Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
VideoGirls BiZ - Blind SQL Injection
CVE-2008-5292webappsphp
SQL injection vulnerability in view_snaps.php in VideoGirls BiZ allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
ReferênciaVexDay Proof
WebStudio eCatalogue - Blind SQL Injection
CVE-2008-5294webappsphp
SQL injection vulnerability in index.php in WebStudio eCatalogue allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
ReferênciaVexDay Proof
Bandwebsite 1.5 - SQL Injection / Cross-Site Scripting
CVE-2008-5337webappsphp
SQL injection vulnerability in lyrics.php in Bandwebsite (aka Bandsite portal system) 1.5 allows remote attackers to exe
23RIESGO
abrir
ReferênciaVexDay Proof
Cold BBS - Remote Database Disclosure
CVE-2008-5597webappsasp
Cold BBS stores sensitive information under the web root with insufficient access control, which allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
4Images 1.7.1 - Local File Inclusion / Remote Code Execution
CVE-2006-0899webappsphp
Directory traversal vulnerability in index.php in 4Images 1.7.1 and earlier allows remote attackers to read and include
23RIESGO
abrir
ReferênciaVexDay Proof
PHP-Fusion Mod TI - 'id' SQL Injection
CVE-2008-5733webappsphp
SQL injection vulnerability in blog.php in the Team Impact TI Blog System mod for PHP-Fusion allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
V3 Chat Profiles/Dating Script 3.0.2 - Authentication Bypass
CVE-2008-5785webappsphp
SQL injection vulnerability in V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
ReferênciaVexDay Proof
DELTAScripts PHP Classifieds 7.5 - SQL Injection
CVE-2008-5805webappsphp
SQL injection vulnerability in detail.php in DeltaScripts PHP Classifieds 7.5 and earlier allows remote attackers to exe
23RIESGO
abrir
ReferênciaVexDay Proof
PHPAlumni - SQL Injection
CVE-2008-5815webappsphp
SQL injection vulnerability in Acomment.php in phpAlumni allows remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir
ReferênciaVexDay Proof
eDContainer 2.22 - Local File Inclusion
CVE-2008-5818webappsphp
Directory traversal vulnerability in index.php in eDreamers eDContainer 2.22, when magic_quotes_gpc is disabled, allows
23RIESGO
abrir
ReferênciaVexDay Proof
clickandemail - SQL Injection / Cross-Site Scripting
CVE-2008-5892webappsasp
Multiple SQL injection vulnerabilities in ClickAndEmail allow remote attackers to execute arbitrary SQL commands via (1)
23RIESGO
abrir
ReferênciaVexDay Proof
Mediatheka 4.2 - 'lang' Local File Inclusion
CVE-2008-5894webappsphp
Directory traversal vulnerability in index.php in Mediatheka 4.2 allows remote attackers to include and execute arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
Umer Inc Songs Portal Script - 'id' SQL Injection
CVE-2008-5921webappsphp
SQL injection vulnerability in albums.php in Umer Inc Songs Portal allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
ReferênciaVexDay Proof
VP-ASP Shopping Cart 6.50 - Database Disclosure
CVE-2008-5929webappsasp
VP-ASP Shopping Cart 6.50 stores sensitive information under the web root with insufficient access control, which allows
23RIESGO
abrir
ReferênciaVexDay Proof
the net guys aspired2blog - SQL Injection / File Disclosure
CVE-2008-5931webappsasp
The Net Guys ASPired2Blog stores sensitive information under the web root with insufficient access control, which allows
23RIESGO
abrir
ReferênciaVexDay Proof
Ocean12 Mailing List Manager Gold - File Disclosure / SQL Injection / Cross-Site Scripting
CVE-2008-5978webappsphp
Multiple SQL injection vulnerabilities in Ocean12 Mailing List Manager Gold allow remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
Jetik Emlak ESA 2.0 - Multiple SQL Injections
CVE-2008-5992webappsphp
Multiple SQL injection vulnerabilities in Jetik Emlak Sistem A (ESA) 2.0 allow remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
DomPHP 0.81 - 'cat' SQL Injection
CVE-2008-6064webappsphp
Multiple SQL injection vulnerabilities in DomPHP 0.81 allow remote attackers to execute arbitrary SQL commands via the c
23RIESGO
abrir
ReferênciaVexDay Proof
Aztek Forum 4.00 - Cross-Site Scripting / SQL Injection
CVE-2006-1111webappsphp
Aztek Forum 4.0 allows remote attackers to obtain sensitive information via a "*/*" in the msg parameter to index.php, w
23RIESGO
abrir
ReferênciaVexDay Proof
Aztek Forum 4.00 - Cross-Site Scripting / SQL Injection
CVE-2006-1112webappsphp
Aztek Forum 4.0 allows remote attackers to obtain sensitive information via a long login value in a register form, which
23RIESGO
abrir
ReferênciaVexDay Proof
CSPartner 1.0 - Delete All Users / SQL Injection
CVE-2008-6165webappsphp
SQL injection vulnerability in gestion.php in CSPartner 0.1, when magic_quotes_gpc is disabled, allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
OWL Intranet Engine 0.82 - 'xrms_file_root' Code Execution
CVE-2006-1149webappsphp
PHP remote file inclusion vulnerability in lib/OWL_API.php in OWL Intranet Engine 0.82, when register_globals is enabled
23RIESGO
abrir
ReferênciaVexDay Proof
Ultrastats 0.2.144/0.3.11 - 'serverid' SQL Injection
CVE-2008-6260webappsphp
SQL injection vulnerability in index.php in Ultrastats 0.2.144 and 0.3.11 allows remote attackers to execute arbitrary S
23RIESGO
abrir
ReferênciaVexDay Proof
Apoll 0.7b - Authentication Bypass
CVE-2008-6270webappsphp
SQL injection vulnerability in admin/index.php in Dragan Mitic Apoll 0.7 beta and 0.7.5 allows remote attackers to execu
23RIESGO
abrir
ReferênciaVexDay Proof
E-topbiz ADManager 4 - 'group' Blind SQL Injection
CVE-2008-6261webappsphp
SQL injection vulnerability in view.php in E-topbiz AdManager 4 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
ReferênciaVexDay Proof
Cyberfolio 7.12.2 - 'theme' Local File Inclusion
CVE-2008-6265webappsphp
Directory traversal vulnerability in portfolio/css.php in Cyberfolio 7.12.2 and earlier allows remote attackers to inclu
23RIESGO
abrir
ReferênciaVexDay Proof
Apoll 0.7b - Authentication Bypass
CVE-2008-6272webappsphp
SQL injection vulnerability in admin/index.php in Dragan Mitic Apoll 0.7 beta and 0.7.5 allows remote attackers to execu
23RIESGO
abrir
ReferênciaVexDay Proof
Family Project 2.x - Authentication Bypass
CVE-2008-6274webappsphp
Multiple SQL injection vulnerabilities in index.php in FamilyProject 2.0 allow remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
Bluo CMS 1.2 - Blind SQL Injection
CVE-2008-6281webappsphp
SQL injection vulnerability in index.php in Bluo CMS 1.2 allows remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir
ReferênciaVexDay Proof
z1exchange 1.0 - 'site' SQL Injection
CVE-2008-6284webappsphp
SQL injection vulnerability in edit.php in Z1Exchange 1.0 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
anteriorpágina 127 / 188siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.