Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.620exploits catalogados
35.647CVEs con explotación pública
24.695probados en laboratorio
22.429 exploits
ReferênciaVexDay Proof
PHPmyGallery 1.5beta - '/common-tpl-vars.php' Local/Remote File Inclusion
CVE-2008-6318webappsphp
PHP remote file inclusion vulnerability in _conf/_php-core/common-tpl-vars.php in PHPmyGallery 1.5 beta allows remote at
23RIESGO
abrir
ReferênciaVexDay Proof
CF_Calendar - 'calendarevent.cfm' SQL Injection
CVE-2008-6319webappsasp
SQL injection vulnerability in calendarevent.cfm in CF_Calendar allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
ReferênciaVexDay Proof
cf shopkart 5.2.2 - SQL Injection / File Disclosure
CVE-2008-6320webappsasp
SQL injection vulnerability in index.cfm in CF Shopkart 5.2.2 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
CFMBLOG - 'categorynbr' Blind SQL Injection
CVE-2008-6322webappsasp
SQL injection vulnerability in index.cfm in CFMSource CFMBlog allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
CF_Auction - Blind SQL Injection
CVE-2008-6323webappsasp
SQL injection vulnerability in forummessages.cfm in CFMSource CF_Auction allows remote attackers to execute arbitrary SQ
23RIESGO
abrir
ReferênciaVexDay Proof
CF_Forum - Blind SQL Injection
CVE-2008-6324webappsasp
SQL injection vulnerability in forummessages.cfm in CF_Forum allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
ReferênciaVexDay Proof
ProQuiz 1.0 - Authentication Bypass
CVE-2008-6327webappsphp
SQL injection vulnerability in index.php in ProQuiz 1.0 allows remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir
Referência
CVE-2023-27350
CVE-2023-27350CRITICALbajo ataqueransomware
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RIESGO
abrir
ReferênciaVexDay Proof
Butterfly ORGanizer 2.0.1 - 'id' SQL Injection
CVE-2008-6328webappsphp
SQL injection vulnerability in view.php in Butterfly Organizer 2.0.0 and 2.0.1 allows remote attackers to execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
Pre Job Board - Authentication Bypass
CVE-2008-6329webappsphp
SQL injection vulnerability in Employee/login.asp in Pre ASP Job Board allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
MyTopix 1.3.0 - SQL Injection
CVE-2008-6330webappsphp
SQL injection vulnerability in index.php in MyTopix 1.3.0 and earlier allows remote authenticated users to execute arbit
23RIESGO
abrir
ReferênciaVexDay Proof
Simple Customer 1.2 - Authentication Bypass
CVE-2008-6332webappsphp
SQL injection vulnerability in login.php in Simple Customer 1.2 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
ReferênciaVexDay Proof
RSS Simple News - SQL Injection
CVE-2008-6333webappsphp
SQL injection vulnerability in news.php in RSS Simple News (RSSSN), when magic_quotes_gpc is disabled, allows remote att
23RIESGO
abrir
ReferênciaVexDay Proof
Extract Website - 'Filename' File Disclosure
CVE-2008-6334webappsphp
Directory traversal vulnerability in download.php in eMetrix Extract Website allows remote attackers to read arbitrary f
23RIESGO
abrir
ReferênciaVexDay Proof
Online Keyword Research Tool - 'download.php' File Disclosure
CVE-2008-6335webappsphp
Directory traversal vulnerability in download.php in eMetrix Online Keyword Research Tool allows remote attackers to rea
23RIESGO
abrir
ReferênciaVexDay Proof
Text Lines Rearrange Script - 'Filename' File Disclosure
CVE-2008-6336webappsphp
Directory traversal vulnerability in download.php in Text Lines Rearrange Script 1.0, when register_globals is enabled,
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component Volunteer 2.0 - SQL Injection
CVE-2008-6337webappsphp
SQL injection vulnerability in the Volunteer Management System (com_volunteer) module 2.0 for Joomla! allows remote atta
23RIESGO
abrir
ReferênciaVexDay Proof
SolarCMS 0.53.8 - 'Forum' Remote Cookies Disclosure
CVE-2008-6345webappsphp
SQL injection vulnerability in Forum.php in SolarCMS 0.53.8 and 1.0 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component ongumatimesheet20 4b - Remote File Inclusion
CVE-2008-6347webappsphp
PHP remote file inclusion vulnerability in lib/onguma.class.php in the Onguma Time Sheet (com_ongumatimesheet20) 2.0 4b
28RIESGO
abrir
ReferênciaVexDay Proof
DevelopItEasy Photo Gallery 1.2 - SQL Injection
CVE-2008-6348webappsphp
Multiple SQL injection vulnerabilities in DevelopItEasy Photo Gallery 1.2 allow remote attackers to execute arbitrary SQ
23RIESGO
abrir
ReferênciaVexDay Proof
TurnkeyForms Business Survey Pro 1.0 - 'id' SQL Injection
CVE-2008-6349webappsphp
SQL injection vulnerability in survey_results_text.php in TurnkeyForms Business Survey Pro 1.0 allows remote attackers t
23RIESGO
abrir
Referência25
watchtowrlabs/watchTowr-vs-FreePBX-CVE-2025-57819
CVE-2025-57819CRITICALbajo ataque
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
100RIESGO
abrir
ReferênciaVexDay Proof
JETIK-WEB Software - 'kat' SQL Injection
CVE-2008-6401webappsphp
SQL injection vulnerability in sayfa.php in JETIK-WEB allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir
Referência
CVE-2012-1261
Cross-site scripting (XSS) vulnerability in cgi-bin/scrut_fa_exclusions.cgi in Plixer International Scrutinizer NetFlow
23RIESGO
abrir
ReferênciaVexDay Proof
OpenRat 0.8-beta4 - 'tpl_dir' Remote File Inclusion
CVE-2008-6403webappsphp
PHP remote file inclusion vulnerability in themes/default/include/html/insert.inc.php in OpenRat 0.8-beta4 and earlier a
23RIESGO
abrir
Referência
CVE-2019-16662
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to a
60RIESGO
abrir
Referência
CVE-2019-16662
An issue was discovered in rConfig 3.9.2. An attacker can directly execute system commands by sending a GET request to a
60RIESGO
abrir
Referência
CVE-2022-33891
CVE-2022-33891HIGHbajo ataque
Apache Spark shell command injection vulnerability via Spark UI
100RIESGO
abrir
Referência
CVE-2023-41892
Craft CMS Remote Code Execution vulnerability
85RIESGO
abrir
Referência
CVE-2019-15976
Cisco Data Center Network Manager Authentication Bypass Vulnerabilities
70RIESGO
abrir
anteriorpágina 506 / 748siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.