Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
miniBloggie 1.0 - 'del.php' Blind SQL Injection
CVE-2008-4628webappsphp
SQL injection vulnerability in del.php in myWebland miniBloggie 1.0 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
ReferênciaVexDay Proof
Catviz 0.4.0 beta1 - Multiple SQL Injections
CVE-2008-3129webappsphp
Multiple SQL injection vulnerabilities in index.php in Catviz 0.4 beta 1 allow remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
pSys 0.7.0 Alpha - 'chatbox.php' SQL Injection
CVE-2008-3131webappsphp
SQL injection vulnerability in chatbox.php in pSys 0.7.0 Alpha, when magic_quotes_gpc is disabled, allows remote attacke
23RIESGO
abrir
ReferênciaVexDay Proof
GNUBoard 4.31.03 (08.12.29) - Local File Inclusion
CVE-2009-0290webappsphp
Directory traversal vulnerability in common.php in SIR GNUBoard 4.31.03 allows remote attackers to include and execute a
23RIESGO
abrir
ReferênciaVexDay Proof
Wazzum Dating Software - 'userid' SQL Injection
CVE-2009-0293webappsphp
SQL injection vulnerability in profile_view.php in Wazzum Dating Software, possibly 2.0, allows remote attackers to exec
23RIESGO
abrir
ReferênciaVexDay Proof
BareNuked CMS 1.1.0 - Arbitrary Add Admin
CVE-2008-3133webappsphp
SQL injection vulnerability in admin/index.php in BareNuked CMS 1.1.0, when magic_quotes_gpc is disabled, allows remote
23RIESGO
abrir
ReferênciaVexDay Proof
AShop Deluxe 4.x - 'catalogue.php' SQL Injection
CVE-2008-3136webappsphp
SQL injection vulnerability in catalogue.php in AShop Deluxe 4.x allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
ReferênciaVexDay Proof
SmartPPC Pay Per Click Script - 'idDirectory' Blind SQL Injection (1)
CVE-2008-3152webappsphp
SQL injection vulnerability in directory.php in SmartPPC and SmartPPC Pro allows remote attackers to execute arbitrary S
23RIESGO
abrir
ReferênciaVexDay Proof
SmartPPC Pay Per Click Script - 'idDirectory' Blind SQL Injection (2)
CVE-2008-3152webappsphp
SQL injection vulnerability in directory.php in SmartPPC and SmartPPC Pro allows remote attackers to execute arbitrary S
23RIESGO
abrir
ReferênciaVexDay Proof
Triton CMS Pro 1.06 - 'x-forwarded-for' Blind SQL Injection
CVE-2008-3153webappsphp
SQL injection vulnerability in Triton CMS Pro allows remote attackers to execute arbitrary SQL commands via the X-Forwar
23RIESGO
abrir
ReferênciaVexDay Proof
CMS WebBlizzard - 'index.php' Blind SQL Injection
CVE-2008-3154webappsphp
SQL injection vulnerability in index.php in WebBlizzard CMS allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir
ReferênciaVexDay Proof
Fuzzylime CMS 3.01 - Remote Command Execution
CVE-2008-3165webappsphp
Directory traversal vulnerability in rss.php in fuzzylime (cms) 3.01a and earlier, when magic_quotes_gpc is disabled, al
23RIESGO
abrir
ReferênciaVexDay Proof
Boonex Dolphin 6.1.2 - Multiple Remote File Inclusions
CVE-2008-3167webappsphp
Multiple PHP remote file inclusion vulnerabilities in BoonEx Dolphin 6.1.2, when register_globals is enabled, allow remo
23RIESGO
abrir
ReferênciaVexDay Proof
ContentNow 1.4.1 - Arbitrary File Upload / Cross-Site Scripting
CVE-2008-3180webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in upload/file/language_menu.php in ContentNow CMS 1.4.1 allow remot
23RIESGO
abrir
ReferênciaVexDay Proof
phpdaily - SQL Injection / Cross-Site Scripting / Local File Download
CVE-2008-4758webappsphp
Directory traversal vulnerability in download_file.php in PHP-Daily allows remote attackers to read arbitrary local file
23RIESGO
abrir
ReferênciaVexDay Proof
freeSSHd 1.2.1 - (Authenticated) SFTP 'realpath' Remote Buffer Overflow (PoC)
CVE-2008-4762doswindows
Stack-based buffer overflow in freeSSHd 1.2.1 allows remote authenticated users to cause a denial of service (service cr
28RIESGO
abrir
ReferênciaVexDay Proof
ITLPoll 2.7 Stable2 - Blind SQL Injection
CVE-2009-0295webappsphp
SQL injection vulnerability in index.php in Information Technology Light Poll Information (ITLPoll) 2.7 Stable 2, when m
23RIESGO
abrir
ReferênciaVexDay Proof
Download Accelerator Plus DAP 8.x - '.m3u' Local Buffer Overflow
CVE-2008-3182localwindows
Stack-based buffer overflow in DAP.exe in Download Accelerator Plus (DAP) 7.0.1.3, 8.6.6.3, and other 8.x versions allow
23RIESGO
abrir
ReferênciaVexDay Proof
Pluck CMS 4.5.1 (Windows) - 'blogpost' Local File Inclusion
CVE-2008-3194webappsphp
Multiple directory traversal vulnerabilities in data/inc/themes/predefined_variables.php in pluck 4.5.1 allow remote att
23RIESGO
abrir
ReferênciaVexDay Proof
Groone's GLink ORGanizer 2.1 - 'cat' Blind SQL Injection
CVE-2009-0299webappsphp
SQL injection vulnerability in index.php in Groone GLinks 2.1 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
AuraCMS 2.2.2 - '/pages_data.php' Arbitrary Edit/Add/Delete
CVE-2008-3203webappsphp
js/pages/pages_data.php in AuraCMS 2.2 through 2.2.2 does not perform authentication, which allows remote attackers to a
23RIESGO
abrir
ReferênciaVexDay Proof
Million Pixels 3 - 'id_cat' SQL Injection
CVE-2008-3204webappsphp
SQL injection vulnerability in tops_top.php in E-topbiz Million Pixels 3 allows remote attackers to execute arbitrary SQ
23RIESGO
abrir
ReferênciaVexDay Proof
Pragyan CMS 2.6.2 - 'sourceFolder' Remote File Inclusion
CVE-2008-3207webappsphp
PHP remote file inclusion vulnerability in cms/modules/form.lib.php in Pragyan CMS 2.6.2, when register_globals is enabl
23RIESGO
abrir
ReferênciaVexDay Proof
Amaya Web Editor 11.0 - XML / HTML Parser
CVE-2009-0323doswindows
Multiple stack-based buffer overflows in W3C Amaya Web Browser 10.0 and 11.0 allow remote attackers to execute arbitrary
50RIESGO
abrir
ReferênciaVexDay Proof
Simple DNS Plus 5.0/4.1 - Remote Denial of Service
CVE-2008-3208doswindows
Simple DNS Plus 4.1, 5.0, and possibly other versions before 5.1.101 allows remote attackers to cause a denial of servic
23RIESGO
abrir
ReferênciaVexDay Proof
PHPizabi 0.848b C1 HFP1 - Remote Code Execution
CVE-2008-3239webappsphp
Unrestricted file upload vulnerability in the writeLogEntry function in system/v_cron_proc.php in PHPizabi 0.848b C1 HFP
23RIESGO
abrir
ReferênciaVexDay Proof
blogit! - SQL Injection / File Disclosure / Cross-Site Scripting
CVE-2009-0335webappsphp
Cross-site scripting (XSS) vulnerability in index.asp in Katy Whitton BlogIt! allows remote attackers to inject arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
ProFTPd - 'mod_mysql' Authentication Bypass
CVE-2009-0542remotemultiple
SQL injection vulnerability in ProFTPD Server 1.3.1 through 1.3.2rc2 allows remote attackers to execute arbitrary SQL co
45RIESGO
abrir
ReferênciaVexDay Proof
PPMate PPMedia Class - ActiveX Control Buffer Overflow (PoC)
CVE-2008-3242doswindows
Heap-based buffer overflow in the PPMedia Class ActiveX control in PPMPlayer.dll in PPMate 2.3.1.93 allows remote attack
28RIESGO
abrir
ReferênciaVexDay Proof
Arctic Issue Tracker 2.0.0 - 'filter' SQL Injection (1)
CVE-2008-3250webappsphp
SQL injection vulnerability in index.php in Arctic Issue Tracker 2.0.0 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.