Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.980exploits catalogados
36.899CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Exploit-DBVexDay Proof
ScrewTurn Software ScrewTurn Wiki 2.0.x - 'System Log' Page HTML Injection
CVE-2008-3483webappsphp11 may 2008
Cross-site scripting (XSS) vulnerability in ScrewTurn Wiki 2.0.29 and 2.0.30 allows remote attackers to inject arbitrary
23RIESGO
abrir
Exploit-DBVexDay Proof
BlogPHP 2.0 - 'index.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2008-6631webappsphp10 may 2008
Multiple cross-site scripting (XSS) vulnerabilities in index.php in BlogPHP 2.0 allow remote attackers to inject arbitra
23RIESGO
abrir
Exploit-DBVexDay Proof
Ktools Photostore 3.5.2 - Multiple SQL Injections
CVE-2008-6647webappsphp10 may 2008
SQL injection vulnerability in gallery.php in Ktools PhotoStore 3.4.3 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
Exploit-DBVexDay Proof
cPanel 11.x - '/scripts2/knowlegebase?issue' Cross-Site Scripting
CVE-2008-2070webappsphp09 may 2008
The WHM interface 11.15.0 for cPanel 11.18 before 11.18.4 and 11.22 before 11.22.3 allows remote attackers to bypass XSS
23RIESGO
abrir
Exploit-DBVexDay Proof
Ktools Photostore 3.5.1 - 'gid' SQL Injection
CVE-2008-6649webappsphp09 may 2008
SQL injection vulnerability in manager/image_details_editor.php in Ktools PhotoStore 2.5, 2.9.8, 3.1.0, and other versio
23RIESGO
abrir
Exploit-DBVexDay Proof
cPanel 11.x - '/scripts2/listaccts?search' Cross-Site Scripting
CVE-2008-2070webappsphp09 may 2008
The WHM interface 11.15.0 for cPanel 11.18 before 11.18.4 and 11.22 before 11.22.3 allows remote attackers to bypass XSS
23RIESGO
abrir
Exploit-DBVexDay Proof
cPanel 11.x - '/scripts2/changeip?user' Cross-Site Scripting
CVE-2008-2070webappsphp09 may 2008
The WHM interface 11.15.0 for cPanel 11.18 before 11.18.4 and 11.22 before 11.22.3 allows remote attackers to bypass XSS
23RIESGO
abrir
Exploit-DBVexDay Proof
Ktools Photostore 3.5.1 - 'gid' SQL Injection
CVE-2008-6648webappsphp09 may 2008
SQL injection vulnerability in crumbs.php in Ktools PhotoStore 3.4.3 and 3.5.2 allows remote attackers to execute arbitr
23RIESGO
abrir
Exploit-DBVexDay Proof
Oracle Application Server Portal 10g - Authentication Bypass
CVE-2008-2138remotemultiple09 may 2008
Oracle Application Server (OracleAS) Portal 10g allows remote attackers to bypass intended access restrictions and read
28RIESGO
abrir
Exploit-DBVexDay Proof
ZyWALL 100 HTTP Referer Header - Cross-Site Scripting
CVE-2008-2167remotemultiple08 may 2008
Cross-site scripting (XSS) vulnerability in ZyXEL ZyWALL 100 allows remote attackers to inject arbitrary web script or H
28RIESGO
abrir
Exploit-DBVexDay Proof
SAP Internet Transaction Server 6200.1017.50954.0 Bu (WGate) - 'wgate.dll?~service' Cross-Site Scripting
CVE-2008-2123webappscgi08 may 2008
Cross-site scripting (XSS) vulnerability in WGate in SAP Internet Transaction Server (ITS) 6.20 allows remote attackers
23RIESGO
abrir
Exploit-DBVexDay Proof
Microsoft Internet Explorer 2 - UTF-7 HTTP Response Handling
CVE-2008-2168remotewindows08 may 2008
Cross-site scripting (XSS) vulnerability in Apache 2.2.6 and earlier allows remote attackers to inject arbitrary web scr
35RIESGO
abrir
Exploit-DBVexDay Proof
Orenosv HTTP/FTP Server 0.8.1 - FTP Commands Remote Buffer Overflow
CVE-2005-1666doswindows08 may 2008
Multiple buffer overflows in Orenosv HTTP/FTP Server 0.8.1 allow remote authenticated users to cause a denial of service
23RIESGO
abrir
Exploit-DBVexDay Proof
SAP Internet Transaction Server 6200.1017.50954.0 - Bu query String JavaScript Splicing Cross-Site Scripting
CVE-2008-2123webappscgi08 may 2008
Cross-site scripting (XSS) vulnerability in WGate in SAP Internet Transaction Server (ITS) 6.20 allows remote attackers
23RIESGO
abrir
Exploit-DBVexDay Proof
SonicWALL Email Security 6.1.1 - Error Page Cross-Site Scripting
CVE-2008-2162remotemultiple08 may 2008
Cross-site scripting (XSS) vulnerability in SonicWall Email Security 6.1.1 allows remote attackers to inject arbitrary w
23RIESGO
abrir
Exploit-DBVexDay Proof
Forum Rank System 6 - 'settings['locale']' Multiple Local File Inclusions
CVE-2008-2227webappsphp07 may 2008
Multiple directory traversal vulnerabilities in PHP-Fusion Forum Rank System 6 allow remote attackers to include and exe
23RIESGO
abrir
Exploit-DBVexDay Proof
Tux CMS 0.1 - Multiple Cross-Site Scripting Vulnerabilities
CVE-2008-2126webappsphp07 may 2008
Multiple cross-site scripting (XSS) vulnerabilities in Tux CMS 0.1 allow remote attackers to inject arbitrary web script
23RIESGO
abrir
Exploit-DBVexDay Proof
Sphider 1.3.4 - 'query' Cross-Site Scripting
CVE-2008-5211webappsphp06 may 2008
Cross-site scripting (XSS) vulnerability in search.php in Sphider 1.3.4, when the search suggestion feature is enabled,
23RIESGO
abrir
Exploit-DBVexDay Proof
QTO File Manager 1.0 - 'qtofm.php' Arbitrary File Upload
CVE-2008-2110webappsphp06 may 2008
Unrestricted file upload vulnerability in qtofm.php in QTOFileManager 1.0 allows remote attackers to execute arbitrary P
23RIESGO
abrir
Exploit-DBVexDay Proof
Yahoo! Assistant 3.6 - 'yNotifier.dll' ActiveX Control Memory Corruption
CVE-2008-2111doswindows06 may 2008
The ActiveX Control (yNotifier.dll) in Yahoo! Assistant 3.6 and earlier allows remote attackers to execute arbitrary cod
23RIESGO
abrir
Exploit-DBVexDay Proof
Maian Uploader 4.0 - 'index.php' Cross-Site Scripting
CVE-2008-2202webappsphp05 may 2008
Multiple cross-site scripting (XSS) vulnerabilities in Maian Uploader 4.0 allow remote attackers to inject arbitrary web
23RIESGO
abrir
Exploit-DBVexDay Proof
iGaming CMS 1.5 - 'poll_vote.php' SQL Injection
CVE-2008-2130webappsphp05 may 2008
SQL injection vulnerability in poll_vote.php in iGaming CMS 1.5 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
Exploit-DBVexDay Proof
Maian Uploader 4.0 - 'keywords' Cross-Site Scripting
CVE-2008-2202webappsphp05 may 2008
Multiple cross-site scripting (XSS) vulnerabilities in Maian Uploader 4.0 allow remote attackers to inject arbitrary web
23RIESGO
abrir
Exploit-DBVexDay Proof
BatmanPorTaL - 'profil.asp?id' SQL Injection
CVE-2008-6640webappsphp05 may 2008
Multiple SQL injection vulnerabilities in BatmanPorTaL allow remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir
Exploit-DBVexDay Proof
LifeType 1.2.8 - 'admin.php' Cross-Site Scripting
CVE-2008-2196webappsphp05 may 2008
Cross-site scripting (XSS) vulnerability in admin.php in LifeType 1.2.8 allows remote attackers to inject arbitrary web
23RIESGO
abrir
Exploit-DBVexDay Proof
Miniweb 2.0 - 'historymonth' SQL Injection
CVE-2008-6582webappsphp05 may 2008
SQL injection vulnerability in index.php in Miniweb 2.0 allows remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir
Exploit-DBVexDay Proof
GEDCOM_TO_MYSQL - '/PHP/prenom.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2008-6655webappsphp05 may 2008
Multiple cross-site scripting (XSS) vulnerabilities in GEDCOM_TO_MYSQL 2 allow remote attackers to inject arbitrary web
23RIESGO
abrir
Exploit-DBVexDay Proof
GEDCOM_TO_MYSQL - '/PHP/info.php' Multiple Cross-Site Scripting Vulnerabilities
CVE-2008-6655webappsphp05 may 2008
Multiple cross-site scripting (XSS) vulnerabilities in GEDCOM_TO_MYSQL 2 allow remote attackers to inject arbitrary web
23RIESGO
abrir
Exploit-DBVexDay Proof
GEDCOM_TO_MYSQL - '/PHP/index.php?nom_branche' Cross-Site Scripting
CVE-2008-6655webappsphp05 may 2008
Multiple cross-site scripting (XSS) vulnerabilities in GEDCOM_TO_MYSQL 2 allow remote attackers to inject arbitrary web
23RIESGO
abrir
Exploit-DBVexDay Proof
BatmanPorTaL - 'uyeadmin.asp?id' SQL Injection
CVE-2008-6640webappsphp05 may 2008
Multiple SQL injection vulnerabilities in BatmanPorTaL allow remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir
anteriorpágina 307 / 824siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.