Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.559exploits catalogados
34.978CVEs con explotación pública
24.695probados en laboratorio
21.899 exploits
Referência
CVE-2010-0698
SQL injection vulnerability in backoffice/login.asp in Dynamicsoft WSC CMS 2.2 allows remote attackers to execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component NeoReferences 1.3.1 - 'catid' SQL Injection
CVE-2008-0686webappsphp
SQL injection vulnerability in index.php in the NeoReferences (com_neoreferences) 1.3.1 and 1.3.3 component for Joomla!
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component com_Marketplace 1.1.1 - SQL Injection
CVE-2008-0689webappsphp
SQL injection vulnerability in index.php in the Marketplace (com_marketplace) 1.1.1 and 1.1.1-pl1 component for Joomla!
23RIESGO
abrir
ReferênciaVexDay Proof
ITechBids 5.0 - 'item_id' SQL Injection
CVE-2008-0692webappsphp
SQL injection vulnerability in bidhistory.php in iTechBids 3 Gold and 5.0 allows remote attackers to execute arbitrary S
23RIESGO
abrir
ReferênciaVexDay Proof
BookmarkX script 2007 - 'topicid' SQL Injection
CVE-2008-0695webappsphp
SQL injection vulnerability in index.php in BookmarkX script 2007 allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir
ReferênciaVexDay Proof
Mihalism Multi Host Download - 'Username' Blind SQL Injection
CVE-2008-0714webappsphp
SQL injection vulnerability in users.php in Mihalism Multi Host allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
ReferênciaVexDay Proof
Mambo Component Sermon 0.2 - 'gid' SQL Injection
CVE-2008-0721webappsphp
SQL injection vulnerability in index.php in the Sermon (com_sermon) 0.2 component for Mambo allows remote attackers to e
23RIESGO
abrir
Referência
CVE-2008-0722
Cross-site scripting (XSS) vulnerability in index.php in Pagetool 1.0.7 allows remote attackers to inject arbitrary web
23RIESGO
abrir
Referência
CVE-2008-0729
Mobile Safari on Apple iPhone 1.1.2 and 1.1.3 allows remote attackers to cause a denial of service (memory exhaustion an
23RIESGO
abrir
ReferênciaVexDay Proof
CandyPress eCommerce suite 4.1.1.26 - Multiple Vulnerabilities
CVE-2008-0736webappsasp
admin/SA_shipFedExMeter.asp in CandyPress (CP) 4.1.1.26, and possibly other 4.x and 3.x versions, allows remote attacker
23RIESGO
abrir
ReferênciaVexDay Proof
PowerNews 2.5.6 - Local File Inclusion
CVE-2008-0742webappsphp
Multiple directory traversal vulnerabilities in PowerScripts PowerNews 2.5.6 allow remote attackers to read and include
23RIESGO
abrir
ReferênciaVexDay Proof
Mambo Component com_gallery - SQL Injection
CVE-2008-0746webappsphp
SQL injection vulnerability in index.php in the Gallery (com_gallery) component for Mambo and Joomla! allows remote atta
23RIESGO
abrir
ReferênciaVexDay Proof
jetAudio 7.0.5 - '.asx' Remote Stack Overflow (PoC)
CVE-2008-0747doswindows
Stack-based buffer overflow in COWON America jetAudio 7.0.5 and earlier allows user-assisted remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
ImageStation - 'SonyISUpload.cab' 1.0.0.38 ActiveX Buffer Overflow
CVE-2008-0748remotewindows
Buffer overflow in the Sony AxRUploadServer.AxRUploadControl.1 ActiveX control in AxRUploadServer.dll 1.0.0.38 in SonyIS
28RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component NeoGallery 1.1 - SQL Injection
CVE-2008-0752webappsphp
SQL injection vulnerability in index.php in the Neogallery (com_neogallery) 1.1 component for Joomla! allows remote atta
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component pcchess 0.8 - SQL Injection
CVE-2008-0761webappsphp
SQL injection vulnerability in index.php in the Prince Clan Chess Club (com_pcchess) 0.8 and earlier component for Jooml
23RIESGO
abrir
ReferênciaVexDay Proof
ibProArcade 3.3.0 - SQL Injection
CVE-2008-0770webappsphp
SQL injection vulnerability in arcade.php in ibProArcade 3.3.0 and earlier allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
Mambo Component Comments 0.5.8.5g - SQL Injection
CVE-2008-0773webappsphp
SQL injection vulnerability in Phil Taylor Comments (com_comments, aka Review Script) 0.5.8.5g and earlier component for
23RIESGO
abrir
ReferênciaVexDay Proof
ITechBids 6.0 - 'item_id' SQL Injection
CVE-2008-0776webappsphp
SQL injection vulnerability in detail.php in iTechBids Gold 6.0 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
ReferênciaVexDay Proof
MoinMoin 1.5.x - 'MOIND_ID' Cookie Login Bypass
CVE-2008-0782webappsphp
Directory traversal vulnerability in MoinMoin 1.5.8 and earlier allows remote attackers to overwrite arbitrary files via
28RIESGO
abrir
Referência
CVE-2010-0711
Cross-site request forgery (CSRF) vulnerability in default.asp in ASPCode CMS 1.5.8, 2.0.0 Build 103, and possibly other
23RIESGO
abrir
ReferênciaVexDay Proof
MyBulletinBoard (MyBB) 1.2.11 - 'private.php' SQL Injection (1)
CVE-2008-0787webappsphp
SQL injection vulnerability in inc/datahandlers/pm.php in MyBB before 1.2.12 allows remote authenticated users to execut
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component xfaq 1.2 - 'aid' SQL Injection
CVE-2008-0795webappsphp
SQL injection vulnerability in index.php in the MGFi XfaQ (com_xfaq) 1.2 component for Mambo and Joomla! allows remote a
23RIESGO
abrir
ReferênciaVexDay Proof
nuBoard 0.5 - 'ssid' SQL Injection
CVE-2008-0796webappsphp
SQL injection vulnerability in threads.php in Nuboard 0.5 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component Quiz 0.81 - 'tid' SQL Injection
CVE-2008-0799webappsphp
SQL injection vulnerability in index.php in the Quiz (com_quiz) 0.81 and earlier component for Mambo and Joomla! allows
23RIESGO
abrir
ReferênciaVexDay Proof
LookStrike Lan Manager 0.9 - Local/Remote File Inclusion
CVE-2008-0803webappsphp
Multiple PHP remote file inclusion vulnerabilities in LookStrike Lan Manager 0.9 allow remote attackers to execute arbit
35RIESGO
abrir
Referência
CVE-2023-28771
CVE-2023-28771CRITICALbajo ataque
Improper error message handling in Zyxel ZyWALL/USG series firmware versions 4.60 through 4.73, VPN series firmware vers
100RIESGO
abrir
Referência
CVE-2023-23333
There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassin
85RIESGO
abrir
ReferênciaVexDay Proof
PHP Live! 3.2.2 - 'questid' SQL Injection (1)
CVE-2008-0821webappsphp
SQL injection vulnerability in admin/traffic/knowledge_searchm.php in OSI Codes Inc. PHP Live! 3.2.2 allows remote attac
23RIESGO
abrir
Referência
CVE-2016-0049
Kerberos in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
28RIESGO
abrir
anteriorpágina 321 / 730siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.