Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.210exploits catalogados
36.420CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
Diesel Job Site - 'job_id' Blind SQL Injection
CVE-2008-6467webappsphp
SQL injection vulnerability in jobs/jobseekers/job-info.php in Diesel Job Site allows remote attackers to execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
Diesel Pay Script - 'area' SQL Injection
CVE-2008-6468webappsphp
SQL injection vulnerability in index.php in Diesel Pay allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir
ReferênciaVexDay Proof
Plaincart 1.1.2 - 'p' SQL Injection
CVE-2008-6469webappsphp
SQL injection vulnerability in index.php in PlainCart 1.1.2 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir
ReferênciaVexDay Proof
Ktools Photostore 3.5.2 - Multiple SQL Injections
CVE-2008-6648webappsphp
SQL injection vulnerability in crumbs.php in Ktools PhotoStore 3.4.3 and 3.5.2 allows remote attackers to execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
miniBloggie 1.0 - 'del.php' Arbitrary Delete Post
CVE-2008-6650webappsphp
del.php in miniBloggie 1.0 allows remote attackers to delete arbitrary posts via a direct request with a modified post_i
23RIESGO
abrir
ReferênciaVexDay Proof
OxYProject 0.85 - 'edithistory.php' Remote Code Execution
CVE-2008-6651webappsphp
Static code injection vulnerability in edithistory.php in OxYProject OxYBox 0.85 allows remote attackers to inject arbit
23RIESGO
abrir
ReferênciaVexDay Proof
phpAuction - 'profile.php' SQL Injection (1)
CVE-2008-6663webappsphp
SQL injection vulnerability in profile.php in PHPAuctions.info PHPAuctions (aka PHPAuctionSystem) allows remote attacker
23RIESGO
abrir
ReferênciaVexDay Proof
nweb2fax 0.2.7 - Multiple Vulnerabilities
CVE-2008-6669webappsphp
viewrq.php in nweb2fax 0.2.7 and earlier allows remote attackers to execute arbitrary code via shell metacharacters in t
23RIESGO
abrir
ReferênciaVexDay Proof
Pre Real Estate Listings - Authentication Bypass
CVE-2008-6796webappsphp
SQL injection vulnerability in manager/login.php in Pre Projects Pre Real Estate Listings allows remote attackers to exe
23RIESGO
abrir
ReferênciaVexDay Proof
Pre Real Estate Listings - Arbitrary File Upload
CVE-2008-6798webappsphp
Multiple SQL injection vulnerabilities in login.php in Pre Projects Pre Real Estate Listings allow remote attackers to e
23RIESGO
abrir
ReferênciaVexDay Proof
Tribiq CMS 5.0.9a (Beta) - Insecure Cookie Handling
CVE-2008-6804webappsphp
Tribiq CMS 5.0.9a beta allows remote attackers to bypass authentication and gain administrative access by setting the CO
23RIESGO
abrir
ReferênciaVexDay Proof
7Shop 1.1 - Arbitrary File Upload
CVE-2008-6806webappsphp
Unrestricted file upload vulnerability in includes/imageupload.php in 7Shop 1.1 and earlier allows remote attackers to e
23RIESGO
abrir
ReferênciaVexDay Proof
SFS EZ Link Directory - 'cat_id' SQL Injection
CVE-2008-6808webappsphp
SQL injection vulnerability in links.php in Scripts for Sites (SFS) EZ Link Directory allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
Booking Centre 2.01 - 'HotelID' SQL Injection
CVE-2008-6809webappsphp
SQL injection vulnerability in hotel_habitaciones.php in Venalsur Booking Centre Booking System for Hotels Group 2.01 al
23RIESGO
abrir
ReferênciaVexDay Proof
Booking Centre 2.01 - Authentication Bypass
CVE-2008-6810webappsphp
Multiple SQL injection vulnerabilities in admin/checklogin.php in Venalsur Booking Centre Booking System for Hotels Grou
23RIESGO
abrir
ReferênciaVexDay Proof
PHPwebnews 0.2 MySQL Edition - 'det' SQL Injection
CVE-2008-6812webappsphp
SQL injection vulnerability in bukutamu.php in phpWebNews 0.2 MySQL Edition allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
Absolute Banner Manager - Insecure Cookie Handling
CVE-2008-6858webappsphp
Absolute Banner Manager .NET 4.0 allows remote attackers to bypass authentication and gain administrative access by sett
23RIESGO
abrir
ReferênciaVexDay Proof
Absolute Control Panel XE 1.5 - Insecure Cookie Handling
CVE-2008-6859webappsphp
Xigla Software Absolute Control Panel XE 1.5 allows remote attackers to bypass authentication and gain administrative ac
23RIESGO
abrir
ReferênciaVexDay Proof
Absolute NewsLetter 6.1 - Insecure Cookie Handling
CVE-2008-6861webappsphp
Xigla Software Absolute Newsletter 6.0 and 6.1 allows remote attackers to bypass authentication and gain administrative
23RIESGO
abrir
ReferênciaVexDay Proof
Absolute Content Rotator 6.0 - Insecure Cookie Handling
CVE-2008-6862webappsphp
Absolute Content Rotator 6.0 allows remote attackers to bypass authentication and gain administrative access by setting
23RIESGO
abrir
ReferênciaVexDay Proof
Absolute Live Support 5.1 - Insecure Cookie Handling
CVE-2008-6864webappsphp
Xigla Software Absolute Live Support .NET 5.1 allows remote attackers to bypass authentication and gain administrative a
23RIESGO
abrir
ReferênciaVexDay Proof
merlix educate servert - Authentication Bypass / File Disclosure
CVE-2008-6870webappsasp
Merlix Educate Server allows remote attackers to bypass intended security restrictions and obtain sensitive information
23RIESGO
abrir
ReferênciaVexDay Proof
merlix educate servert - Authentication Bypass / File Disclosure
CVE-2008-6871webappsasp
Merlix Educate Server stores db.mdb under the web root with insufficient access control, which allows remote attackers t
23RIESGO
abrir
ReferênciaVexDay Proof
Active Web Mail 4 - Blind SQL Injection
CVE-2008-6873webappsasp
SQL injection vulnerability in Active Web Mail 4.0 allows remote attackers to execute arbitrary SQL commands via the Tab
23RIESGO
abrir
ReferênciaVexDay Proof
ASPSiteWare Automotive Dealer 1.0/2.0 - SQL Injection
CVE-2008-6874webappsphp
Multiple SQL injection vulnerabilities in ASP SiteWare autoDealer 1 and 2 allow remote attackers to execute arbitrary SQ
23RIESGO
abrir
ReferênciaVexDay Proof
exV2 < 2.0.4.3 - 'extract()' Remote Command Execution
CVE-2006-7080webappsphp
Directory traversal vulnerability in the avatar upload feature in exV2 2.0.4.3 and earlier allows remote attackers to de
23RIESGO
abrir
ReferênciaVexDay Proof
Simple Machines Forum (SMF) 1.1.5 (Windows x86) - Admin Reset Password
CVE-2008-6971webappsphp
The password reset functionality in Simple Machines Forum (SMF) 1.0.x before 1.0.14, 1.1.x before 1.1.6, and 2.0 before
23RIESGO
abrir
ReferênciaVexDay Proof
phpBB ezBoard Converter 0.2 - 'ezconvert_dir' Remote File Inclusion
CVE-2007-0761webappsphp
PHP remote file inclusion vulnerability in config.php in phpBB ezBoard converter (ezconvert) 0.2 allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
phpBB++ Build 100 - 'phpbb_root_path' Remote File Inclusion
CVE-2007-0762webappsphp
PHP remote file inclusion vulnerability in includes/functions.php in phpBB++ Build 100 allows remote attackers to execut
23RIESGO
abrir
ReferênciaVexDay Proof
Rigter Portal System (RPS) 6.2 - Blind SQL Injection
CVE-2007-1293webappsphp
SQL injection vulnerability in Rigter Portal System (RPS) 6.2, when magic_quotes_gpc is disabled, allows remote attacker
23RIESGO
abrir
anteriorpágina 115 / 188siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.