Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.859exploits catalogados
38.203CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
Brim 1.2.1 - 'renderer' Multiple Remote File Inclusions
CVE-2006-5429—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Barry Nauta BRIM 1.2.1 and earlier allow remote attackers to execu
23RIESGO
abrir ↗
Referência✓ VexDay Proof
DELTAScripts PHP Classifieds 7.5 - Authentication Bypass
CVE-2008-5806—webappsphp
SQL injection vulnerability in login.php in DeltaScripts PHP Classifieds 7.5 and earlier allows remote attackers to exec
23RIESGO
abrir ↗
Referência✓ VexDay Proof
minimal ablog 0.4 - SQL Injection / Arbitrary File Upload / Authentication Bypass
CVE-2008-6611—webappsphp
SQL injection vulnerability in index.php in Minimal ABlog 0.4 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗
Referência✓ VexDay Proof
e107 - 'include()' Remote File Upload
CVE-2004-2262—webappsphp
ImageManager in e107 before 0.617 does not properly check the types of uploaded files, which allows remote attackers to
28RIESGO
abrir ↗
Referência✓ VexDay Proof
PHPPowerCards 2.10 - 'txt.inc.php' Remote Code Execution
CVE-2006-5432—webappsphp
Multiple direct static code injection vulnerabilities in db/txt.inc.php in phpPowerCards 2.10, when register_globals is
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PsychoStats 2.3.3 - Multiple SQL Injections
CVE-2008-6422—webappsphp
Multiple SQL injection vulnerabilities in PsychoStats 2.3, 2.3.1, and 2.3.3 allow remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component mad4Joomla! - SQL Injection
CVE-2008-6181—webappsphp
SQL injection vulnerability in the Mad4Joomla Mailforms (com_mad4joomla) component before 1.1.8.2 for Joomla! allows rem
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Softerra PHP Developer Library 1.5.3 - Remote File Inclusion
CVE-2006-5472—webappsphp
PHP remote file inclusion vulnerability in Softerra PHP Developer Library 1.5.3 and earlier allows remote attackers to e
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Web Directory Script 2.0 - 'name' SQL Injection
CVE-2008-3787—webappsphp
SQL injection vulnerability in listing_view.php in Web Directory Script 2.0 and earlier allows remote attackers to execu
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PEEL CMS 3.x - Admin Hash Extraction / Arbitrary File Upload
CVE-2008-1496—webappsphp
Multiple SQL injection vulnerabilities in PEEL, possibly 3.x and earlier, allow remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗
Referência✓ VexDay Proof
phpComasy 0.9.1 - 'entry_id' SQL Injection
CVE-2009-1023—webappsphp
SQL injection vulnerability in index.php in phpComasy 0.9.1 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
DigitalHive 2.0 RC2 - 'base_include.php' Remote File Inclusion
CVE-2006-5493—webappsphp
PHP remote file inclusion vulnerability in template/purpletech/base_include.php in DigitalHive 2.0 RC2 allows remote att
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component mDigg 2.2.8 - 'category' SQL Injection
CVE-2008-6149—webappsphp
SQL injection vulnerability in the mDigg (com_mdigg) component 2.2.8 for Joomla! allows remote attackers to execute arbi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Pilot Group PG Roommate Finder Solution - Authentication Bypass
CVE-2008-5307—webappsphp
SQL injection vulnerability in admin/index.php in PG Roommate Finder Solution allows remote attackers to execute arbitra
23RIESGO
abrir ↗
Referência✓ VexDay Proof
pandaBB - 'displayCategory' Remote File Inclusion
CVE-2006-5494—webappsphp
Multiple PHP remote file inclusion vulnerabilities in modules/My_eGallery/public/displayCategory.php in the pandaBB modu
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP-Ring Webring System 0.9 - SQL Injection
CVE-2007-2183—webappsphp
SQL injection vulnerability in index.php in PHP-Ring Webring System (aka uPHP_ring_website) 0.9 allows remote attackers
23RIESGO
abrir ↗
Referência✓ VexDay Proof
HLStats 1.34 - 'hlstats.php' SQL Injection
CVE-2006-6780—webappsphp
SQL injection vulnerability in the login form in HLstats 1.20 through 1.34 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
AssetMan 2.5-b - SQL Injection using Session Fixation
CVE-2008-4161—webappsphp
SQL injection vulnerability in search_inv.php in Assetman 2.5b allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Basic Forum 1.1 - 'edit.asp' SQL Injection
CVE-2006-6193—webappsasp
SQL injection vulnerability in edit.asp in BasicForum 1.1 and earlier allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MyFWB 1.0 - 'index.php' SQL Injection
CVE-2008-5097—webappsphp
SQL injection vulnerability in index.php in MyFWB 1.0 allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SiteEngine 5.x - Multiple Vulnerabilities
CVE-2008-7267—webappsphp
SQL injection vulnerability in announcements.php in SiteEngine 5.x allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Yblog 0.2.2.2 - Cross-Site Scripting / SQL Injection
CVE-2008-2669—webappsphp
Multiple SQL injection vulnerabilities in yBlog 0.2.2.2 allow remote attackers to execute arbitrary SQL commands via (1)
23RIESGO
abrir ↗
Referência✓ VexDay Proof
DataTrac Activity Console - Denial of Service
CVE-2005-1667—doswindows
DataTrac Activity Console 1.1 allows remote attackers to cause a denial of service via a long HTTP GET request.
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHPMyRing 4.2.1 - 'cherche.php' SQL Injection
CVE-2006-5638—webappsphp
Multiple SQL injection vulnerabilities in cherche.php in PHPMyRing 4.2.1 and earlier allow remote attackers to execute a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Attachmax Dolphin 2.1.0 - Multiple Vulnerabilities
CVE-2008-4205—webappsphp
SQL injection vulnerability in search.php Attachmax Dolphin 2.1.0 and earlier allows remote attackers to execute arbitra
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MySpace Resource Script (MSRS) 1.21 - Remote File Inclusion
CVE-2007-5721—webappsphp
PHP remote file inclusion vulnerability in _theme/breadcrumb.php in MySpacePros MySpace Resource Script (MSRS) 1.21 allo
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ITechBids 7.0 gold - Cross-Site Scripting / SQL Injection
CVE-2008-3238—webappsphp
Multiple SQL injection vulnerabilities in ITechBids 7.0 Gold allow remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Battle Blog 1.25 - 'comment.asp' SQL Injection
CVE-2008-2626—webappsphp
SQL injection vulnerability in comment.asp in Battle Blog 1.25 and earlier allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Poll Pro 2.0 - Authentication Bypass
CVE-2008-5573—webappsasp
SQL injection vulnerability in the login feature in Poll Pro 2.0 allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mambo Component Quran 1.1 - 'surano' SQL Injection
CVE-2008-0832—webappsphp
SQL injection vulnerability in index.php in the Kemas Antonius com_quran 1.1 and earlier component for Mambo and Joomla!
23RIESGO
abrir ↗
← anteriorpágina 732 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.