Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.449exploits catalogados
35.552CVEs con explotación pública
24.695probados en laboratorio
22.367 exploits
ReferênciaVexDay Proof
EasyCalendar 4.0tr - Multiple Vulnerabilities
CVE-2008-1345webappsphp
Cross-site scripting (XSS) vulnerability in plugins/calendar/calendar_backend.php in MyioSoft EasyCalendar 4.0tr and ear
23RIESGO
abrir
ReferênciaVexDay Proof
Fully Modded phpBB - 'kb.php' SQL Injection
CVE-2008-1350webappsphp
SQL injection vulnerability in kb.php in Fully Modded phpBB (phpbbfm) 80220 allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
XOOPS Module tutorials 2.1b - 'printpage.php' SQL Injection
CVE-2008-1351webappsphp
SQL injection vulnerability in the Tutorials 2.1b module for XOOPS allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
ReferênciaVexDay Proof
Alt-N MDaemon IMAP server 9.6.4 - 'FETCH' Remote Buffer Overflow
CVE-2008-1358remotewindows
Stack-based buffer overflow in the IMAP server in Alt-N Technologies MDaemon 9.6.4 allows remote authenticated users to
50RIESGO
abrir
Referência
CVE-2026-67599
ClearOS 7.9 OS Command Injection via Log Viewer filter parameter
41RIESGO
abrir
ReferênciaVexDay Proof
PhpBlock a8.4 - 'PATH_TO_CODE' Remote File Inclusion
CVE-2008-1776webappsphp
PHP remote file inclusion vulnerability in modules/basicfog/basicfogfactory.class.php in PhpBlock A8.4 allows remote att
28RIESGO
abrir
ReferênciaVexDay Proof
Prozilla Forum Service - 'forum' SQL Injection
CVE-2008-1789webappsphp
SQL injection vulnerability in forum.php in Prozilla Forum allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
ReferênciaVexDay Proof
rdesktop 1.5.0 - 'process_redirect_pdu()' BSS Overflow (PoC)
CVE-2008-1802doslinux
Buffer overflow in the process_redirect_pdu (rdp.c) function in rdesktop 1.5.0 allows remote attackers to execute arbitr
28RIESGO
abrir
ReferênciaVexDay Proof
724CMS 4.01 Enterprise - 'index.php' SQL Injection
CVE-2008-1858webappsphp
SQL injection vulnerability in index.php in 724Networks 724CMS 4.01 and earlier allows remote attackers to execute arbit
23RIESGO
abrir
ReferênciaVexDay Proof
iScripts Socialware - 'id' SQL Injection
CVE-2008-1859webappsphp
SQL injection vulnerability in events.php in iScripts SocialWare allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
ReferênciaVexDay Proof
Blog PixelMotion - 'categorie' SQL Injection
CVE-2008-1867webappsphp
SQL injection vulnerability in Blog Pixel Motion (aka Blog PixelMotion) allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
PIGMy-SQL 1.4.1 - 'getdata.php' Blind SQL Injection
CVE-2008-1870webappsphp
SQL injection vulnerability in getdata.php in PIGMy-SQL 1.4.1 and earlier allows remote attackers to execute arbitrary S
23RIESGO
abrir
ReferênciaVexDay Proof
Comdev News Publisher 4.1.2 - SQL Injection
CVE-2008-1872webappsphp
SQL injection vulnerability in home.news.php in Comdev News Publisher 4.1.2 allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
Xine-Lib 1.1.12 - NSF demuxer Stack Overflow (PoC)
CVE-2008-1878doslinux
Stack-based buffer overflow in the demux_nsf_send_chunk function in src/demuxers/demux_nsf.c in xine-lib 1.1.12 and earl
28RIESGO
abrir
ReferênciaVexDay Proof
CDNetworks Nefficient Download - 'NeffyLauncher.dll' Code Execution
CVE-2008-1886remotewindows
The NeffyLauncher 1.0.5 ActiveX control (NeffyLauncher.dll) in CDNetworks Nefficient Download uses weak cryptography for
23RIESGO
abrir
ReferênciaVexDay Proof
Carbon Communities 2.4 - Multiple Vulnerabilities
CVE-2008-1896webappsasp
Multiple cross-site scripting (XSS) vulnerabilities in Carbon Communities 2.4 and earlier allow remote attackers to inje
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Works 7 - 'WkImgSrv.dll' ActiveX Denial of Service (PoC)
CVE-2008-1898doswindows
A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and
50RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Works 7 - 'WkImgSrv.dll' ActiveX Remote Buffer Overflow
CVE-2008-1898remotewindows
A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and
50RIESGO
abrir
ReferênciaVexDay Proof
Borland Interbase 2007 - 'ibserver.exe' Buffer Overflow (PoC)
CVE-2008-1910doswindows
Stack-based buffer overflow in the database service (ibserver.exe) in Borland InterBase 2007 SP2 allows remote attackers
23RIESGO
abrir
Referência
CVE-2026-67181
Rouille 0.3.3 - 3.6.2 HTTP Request Smuggling via proxy Transfer-Encoding Header
33RIESGO
abrir
Referência
CVE-2026-18038
nextlevelbuilder GoClaw jq Handler tools_invoke.go ExecTool.Execute information disclosure
33RIESGO
abrir
Referência
CVE-2026-66731
facil.io 0.7.5 - 0.7.6 HTTP/1.1 Chunked Transfer Encoding Parser Crash DoS
41RIESGO
abrir
Referência
CVE-2026-66729
facil.io 0.6.0 - 0.7.6 Integer Underflow DoS via Multipart MIME Body Parser
41RIESGO
abrir
Referência
CVE-2026-17432
NousResearch hermes-agent SimpleX Gateway Authorization adapter.py access control
28RIESGO
abrir
Referência
CVE-2026-16767
Ne-Lexa php-zip ZIP ZipFile.php extractTo path traversal
33RIESGO
abrir
Referência
CVE-2026-65694
Microweber CMS 2.0.20 Path Traversal via ServeStaticFileController
56RIESGO
abrir
Referência
CVE-2026-12082
Praison AI SEO < 5.0.7 - Unauthenticated Multiple Missing Authorization (Post Permalink Modification, Plugin Settings Disclosure)
41RIESGO
abrir
ReferênciaVexDay Proof
Siteman 2.x - Code Execution / Local File Inclusion / Cross-Site Scripting
CVE-2008-2081webappsphp
Directory traversal vulnerability in index.php in Siteman 2.0.x2 allows remote authenticated administrators to include a
23RIESGO
abrir
ReferênciaVexDay Proof
PHP Forge 3 Beta 2 - 'id' SQL Injection
CVE-2008-2088webappsphp
SQL injection vulnerability in admin/news.php in PHP Forge 3.0 beta 2 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component FlippingBook 1.0.4 - SQL Injection
CVE-2008-2095webappsphp
SQL injection vulnerability in index.php in the FlippingBook (com_flippingbook) 1.0.4 component for Joomla! allows remot
23RIESGO
abrir
anteriorpágina 471 / 746siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.