Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
Visagesoft eXPert PDF ViewerX - 'VSPDFViewerX.ocx' File Overwrite
CVE-2008-4919remotewindows
Insecure method vulnerability in VISAGESOFT eXPert PDF Viewer X ActiveX control (VSPDFViewerX.ocx) 3.0.990.0 allows remo
23RIESGO
abrir
ReferênciaVexDay Proof
DjVu - ActiveX Control 3.0 ImageURL Property Overflow
CVE-2008-4922remotewindows
Buffer overflow in the DjVu ActiveX Control 3.0 for Microsoft Office (DjVu_ActiveX_MSOffice.dll) allows remote attackers
50RIESGO
abrir
ReferênciaVexDay Proof
MW6 Aztec - ActiveX 'Aztec.dll' Remote Insecure Method
CVE-2008-4923remotewindows
Multiple insecure method vulnerabilities in MW6 Technologies Aztec ActiveX control (AZTECLib.MW6Aztec, Aztec.dll) 3.0.0.
23RIESGO
abrir
ReferênciaVexDay Proof
MW6 Barcode - ActiveX 'Barcode.dll' Insecure Method
CVE-2008-4924remotewindows
Multiple insecure method vulnerabilities in MW6 Technologies 1D Barcode ActiveX control (BARCODELib.MW6Barcode, Barcode.
23RIESGO
abrir
ReferênciaVexDay Proof
MyForum 1.3 - Insecure Cookie Handling
CVE-2008-5040webappsphp
Graphiks MyForum 1.3 allows remote attackers to bypass authentication and gain administrative access by setting the (1)
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component JooBlog 0.1.1 - 'PostID' SQL Injection
CVE-2008-5051webappsphp
SQL injection vulnerability in the JooBlog (com_jb2) component 0.1.1 for Joomla! allows remote attackers to execute arbi
23RIESGO
abrir
ReferênciaVexDay Proof
DevelopItEasy Membership System 1.3 - Authentication Bypass
CVE-2008-5054webappsphp
Multiple SQL injection vulnerabilities in Develop It Easy Membership System 1.3 allow remote attackers to execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
Agares ThemeSiteScript 1.0 - 'loadadminpage' Remote File Inclusion
CVE-2008-5066webappsphp
PHP remote file inclusion vulnerability in upload/admin/frontpage_right.php in Agares Media ThemeSiteScript 1.0 allows r
23RIESGO
abrir
ReferênciaVexDay Proof
PromoteWeb MySQL - 'id' SQL Injection
CVE-2008-5069webappsphp
SQL injection vulnerability in go.php in Panuwat PromoteWeb MySQL, when magic_quotes_gpc is disabled, allows remote atta
23RIESGO
abrir
ReferênciaVexDay Proof
Pro Chat Rooms 3.0.3 - SQL Injection
CVE-2008-5070webappsphp
SQL injection vulnerability in Pro Chat Rooms 3.0.3, when magic_quotes_gpc is disabled, allows remote attackers to execu
23RIESGO
abrir
ReferênciaVexDay Proof
Yoxel 1.23beta - 'itpm_estimate.php' Remote Code Execution
CVE-2008-5071webappsphp
Multiple eval injection vulnerabilities in itpm_estimate.php in Yoxel 1.23beta and earlier allow remote authenticated us
23RIESGO
abrir
ReferênciaVexDay Proof
CCLeague Pro 1.2 - Insecure Cookie Authentication
CVE-2008-5123webappsphp
SQL injection vulnerability in admin.php in CCleague Pro 1.2 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
ReferênciaVexDay Proof
SePortal 2.4 - 'poll_id' SQL Injection
CVE-2008-5191webappsphp
Multiple SQL injection vulnerabilities in SePortal 2.4 allow remote attackers to execute arbitrary SQL commands via the
43RIESGO
abrir
ReferênciaVexDay Proof
PHP-Fusion Mod Kroax 4.42 - 'category' SQL Injection
CVE-2008-5196webappsphp
SQL injection vulnerability in kroax.php in the Kroax (the_kroax) 4.42 and earlier module for PHP-Fusion allows remote a
23RIESGO
abrir
ReferênciaVexDay Proof
AJ Article 1.0 - 'featured_article.php' SQL Injection
CVE-2008-5213webappsphp
SQL injection vulnerability in featured_article.php in AJ Article 1.0 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
ReferênciaVexDay Proof
ClanLite 2.x - SQL Injection / Cross-Site Scripting
CVE-2008-5215webappsphp
SQL injection vulnerability in service/profil.php in ClanLite 2.2006.05.20 allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
wPortfolio 0.3 - Arbitrary File Upload
CVE-2008-5220webappsphp
Unrestricted file upload vulnerability in admin/upload_form.php in wPortfolio 0.3 and earlier allows remote attackers to
28RIESGO
abrir
ReferênciaVexDay Proof
Experts 1.0.0 - 'answer.php' SQL Injection
CVE-2008-5267webappsphp
SQL injection vulnerability in answer.php in Experts 1.0.0, when magic_quotes_gpc is disabled, allows remote attackers t
23RIESGO
abrir
ReferênciaVexDay Proof
ASPPortal Free Version - 'Topic_Id' SQL Injection
CVE-2008-5268webappsasp
SQL injection vulnerability in content/forums/reply.asp in ASPPortal allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir
ReferênciaVexDay Proof
pSys 0.7.0.a - 'shownews' SQL Injection
CVE-2008-5269webappsphp
SQL injection vulnerability in index.php in pSys 0.7.0 alpha allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
ReferênciaVexDay Proof
Yuhhu 2008 SuperStar - 'board' SQL Injection
CVE-2008-5270webappsphp
SQL injection vulnerability in view.topics.php in Yuhhu Superstar 2008 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
Professional Download Assistant 0.1 - Authentication Bypass
CVE-2008-5571webappsasp
SQL injection vulnerability in admin/login.asp in Professional Download Assistant 0.1 allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
Professional Download Assistant 0.1 - Database Disclosure
CVE-2008-5572webappsasp
Professional Download Assistant 0.1 stores sensitive information under the web root with insufficient access control, wh
23RIESGO
abrir
ReferênciaVexDay Proof
sCssBoard (Multiple Versions) - 'pwnpack' Remote s
CVE-2008-5578webappsphp
Multiple SQL injection vulnerabilities in index.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allow remote attackers to exec
23RIESGO
abrir
ReferênciaVexDay Proof
Nukedit 4.9.x - Remote Create Admin
CVE-2008-5582webappsphp
SQL injection vulnerability in utilities/login.asp in Nukedit 4.9.x, and possibly earlier, allows remote attackers to ex
23RIESGO
abrir
ReferênciaVexDay Proof
lcxbbportal 0.1 alpha 2 - Remote File Inclusion
CVE-2008-5585webappsphp
Multiple PHP remote file inclusion vulnerabilities in lcxBBportal 0.1 Alpha 2 allow remote attackers to execute arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
Merlix Teamworx Server - File Disclosure/Bypass
CVE-2008-5599webappsphp
SQL injection vulnerability in default.asp in Merlix Teamworx Server allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir
ReferênciaVexDay Proof
QMail Mailing List Manager 1.2 - Database Disclosure
CVE-2008-5606webappsasp
Gazatem QMail Mailing List Manager 1.2 stores sensitive information under the web root with insufficient access control,
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component JMovies 1.1 - 'id' SQL Injection
CVE-2008-5607webappsphp
SQL injection vulnerability in the JMovies (aka JM or com_jmovies) component 1.1 for Joomla! allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
ASP AutoDealer - Remote Database Disclosure
CVE-2008-5608webappsasp
ASP AutoDealer stores sensitive information under the web root with insufficient access control, which allows remote att
23RIESGO
abrir
anteriorpágina 122 / 188siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.