Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.207exploits catalogados
36.419CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
MyTopix 1.3.0 - SQL Injection
CVE-2008-6330webappsphp
SQL injection vulnerability in index.php in MyTopix 1.3.0 and earlier allows remote authenticated users to execute arbit
23RIESGO
abrir
ReferênciaVexDay Proof
Simple Customer 1.2 - Authentication Bypass
CVE-2008-6332webappsphp
SQL injection vulnerability in login.php in Simple Customer 1.2 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
ReferênciaVexDay Proof
RSS Simple News - SQL Injection
CVE-2008-6333webappsphp
SQL injection vulnerability in news.php in RSS Simple News (RSSSN), when magic_quotes_gpc is disabled, allows remote att
23RIESGO
abrir
ReferênciaVexDay Proof
PostNuke 0.763 - 'PNSV lang' Remote Code Execution
CVE-2006-5733webappsphp
Directory traversal vulnerability in error.php in PostNuke 0.763 and earlier allows remote attackers to include and exec
23RIESGO
abrir
ReferênciaVexDay Proof
Calendar MX Professional 2.0.0 - Blind SQL Injection
CVE-2008-6378webappsasp
SQL injection vulnerability in calendar_Eventupdate.asp in Calendar Mx Professional 2.0.0 allows remote attackers to exe
23RIESGO
abrir
ReferênciaVexDay Proof
Gallery MX 2.0.0 - Blind SQL Injection
CVE-2008-6379webappsasp
SQL injection vulnerability in pics_pre.asp in Gallery MX 2.0.0 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
ReferênciaVexDay Proof
6rbScript 3.3 - 'section.php' Local File Inclusion
CVE-2008-6453webappsphp
Directory traversal vulnerability in section.php in 6rbScript 3.3, when magic_quotes_gpc is disabled, allows remote atta
23RIESGO
abrir
ReferênciaVexDay Proof
6rbScript 3.3 - 'singerid' SQL Injection
CVE-2008-6454webappsphp
SQL injection vulnerability in section.php in 6rbScript 3.3 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir
ReferênciaVexDay Proof
e107 Plugin Image Gallery 0.9.6.2 - SQL Injection
CVE-2008-6466webappsphp
SQL injection vulnerability in image_gallery.php in the Akira Powered Image Gallery (image_gallery) plugin 0.9.6.2 for e
23RIESGO
abrir
ReferênciaVexDay Proof
Diesel Job Site - 'job_id' Blind SQL Injection
CVE-2008-6467webappsphp
SQL injection vulnerability in jobs/jobseekers/job-info.php in Diesel Job Site allows remote attackers to execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
Diesel Pay Script - 'area' SQL Injection
CVE-2008-6468webappsphp
SQL injection vulnerability in index.php in Diesel Pay allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir
ReferênciaVexDay Proof
Plaincart 1.1.2 - 'p' SQL Injection
CVE-2008-6469webappsphp
SQL injection vulnerability in index.php in PlainCart 1.1.2 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir
ReferênciaVexDay Proof
WEBBDOMAIN Post Card 1.02 - 'catid' SQL Injection
CVE-2008-6622webappsphp
SQL injection vulnerability in choosecard.php in WEBBDOMAIN Post Card (aka Web Postcards) 1.02, 1.01, and earlier allows
23RIESGO
abrir
ReferênciaVexDay Proof
WEBBDOMAIN Petition 1.02/2.0/3.0 - Authentication Bypass
CVE-2008-6624webappsphp
SQL injection vulnerability in getin.php in WEBBDOMAIN Petition 1.02, 2.0, and 3.0 allows remote attackers to execute ar
23RIESGO
abrir
ReferênciaVexDay Proof
MercuryBoard 1.1.5 - 'login.php' Blind SQL Injection
CVE-2008-6632webappsphp
SQL injection vulnerability in func/login.php in MercuryBoard 1.1.5 and earlier allows remote attackers to execute arbit
23RIESGO
abrir
ReferênciaVexDay Proof
RoomPHPlanning 1.5 - 'idresa' SQL Injection
CVE-2008-6633webappsphp
SQL injection vulnerability in RoomPHPlanning 1.5 allows remote attackers to execute arbitrary SQL commands via the idre
23RIESGO
abrir
ReferênciaVexDay Proof
RoomPHPlanning 1.5 - Multiple SQL Injections
CVE-2008-6634webappsphp
SQL injection vulnerability in RoomPHPlanning 1.5 allows remote attackers to execute arbitrary SQL commands via the idro
23RIESGO
abrir
ReferênciaVexDay Proof
phpAuction - 'profile.php' SQL Injection (1)
CVE-2008-6663webappsphp
SQL injection vulnerability in profile.php in PHPAuctions.info PHPAuctions (aka PHPAuctionSystem) allows remote attacker
23RIESGO
abrir
ReferênciaVexDay Proof
nweb2fax 0.2.7 - Multiple Vulnerabilities
CVE-2008-6669webappsphp
viewrq.php in nweb2fax 0.2.7 and earlier allows remote attackers to execute arbitrary code via shell metacharacters in t
23RIESGO
abrir
ReferênciaVexDay Proof
Pre Real Estate Listings - Authentication Bypass
CVE-2008-6796webappsphp
SQL injection vulnerability in manager/login.php in Pre Projects Pre Real Estate Listings allows remote attackers to exe
23RIESGO
abrir
ReferênciaVexDay Proof
Pre Real Estate Listings - Arbitrary File Upload
CVE-2008-6798webappsphp
Multiple SQL injection vulnerabilities in login.php in Pre Projects Pre Real Estate Listings allow remote attackers to e
23RIESGO
abrir
ReferênciaVexDay Proof
Tribiq CMS 5.0.9a (Beta) - Insecure Cookie Handling
CVE-2008-6804webappsphp
Tribiq CMS 5.0.9a beta allows remote attackers to bypass authentication and gain administrative access by setting the CO
23RIESGO
abrir
ReferênciaVexDay Proof
7Shop 1.1 - Arbitrary File Upload
CVE-2008-6806webappsphp
Unrestricted file upload vulnerability in includes/imageupload.php in 7Shop 1.1 and earlier allows remote attackers to e
23RIESGO
abrir
ReferênciaVexDay Proof
SFS EZ Link Directory - 'cat_id' SQL Injection
CVE-2008-6808webappsphp
SQL injection vulnerability in links.php in Scripts for Sites (SFS) EZ Link Directory allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
Booking Centre 2.01 - 'HotelID' SQL Injection
CVE-2008-6809webappsphp
SQL injection vulnerability in hotel_habitaciones.php in Venalsur Booking Centre Booking System for Hotels Group 2.01 al
23RIESGO
abrir
ReferênciaVexDay Proof
Booking Centre 2.01 - Authentication Bypass
CVE-2008-6810webappsphp
Multiple SQL injection vulnerabilities in admin/checklogin.php in Venalsur Booking Centre Booking System for Hotels Grou
23RIESGO
abrir
ReferênciaVexDay Proof
PHPwebnews 0.2 MySQL Edition - 'det' SQL Injection
CVE-2008-6812webappsphp
SQL injection vulnerability in bukutamu.php in phpWebNews 0.2 MySQL Edition allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
Calendar MX BASIC 1.0.2 - 'ID' SQL Injection
CVE-2006-6792webappsasp
SQL injection vulnerability in calendar_detail.asp in Calendar MX BASIC 1.0.2 and earlier allows remote attackers to exe
23RIESGO
abrir
ReferênciaVexDay Proof
ExoPHPDesk 1.2 Final - Authentication Bypass
CVE-2008-6917webappsphp
SQL injection vulnerability in admin.php in Exocrew ExoPHPDesk 1.2 Final allows remote attackers to execute arbitrary SQ
23RIESGO
abrir
ReferênciaVexDay Proof
ThePortal 2.2 - Arbitrary File Upload
CVE-2008-6918webappsphp
Unrestricted file upload vulnerability in admin/galeria.php in ThePortal2 2.2 allows remote attackers to execute arbitra
23RIESGO
abrir
anteriorpágina 113 / 188siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.