Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

81.924exploits catalogados
38.251CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
DigiLeave 1.2 - 'book_id' Blind SQL Injection
CVE-2008-3309—webappsasp
SQL injection vulnerability in info_book.asp in DigiLeave 1.2 and earlier allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MyBulletinBoard (MyBB) 1.2.10 - Remote Code Execution
CVE-2008-0382—webappsphp
Multiple eval injection vulnerabilities in MyBB 1.2.10 and earlier allow remote attackers to execute arbitrary code via
35RIESGO
abrir ↗
Referência✓ VexDay Proof
V3 Chat Profiles/Dating Script 3.0.2 - Authentication Bypass
CVE-2008-5785—webappsphp
SQL injection vulnerability in V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir ↗
Referência✓ VexDay Proof
plx Ad Trader 3.2 - 'adid' SQL Injection
CVE-2008-3025—webappsphp
SQL injection vulnerability in ad.php in plx Ad Trader 3.2 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Live Music Plus 1.1.0 - 'id' SQL Injection
CVE-2008-3352—webappsphp
SQL injection vulnerability in index.php in Live Music Plus 1.1.0 allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir ↗
Referência✓ VexDay Proof
deeemm CMS (dmcms) 0.7.4 - Multiple Vulnerabilities
CVE-2008-3720—webappsphp
SQL injection vulnerability in index.php in DeeEmm CMS (DMCMS) 0.7.4 allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MyCard 1.0.2 - 'id' SQL Injection
CVE-2008-4738—webappsphp
SQL injection vulnerability in gallery.php in MyCard 1.0.2 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ASPSiteWare Home Builder 1.0/2.0 - SQL Injection
CVE-2008-5774—webappsasp
Multiple SQL injection vulnerabilities in ASPSiteWare HomeBuilder 1.0 and 2.0 allow remote attackers to execute arbitrar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
AJSquare Free Polling Script - 'DB' Multiple Vulnerabilities
CVE-2008-7044—webappsphp
SQL injection vulnerability in admin/include/newpoll.php in AJ Square Free Polling Script (AJPoll) Database version allo
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Jamit Job Board 3.x - Blind SQL Injection
CVE-2008-5295—webappsphp
SQL injection vulnerability in index.php in Jamit Job Board 3.4.10 allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗
Referência✓ VexDay Proof
FAQ Manager 1.2 - 'categorie.php' SQL Injection
CVE-2008-5287—webappsphp
SQL injection vulnerability in catagorie.php in Werner Hilversum FAQ Manager 1.2 allows remote attackers to execute arbi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
E-topbiz Number Links 1 - 'id' SQL Injection
CVE-2008-5804—webappsphp
SQL injection vulnerability in admin/admin_catalog.php in e-topbiz Number Links 1 Php Script allows remote attackers to
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SFS EZ Auction - Blind SQL Injection
CVE-2008-6778—webappsphp
SQL injection vulnerability in viewfaqs.php in Scripts for Sites (SFS) EZ Auction allows remote attackers to execute arb
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component live chat - SQL Injection / Open Proxy
CVE-2008-6883—webappsphp
SQL injection vulnerability in the Live Chat (com_livechat) component 1.0 for Joomla! allows remote attackers to execute
23RIESGO
abrir ↗
Referência✓ VexDay Proof
phpdaily - SQL Injection / Cross-Site Scripting / Local File Download
CVE-2008-4757—webappsphp
Multiple SQL injection vulnerabilities in PHP-Daily allow remote attackers to execute arbitrary SQL commands via the (1)
23RIESGO
abrir ↗
Referência✓ VexDay Proof
NewsLetter 3.5 - 'NL_PATH' Remote File Inclusion
CVE-2006-3986—webappsphp
PHP remote file inclusion vulnerability in index.php in Knusperleicht Newsletter 3.5 and earlier allows remote attackers
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Hummingbird Deployment Wizard 2008 - ActiveX Command Execution
CVE-2008-4728—remotewindows
Multiple insecure method vulnerabilities in the DeployRun.DeploymentSetup.1 (DeployRun.dll) ActiveX control 10.0.0.44 in
35RIESGO
abrir ↗
Referência✓ VexDay Proof
Hummingbird Deployment Wizard 2008 - ActiveX File Execution(2)
CVE-2008-4728—remotewindows
Multiple insecure method vulnerabilities in the DeployRun.DeploymentSetup.1 (DeployRun.dll) ActiveX control 10.0.0.44 in
35RIESGO
abrir ↗
Referência✓ VexDay Proof
wbstreet 1.0 - SQL Injection / File Disclosure
CVE-2008-5955—webappsphp
SQL injection vulnerability in show.php in Wbstreet (aka PHPSTREET Webboard) 1.0 allows remote attackers to execute arbi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
IncCMS Core 1.0.0 - 'settings.php' Remote File Inclusion
CVE-2006-5304—webappsphp
PHP remote file inclusion vulnerability in inc/settings.php in IncCMS Core 1.0.0 and earlier allows remote attackers to
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Ocean12 Mailing List Manager Gold - File Disclosure / SQL Injection / Cross-Site Scripting
CVE-2008-5980—webappsphp
Ocean12 Mailing List Manager Gold stores sensitive data under the web root with insufficient access control, which allow
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MFORUM 0.1a - Arbitrary Add Admin
CVE-2008-3191—webappsphp
Multiple SQL injection vulnerabilities in usercp.php in mForum 0.1a, when magic_quotes_gpc is disabled, allow remote att
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP-Nuke Module books SQL - 'cid' SQL Injection
CVE-2008-0827—webappsphp
SQL injection vulnerability in the Books module of PHP-Nuke allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Exponent CMS 0.96.3 - 'view' Remote Command Execution
CVE-2006-4963—webappsphp
Directory traversal vulnerability in index.php in Exponent CMS 0.96.3 allows remote attackers to read and execute arbitr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WzdFTPD 0.8.0 - 'USER' Remote Denial of Service
CVE-2007-5300—doswindows
Off-by-one error in the do_login_loop function in libwzd-core/wzd_login.c in wzdftpd 0.8.0, 0.8.2, and possibly other ve
23RIESGO
abrir ↗
Referência✓ VexDay Proof
sma-db 0.3.12 - Remote File Inclusion / Cross-Site Scripting
CVE-2009-1450—webappsphp
PHP remote file inclusion vulnerability in format.php in SMA-DB 0.3.12 allows remote attackers to execute arbitrary PHP
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Firefly Media Server 0.2.4 - Remote Denial of Service
CVE-2007-5824—doslinux
webserver.c in mt-dappd in Firefly Media Server 0.2.4 and earlier allows remote attackers to cause a denial of service (
23RIESGO
abrir ↗
Referência✓ VexDay Proof
nuBoard 0.5 - 'site' Remote File Inclusion
CVE-2007-5841—webappsphp
PHP remote file inclusion vulnerability in admin/index.php in nuBoard 0.5 allows remote attackers to execute arbitrary P
35RIESGO
abrir ↗
Referência✓ VexDay Proof
GuppY 4.6.3 - 'index.php?selskin' Remote File Inclusion
CVE-2007-5844—webappsphp
Directory traversal vulnerability in inc/includes.inc in GuppY 4.6.3 allows remote attackers to include and execute arbi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
LulieBlog 1.02 - SQL Injection
CVE-2008-0446—webappsphp
SQL injection vulnerability in voircom.php in LulieBlog 1.02 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗
← anteriorpágina 746 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.