Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
22.910 exploits
Referência
CVE-2016-10073
The from method in library/core/class.email.php in Vanilla Forums before 2.3.1 allows remote attackers to spoof the emai
60RIESGO
abrir
Referência
CVE-2021-25094
Tatsu < 3.3.12 - Unauthenticated RCE
60RIESGO
abrir
ReferênciaVexDay Proof
Mole Group Hotel Script 1.0 - SQL Injection
CVE-2008-3124webappsphp
SQL injection vulnerability in index.php in Mole Group Hotel Script 1.0 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
Mole Group Last Minute Script 4.0 - SQL Injection
CVE-2008-3125webappsphp
SQL injection vulnerability in index.php in Mole Group Lastminute Script 4.0 allows remote attackers to execute arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
miniBloggie 1.0 - 'del.php' Blind SQL Injection
CVE-2008-4628webappsphp
SQL injection vulnerability in del.php in myWebland miniBloggie 1.0 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
Referência
CVE-2010-2075
UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally
60RIESGO
abrir
Referência
CVE-2016-10073
The from method in library/core/class.email.php in Vanilla Forums before 2.3.1 allows remote attackers to spoof the emai
60RIESGO
abrir
Referência
CVE-2013-5311
Multiple SQL injection vulnerabilities in Vastal I-Tech phpVID 1.2.3 allow remote attackers to execute arbitrary SQL com
23RIESGO
abrir
ReferênciaVexDay Proof
Catviz 0.4.0 beta1 - Multiple SQL Injections
CVE-2008-3129webappsphp
Multiple SQL injection vulnerabilities in index.php in Catviz 0.4 beta 1 allow remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
pSys 0.7.0 Alpha - 'chatbox.php' SQL Injection
CVE-2008-3131webappsphp
SQL injection vulnerability in chatbox.php in pSys 0.7.0 Alpha, when magic_quotes_gpc is disabled, allows remote attacke
23RIESGO
abrir
ReferênciaVexDay Proof
GNUBoard 4.31.03 (08.12.29) - Local File Inclusion
CVE-2009-0290webappsphp
Directory traversal vulnerability in common.php in SIR GNUBoard 4.31.03 allows remote attackers to include and execute a
23RIESGO
abrir
ReferênciaVexDay Proof
Wazzum Dating Software - 'userid' SQL Injection
CVE-2009-0293webappsphp
SQL injection vulnerability in profile_view.php in Wazzum Dating Software, possibly 2.0, allows remote attackers to exec
23RIESGO
abrir
ReferênciaVexDay Proof
BareNuked CMS 1.1.0 - Arbitrary Add Admin
CVE-2008-3133webappsphp
SQL injection vulnerability in admin/index.php in BareNuked CMS 1.1.0, when magic_quotes_gpc is disabled, allows remote
23RIESGO
abrir
ReferênciaVexDay Proof
AShop Deluxe 4.x - 'catalogue.php' SQL Injection
CVE-2008-3136webappsphp
SQL injection vulnerability in catalogue.php in AShop Deluxe 4.x allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
ReferênciaVexDay Proof
SmartPPC Pay Per Click Script - 'idDirectory' Blind SQL Injection (1)
CVE-2008-3152webappsphp
SQL injection vulnerability in directory.php in SmartPPC and SmartPPC Pro allows remote attackers to execute arbitrary S
23RIESGO
abrir
ReferênciaVexDay Proof
SmartPPC Pay Per Click Script - 'idDirectory' Blind SQL Injection (2)
CVE-2008-3152webappsphp
SQL injection vulnerability in directory.php in SmartPPC and SmartPPC Pro allows remote attackers to execute arbitrary S
23RIESGO
abrir
ReferênciaVexDay Proof
Triton CMS Pro 1.06 - 'x-forwarded-for' Blind SQL Injection
CVE-2008-3153webappsphp
SQL injection vulnerability in Triton CMS Pro allows remote attackers to execute arbitrary SQL commands via the X-Forwar
23RIESGO
abrir
ReferênciaVexDay Proof
CMS WebBlizzard - 'index.php' Blind SQL Injection
CVE-2008-3154webappsphp
SQL injection vulnerability in index.php in WebBlizzard CMS allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir
ReferênciaVexDay Proof
Fuzzylime CMS 3.01 - Remote Command Execution
CVE-2008-3165webappsphp
Directory traversal vulnerability in rss.php in fuzzylime (cms) 3.01a and earlier, when magic_quotes_gpc is disabled, al
23RIESGO
abrir
ReferênciaVexDay Proof
Boonex Dolphin 6.1.2 - Multiple Remote File Inclusions
CVE-2008-3167webappsphp
Multiple PHP remote file inclusion vulnerabilities in BoonEx Dolphin 6.1.2, when register_globals is enabled, allow remo
23RIESGO
abrir
ReferênciaVexDay Proof
ContentNow 1.4.1 - Arbitrary File Upload / Cross-Site Scripting
CVE-2008-3180webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in upload/file/language_menu.php in ContentNow CMS 1.4.1 allow remot
23RIESGO
abrir
ReferênciaVexDay Proof
phpdaily - SQL Injection / Cross-Site Scripting / Local File Download
CVE-2008-4758webappsphp
Directory traversal vulnerability in download_file.php in PHP-Daily allows remote attackers to read arbitrary local file
23RIESGO
abrir
ReferênciaVexDay Proof
freeSSHd 1.2.1 - (Authenticated) SFTP 'realpath' Remote Buffer Overflow (PoC)
CVE-2008-4762doswindows
Stack-based buffer overflow in freeSSHd 1.2.1 allows remote authenticated users to cause a denial of service (service cr
28RIESGO
abrir
ReferênciaVexDay Proof
ITLPoll 2.7 Stable2 - Blind SQL Injection
CVE-2009-0295webappsphp
SQL injection vulnerability in index.php in Information Technology Light Poll Information (ITLPoll) 2.7 Stable 2, when m
23RIESGO
abrir
Referência
CVE-2017-11317
CVE-2017-11317CRITICALbajo ataque
Telerik.Web.UI in Progress Telerik UI for ASP.NET AJAX before R1 2017 and R2 before R2 2017 SP2 uses weak RadAsyncUpload
100RIESGO
abrir
Referência
CVE-2017-17587
FS Indiamart Clone 1.0 has SQL Injection via the catcompany.php token parameter, buyleads-details.php id parameter, or c
23RIESGO
abrir
Referência
CVE-2019-1935
Cisco Integrated Management Controller Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data SCP User Default Credentials Vulnerability
85RIESGO
abrir
ReferênciaVexDay Proof
Download Accelerator Plus DAP 8.x - '.m3u' Local Buffer Overflow
CVE-2008-3182localwindows
Stack-based buffer overflow in DAP.exe in Download Accelerator Plus (DAP) 7.0.1.3, 8.6.6.3, and other 8.x versions allow
23RIESGO
abrir
Referência
CVE-2019-1935
Cisco Integrated Management Controller Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data SCP User Default Credentials Vulnerability
85RIESGO
abrir
ReferênciaVexDay Proof
Pluck CMS 4.5.1 (Windows) - 'blogpost' Local File Inclusion
CVE-2008-3194webappsphp
Multiple directory traversal vulnerabilities in data/inc/themes/predefined_variables.php in pluck 4.5.1 allow remote att
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.