Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
AIOCP 1.4 - 'poll_id' SQL Injection
CVE-2008-4782webappsphp
SQL injection vulnerability in public/code/cp_polls_results.php in All In One Control Panel (AIOCP) 1.4 allows remote at
23RIESGO
abrir
ReferênciaVexDay Proof
ASPSiteWare Home Builder 1.0/2.0 - SQL Injection
CVE-2008-5774webappsasp
Multiple SQL injection vulnerabilities in ASPSiteWare HomeBuilder 1.0 and 2.0 allow remote attackers to execute arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
Mediatheka 4.2 - Blind SQL Injection
CVE-2008-5895webappsphp
SQL injection vulnerability in connection.php in Mediatheka 4.2 and earlier allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
AJSquare Free Polling Script - 'DB' Multiple Vulnerabilities
CVE-2008-7044webappsphp
SQL injection vulnerability in admin/include/newpoll.php in AJ Square Free Polling Script (AJPoll) Database version allo
23RIESGO
abrir
ReferênciaVexDay Proof
WebCMS Portal Edition - 'id' SQL Injection
CVE-2008-3213webappsphp
SQL injection vulnerability in secciones/tablon/tablon.php in WebCMS Portal Edition allows remote attackers to execute a
23RIESGO
abrir
ReferênciaVexDay Proof
Affiliate Directory - 'id' SQL Injection
CVE-2008-3719webappsphp
SQL injection vulnerability in directory.php in SFS Affiliate Directory allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
AstroSPACES 1.1.1 - 'id' SQL Injection
CVE-2008-4642webappsphp
SQL injection vulnerability in profile.php in AstroSPACES 1.1.1 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
ReferênciaVexDay Proof
Jamit Job Board 3.x - Blind SQL Injection
CVE-2008-5295webappsphp
SQL injection vulnerability in index.php in Jamit Job Board 3.4.10 allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
ReferênciaVexDay Proof
The Classified Ad System 1.0 - 'main' SQL Injection
CVE-2006-6349webappsasp
Multiple SQL injection vulnerabilities in PWP Technologies The Classified Ad System allow remote attackers to execute ar
23RIESGO
abrir
ReferênciaVexDay Proof
F-Prot AntiVirus 4.6.6 - 'ACE' Denial of Service
CVE-2006-6352doslinux
FRISK Software F-Prot Antivirus before 4.6.7 allows user-assisted remote attackers to cause a denial of service (infinit
23RIESGO
abrir
ReferênciaVexDay Proof
E-topbiz Number Links 1 - 'id' SQL Injection
CVE-2008-5804webappsphp
SQL injection vulnerability in admin/admin_catalog.php in e-topbiz Number Links 1 Php Script allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component PAX Gallery 0.1 - Blind SQL Injection
CVE-2008-5811webappsphp
SQL injection vulnerability in the PaxGallery (com_paxgallery) component 0.1 for Joomla! allows remote attackers to exec
23RIESGO
abrir
ReferênciaVexDay Proof
SFS EZ Auction - Blind SQL Injection
CVE-2008-6778webappsphp
SQL injection vulnerability in viewfaqs.php in Scripts for Sites (SFS) EZ Auction allows remote attackers to execute arb
23RIESGO
abrir
ReferênciaVexDay Proof
SFS EZ Pub Site - SQL Injection
CVE-2008-6794webappsphp
SQL injection vulnerability in directory.php in Scripts For Sites (SFS) EZ Pub Site allows remote attackers to execute a
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component live chat - SQL Injection / Open Proxy
CVE-2008-6883webappsphp
SQL injection vulnerability in the Live Chat (com_livechat) component 1.0 for Joomla! allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
ASPReferral 5.3 - 'AccountID' Blind SQL Injection
CVE-2008-6889webappsasp
SQL injection vulnerability in Merchantsadd.asp in ASPReferral 5.3 allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
ReferênciaVexDay Proof
CMS Buzz - 'id' SQL Injection
CVE-2008-4374webappsphp
SQL injection vulnerability in index.php in CMS Buzz allows remote attackers to execute arbitrary SQL commands via the i
23RIESGO
abrir
ReferênciaVexDay Proof
Pre Podcast Portal - SQL Injection
CVE-2008-6230webappsphp
SQL injection vulnerability in Tour.php in Pre Projects Pre Podcast Portal allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
RakhiSoftware Shopping Cart - SQL Injection
CVE-2008-6277webappsphp
SQL injection vulnerability in product.php in RakhiSoftware Price Comparison Script (aka Shopping Cart) allows remote at
23RIESGO
abrir
ReferênciaVexDay Proof
PHP TV Portal 2.0 - 'mid' SQL Injection
CVE-2008-6285webappsphp
SQL injection vulnerability in index.php in PHP TV Portal 2.0 and earlier allows remote attackers to execute arbitrary S
23RIESGO
abrir
ReferênciaVexDay Proof
FOSS Gallery Public 1.0 - Arbitrary File Upload (PoC)
CVE-2008-4509webappsphp
Unrestricted file upload vulnerability in processFiles.php in FOSS Gallery Admin and FOSS Gallery Public 1.0 beta allows
23RIESGO
abrir
ReferênciaVexDay Proof
MySpeach 3.0.2 - 'my_ms[root]' Remote File Inclusion
CVE-2006-4630webappsphp
PHP remote file inclusion vulnerability in jscript.php in Sky GUNNING MySpeach 3.0.2 and earlier, when register_globals
23RIESGO
abrir
ReferênciaVexDay Proof
Galerie 3.2 - 'pic' WBB Lite Addon Blind SQL Injection
CVE-2008-4516webappsphp
SQL injection vulnerability in galerie.php in Galerie 3.2 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
ReferênciaVexDay Proof
SoftBB 0.1 - 'cmd' Remote Command Execution
CVE-2006-4633webappsphp
index.php in SoftBB 0.1, and possibly earlier, allows remote attackers to obtain the installation path via a null or inv
23RIESGO
abrir
ReferênciaVexDay Proof
PHP-Fusion Mod raidtracker_panel - 'INFO_RAID_ID' SQL Injection
CVE-2008-4521webappsphp
SQL injection vulnerability in thisraidprogress.php in the World of Warcraft tracker infusion (raidtracker_panel) module
23RIESGO
abrir
ReferênciaVexDay Proof
JMweb - 'src' Local File Inclusion
CVE-2008-4522webappsphp
Multiple directory traversal vulnerabilities in JMweb MP3 Music Audio Search and Download Script allow remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
IP Reg 0.4 - Blind SQL Injection
CVE-2008-4523webappsphp
SQL injection vulnerability in login.php in IP Reg 0.4 and earlier allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
ReferênciaVexDay Proof
Muratsoft Haber Portal 3.6 - 'tr' SQL Injection
CVE-2006-4641webappsasp
SQL injection vulnerability in kategori.asp in Muratsoft Haber Portal 3.6 allows remote attackers to execute arbitrary S
23RIESGO
abrir
ReferênciaVexDay Proof
GuildFTPd 0.999.8.11/0.999.14 - Heap Corruption (PoC) / Denial of Service
CVE-2008-4572doswindows
GuildFTPd 0.999.14, and possibly other versions, allows remote attackers to cause a denial of service (crash) and possib
50RIESGO
abrir
ReferênciaVexDay Proof
MunzurSoft Wep Portal W3 - 'kat' SQL Injection
CVE-2008-4573webappsasp
SQL injection vulnerability in kategori.asp in MunzurSoft Wep Portal W3 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
anteriorpágina 177 / 188siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.