Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.859exploits catalogados
38.203CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
CaupoShop Classic 1.3 - 'saArticle[ID]' SQL Injection
CVE-2008-2866—webappsphp
SQL injection vulnerability in csc_article_details.php in Caupo.net CaupoShop Classic 1.3 allows remote attackers to exe
23RIESGO
abrir ↗
Referência✓ VexDay Proof
E-topbiz ViralDX 2.07 - 'bannerid' SQL Injection
CVE-2008-2867—webappsphp
SQL injection vulnerability in adclick.php in E-topbiz Viral DX 1 2.07 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component Car Manager 1.1 - SQL Injection
CVE-2007-1704—webappsphp
SQL injection vulnerability in index.php in the Car Manager (com_resman) 1.1 and earlier component for Joomla! allows re
23RIESGO
abrir ↗
Referência✓ VexDay Proof
celerbb 0.0.2 - Multiple Vulnerabilities
CVE-2009-0851—webappsphp
Multiple SQL injection vulnerabilities in CelerBB 0.0.2, when magic_quotes_gpc is disabled, allow remote attackers to ex
23RIESGO
abrir ↗
Referência✓ VexDay Proof
XOOPS Module myAlbum-P 2.0 - 'cid' SQL Injection
CVE-2007-1807—webappsphp
SQL injection vulnerability in modules/myalbum/viewcat.php in the myAlbum-P 2.0 and earlier module for Xoops allows remo
23RIESGO
abrir ↗
Referência✓ VexDay Proof
gf-3xplorer 2.4 - Cross-Site Scripting / Local File Inclusion
CVE-2007-6474—webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in GF-3XPLORER 2.4 allow remote attackers to inject arbitrary web sc
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Dokeos 1.8.0 - 'my_progress.php?course' SQL Injection
CVE-2007-2902—webappsphp
SQL injection vulnerability in main/auth/my_progress.php in Dokeos 1.8.0 and earlier allows remote authenticated users t
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Butterfly ORGanizer 2.0.1 - 'id' SQL Injection
CVE-2008-6311—webappsphp
SQL injection vulnerability in view.php in Butterfly Organizer 2.0.1 allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Elkagroup Image Gallery 1.0 - SQL Injection
CVE-2007-3461—webappsphp
SQL injection vulnerability in property.php in elkagroup Image Gallery 1.0 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Blog:CMS 4.2.1b - SQL Injection / Cross-Site Scripting
CVE-2008-0360—webappsphp
Multiple SQL injection vulnerabilities in BLOG:CMS 4.2.1b allow remote attackers to execute arbitrary SQL commands via (
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component com_doc - SQL Injection
CVE-2008-0772—webappsphp
SQL injection vulnerability in index.php in the com_doc component for Joomla! and Mambo allows remote attackers to execu
23RIESGO
abrir ↗
Referência✓ VexDay Proof
TUTOS 1.3 - 'cmd.php' Remote Command Execution
CVE-2008-0149—webappsphp
TUTOS 1.3 allows remote attackers to read system information via a direct request to php/admin/phpinfo.php, which calls
23RIESGO
abrir ↗
Referência✓ VexDay Proof
FlexBB 0.6.3 - Cookies SQL Injection
CVE-2008-0157—webappsphp
SQL injection vulnerability in FlexBB 0.6.3 and earlier allows remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ShareCMS 0.1 - Multiple SQL Injections
CVE-2008-2870—webappsphp
Multiple SQL injection vulnerabilities in ShareCMS 0.1 Beta allow remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗
Referência✓ VexDay Proof
e107 Plugin lyrics_menu - 'l_id' SQL Injection
CVE-2008-4906—webappsphp
SQL injection vulnerability in lyrics_song.php in the Lyrics (lyrics_menu) plugin 0.42 for e107 allows remote attackers
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MTCMS 2.0 - SQL Injection
CVE-2008-0280—webappsphp
SQL injection vulnerability in index.php in MTCMS 2.0 and possibly earlier versions allows remote attackers to execute a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
vbLOGIX Tutorial Script 1.0 - 'cat_id' SQL Injection
CVE-2008-4350—webappsphp
SQL injection vulnerability in main.php in vbLOGIX Tutorial Script 1.0 and earlier allows remote attackers to execute ar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mambo 4.6.4 - 'Output.php' Remote File Inclusion
CVE-2008-2905—webappsphp
PHP remote file inclusion vulnerability in includes/Cache/Lite/Output.php in the Cache_Lite package in Mambo 4.6.4 and e
43RIESGO
abrir ↗
Referência✓ VexDay Proof
Pre ADS Portal 2.0 - SQL Injection
CVE-2008-2916—webappsphp
Multiple SQL injection vulnerabilities in Pre ADS Portal 2.0 and earlier, when magic_quotes_gpc is disabled, allow remot
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Dana IRC 1.3 - Remote Buffer Overflow (PoC)
CVE-2008-2922—doswindows
Stack-based buffer overflow in artegic Dana IRC client 1.3 and earlier allows remote attackers to cause a denial of serv
23RIESGO
abrir ↗
Referência✓ VexDay Proof
TualBLOG 1.0 - 'icerikno' SQL Injection
CVE-2006-4793—webappsasp
Multiple SQL injection vulnerabilities in icerik.asp in TualBLOG 1.0 allow remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP-Nuke Module EasyContent - 'page_id' SQL Injection
CVE-2008-0880—webappsphp
SQL injection vulnerability in modules.php in the EasyContent module for PHP-Nuke allows remote attackers to execute arb
23RIESGO
abrir ↗
Referência✓ VexDay Proof
vShare YouTube Clone 2.6 - 'tid' SQL Injection
CVE-2008-2223—webappsphp
SQL injection vulnerability in group_posts.php in vShare YouTube Clone 2.6 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
X7 Chat 2.0.4 - 'old_prefix' Blind SQL Injection
CVE-2006-3851—webappsphp
SQL injection vulnerability in upgradev1.php in X7 Chat 2.0.4 and earlier allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Web-MeetMe 3.0.3 - 'play.php' Remote File Disclosure
CVE-2007-6215—webappsphp
Multiple directory traversal vulnerabilities in play.php in Web-MeetMe 3.0.3 allow remote attackers to read arbitrary fi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
LearnLoop 2.0beta7 - 'sFilePath' Remote File Disclosure
CVE-2007-6214—webappsphp
Directory traversal vulnerability in include/file_download.php in LearnLoop 2.0 beta7 allows remote attackers to read ar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ActualAnalyzer - 'ant' Cookie Command Execution (Metasploit)
CVE-2014-5470CRITICALremoteunix
Actual Analyzer through 2014-08-29 allows code execution via shell metacharacters because untrusted input is used for pa
68RIESGO
abrir ↗
Referência✓ VexDay Proof
Binn SBuilder - 'nid' Blind SQL Injection
CVE-2008-0253—webappsphp
SQL injection vulnerability in full_text.php in Binn SBuilder allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗
Referência✓ VexDay Proof
psipuss 1.0 - Multiple SQL Injections
CVE-2008-3598—webappsphp
Multiple SQL injection vulnerabilities in psipuss 1.0 allow remote attackers to execute arbitrary SQL commands via (1) t
23RIESGO
abrir ↗
Referência✓ VexDay Proof
BolinOS 4.6.1 - Local File Inclusion / Cross-Site Scripting
CVE-2008-1556—webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in BolinOS 4.6.1 allow remote attackers to inject arbitrary web scri
23RIESGO
abrir ↗
← anteriorpágina 727 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.