Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.230exploits catalogados
36.424CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
ABG Blocking Script 1.0a - 'abg_path' Remote File Inclusion
CVE-2008-3570webappsphp
PHP remote file inclusion vulnerability in index.php in Africa Be Gone (ABG) 1.0a allows remote attackers to execute arb
23RIESGO
abrir
ReferênciaVexDay Proof
k-links directory - SQL Injection / Cross-Site Scripting
CVE-2008-3580webappsphp
Multiple SQL injection vulnerabilities in Qsoft K-Links allow remote attackers to execute arbitrary SQL commands via (1)
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Visual Studio - 'Msmask32.ocx' ActiveX Remote Buffer Overflow (PoC)
CVE-2008-3704doswindows
Heap-based buffer overflow in the MaskedEdit ActiveX control in Msmask32.ocx 6.0.81.69, and possibly other versions befo
50RIESGO
abrir
ReferênciaVexDay Proof
osTicket 1.12 - Persistent Cross-Site Scripting via File Upload
CVE-2019-14748webappsphp
An issue was discovered in osTicket before 1.10.7 and 1.12.x before 1.12.1. The Ticket creation form allows users to upl
23RIESGO
abrir
ReferênciaVexDay Proof
InoutMailingListManager 3.1 - Remote Command Execution
CVE-2006-0658webappsphp
Incomplete blacklist vulnerability in connector.php in FCKeditor 2.0 and 2.2, as used in products such as RunCMS, allows
23RIESGO
abrir
ReferênciaVexDay Proof
pPIM 1.0 - Upload/Change Password
CVE-2008-4427webappsphp
changepassword.php in Phlatline's Personal Information Manager (pPIM) 1.0 and earlier does not require administrative au
23RIESGO
abrir
ReferênciaVexDay Proof
phpdaily - SQL Injection / Cross-Site Scripting / Local File Download
CVE-2008-4757webappsphp
Multiple SQL injection vulnerabilities in PHP-Daily allow remote attackers to execute arbitrary SQL commands via the (1)
23RIESGO
abrir
ReferênciaVexDay Proof
ilchClan 1.05g - 'tid' SQL Injection
CVE-2006-0851webappsphp
SQL injection vulnerability in the forum module of ilchClan 1.05g and earlier allows remote attackers to execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
Admbook 1.2.2 - 'x-forwarded-for' Remote Command Execution
CVE-2006-0852webappsphp
Direct static code injection vulnerability in write.php in Admbook 1.2.2 and earlier allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
Orca 2.0/2.0.2 - 'params.php?gConf[dir][layouts]' Remote File Inclusion
CVE-2008-5167webappsphp
PHP remote file inclusion vulnerability in layout/default/params.php in Boonex Orca 2.0 and 2.0.2, when register_globals
23RIESGO
abrir
ReferênciaVexDay Proof
Cheats Complete Website 1.1.1 - 'itemID' SQL Injection
CVE-2008-5170webappsphp
SQL injection vulnerability in item.php in Cheats Complete Website 1.1.1 allows remote attackers to execute arbitrary SQ
23RIESGO
abrir
ReferênciaVexDay Proof
SebracCMS 0.4 - Multiple SQL Injections
CVE-2008-5195webappsphp
Multiple SQL injection vulnerabilities in SebracCMS (sbcms) 0.4 allow remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
AcmlmBoard 1.A2 - 'pow' SQL Injection
CVE-2008-5198webappsphp
SQL injection vulnerability in memberlist.php in Acmlmboard 1.A2 allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
ReferênciaVexDay Proof
AJ Auction 6.2.1 - 'classifide_ad.php' SQL Injection
CVE-2008-5212webappsphp
SQL injection vulnerability in classifide_ad.php in AJ Auction 6.2.1 and earlier allows remote attackers to execute arbi
23RIESGO
abrir
ReferênciaVexDay Proof
Invision Power Board 2.1.4 - Register Users Denial of Service
CVE-2006-0888dosmultiple
index.php in Invision Power Board (IPB) 2.0.1, with Code Confirmation disabled, allows remote attackers to cause an unsp
23RIESGO
abrir
ReferênciaVexDay Proof
FAQ Manager 1.2 - 'categorie.php' SQL Injection
CVE-2008-5287webappsphp
SQL injection vulnerability in catagorie.php in Werner Hilversum FAQ Manager 1.2 allows remote attackers to execute arbi
23RIESGO
abrir
ReferênciaVexDay Proof
Clean CMS 1.5 - Blind SQL Injection / Cross-Site Scripting
CVE-2008-5290webappsphp
Cross-site scripting (XSS) vulnerability in full_txt.php in Werner Hilversum Clean CMS 1.5 allows remote attackers to in
23RIESGO
abrir
ReferênciaVexDay Proof
VideoGirls BiZ - Blind SQL Injection
CVE-2008-5292webappsphp
SQL injection vulnerability in view_snaps.php in VideoGirls BiZ allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
ReferênciaVexDay Proof
WebStudio eCatalogue - Blind SQL Injection
CVE-2008-5294webappsphp
SQL injection vulnerability in index.php in WebStudio eCatalogue allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
ReferênciaVexDay Proof
Cold BBS - Remote Database Disclosure
CVE-2008-5597webappsasp
Cold BBS stores sensitive information under the web root with insufficient access control, which allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
XM Easy Personal FTP Server 5.6.0 - Remote Denial of Service
CVE-2008-5626doswindows
XM Easy Personal FTP Server 5.6.0 allows remote authenticated users to cause a denial of service via a crafted argument
50RIESGO
abrir
ReferênciaVexDay Proof
Active Trade 2 - Authentication Bypass
CVE-2008-5627webappsasp
SQL injection vulnerability in account.asp in Active Trade 2 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
ReferênciaVexDay Proof
CMS little 0.0.1 - 'term' SQL Injection
CVE-2008-5628webappsphp
SQL injection vulnerability in index.php in CMS little 0.0.1 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
ReferênciaVexDay Proof
Turnkey Arcade Script - SQL Injection (1)
CVE-2008-5629webappsphp
SQL injection vulnerability in index.php in Turnkey Arcade Script allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir
ReferênciaVexDay Proof
V3 Chat Profiles/Dating Script 3.0.2 - Authentication Bypass
CVE-2008-5785webappsphp
SQL injection vulnerability in V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
ReferênciaVexDay Proof
DELTAScripts PHP Classifieds 7.5 - SQL Injection
CVE-2008-5805webappsphp
SQL injection vulnerability in detail.php in DeltaScripts PHP Classifieds 7.5 and earlier allows remote attackers to exe
23RIESGO
abrir
ReferênciaVexDay Proof
PHPAlumni - SQL Injection
CVE-2008-5815webappsphp
SQL injection vulnerability in Acomment.php in phpAlumni allows remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir
ReferênciaVexDay Proof
eDContainer 2.22 - Local File Inclusion
CVE-2008-5818webappsphp
Directory traversal vulnerability in index.php in eDreamers eDContainer 2.22, when magic_quotes_gpc is disabled, allows
23RIESGO
abrir
ReferênciaVexDay Proof
VP-ASP Shopping Cart 6.50 - Database Disclosure
CVE-2008-5929webappsasp
VP-ASP Shopping Cart 6.50 stores sensitive information under the web root with insufficient access control, which allows
23RIESGO
abrir
ReferênciaVexDay Proof
the net guys aspired2blog - SQL Injection / File Disclosure
CVE-2008-5931webappsasp
The Net Guys ASPired2Blog stores sensitive information under the web root with insufficient access control, which allows
23RIESGO
abrir
anteriorpágina 182 / 188siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.