Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.449exploits catalogados
35.552CVEs con explotación pública
24.695probados en laboratorio
22.367 exploits
Referência
CVE-2018-2628
CVE-2018-2628CRITICALbajo ataque
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir
Referência
CVE-2018-2628
CVE-2018-2628CRITICALbajo ataque
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: WLS Core Components). S
100RIESGO
abrir
ReferênciaVexDay Proof
PHP Links 1.3 - 'id' SQL Injection
CVE-2008-0565webappsphp
SQL injection vulnerability in vote.php in DeltaScripts PHP Links 1.3 and earlier allows remote attackers to execute arb
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component ChronoForms 2.3.5 - Remote File Inclusion
CVE-2008-0567webappsphp
Multiple PHP remote file inclusion vulnerabilities in ChronoEngine ChronoForms (com_chronocontact) 2.3.5 component for J
35RIESGO
abrir
ReferênciaVexDay Proof
Mindmeld 1.2.0.10 - Multiple Remote File Inclusions
CVE-2008-0572webappsphp
Multiple PHP remote file inclusion vulnerabilities in Mindmeld 1.2.0.10 allow remote attackers to execute arbitrary PHP
28RIESGO
abrir
ReferênciaVexDay Proof
SafeNet 10.4.0.12 - 'IPSecDrv.sys' Local kernel Ring0 SYSTEM
CVE-2008-0573localwindows
IPSecDrv.sys 10.4.0.12 in SafeNET HighAssurance Remote and SoftRemote allows local users to gain privileges via a crafte
23RIESGO
abrir
ReferênciaVexDay Proof
Ipswitch WS_FTP Server with SSH 6.1.0.0 - Remote Buffer Overflow (PoC)
CVE-2008-0590doswindows
Buffer overflow in Ipswitch WS_FTP Server with SSH 6.1.0.0 allows remote authenticated users to cause a denial of servic
28RIESGO
abrir
ReferênciaVexDay Proof
Linux Kernel 2.6.17 < 2.6.24.1 - 'vmsplice' Local Privilege Escalation (2)
CVE-2008-0600locallinux
The vmsplice_to_pipe function in Linux kernel 2.6.17 through 2.6.24.1 does not validate a certain userspace pointer befo
23RIESGO
abrir
ReferênciaVexDay Proof
All Club CMS 0.0.2 - 'index.php' SQL Injection
CVE-2008-0601webappsphp
SQL injection vulnerability in index.php in All Club CMS (ACCMS) 0.0.1f and earlier allows remote attackers to execute a
23RIESGO
abrir
ReferênciaVexDay Proof
All Club CMS 0.0.1f - 'index.php' Local File Inclusion
CVE-2008-0602webappsphp
Directory traversal vulnerability in index.php in All Club CMS (ACCMS) 0.0.1f and earlier allows remote attackers to inc
23RIESGO
abrir
ReferênciaVexDay Proof
Mambo Component 'com_awesom' 0.3.2 - 'listid' SQL Injection
CVE-2008-0603webappsphp
SQL injection vulnerability in index.php in the amazOOP Awesom! (com_awesom) 0.3.2component for Mambo and Joomla! allows
23RIESGO
abrir
ReferênciaVexDay Proof
Mambo Component Shambo2 - 'itemID' SQL Injection
CVE-2008-0606webappsphp
SQL injection vulnerability in index.php in the Shambo2 (com_shambo2) component for Mambo and Joomla! allows remote atta
23RIESGO
abrir
ReferênciaVexDay Proof
RMSOFT Gallery System 2.0 - 'id' SQL Injection
CVE-2008-0611webappsphp
SQL injection vulnerability in rmgs/images.php in the RMSOFT Gallery System 2.0 module for XOOPS allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
PhotoKorn Gallery 1.543 - 'pic' SQL Injection
CVE-2008-0614webappsphp
SQL injection vulnerability in index.php in Photokorn Gallery 1.543 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
ReferênciaVexDay Proof
NERO Media Player 1.4.0.35b - '.m3u' File Buffer Overflow (PoC)
CVE-2008-0619doswindows
Buffer overflow in NeroMediaPlayer.exe in Nero Media Player 1.4.0.35 and earlier allows remote attackers to execute arbi
28RIESGO
abrir
ReferênciaVexDay Proof
Yahoo! Music Jukebox 2.2 - 'AddImage()' ActiveX Remote Buffer Overflow (1)
CVE-2008-0623remotewindows
Stack-based buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! Music Jukebox 2.2.2.056 allows
23RIESGO
abrir
ReferênciaVexDay Proof
Yahoo! Music Jukebox 2.2 - 'AddImage()' ActiveX Remote Buffer Overflow (2)
CVE-2008-0623remotewindows
Stack-based buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! Music Jukebox 2.2.2.056 allows
23RIESGO
abrir
ReferênciaVexDay Proof
Yahoo! Music JukeBox 2.2 - 'AddButton()' ActiveX Remote Buffer Overflow
CVE-2008-0624remotewindows
Buffer overflow in the YMP Datagrid ActiveX control (datagrid.dll) in Yahoo! JukeBox 2.2.2.56 allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
Astanda Directory Project 1.2 - 'link_id' SQL Injection
CVE-2008-0649webappsphp
SQL injection vulnerability in detail.php in Astanda Directory Project (ADP) 1.2 and 1.3 allows remote attackers to exec
23RIESGO
abrir
ReferênciaVexDay Proof
AuraCMS 2.2.1 - 'X-Forwarded-For' HTTP Header Blind SQL Injection
CVE-2008-1398webappsphp
SQL injection vulnerability in online.php in AuraCMS 2.0 through 2.2.1 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
MG-SOFT Net Inspector 6.5.0.828 - Multiple Vulnerabilities
CVE-2008-1402remotewindows
MG-SOFT Net Inspector 6.5.0.828 and earlier for Windows allows remote attackers to cause a (1) denial of service (except
23RIESGO
abrir
ReferênciaVexDay Proof
eXV2 Module Viso 2.0.4.3 - 'kid' SQL Injection
CVE-2008-1404webappsphp
SQL injection vulnerability in index.php in the Viso (Industry Book) 2.04 and 2.03 module for eXV2 allows remote attacke
23RIESGO
abrir
ReferênciaVexDay Proof
acronis pxe server 2.0.0.1076 - Directory Traversal / Null Pointer
CVE-2008-1410remotewindows
Directory traversal vulnerability in the PXE Server (pxesrv.exe) in Acronis Snap Deploy 2.0.0.1076 and earlier allows re
23RIESGO
abrir
ReferênciaVexDay Proof
phpAuction GPL Enhanced 2.51 - Multiple Remote File Inclusions
CVE-2008-1416webappsphp
Multiple PHP remote file inclusion vulnerabilities in PHPauction GPL 2.51 allow remote attackers to execute arbitrary PH
35RIESGO
abrir
ReferênciaVexDay Proof
Easy-Clanpage 2.2 - 'id' SQL Injection
CVE-2008-1425webappsphp
SQL injection vulnerability in index.php in the gallery module in Easy-Clanpage 2.2 allows remote attackers to execute a
23RIESGO
abrir
Referência
CVE-2018-4404
In iOS before 11.4 and macOS High Sierra before 10.13.5, a memory corruption issue exists and was addressed with improve
61RIESGO
abrir
Referência
CVE-2026-14574
In Eclipse Theia versions 0.7.0 and up until including 1.73.1, the `PreferenceUtils.merge` function in `@theia/core` rec
33RIESGO
abrir
Referência
CVE-2026-19006
mf-yang openclaw-cn Ggateway Exec Approval Flow bash-tools.exec.ts authorization
33RIESGO
abrir
ReferênciaVexDay Proof
BIND 9.x - Remote DNS Cache Poisoning
CVE-2008-1447remotemultiple
The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windo
60RIESGO
abrir
ReferênciaVexDay Proof
RunCMS Module section - 'artid' SQL Injection
CVE-2008-1462webappsphp
SQL injection vulnerability in the sections (Section) module in RunCMS allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
anteriorpágina 474 / 746siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.