Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.902exploits catalogados
34.597CVEs con explotación pública
24.695probados en laboratorio
21.624 exploits
Referência
CVE-2011-5044
SopCast 3.4.7.45585 uses weak permissions (Everyone:Full Control) for Diagnose.exe, which allows local users to execute
23RIESGO
abrir
ReferênciaVexDay Proof
ASPSiteWare Automotive Dealer 1.0/2.0 - SQL Injection
CVE-2008-6874webappsphp
Multiple SQL injection vulnerabilities in ASP SiteWare autoDealer 1 and 2 allow remote attackers to execute arbitrary SQ
23RIESGO
abrir
Referência
CVE-2008-6887
SQL injection vulnerability in detailad.asp in Pre Classified Listings 1.0 allows remote attackers to execute arbitrary
23RIESGO
abrir
Referência
CVE-2008-6890
SQL injection vulnerability in messages.asp in ASP Forum Script allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
ReferênciaVexDay Proof
BabbleBoard 1.1.6 - Cross-Site Request Forgery/Cookie Grabber
CVE-2008-6905webappsphp
Cross-site request forgery (CSRF) vulnerability in index.php in BabbleBoard 1.1.6 allows remote authenticated users to h
23RIESGO
abrir
ReferênciaVexDay Proof
2532/Gigs 1.2.2 Stable - Remote Authentication Bypass
CVE-2008-6907webappsphp
Multiple SQL injection vulnerabilities in checkuser.php in 2532designs 2532|Gigs 1.2.2 Stable, when magic_quotes_gpc is
23RIESGO
abrir
ReferênciaVexDay Proof
ExoPHPDesk 1.2 Final - Authentication Bypass
CVE-2008-6917webappsphp
SQL injection vulnerability in admin.php in Exocrew ExoPHPDesk 1.2 Final allows remote attackers to execute arbitrary SQ
23RIESGO
abrir
ReferênciaVexDay Proof
ThePortal 2.2 - Arbitrary File Upload
CVE-2008-6918webappsphp
Unrestricted file upload vulnerability in admin/galeria.php in ThePortal2 2.2 allows remote attackers to execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
PHPAdBoard - PHP uploads Arbitrary File Upload
CVE-2008-6921webappsphp
Unrestricted file upload vulnerability in index.php in phpAdBoard 1.8 allows remote attackers to execute arbitrary code
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component Content 1.0.0 - 'itemID' SQL Injection
CVE-2008-6923webappsphp
SQL injection vulnerability in the content component (com_content) 1.0.0 for Joomla! allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
PHPStore PHP Job Search Script - Arbitrary File Upload
CVE-2008-6931webappsphp
Unrestricted file upload vulnerability in PHPStore Job Search (aka PHPCareers) allows remote authenticated users to exec
23RIESGO
abrir
ReferênciaVexDay Proof
Exodus 0.10 - URI Handler Arbitrary Parameter Injection (2)
CVE-2008-6935remotewindows
Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, over
23RIESGO
abrir
ReferênciaVexDay Proof
ScriptsFeed (SF) Recipes Listing Portal - Arbitrary File Upload
CVE-2008-6943webappsphp
Unrestricted file upload vulnerability in ScriptsFeed Recipes Listing Portal allows remote authenticated users to execut
23RIESGO
abrir
ReferênciaVexDay Proof
ScriptsFeed (SF) Auto Classifieds Software - Arbitrary File Upload
CVE-2008-6944webappsphp
Unrestricted file upload vulnerability in ScriptsFeed Auto Classifieds allows remote authenticated users to execute arbi
23RIESGO
abrir
Referência
CVE-2015-1538
Integer overflow in the SampleTable::setSampleToChunkParams function in SampleTable.cpp in libstagefright in Android bef
45RIESGO
abrir
ReferênciaVexDay Proof
Bankoi Webhost Panel 1.20 - Authentication Bypass
CVE-2008-6950webappsasp
Multiple SQL injection vulnerabilities in login.asp in Bankoi WebHosting Control Panel 1.20 allow remote attackers to ex
23RIESGO
abrir
ReferênciaVexDay Proof
X7 Chat 2.0.5 - Authentication Bypass
CVE-2008-6964webappsphp
SQL injection vulnerability in the login page in X7 Chat 2.0.5 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
Simple Machines Forum (SMF) 1.1.5 (Windows x86) - Admin Reset Password
CVE-2008-6971webappsphp
The password reset functionality in Simple Machines Forum (SMF) 1.0.x before 1.0.14, 1.1.x before 1.1.6, and 2.0 before
23RIESGO
abrir
ReferênciaVexDay Proof
aspwebalbum 3.2 - Multiple Vulnerabilities
CVE-2008-6978webappsasp
Unrestricted file upload vulnerability in Full Revolution aspWebAlbum 3.2 allows remote attackers to execute arbitrary c
23RIESGO
abrir
ReferênciaVexDay Proof
aspwebalbum 3.2 - Arbitrary File Upload / SQL Injection / Cross-Site Scripting
CVE-2008-6978webappsphp
Unrestricted file upload vulnerability in Full Revolution aspWebAlbum 3.2 allows remote attackers to execute arbitrary c
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component jabode - 'id' SQL Injection
CVE-2008-7169webappsphp
SQL injection vulnerability in Jabode horoscope extension (com_jabode) for Joomla! allows remote attackers to execute ar
23RIESGO
abrir
ReferênciaVexDay Proof
Facil-CMS 0.1RC - Multiple Local File Inclusions
CVE-2008-7176webappsphp
Multiple directory traversal vulnerabilities in Facil CMS 0.1RC allow remote attackers to read arbitrary files via a ..
23RIESGO
abrir
ReferênciaVexDay Proof
Butterfly ORGanizer 2.0.0 - Arbitrary Delete (Category/Account)
CVE-2008-7181webappsphp
Butterfly Organizer 2.0.0 allows remote attackers to (1) delete arbitrary categories via a modified tablehere parameter
23RIESGO
abrir
Referência
CVE-2008-7269
Open redirect vulnerability in api.php in SiteEngine 5.x allows user-assisted remote attackers to redirect users to arbi
38RIESGO
abrir
Referência
CVE-2011-5116
SQL injection vulnerability in setseed-hub in SetSeed CMS 5.8.20, 5.11.2, and earlier allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Internet Explorer 7 - Memory Corruption (PoC) (MS09-002)
CVE-2009-0075doswindows
Microsoft Internet Explorer 7 does not properly handle errors during attempted access to deleted objects, which allows r
60RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Internet Explorer 7 (Windows 2003 SP2) - Memory Corruption (MS09-002)
CVE-2009-0075remotewindows
Microsoft Internet Explorer 7 does not properly handle errors during attempted access to deleted objects, which allows r
60RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Internet Explorer 7 (Windows XP SP2) - Memory Corruption (MS09-002)
CVE-2009-0075remotewindows
Microsoft Internet Explorer 7 does not properly handle errors during attempted access to deleted objects, which allows r
60RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Internet Explorer 7 - Memory Corruption (MS09-002)
CVE-2009-0075remotewindows
Microsoft Internet Explorer 7 does not properly handle errors during attempted access to deleted objects, which allows r
60RIESGO
abrir
ReferênciaVexDay Proof
ezpack 4.2b2 - Cross-Site Scripting / SQL Injection
CVE-2009-0104webappsphp
SQL injection vulnerability in index.php in EZpack 4.2b2 allows remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir
anteriorpágina 245 / 721siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.