Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
Youtuber Clone - SQL Injection
CVE-2008-3419webappsphp
SQL injection vulnerability in ugroups.php in Youtuber Clone allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
ReferênciaVexDay Proof
Mobius 1.4.4.1 - SQL Injection
CVE-2008-3420webappsphp
Multiple SQL injection vulnerabilities in Mobius for Mimsy XG 1 1.4.4.1 and earlier allow remote attackers to execute ar
23RIESGO
abrir
ReferênciaVexDay Proof
phpMyRealty 2.0.0 - 'location' SQL Injection
CVE-2008-3445webappsphp
SQL injection vulnerability in index.php in phpMyRealty (PMR) 2.0.0 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
ReferênciaVexDay Proof
IPNPro3 < 1.44 - Admin Password Changing
CVE-2008-5568webappsphp
Cross-site request forgery (CSRF) vulnerability in admin/settings.php in IPN Pro 3 1.44 and earlier allows remote attack
23RIESGO
abrir
ReferênciaVexDay Proof
AdaptCMS Lite 1.4 - Cross-Site Scripting / Remote File Inclusion
CVE-2009-0526webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in index.php in AdaptCMS Lite 1.4 allow remote attackers to inject a
23RIESGO
abrir
ReferênciaVexDay Proof
LetterIt 2 - 'Language' Local File Inclusion
CVE-2008-3446webappsphp
Directory traversal vulnerability in inc/wysiwyg.php in LetterIt 2 allows remote attackers to include and execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
F-PROT AntiVirus 6.2.1.4252 - Malformed Archive Infinite Loop Denial of Service
CVE-2008-3447dosmultiple
The scanning engine in F-Prot Antivirus 6.2.1 4252 allows remote attackers to cause a denial of service (infinite loop)
23RIESGO
abrir
ReferênciaVexDay Proof
eNdonesia 8.4 (Calendar Module) - SQL Injection
CVE-2008-3452webappsphp
SQL injection vulnerability in the Calendar module in eNdonesia 8.4 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
ReferênciaVexDay Proof
PHP Hosting Directory 2.0 - Insecure Cookie Handling
CVE-2008-3454webappsphp
JnSHosts PHP Hosting Directory 2.0 allows remote attackers to bypass authentication and gain administrative access by se
23RIESGO
abrir
ReferênciaVexDay Proof
WebMaster Marketplace - SQL Injection
CVE-2008-5574webappsphp
SQL injection vulnerability in member.php in Webmaster Marketplace allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
ReferênciaVexDay Proof
PHP Hosting Directory 2.0 - Remote File Inclusion
CVE-2008-3455webappsphp
PHP remote file inclusion vulnerability in include/admin.php in JnSHosts PHP Hosting Directory 2.0 allows remote attacke
23RIESGO
abrir
ReferênciaVexDay Proof
Vistered Little 1.6a - 'skin' Remote File Disclosure
CVE-2007-2934webappsphp
Directory traversal vulnerability in skins/common.css.php in Vistered Little 1.6a allows remote attackers to read arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Windows Server 2000 SP4 (Advanced Server) - Message Queue (MS07-065)
CVE-2007-3039remotewindows
Stack-based buffer overflow in the Microsoft Message Queuing (MSMQ) service in Microsoft Windows 2000 Server SP4, Window
50RIESGO
abrir
ReferênciaVexDay Proof
Anzio Web Print Object 3.2.30 - ActiveX Buffer Overflow
CVE-2008-3480remotewindows
Stack-based buffer overflow in the Anzio Web Print Object (WePO) ActiveX control 3.2.19 and 3.2.24, as used in Anzio Pri
28RIESGO
abrir
ReferênciaVexDay Proof
eStoreAff 0.1 - 'cid' SQL Injection
CVE-2008-3484webappsphp
SQL injection vulnerability in eStoreAff 0.1 allows remote attackers to execute arbitrary SQL commands via the cid param
23RIESGO
abrir
ReferênciaVexDay Proof
TROforum 0.1 - 'admin.php?site_url' Remote File Inclusion
CVE-2007-2937webappsphp
PHP remote file inclusion vulnerability in admin/admin.php in TROforum 0.1 allows remote attackers to execute arbitrary
35RIESGO
abrir
ReferênciaVexDay Proof
ASPThai.Net WebBoard 6.0 - SQL Injection
CVE-2009-0703webappsphp
SQL injection vulnerability in bview.asp in ASPThai.Net Webboard 6.0 allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir
ReferênciaVexDay Proof
E-topbiz Dating 3 PHP Script - 'mail_id' SQL Injection
CVE-2008-3490webappsphp
SQL injection vulnerability in members/mail.php in E-topbiz Online Dating 3 1.0 allows remote authenticated users to exe
23RIESGO
abrir
ReferênciaVexDay Proof
Mercury/32 Mail Server 4.01 - 'Pegasus' IMAP Buffer Overflow (3)
CVE-2004-2513remotewindows
Buffer overflow in the IMAP service of Mercury (Pegasus) Mail 4.01 allows remote attackers to execute arbitrary code via
23RIESGO
abrir
ReferênciaVexDay Proof
Scripts24 iPost 1.0.1 - 'id' SQL Injection
CVE-2008-3491webappsphp
SQL injection vulnerability in go.php in Scripts24 iPost 1.0.1 and iTGP 1.0.4 allows remote attackers to execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
QMail Mailing List Manager 1.2 - Database Disclosure
CVE-2008-5606webappsasp
Gazatem QMail Mailing List Manager 1.2 stores sensitive information under the web root with insufficient access control,
23RIESGO
abrir
ReferênciaVexDay Proof
BlueBird Pre-Release - Authentication Bypass
CVE-2009-0740webappsphp
SQL injection vulnerability in login.php in BlueBird Prelease allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
smNews 1.0 - Authentication Bypass / Column Truncation
CVE-2009-0750webappsphp
SQL injection vulnerability in login.php in the smNews example script for txtSQL 2.2 Final allows remote attackers to ex
23RIESGO
abrir
ReferênciaVexDay Proof
Scripts24 iTGP 1.0.4 - 'id' SQL Injection
CVE-2008-3491webappsphp
SQL injection vulnerability in go.php in Scripts24 iPost 1.0.1 and iTGP 1.0.4 allows remote attackers to execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
RealVNC Windows Client 4.1.2 - Remote Denial of Service Crash (PoC)
CVE-2008-3493doswindows
vncviewer.exe in RealVNC Windows Client 4.1.2.0 allows remote VNC servers to cause a denial of service (application cras
23RIESGO
abrir
ReferênciaVexDay Proof
MyPHP CMS 0.3.1 - 'pid' SQL Injection
CVE-2008-3497webappsphp
SQL injection vulnerability in pages.php in MyPHP CMS 0.3.1 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir
ReferênciaVexDay Proof
polypager 1.0rc2 - SQL Injection / Cross-Site Scripting
CVE-2008-3505webappsphp
Cross-site scripting (XSS) vulnerability in PolyPager 1.0 rc2 and earlier allows remote attackers to inject arbitrary we
23RIESGO
abrir
ReferênciaVexDay Proof
AdminBot 9.0.5 - 'live_status.lib.php' Remote File Inclusion
CVE-2007-2986webappsphp
PHP remote file inclusion vulnerability in lib/live_status.lib.php in AdminBot MX 9.0.5 allows remote attackers to execu
35RIESGO
abrir
ReferênciaVexDay Proof
LiteNews 0.1 - 'id' SQL Injection
CVE-2008-3507webappsphp
SQL injection vulnerability in index.php in LiteNews 0.1 (aka 01), and possibly 1.2 and earlier, allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
MDPro Module My_eGallery - 'pid' SQL Injection
CVE-2009-0728webappsphp
SQL injection vulnerability in the My_eGallery module for MAXdev MDPro (MD-Pro) and Postnuke allows remote attackers to
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.