Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.533exploits catalogados
35.607CVEs con explotación pública
24.695probados en laboratorio
22.407 exploits
ReferênciaVexDay Proof
Bonza Cart 1.10 - Admin Password Changing
CVE-2008-5567webappsphp
Cross-site request forgery (CSRF) vulnerability in admin/ad_settings.php in Bonza Cart 1.10 and earlier allows remote at
23RIESGO
abrir
ReferênciaVexDay Proof
IPNPro3 < 1.44 - Admin Password Changing
CVE-2008-5568webappsphp
Cross-site request forgery (CSRF) vulnerability in admin/settings.php in IPN Pro 3 1.44 and earlier allows remote attack
23RIESGO
abrir
ReferênciaVexDay Proof
Professional Download Assistant 0.1 - Authentication Bypass
CVE-2008-5571webappsasp
SQL injection vulnerability in admin/login.asp in Professional Download Assistant 0.1 allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
Professional Download Assistant 0.1 - Database Disclosure
CVE-2008-5572webappsasp
Professional Download Assistant 0.1 stores sensitive information under the web root with insufficient access control, wh
23RIESGO
abrir
ReferênciaVexDay Proof
WebMaster Marketplace - SQL Injection
CVE-2008-5574webappsphp
SQL injection vulnerability in member.php in Webmaster Marketplace allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
ReferênciaVexDay Proof
sCssBoard (Multiple Versions) - 'pwnpack' Remote s
CVE-2008-5578webappsphp
Multiple SQL injection vulnerabilities in index.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allow remote attackers to exec
23RIESGO
abrir
ReferênciaVexDay Proof
Nukedit 4.9.x - Remote Create Admin
CVE-2008-5582webappsphp
SQL injection vulnerability in utilities/login.asp in Nukedit 4.9.x, and possibly earlier, allows remote attackers to ex
23RIESGO
abrir
Referência
CVE-2008-5585
Multiple PHP remote file inclusion vulnerabilities in lcxBBportal 0.1 Alpha 2 allow remote attackers to execute arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
Active Photo Gallery 6.2 - Authentication Bypass
CVE-2008-5641webappsphp
SQL injection vulnerability in account.asp in Active Photo Gallery 6.2 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component com_books - 'book_id' SQL Injection
CVE-2008-5643webappsphp
SQL injection vulnerability in the Books (com_books) component for Joomla! allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
DELTAScripts PHP Shop 1.0 - Authentication Bypass
CVE-2008-5648webappsphp
SQL injection vulnerability in admin/login.php in DeltaScripts PHP Shop 1.0 allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
WinFTP Server 2.3.0 - 'PASV Mode' Remote Denial of Service
CVE-2008-5666doswindows
WinFTP FTP Server 2.3.0, when passive (aka PASV) mode is used, allows remote authenticated users to cause a denial of se
43RIESGO
abrir
Referência
CVE-2026-17459
perwendel spark SparkJava ExternalResourceHandler.jav staticFiles.externalLocation symlink
33RIESGO
abrir
ReferênciaVexDay Proof
SAWStudio 3.9i - '.prf' Local Buffer Overflow (PoC)
CVE-2008-5722doswindows
Buffer overflow in SAWStudio 3.9i allows user-assisted remote attackers to cause a denial of service (application crash)
28RIESGO
abrir
ReferênciaVexDay Proof
PowerStrip 3.84 - 'pstrip.sys' Local Privilege Escalation
CVE-2008-5725localwindows
The NT kernel-mode driver (aka pstrip.sys) 5.0.1.1 and earlier in EnTech Taiwan PowerStrip 3.84 and earlier allows local
23RIESGO
abrir
ReferênciaVexDay Proof
CMS NetCat 3.12 - 'password_recovery.php' Blind SQL Injection
CVE-2008-5727webappsphp
SQL injection vulnerability in modules/auth/password_recovery.php in AIST NetCat 3.12 and earlier, when magic_quotes_gpc
23RIESGO
abrir
ReferênciaVexDay Proof
CMS NetCat 3.12 - Multiple Vulnerabilities
CVE-2008-5730webappsphp
Multiple CRLF injection vulnerabilities in AIST NetCat 3.12 and earlier allow remote attackers to have an unknown impact
23RIESGO
abrir
ReferênciaVexDay Proof
PGP Desktop 9.0.6 - 'PGPwded.sys' Local Denial of Service
CVE-2008-5731doswindows
The PGPwded device driver (aka PGPwded.sys) in PGP Corporation PGP Desktop 9.0.6 build 6060 and 9.9.0 build 397 allows l
23RIESGO
abrir
ReferênciaVexDay Proof
BLOG 1.55B - 'image_upload.php' Arbitrary File Upload
CVE-2008-5732webappsphp
Unrestricted file upload vulnerability in lib/image_upload.php in KafooeyBlog 1.55b allows remote attackers to execute a
28RIESGO
abrir
Referência
CVE-2026-17458
mf-yang openclaw-cn Browser Control HTTP API agent.act.ts clickViaPlaywright server-side request forgery
33RIESGO
abrir
Referência
CVE-2026-17457
mf-yang openclaw-cn Scheme navigation-guard.ts assertBrowserNavigationAllowed information disclosure
33RIESGO
abrir
ReferênciaVexDay Proof
PHP-Fusion Mod TI - 'id' SQL Injection
CVE-2008-5733webappsphp
SQL injection vulnerability in blog.php in the Team Impact TI Blog System mod for PHP-Fusion allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
Calendar Script 1.1 - Authentication Bypass
CVE-2008-5737webappsphp
SQL injection vulnerability in index.php in Nodstrum MySQL Calendar 1.1 and 1.2 allows remote attackers to execute arbit
23RIESGO
abrir
ReferênciaVexDay Proof
CoolPlayer 2.19 - '.Skin' Local Buffer Overflow
CVE-2008-5735localwindows
Stack-based buffer overflow in skin.c in CoolPlayer 2.17 through 2.19 allows remote attackers to execute arbitrary code
23RIESGO
abrir
ReferênciaVexDay Proof
CoolPlayer 2.19 - '.Skin' Local Buffer Overflow
CVE-2008-5735localwindows
Stack-based buffer overflow in skin.c in CoolPlayer 2.17 through 2.19 allows remote attackers to execute arbitrary code
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Windows Media Player - '.wav' Remote Crash (PoC)
CVE-2008-5745doswindows
Integer overflow in quartz.dll in the DirectShow framework in Microsoft Windows Media Player (WMP) 9, 10, and 11, includ
28RIESGO
abrir
ReferênciaVexDay Proof
Google Chrome - 'ChromeHTML://' Remote Parameter Injection
CVE-2008-5750remotewindows
Argument injection vulnerability in Microsoft Internet Explorer 8 beta 2 on Windows XP SP3 allows remote attackers to ex
28RIESGO
abrir
ReferênciaVexDay Proof
Alstrasoft Web Email Script Enterprise - 'id' SQL Injection
CVE-2008-5751webappsphp
SQL injection vulnerability in index.php in AlstraSoft Web Email Script Enterprise (ESE) allows remote attackers to exec
23RIESGO
abrir
Referência
CVE-2026-63097
Dendrite 0.13.8 syncapi /context Endpoint Post-Leave State Exposure
33RIESGO
abrir
ReferênciaVexDay Proof
WordPress Plugin Page Flip Image Gallery 0.2.2 - Remote File Disclosure
CVE-2008-5752webappsphp
Directory traversal vulnerability in getConfig.php in the Page Flip Image Gallery plugin 0.2.2 and earlier for WordPress
23RIESGO
abrir
anteriorpágina 484 / 747siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.