Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.689exploits catalogados
38.075CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
JMweb - 'src' Local File Inclusion
CVE-2008-4522—webappsphp
Multiple directory traversal vulnerabilities in JMweb MP3 Music Audio Search and Download Script allow remote attackers
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP-Fusion Mod raidtracker_panel - 'INFO_RAID_ID' SQL Injection
CVE-2008-4521—webappsphp
SQL injection vulnerability in thisraidprogress.php in the World of Warcraft tracker infusion (raidtracker_panel) module
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Oceandir 2.9 - 'show_vote.php' SQL Injection
CVE-2008-6452—webappsphp
SQL injection vulnerability in show_vote.php in Oceandir 2.9 and earlier allows remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Built2Go PHP Realestate 1.5 - 'event_detail.php' SQL Injection
CVE-2008-4497—webappsphp
SQL injection vulnerability in event_detail.php in Built2Go Real Estate Listings 1.5 allows remote attackers to execute
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Microsoft PicturePusher - ActiveX Cross-Site Arbitrary File Upload
CVE-2008-4493—remotewindows
Microsoft PicturePusher ActiveX control (PipPPush.DLL 7.00.0709), as used in Microsoft Digital Image 2006 Starter Editio
28RIESGO
abrir ↗
Referência✓ VexDay Proof
phpdaily - SQL Injection / Cross-Site Scripting / Local File Download
CVE-2008-4756—webappsphp
Cross-site scripting (XSS) vulnerability in add_prest_date.php in PHP-Daily allows remote attackers to inject arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Microsoft Works 7 - 'WkImgSrv.dll' ActiveX Denial of Service (PoC)
CVE-2008-1898—doswindows
A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and
50RIESGO
abrir ↗
Referência✓ VexDay Proof
mm chat 1.5 - Local File Inclusion / Cross-Site Scripting
CVE-2008-2973—webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in chathead.php in MM Chat 1.5 allow remote attackers to inject arbi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Butterfly ORGanizer 2.0.0 - SQL Injection / Cross-Site Scripting
CVE-2008-6700—webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in Butterfly Organizer 2.0.0 allow remote attackers to inject arbitr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Yourownbux 4.0 - 'cookie' SQL Injection
CVE-2008-4492—webappsphp
SQL injection vulnerability in referrals.php in YourOwnBux 4.0 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗
Referência✓ VexDay Proof
pNews 2.08 - 'shownews' SQL Injection
CVE-2008-2673—webappsphp
SQL injection vulnerability in index.php in Powie pNews 2.08 and 2.10, when magic_quotes_gpc is disabled, allows remote
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Yerba SACphp 6.3 - Local File Inclusion
CVE-2008-4486—webappsphp
Directory traversal vulnerability in index.php in SAC.php (SACphp), as used in Yerba 6.3 and earlier, allows remote atta
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Numark Cue 5.0 rev 2 - '.m3u' File Local Stack Buffer Overflow
CVE-2008-4470—localwindows
Stack-based buffer overflow in Numark CUE 5.0 rev2 allows user-assisted attackers to cause a denial of service (applicat
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Vastal I-Tech Toner Cart - 'id' SQL Injection
CVE-2008-4467—webappsphp
SQL injection vulnerability in show_series_ink.php in Vastal I-Tech Toner Cart allows remote attackers to execute arbitr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CS-Cart 1.3.5 - Authentication Bypass
CVE-2008-6394—webappsphp
SQL injection vulnerability in core/user.php in CS-Cart 1.3.5 and earlier allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Codefixer MailingListPro - Database Disclosure
CVE-2008-6374—webappsasp
CodefixerSoftware MailingListPro Free Edition stores sensitive information under the web root with insufficient access c
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Vastal I-Tech Software Zone - 'cat_id' SQL Injection
CVE-2008-6209—webappsphp
SQL injection vulnerability in view_product.php in Vastal I-Tech Software Zone allows remote attackers to execute arbitr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Carbon Communities 2.4 - Multiple Vulnerabilities
CVE-2008-1896—webappsasp
Multiple cross-site scripting (XSS) vulnerabilities in Carbon Communities 2.4 and earlier allow remote attackers to inje
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Vastal I-Tech DVD Zone - 'cat_id' SQL Injection
CVE-2008-4465—webappsphp
SQL injection vulnerability in view_mags.php in Vastal I-Tech DVD Zone allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Vastal I-Tech Jobs Zone - 'news_id' SQL Injection
CVE-2008-4463—webappsphp
SQL injection vulnerability in view_news.php in Vastal I-Tech Jobs Zone allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Vastal I-Tech MMORPG Zone - 'game_id' SQL Injection
CVE-2008-4460—webappsphp
SQL injection vulnerability in game.php in Vastal I-Tech MMORPG Zone allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MySQL Quick Admin 1.5.5 - 'cookie' Local File Inclusion
CVE-2008-4455—webappsphp
Directory traversal vulnerability in index.php in EKINdesigns MySQL Quick Admin 1.5.5 and earlier, when magic_quotes_gpc
23RIESGO
abrir ↗
Referência✓ VexDay Proof
mIRC 6.34 - Remote Buffer Overflow (PoC)
CVE-2008-4449—doswindows
Stack-based buffer overflow in mIRC 6.34 allows remote attackers to execute arbitrary code via a long hostname in a PRIV
50RIESGO
abrir ↗
Referência✓ VexDay Proof
pPIM 1.0 - Upload/Change Password
CVE-2008-4427—webappsphp
changepassword.php in Phlatline's Personal Information Manager (pPIM) 1.0 and earlier does not require administrative au
23RIESGO
abrir ↗
Referência✓ VexDay Proof
phpBB Mod Small ShoutBox 1.4 - Remote Edit/Delete Messages
CVE-2008-6301—webappsphp
SQL injection vulnerability in shoutbox_view.php in the Small ShoutBox module 1.4 for phpBB allows remote attackers to e
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WebCMS Portal Edition - 'id' Blind SQL Injection
CVE-2008-4185—webappsphp
SQL injection vulnerability in index.php in webCMS Portal Edition allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Integramod 1.4.x - Insecure Directory Download Database
CVE-2008-4183—webappsphp
IntegraMOD 1.4.x stores sensitive information under the web root with insufficient access control, which allows remote a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
EgyPlus 7ml 1.0.1 - Authentication Bypass
CVE-2009-2167—webappsphp
Multiple SQL injection vulnerabilities in cpanel/login.php in EgyPlus 7ammel (aka 7ml) 1.0.1 and earlier, when magic_quo
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Butterfly ORGanizer 2.0.0 - Arbitrary Delete (Category/Account)
CVE-2008-7181—webappsphp
Butterfly Organizer 2.0.0 allows remote attackers to (1) delete arbitrary categories via a modified tablehere parameter
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component astatsPRO 1.0 - 'refer.php' SQL Injection
CVE-2008-0839—webappsphp
SQL injection vulnerability in refer.php in the astatsPRO (com_astatspro) 1.0 component for Joomla! allows remote attack
23RIESGO
abrir ↗
← anteriorpágina 681 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.