Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.859exploits catalogados
38.203CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
eStoreAff 0.1 - 'cid' SQL Injection
CVE-2008-3484—webappsphp
SQL injection vulnerability in eStoreAff 0.1 allows remote attackers to execute arbitrary SQL commands via the cid param
23RIESGO
abrir ↗
Referência✓ VexDay Proof
phpAuction GPL Enhanced 2.51 - 'profile.php' SQL Injection
CVE-2008-3487—webappsphp
SQL injection vulnerability in profile.php in PHPAuction GPL Enhanced 2.51 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WEBBDOMAIN Polls 1.01 - Authentication Bypass
CVE-2008-6625—webappsphp
SQL injection vulnerability in getin.php in WEBBDOMAIN Polls (aka Poll) 1.0 and 1.01 allows remote attackers to execute
23RIESGO
abrir ↗
Referência✓ VexDay Proof
minimal ablog 0.4 - SQL Injection / Arbitrary File Upload / Authentication Bypass
CVE-2008-6612—webappsphp
Unrestricted file upload vulnerability in admin/uploader.php in Minimal ABlog 0.4 allows remote attackers to execute arb
23RIESGO
abrir ↗
Referência✓ VexDay Proof
2WIRE DSL Router - 'xslt' Denial of Service
CVE-2008-6605—doshardware
Cross-site request forgery (CSRF) vulnerability in the xslt script in the web-based management interface on the 2wire 17
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Miniweb 2.0 - Authentication Bypass
CVE-2008-6582—webappsphp
SQL injection vulnerability in index.php in Miniweb 2.0 allows remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Bea Weblogic Apache Connector - Code Execution / Denial of Service
CVE-2008-3257—remotewindows
Stack-based buffer overflow in the Apache Connector (mod_wl) in Oracle WebLogic Server (formerly BEA WebLogic Server) 10
60RIESGO
abrir ↗
Referência✓ VexDay Proof
Crafty Syntax Live Help 2.14.6 - 'department' SQL Injection
CVE-2008-3845—webappsphp
Multiple SQL injection vulnerabilities in Crafty Syntax Live Help (CSLH) 2.14.6 and earlier allow remote attackers to ex
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Pragyan CMS 2.6.2 - 'sourceFolder' Remote File Inclusion
CVE-2008-3207—webappsphp
PHP remote file inclusion vulnerability in cms/modules/form.lib.php in Pragyan CMS 2.6.2, when register_globals is enabl
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CMME 1.12 - Local File Inclusion / Cross-Site Scripting / Cross-Site Request Forgery/Download Backup/Make Directory
CVE-2008-3923—webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in statistics.php in Content Management Made Easy (CMME) 1.12 allow
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Vastal I-Tech Shaadi Zone 1.0.9 - 'tage' SQL Injection
CVE-2008-3953—webappsphp
SQL injection vulnerability in keyword_search_action.php in Vastal I-Tech Shaadi Zone 1.0.9 allows remote attackers to e
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Microsoft Windows - SmbRelay3 NTLM Replay (MS08-068)
CVE-2008-4037—remotewindows
Microsoft Windows 2000 Gold through SP4, XP Gold through SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 20
50RIESGO
abrir ↗
Referência✓ VexDay Proof
Kolifa.net Download Script 1.2 - 'id' SQL Injection
CVE-2008-4054—webappsphp
SQL injection vulnerability in indir.php in Kolifa.net Download Script 1.2 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ActiveBuyandSell 6.2 - 'buyersend.asp?catid' SQL Injection
CVE-2005-2062—webappsasp
Multiple SQL injection vulnerabilities in ActiveBuyAndSell 6.2 allow remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Million Pixels 3 - 'id_cat' SQL Injection
CVE-2008-3204—webappsphp
SQL injection vulnerability in tops_top.php in E-topbiz Million Pixels 3 allows remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗
Referência✓ VexDay Proof
TWiki 4.2.0 - 'configure' Remote File Disclosure
CVE-2008-3195—webappscgi
Directory traversal vulnerability in bin/configure in TWiki before 4.2.3, when a certain step in the installation guide
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CMS Buzz - 'id' SQL Injection
CVE-2008-4374—webappsphp
SQL injection vulnerability in index.php in CMS Buzz allows remote attackers to execute arbitrary SQL commands via the i
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Creator CMS 5.0 - 'sideid' SQL Injection
CVE-2008-4377—webappsasp
SQL injection vulnerability in index.asp in Creative Mind Creator CMS 5.0 allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Hot Links SQL-PHP 3 - 'report.php' Multiple Vulnerabilities
CVE-2008-4378—webappsphp
SQL injection vulnerability in report.php in Mr. CGI Guy Hot Links SQL-PHP 3.0 and earlier allows remote attackers to ex
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Fuzzylime CMS 3.01 - Remote Command Execution
CVE-2008-3165—webappsphp
Directory traversal vulnerability in rss.php in fuzzylime (cms) 3.01a and earlier, when magic_quotes_gpc is disabled, al
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP Autos 2.9.1 - 'catid' SQL Injection
CVE-2008-4498—webappsphp
SQL injection vulnerability in searchresults.php in PHP Autos 2.9.1 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Konqueror 3.5.9 - 'font color' Remote Crash
CVE-2008-4514—doslinux
The HTML parser in KDE Konqueror 3.5.9 allows remote attackers to cause a denial of service (application crash) via a fo
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Fastpublish CMS 1.9999 - Local File Inclusion / SQL Injection
CVE-2008-4518—webappsphp
Multiple SQL injection vulnerabilities in Fastpublish CMS 1.9.9.9.9 d (1.9999 d) allow remote attackers to execute arbit
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CafeEngine - Multiple SQL Injections
CVE-2008-4605—webappsphp
SQL injection vulnerability in CafeEngine allows remote attackers to execute arbitrary SQL commands via the id parameter
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Scout Portal Toolkit 1.4.0 - 'ParentId' SQL Injection
CVE-2005-4195—webappsphp
Multiple SQL injection vulnerabilities in Scout Portal Toolkit (SPT) 1.3.1 and earlier allow remote attackers to execute
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component actualite 1.0 - 'id' SQL Injection
CVE-2008-4617—webappsphp
SQL injection vulnerability in the actualite module 1.0 for Joomla! allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗
Referência✓ VexDay Proof
more.groupware 0.74 - 'new_calendarid' SQL Injection
CVE-2006-4906—webappsphp
SQL injection vulnerability in modules/calendar/week.php in More.groupware 0.74 allows remote attackers to execute arbit
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Ultimate WebBoard 3.00 - 'Category' SQL Injection
CVE-2008-4666—webappsphp
SQL injection vulnerability in webboard.php in Ultimate Webboard 3.00 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component Highwood Design hwdVideoShare - SQL Injection
CVE-2008-0916—webappsphp
SQL injection vulnerability in the Highwood Design hwdVideoShare (com_hwdvideoshare) 1.1.3 Alpha component for Joomla!
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHPmotion 2.0 - 'update_profile.php' Arbitrary File Upload
CVE-2008-3118—webappsphp
SQL injection vulnerability in play.php in PHPmotion 2.0 and earlier allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗
← anteriorpágina 738 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.