Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
RevokeBB 1.0 RC4 - Blind SQL Injection / Hash Retrieve
CVE-2007-3051webappsphp
SQL injection vulnerability in inc/class_users.php in RevokeSoft RevokeBB 1.0 RC4 and earlier allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
CascadianFAQ 4.1 - 'index.php' SQL Injection
CVE-2007-0631webappsphp
SQL injection vulnerability in index.php in Eclectic Designs CascadianFAQ 4.1 and earlier allows remote attackers to exe
23RIESGO
abrir
ReferênciaVexDay Proof
myPHPNuke < 1.8.8_8rc2 - Cross-Site Scripting / SQL Injection
CVE-2008-4088webappsphp
SQL injection vulnerability in print.php in myPHPNuke (MPN) before 1.8.8_8rc2 allows remote attackers to execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
LushiWarPlaner 1.0 - 'register.php' SQL Injection
CVE-2007-0864webappsphp
SQL injection vulnerability in register.php in LushiWarPlaner 1.0 allows remote attackers to inject arbitrary SQL comman
23RIESGO
abrir
ReferênciaVexDay Proof
GaziYapBoz Game Portal - 'kategori.asp' SQL Injection
CVE-2007-1410webappsasp
SQL injection vulnerability in kategori.asp in GaziYapBoz Game Portal allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
ReferênciaVexDay Proof
Papoo 3.02 - kontakt menuid SQL Injection
CVE-2007-2320webappsphp
SQL injection vulnerability in kontakt.php in Papoo 3.02 and earlier allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir
ReferênciaVexDay Proof
Simple Invoices 2007 05 25 - 'index.php?submit' SQL Injection
CVE-2007-3430webappsphp
SQL injection vulnerability in index.php in Simple Invoices 2007 05 25 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
eSyndiCat Directory Software - Multiple SQL Injections
CVE-2007-3811webappsphp
Multiple SQL injection vulnerabilities in eSyndiCat allow remote attackers to execute arbitrary SQL commands via (1) the
23RIESGO
abrir
ReferênciaVexDay Proof
WSN Links Basic Edition - 'catid' SQL Injection
CVE-2007-3981webappsphp
SQL injection vulnerability in index.php in WSN Links Basic Edition allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
ReferênciaVexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
CVE-2007-6498webappsasp
Multiple SQL injection vulnerabilities in Hosting Controller 6.1 Hot fix 3.3 and earlier allow remote authenticated user
23RIESGO
abrir
ReferênciaVexDay Proof
Carbon Communities 2.4 - Multiple Vulnerabilities
CVE-2008-1895webappsasp
Multiple SQL injection vulnerabilities in Carbon Communities 2.4 and earlier allow remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
myPHPNuke < 1.8.8_8rc2 - 'artid' SQL Injection
CVE-2008-4092webappsphp
SQL injection vulnerability in printfeature.php in myPHPNuke (MPN) before 1.8.8_8rc2 allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
Adult Banner Exchange Website - 'targetid' SQL Injection
CVE-2008-6101webappsphp
SQL injection vulnerability in click.php in Adult Banner Exchange Website allows remote attackers to execute arbitrary S
23RIESGO
abrir
ReferênciaVexDay Proof
CS-Cart 1.3.5 - Authentication Bypass
CVE-2008-6394webappsphp
SQL injection vulnerability in core/user.php in CS-Cart 1.3.5 and earlier allows remote attackers to execute arbitrary S
23RIESGO
abrir
ReferênciaVexDay Proof
ComicShout 2.8 - 'news_id' SQL Injection
CVE-2008-6425webappsphp
SQL injection vulnerability in news.php in ComicShout 2.8 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
ReferênciaVexDay Proof
Web Calendar 4.1 - Blind SQL Injection
CVE-2008-1954webappsphp
SQL injection vulnerability in one_day.php in Web Calendar Pro 4.1 and earlier allows remote attackers to execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
TR News 2.1 - 'nb' SQL Injection
CVE-2008-1957webappsphp
SQL injection vulnerability in news.php in Tr Script News 2.1 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
Kolifa.net Download Script 1.2 - 'id' SQL Injection
CVE-2008-4054webappsphp
SQL injection vulnerability in indir.php in Kolifa.net Download Script 1.2 allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
DZCP (deV!L_z Clanportal) 1.4.9.6 - Blind SQL Injection
CVE-2008-4889webappsphp
SQL injection vulnerability in index.php in deV!L'z Clanportal (DZCP) 1.4.9.6 and earlier allows remote attackers to exe
23RIESGO
abrir
ReferênciaVexDay Proof
Pro Traffic One - 'poll_results.php' SQL Injection
CVE-2008-6214webappsphp
SQL injection vulnerability in poll_results.php in Harlandscripts Pro Traffic One allows remote attackers to execute arb
23RIESGO
abrir
ReferênciaVexDay Proof
Yblog 0.2.2.2 - Cross-Site Scripting / SQL Injection
CVE-2008-2669webappsphp
Multiple SQL injection vulnerabilities in yBlog 0.2.2.2 allow remote attackers to execute arbitrary SQL commands via (1)
23RIESGO
abrir
ReferênciaVexDay Proof
Attachmax Dolphin 2.1.0 - Multiple Vulnerabilities
CVE-2008-4205webappsphp
SQL injection vulnerability in search.php Attachmax Dolphin 2.1.0 and earlier allows remote attackers to execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
NetRisk 2.0 - Cross-Site Scripting / SQL Injection
CVE-2008-4887webappsphp
SQL injection vulnerability in index.php in NetRisk 2.0 and earlier allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
ReferênciaVexDay Proof
SiteEngine 5.x - Multiple Vulnerabilities
CVE-2008-7267webappsphp
SQL injection vulnerability in announcements.php in SiteEngine 5.x allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
ReferênciaVexDay Proof
MOTIONBORG Web Real Estate 2.1 - SQL Injection
CVE-2007-0196webappsasp
SQL injection vulnerability in admin_check_user.asp in Motionborg Web Real Estate 2.1 and earlier allows remote attacker
23RIESGO
abrir
ReferênciaVexDay Proof
MyFWB 1.0 - 'index.php' SQL Injection
CVE-2008-5097webappsphp
SQL injection vulnerability in index.php in MyFWB 1.0 allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir
ReferênciaVexDay Proof
DreamPics Photo/Video Gallery - Blind SQL Injection
CVE-2009-0445webappsphp
SQL injection vulnerability in index.php in Dreampics Gallery Builder allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
ReferênciaVexDay Proof
HLStats 1.34 - 'hlstats.php' SQL Injection
CVE-2006-6780webappsphp
SQL injection vulnerability in the login form in HLstats 1.20 through 1.34 allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
AssetMan 2.5-b - SQL Injection using Session Fixation
CVE-2008-4161webappsphp
SQL injection vulnerability in search_inv.php in Assetman 2.5b allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
MemHT Portal 3.9.0 - Remote Create Shell
CVE-2008-4164webappsphp
cron.php in MemHT Portal 3.9.0 and earlier allows remote attackers to obtain sensitive information via a direct request,
23RIESGO
abrir
anteriorpágina 106 / 188siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.