Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.859exploits catalogados
38.203CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
ClipShare < 3.0.1 - 'tid' SQL Injection
CVE-2008-2793—webappsphp
SQL injection vulnerability in group_posts.php in ClipShare before 3.0.1 allows remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗
Referência✓ VexDay Proof
doITlive CMS 2.50 - SQL Injection / Cross-Site Scripting
CVE-2008-2842—webappsasp
Cross-site scripting (XSS) vulnerability in edit/showmedia.asp in doITLive CMS 2.50 and earlier allows remote attackers
23RIESGO
abrir ↗
Referência✓ VexDay Proof
BoatScripts Classifieds - 'type' SQL Injection
CVE-2008-2846—webappsphp
SQL injection vulnerability in index.php in BoatScripts Classifieds allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Softbiz Ad Management plus Script 1 - SQL Injection
CVE-2007-5998—webappsphp
SQL injection vulnerability in ads.php in Softbiz Ad Management plus Script 1 allows remote authenticated users to execu
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Kmita Tellfriend 2.0 - 'file' Remote File Inclusion
CVE-2008-2198—webappsphp
PHP remote file inclusion vulnerability in kmitaadmin/kmitat/htmlcode.php in Kmita Tellfriend 2.0 and earlier, when regi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Hospital Management System 4.0 - Persistent Cross-Site Scripting
CVE-2020-5191—webappsphp
PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple Persistent XSS vulnerabilities.
38RIESGO
abrir ↗
Referência✓ VexDay Proof
ZeroCMS 1.0 Alpha - Arbitrary File Upload / SQL Injection
CVE-2008-0232—webappsphp
Multiple SQL injection vulnerabilities in Zero CMS 1.0 Alpha allow remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mini File Host 1.2 - 'language' Local File Inclusion
CVE-2008-0357—webappsphp
Directory traversal vulnerability in pages/upload.php in Galaxyscripts Mini File Host 1.2.1 and earlier allows remote at
23RIESGO
abrir ↗
Referência✓ VexDay Proof
IceBB 1.0-rc6 - Remote Database Authentication Details
CVE-2007-6083—webappsphp
SQL injection vulnerability in admin/index.php in IceBB 1.0-rc6 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PortalApp 4.0 - SQL Injection / Cross-Site Scripting / Authentication Bypass
CVE-2008-4613—webappsasp
SQL injection vulnerability in forums.asp in PortalApp 4.0 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ZeroCMS 1.0 Alpha - Arbitrary File Upload / SQL Injection
CVE-2008-0233—webappsphp
Unrestricted file upload vulnerability in Zero CMS 1.0 Alpha and earlier allows remote attackers to bypass intended acce
23RIESGO
abrir ↗
Referência✓ VexDay Proof
QuickTime Player 7.3.1.70 - 'RTSP' Buffer Overflow (PoC)
CVE-2008-0234—doswindows
Buffer overflow in Apple Quicktime Player 7.3.1.70 and other versions before 7.4.1, when RTSP tunneling is enabled, allo
28RIESGO
abrir ↗
Referência✓ VexDay Proof
ResearchGuide 0.5 - 'id' SQL Injection
CVE-2008-2964—webappsphp
SQL injection vulnerability in guide.php in ResearchGuide 0.5 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗
Referência✓ VexDay Proof
project alumni 1.0.9 - Cross-Site Scripting / SQL Injection
CVE-2007-6126—webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in project alumni 1.0.9 and earlier allow remote attackers to inject
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WorkingOnWeb 2.0.1400 - 'events.php' SQL Injection
CVE-2007-6128—webappsphp
SQL injection vulnerability in events.php in WorkingOnWeb 2.0.1400 allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Content Injector 1.52 - 'index.php?cat' SQL Injection
CVE-2007-6137—webappsphp
SQL injection vulnerability in news.php in Content Injector 1.52 allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Small Axe 0.3.1 - 'cfile' Remote File Inclusion
CVE-2008-0376—webappsphp
PHP remote file inclusion vulnerability in inc/linkbar.php in Small Axe Weblog 0.3.1 allows remote attackers to execute
35RIESGO
abrir ↗
Referência✓ VexDay Proof
YaBBSM 3.0.0 - 'Offline.php' Remote File Inclusion
CVE-2006-5413—webappsphp
Multiple PHP remote file inclusion vulnerabilities in SuperMod 3.0.0 for YABB (YaBBSM) allow remote attackers to execute
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Crystal Reports XI Release 2 (Enterprise Tree Control) - ActiveX Buffer Overflow (Denial of Service) (PoC)
CVE-2008-0379—doswindows
Race condition in the Enterprise Tree ActiveX control (EnterpriseControls.dll 11.5.0.313) in Crystal Reports XI Release
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Ultrastats 0.2.144/0.3.11 - 'serverid' SQL Injection
CVE-2008-6260—webappsphp
SQL injection vulnerability in index.php in Ultrastats 0.2.144 and 0.3.11 allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Apoll 0.7b - Authentication Bypass
CVE-2008-6270—webappsphp
SQL injection vulnerability in admin/index.php in Dragan Mitic Apoll 0.7 beta and 0.7.5 allows remote attackers to execu
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Apoll 0.7b - Authentication Bypass
CVE-2008-6272—webappsphp
SQL injection vulnerability in admin/index.php in Dragan Mitic Apoll 0.7 beta and 0.7.5 allows remote attackers to execu
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Cdsagenda 4.2.9 - 'SendAlertEmail.php' File Inclusion
CVE-2006-5384—webappsphp
PHP remote file inclusion vulnerability in modification/SendAlertEmail.php in CDS Software Consortium CDS Agenda 4.2.9 a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
JASmine 0.0.2 - 'index.php' Remote File Inclusion
CVE-2006-5318—webappsphp
PHP remote file inclusion vulnerability in index.php in Nayco JASmine (aka Jasmine-Web) allows remote attackers to execu
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CSPartner 1.0 - Delete All Users / SQL Injection
CVE-2008-6165—webappsphp
SQL injection vulnerability in gestion.php in CSPartner 0.1, when magic_quotes_gpc is disabled, allows remote attackers
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Vlog System 1.1 - SQL Injection
CVE-2008-6111—webappsphp
SQL injection vulnerability in blog.php in NetArt Media Vlog System 1.1 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Download-Engine 1.4.2 - 'spaw' Remote File Inclusion
CVE-2006-5291—webappsphp
PHP remote file inclusion vulnerability in admin/includes/spaw/spaw_control.class.php in Download-Engine 1.4.2 allows re
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Limbo CMS - Private Messaging Component SQL Injection
CVE-2008-6078—webappsphp
SQL injection vulnerability in open.php in the Private Messaging (com_privmsg) component for Limbo CMS allows remote att
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Minichat 6.0 - 'ftag.php' Remote File Inclusion
CVE-2006-5283—webappsphp
PHP remote file inclusion vulnerability in ftag.php in Minichat 6.0 allows remote attackers to execute arbitrary PHP cod
23RIESGO
abrir ↗
Referência✓ VexDay Proof
aspwebalbum 3.2 - Multiple Vulnerabilities
CVE-2004-1553—webappsasp
SQL injection vulnerability in aspWebAlbum allows remote attackers to execute arbitrary SQL statements via (1) the usern
23RIESGO
abrir ↗
← anteriorpágina 729 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.