Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
plx Ad Trader 3.2 - 'adid' SQL Injection
CVE-2008-3025webappsphp
SQL injection vulnerability in ad.php in plx Ad Trader 3.2 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
ReferênciaVexDay Proof
Live Music Plus 1.1.0 - 'id' SQL Injection
CVE-2008-3352webappsphp
SQL injection vulnerability in index.php in Live Music Plus 1.1.0 allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir
ReferênciaVexDay Proof
Pligg CMS 9.9.0 - 'story.php' SQL Injection
CVE-2008-3366webappsphp
SQL injection vulnerability in story.php in Pligg CMS Beta 9.9.0 allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
ReferênciaVexDay Proof
deeemm CMS (dmcms) 0.7.4 - Multiple Vulnerabilities
CVE-2008-3720webappsphp
SQL injection vulnerability in index.php in DeeEmm CMS (DMCMS) 0.7.4 allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir
ReferênciaVexDay Proof
MyCard 1.0.2 - 'id' SQL Injection
CVE-2008-4738webappsphp
SQL injection vulnerability in gallery.php in MyCard 1.0.2 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
ReferênciaVexDay Proof
AIOCP 1.4 - 'poll_id' SQL Injection
CVE-2008-4782webappsphp
SQL injection vulnerability in public/code/cp_polls_results.php in All In One Control Panel (AIOCP) 1.4 allows remote at
23RIESGO
abrir
ReferênciaVexDay Proof
ASPSiteWare Home Builder 1.0/2.0 - SQL Injection
CVE-2008-5774webappsasp
Multiple SQL injection vulnerabilities in ASPSiteWare HomeBuilder 1.0 and 2.0 allow remote attackers to execute arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
Mediatheka 4.2 - Blind SQL Injection
CVE-2008-5895webappsphp
SQL injection vulnerability in connection.php in Mediatheka 4.2 and earlier allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
AJSquare Free Polling Script - 'DB' Multiple Vulnerabilities
CVE-2008-7044webappsphp
SQL injection vulnerability in admin/include/newpoll.php in AJ Square Free Polling Script (AJPoll) Database version allo
23RIESGO
abrir
ReferênciaVexDay Proof
chernobiLe Portal 1.0 - 'default.asp' SQL Injection
CVE-2007-0582webappsasp
SQL injection vulnerability in default.asp in ChernobiLe 1.0 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
ReferênciaVexDay Proof
WBB2-Addon: Acrotxt 1.0 - 'show' SQL Injection
CVE-2007-4581webappsphp
SQL injection vulnerability in acrotxt.php in WBB2-Addon: Acrotxt 1 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
ReferênciaVexDay Proof
KwsPHP 1.0 mg2 Module - SQL Injection
CVE-2007-5485webappsphp
SQL injection vulnerability in index.php in the mg2 1.0 module for KwsPHP allows remote attackers to execute arbitrary S
23RIESGO
abrir
ReferênciaVexDay Proof
MiniBB 2.1 - 'table' SQL Injection
CVE-2007-5719webappsphp
SQL injection vulnerability in bb_func_search.php in miniBB 2.1 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
ReferênciaVexDay Proof
emagiC CMS.Net 4.0 - 'emc.asp' SQL Injection
CVE-2007-5783webappsasp
SQL injection vulnerability in emc.asp in emagiC CMS.Net 4.0 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
ReferênciaVexDay Proof
MMSLamp - 'idpro' SQL Injection
CVE-2007-6575webappsphp
SQL injection vulnerability in default.php in MMSLamp allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir
ReferênciaVexDay Proof
PHP ZLink 0.3 - 'go.php' SQL Injection
CVE-2007-6578webappsphp
SQL injection vulnerability in go.php in PHP ZLink 0.3 allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir
ReferênciaVexDay Proof
ClipShare - 'UID' SQL Injection
CVE-2008-0089webappsphp
SQL injection vulnerability in uprofile.php in ClipShare allows remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir
ReferênciaVexDay Proof
SCO UnixWare < 7.1.4 p534589 - 'pkgadd' Local Privilege Escalation
CVE-2008-0310localsco
Directory traversal vulnerability in pkgadd in SCO UnixWare 7.1.4 before p534589 allows local users to create or append
23RIESGO
abrir
ReferênciaVexDay Proof
EasyWay CMS - 'mid' SQL Injection
CVE-2008-2555webappsphp
SQL injection vulnerability in index.php in EasyWay CMS allows remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir
ReferênciaVexDay Proof
GLLCTS2 < 4.2.4 - 'detail' SQL Injection
CVE-2008-2746webappsphp
SQL injection vulnerability in login.php in Gryphon gllcTS2 4.2.4 allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir
ReferênciaVexDay Proof
HoMaP-CMS 0.1 - 'go' SQL Injection
CVE-2008-2989webappsphp
SQL injection vulnerability in index.php in HoMaP-CMS 0.1 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
ReferênciaVexDay Proof
CMS WebBlizzard - 'index.php' Blind SQL Injection
CVE-2008-3154webappsphp
SQL injection vulnerability in index.php in WebBlizzard CMS allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir
ReferênciaVexDay Proof
pLink 2.07 - 'linkto.php' Blind SQL Injection
CVE-2008-4357webappsphp
SQL injection vulnerability in linkto.php in Powie pLink 2.07 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
DESlock+ 3.2.7 - 'vdlptokn.sys' Local Denial of Service
CVE-2008-4362doswindows
The Virtual Token driver (vdlptokn.sys) 1.0.2.43 in DESlock+ 3.2.7 allows local users to cause a denial of service (syst
23RIESGO
abrir
ReferênciaVexDay Proof
DESlock+ < 3.2.7 - 'probe read' Local Kernel Denial of Service (PoC)
CVE-2008-4363doswindows
DLMFENC.sys 1.0.0.28 in DESlock+ 3.2.7 allows local users to cause a denial of service (system crash) or potentially exe
23RIESGO
abrir
ReferênciaVexDay Proof
YourFreeWorld Autoresponder Hosting - 'tr.php' SQL Injection
CVE-2008-4882webappsphp
SQL injection vulnerability in tr.php in YourFreeWorld Autoresponder Hosting Script allows remote attackers to execute a
23RIESGO
abrir
ReferênciaVexDay Proof
WebCal - 'webCal3_detail.asp?event_id' SQL Injection
CVE-2009-1945webappsphp
SQL injection vulnerability in webCal3_detail.asp in WebCal 3.04 allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
ReferênciaVexDay Proof
Open Biller 0.1 - 'Username' Blind SQL Injection
CVE-2009-2036webappsphp
SQL injection vulnerability in index.php in Open Biller 0.1 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir
ReferênciaVexDay Proof
WebCMS Portal Edition - 'id' SQL Injection
CVE-2008-3213webappsphp
SQL injection vulnerability in secciones/tablon/tablon.php in WebCMS Portal Edition allows remote attackers to execute a
23RIESGO
abrir
ReferênciaVexDay Proof
Affiliate Directory - 'id' SQL Injection
CVE-2008-3719webappsphp
SQL injection vulnerability in directory.php in SFS Affiliate Directory allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
anteriorpágina 125 / 188siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.