Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.533exploits catalogados
35.607CVEs con explotación pública
24.695probados en laboratorio
22.407 exploits
ReferênciaVexDay Proof
YourFreeWorld Classifieds Hosting - SQL Injection
CVE-2008-4884webappsphp
SQL injection vulnerability in tr.php in YourFreeWorld Classifieds Hosting Script allows remote attackers to execute arb
23RIESGO
abrir
ReferênciaVexDay Proof
YourFreeWorld Scrolling Text Ads - SQL Injection
CVE-2008-4885webappsphp
SQL injection vulnerability in tr1.php in YourFreeWorld Scrolling Text Ads Script allows remote attackers to execute arb
23RIESGO
abrir
ReferênciaVexDay Proof
NetRisk 2.0 - Cross-Site Scripting / SQL Injection
CVE-2008-4888webappsphp
Cross-site scripting (XSS) vulnerability in error.php in NetRisk 2.0 and earlier allows remote attackers to inject arbit
23RIESGO
abrir
ReferênciaVexDay Proof
YourFreeWorld Downline Builder - 'tr.php' SQL Injection
CVE-2008-4895webappsphp
SQL injection vulnerability in tr.php in YourFreeWorld Downline Builder allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
Logz podcast CMS 1.3.1 - 'art' SQL Injection
CVE-2008-4897webappsphp
SQL injection vulnerability in fichiers/add_url.php in Logz podcast CMS 1.3.1, when magic_quotes_gpc is disabled, allows
23RIESGO
abrir
ReferênciaVexDay Proof
YourFreeWorld Classifieds Blaster - SQL Injection
CVE-2008-4900webappsphp
SQL injection vulnerability in tr.php in YourFreeWorld Classifieds Blaster Script allows remote attackers to execute arb
23RIESGO
abrir
ReferênciaVexDay Proof
Article Publisher PRO 1.5 - Authentication Bypass
CVE-2008-4901webappsphp
SQL injection vulnerability in admin/admin.php in Article Publisher Pro 1.5 allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
Article Publisher PRO - 'userid' SQL Injection
CVE-2008-4902webappsphp
SQL injection vulnerability in contact_author.php in Article Publisher Pro 1.5 allows remote attackers to execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
RX Maxsoft - 'fotoID' SQL Injection
CVE-2008-4912webappsphp
SQL injection vulnerability in popup_img.php in the fotogalerie module in RS MAXSOFT allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
Visagesoft eXPert PDF ViewerX - 'VSPDFViewerX.ocx' File Overwrite
CVE-2008-4919remotewindows
Insecure method vulnerability in VISAGESOFT eXPert PDF Viewer X ActiveX control (VSPDFViewerX.ocx) 3.0.990.0 allows remo
23RIESGO
abrir
ReferênciaVexDay Proof
DjVu - ActiveX Control 3.0 ImageURL Property Overflow
CVE-2008-4922remotewindows
Buffer overflow in the DjVu ActiveX Control 3.0 for Microsoft Office (DjVu_ActiveX_MSOffice.dll) allows remote attackers
50RIESGO
abrir
ReferênciaVexDay Proof
MW6 Aztec - ActiveX 'Aztec.dll' Remote Insecure Method
CVE-2008-4923remotewindows
Multiple insecure method vulnerabilities in MW6 Technologies Aztec ActiveX control (AZTECLib.MW6Aztec, Aztec.dll) 3.0.0.
23RIESGO
abrir
ReferênciaVexDay Proof
MW6 Barcode - ActiveX 'Barcode.dll' Insecure Method
CVE-2008-4924remotewindows
Multiple insecure method vulnerabilities in MW6 Technologies 1D Barcode ActiveX control (BARCODELib.MW6Barcode, Barcode.
23RIESGO
abrir
ReferênciaVexDay Proof
MW6 Datamatrix - ActiveX 'Datamatrix.dll' Insecure Method
CVE-2008-4925remotewindows
Multiple insecure method vulnerabilities in MW6 Technologies DataMatrix ActiveX control (DATAMATRIXLib.MW6DataMatrix, Da
23RIESGO
abrir
ReferênciaVexDay Proof
MW6 PDF417 - ActiveX 'MW6PDF417.dll' Remote Insecure Method
CVE-2008-4926remotewindows
Multiple insecure method vulnerabilities in MW6 Technologies PDF417 ActiveX control (MW6PDF417Lib.PDF417, MW6PDF417.dll)
23RIESGO
abrir
ReferênciaVexDay Proof
U-Mail Webmail 4.91 - 'edit.php' Arbitrary File Write
CVE-2008-4932webappsphp
webmail/modules/filesystem/edit.php in U-Mail Webmail server 4.91 allows remote attackers to overwrite arbitrary files v
23RIESGO
abrir
ReferênciaVexDay Proof
PHPX 3.5.16 - 'news_id' SQL Injection
CVE-2008-5000webappsphp
SQL injection vulnerability in admin/includes/news.inc.php in PHPX 3.5.16, when magic_quotes_gpc is disabled, allows rem
23RIESGO
abrir
ReferênciaVexDay Proof
Bloggie Lite 0.0.2 Beta - Insecure Cookie Handling / SQL Injection
CVE-2008-5004webappsphp
SQL injection vulnerability in genscode.php in myWebland Bloggie Lite 0.0.2 beta allows remote attackers to execute arbi
23RIESGO
abrir
Referência
CVE-2008-5037
SQL injection vulnerability in view.php in ElkaGroup Image Gallery 1.0 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
FTP Now 2.6 Server - Response Remote Crash (PoC)
CVE-2008-5045doswindows
Heap-based buffer overflow in Network-Client FTP Now 2.6, and possibly other versions, allows remote FTP servers to caus
23RIESGO
abrir
Referência
CVE-2026-16532
Link Library < 7.9.3 - Unauthenticated SQL Injection via the Front-End Link Submission Form
48RIESGO
abrir
Referência
CVE-2026-12696
wpForo Forum < 3.1.2 - Subscriber+ Stored XSS via Profile Location Field
33RIESGO
abrir
Referência
CVE-2026-15234
Codeless Page Builder <= 1.1.4 - Contributor+ Stored XSS via Shortcode Attribute
33RIESGO
abrir
Referência
CVE-2026-15262
Admin Columns for ACF Fields <= 0.3.2 - Contributor+ Stored XSS via ACF Field Value Column
33RIESGO
abrir
Referência
CVE-2026-14836
Login/Signup Popup < 3.2.5 - Unauthenticated Account Takeover via Password Reset Rate Limit Bypass
41RIESGO
abrir
Referência
CVE-2026-14596
DynamicKit for Elementor < 1.0.3 - Unauthenticated Account Takeover via Password Reset Link Host Injection
41RIESGO
abrir
Referência
CVE-2026-14309
Chat On Desk < 1.0.9 - Unauthenticated Account Takeover via Password Reset OTP Bypass
41RIESGO
abrir
Referência
CVE-2026-14197
Fluent Support < 2.3.1 - Agent+ Arbitrary Ticket Customer Reassignment via IDOR
28RIESGO
abrir
Referência
CVE-2025-15669
Bit Form < 3.1.4 - Admin+ Stored XSS via Conversational Form Progress Label
33RIESGO
abrir
Referência
CVE-2026-15932
Support Genix Lite < 1.4.48 - Unauthenticated Arbitrary File Read via Path Traversal
33RIESGO
abrir
anteriorpágina 485 / 747siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.