injection
CVE-2008-0734webappsphp
SQL injection vulnerability in class_auth.php in Limbo CMS 1.0.4.2, and possibly earlier versions, allows remote attacke
23RIESGO
abrir
ReferênciaVexDay Proof
Remote Mouse GUI 3.008 - Local Privilege Escalation
CVE-2021-35448localwindows
Emote Interactive Remote Mouse 3.008 on Windows allows attackers to execute arbitrary programs as Administrator by using
23RIESGO
abrir
ReferênciaVexDay Proof
PostNuke Module pnFlashGames 2.5 - SQL Injection
CVE-2008-2013webappsphp
SQL injection vulnerability in index.php in the pnFlashGames 1.5 through 2.5 module for PostNuke, when magic_quotes_gpc
23RIESGO
abrir
ReferênciaVexDay Proof
NuMedia Soft Nms DVD Burning SDK - ActiveX 'NMSDVDX.dll' Command Execution
CVE-2008-4342remotewindows
NuMedia Soft NMS DVD Burning SDK Activex NMSDVDX.DVDEngineX.1 ActiveX control (NMSDVDX.dll) 1.013C and earlier, as used
28RIESGO
abrir
ReferênciaVexDay Proof
eReservations - Authentication Bypass
CVE-2009-0252webappsasp
Multiple SQL injection vulnerabilities in default.asp in Enthrallweb eReservations allow remote attackers to execute arb
23RIESGO
abrir
ReferênciaVexDay Proof
Arcadwy Arcade Script - (Authentication Bypass) Insecure Cookie Handling
CVE-2009-1229webappsphp
SQL injection vulnerability in Arcadwy Arcade Script allows remote attackers to execute arbitrary SQL commands via the u
23RIESGO
abrir
ReferênciaVexDay Proof
JGBBS 3.0beta1 - 'search.asp?author' SQL Injection
CVE-2007-1440webappsasp
SQL injection vulnerability in search.asp in JGBBS 3.0 Beta 1 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
Quick and Dirty Blog (qdblog) 0.4 - SQL Injection / Local File Inclusion
CVE-2007-2305webappsphp
Multiple SQL injection vulnerabilities in authenticate.php in Quick and Dirty Blog (QDBlog) 0.4, and possibly earlier, a
23RIESGO
abrir
ReferênciaVexDay Proof
Fuzzylime Forum 1.0 - 'low.php?topic' SQL Injection
CVE-2007-3234webappsphp
SQL injection vulnerability in low.php in Fuzzylime Forum 1.0 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
Solar Empire 2.9.1.1 - Blind SQL Injection / Hash Retrieve
CVE-2007-3307webappsphp
SQL injection vulnerability in game_listing.php in Solar Empire 2.9.1.1 and earlier allows remote attackers to execute a
23RIESGO
abrir
ReferênciaVexDay Proof
YouTube blog 0.1 - Remote File Inclusion / SQL Injection / Cross-Site Scripting
CVE-2008-3307webappsphp
SQL injection vulnerability in todos.php in C. Desseno YouTube Blog (ytb) 0.1 allows remote attackers to execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
FipsCMS Light 2.1 - 'r' SQL Injection
CVE-2008-3417webappsasp
SQL injection vulnerability in home/index.asp in fipsCMS light 2.1 and earlier allows remote attackers to execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
Vastal I-Tech Freelance Zone - 'coder_id' SQL Injection
CVE-2008-4469webappsphp
SQL injection vulnerability in view_cresume.php in Vastal I-Tech Freelance Zone allows remote attackers to execute arbit
23RIESGO
abrir
ReferênciaVexDay Proof
Netartmedia Blog System - SQL Injection
CVE-2008-5311webappsphp
SQL injection vulnerability in image.php in NetArt Media Blog System 1.5 allows remote attackers to execute arbitrary SQ
23RIESGO
abrir
ReferênciaVexDay Proof
TurnkeyForms Text Link Sales - 'id' Cross-Site Scripting / SQL Injection
CVE-2008-5486webappsphp
SQL injection vulnerability in admin.php in TurnkeyForms Text Link Sales allows remote attackers to execute arbitrary SQ
23RIESGO
abrir
ReferênciaVexDay Proof
MyioSoft EasyCalendar - Authentication Bypass
CVE-2008-5654webappsphp
SQL injection vulnerability in the loginADP function in ajaxp.php in MyioSoft EasyCalendar 4.0 allows remote attackers t
23RIESGO
abrir
ReferênciaVexDay Proof
the net guys aspired2blog - SQL Injection / File Disclosure
CVE-2008-5930webappsasp
SQL injection vulnerability in admin/blog_comments.asp in The Net Guys ASPired2Blog allows remote attackers to execute a
23RIESGO
abrir
ReferênciaVexDay Proof
SFS EZ Career - SQL Injection
CVE-2008-6867webappsphp
SQL injection vulnerability in content.php in Scripts For Sites (SFS) EZ Career allows remote attackers to execute arbit
23RIESGO
abrir
ReferênciaVexDay Proof
vBulletin Mod RPG Inferno 2.4 - 'inferno.php' SQL Injection
CVE-2007-3687webappsphp
SQL injection vulnerability in inferno.php in the Inferno Technologies RPG Inferno 2.4 and earlier, a vBulletin module,
23RIESGO
abrir
ReferênciaVexDay Proof
FLDS 1.2a - 'lpro.php' SQL Injection
CVE-2008-5779webappsphp
SQL injection vulnerability in lpro.php in Free Links Directory Script (FLDS) 1.2a allows remote attackers to execute ar
23RIESGO
abrir
ReferênciaVexDay Proof
AskPert - Authentication Bypass
CVE-2008-6309webappsphp
SQL injection vulnerability in index.php in W3matter AskPert allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
ReferênciaVexDay Proof
Groone's GLink ORGanizer - 'index.php?cat' SQL Injection
CVE-2009-0299webappsphp
SQL injection vulnerability in index.php in Groone GLinks 2.1 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
phpsmartcom 0.2 - Local File Inclusion / SQL Injection
CVE-2008-4351webappsphp
Directory traversal vulnerability in index.php in phpSmartCom 0.2 allows remote attackers to include and execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
FLDS 1.2a - 'redir.php' SQL Injection
CVE-2008-5928webappsphp
SQL injection vulnerability in redir.php in Free Links Directory Script (FLDS) 1.2a allows remote attackers to execute a
23RIESGO
abrir
ReferênciaVexDay Proof
SFS EZ Hosting Directory - 'cat_id' SQL Injection
CVE-2008-6782webappsphp
SQL injection vulnerability in directory.php in Sites for Scripts (SFS) EZ Hosting Directory allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
PHPAuctionSystem - Cross-Site Scripting / SQL Injection
CVE-2009-0106webappsphp
SQL injection vulnerability in profile.php in PHPAuctions (aka PHPAuctionSystem) allows remote attackers to execute arbi
23RIESGO
abrir
ReferênciaVexDay Proof
BusinessSpace 1.2 - 'id' SQL Injection
CVE-2009-0516webappsphp
SQL injection vulnerability in the classified page (classified.php) in BusinessSpace 1.2 and earlier allows remote attac
23RIESGO
abrir
anteriorpágina 103 / 188siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.