Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
Web Group Communication Center (WGCC) 1.0.3 - SQL Injection
CVE-2008-2445webappsphp
Cross-site scripting (XSS) vulnerability in profile.php in Web Group Communication Center (WGCC) 1.0.3 PreRelease 1 and
23RIESGO
abrir
ReferênciaVexDay Proof
e-107 Plugin ZoGo-Shop 1.16 Beta 13 - SQL Injection
CVE-2008-2447webappsphp
SQL injection vulnerability in products.php in the Mytipper ZoGo-shop plugin 1.15.5 and 1.16 Beta 13 for e107 allows rem
23RIESGO
abrir
ReferênciaVexDay Proof
ComicShout 2.5 - 'comic_id' SQL Injection
CVE-2008-2456webappsphp
SQL injection vulnerability in index.php in ComicShout 2.5 and earlier allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
μTorrent (uTorrent) 1.6 build 474 - 'announce' Key Remote Heap Overflow
CVE-2007-0927remotewindows
Heap-based buffer overflow in uTorrent 1.6 allows remote attackers to execute arbitrary code via a torrent file with a c
35RIESGO
abrir
ReferênciaVexDay Proof
LibSPF2 < 1.2.8 - DNS TXT Record Parsing Bug Heap Overflow (PoC)
CVE-2008-2469dosmultiple
Heap-based buffer overflow in the SPF_dns_resolv_lookup function in Spf_dns_resolv.c in libspf2 before 1.2.8 allows remo
28RIESGO
abrir
ReferênciaVexDay Proof
Total Video Player 1.20 - '.m3u' File Local Stack Buffer Overflow
CVE-2007-0949localwindows
Stack-based buffer overflow in iTinySoft Studio Total Video Player 1.03, and possibly earlier, allows remote attackers t
28RIESGO
abrir
ReferênciaVexDay Proof
PHPRaider 1.0.7 - 'PHPbb3.functions.php' Remote File Inclusion
CVE-2008-2481webappsphp
PHP remote file inclusion vulnerability in authentication/phpbb3/phpbb3.functions.php in phpRaider 1.0.7 and 1.0.7a, whe
23RIESGO
abrir
ReferênciaVexDay Proof
Xomol CMS 1.2 - Authentication Bypass / Local File Inclusion
CVE-2008-2484webappsphp
SQL injection vulnerability in index.php in Xomol CMS 1.20071213, when magic_quotes_gpc is disabled, allows remote attac
23RIESGO
abrir
ReferênciaVexDay Proof
RoomPHPlanning 1.5 - Arbitrary Add Admin
CVE-2008-2488webappsphp
admin/userform.php in RoomPHPlanning 1.5 does not require administrative credentials, which allows remote authenticated
23RIESGO
abrir
ReferênciaVexDay Proof
Netbutikker 4 - SQL Injection
CVE-2008-2504webappsphp
Multiple SQL injection vulnerabilities in Simpel Side Netbutik 1 through 4 allow remote attackers to execute arbitrary S
23RIESGO
abrir
ReferênciaVexDay Proof
CA Internet Security Suite 2008 - 'SaveToFile()' File Corruption (PoC)
CVE-2008-2511doswindows
Directory traversal vulnerability in the UmxEventCli.CachedAuditDataList.1 (aka UmxEventCliLib) ActiveX control in UmxEv
28RIESGO
abrir
ReferênciaVexDay Proof
Mega File Hosting Script 1.2 - 'fid' SQL Injection
CVE-2008-2521webappsphp
SQL injection vulnerability in members.php in YABSoft Mega File Hosting Script (aka MFH or MFHS) 1.2 allows remote authe
23RIESGO
abrir
ReferênciaVexDay Proof
Enrollment System Project v1.0 - SQL Injection Authentication Bypass (SQLI)
CVE-2023-33584CRITICALwebappsphp
Sourcecodester Enrollment System Project V1.0 is vulnerable to SQL Injection (SQLI) attacks, which allow an attacker to
53RIESGO
abrir
ReferênciaVexDay Proof
TutorialCMS 1.01 - Authentication Bypass
CVE-2007-2822webappsphp
TutorialCMS 1.01 and earlier, when register_globals is enabled, allows remote attackers to bypass authentication via the
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Visual Basic 6.0 Project - Company Name Stack Overflow (PoC)
CVE-2007-2884doswindows
Multiple stack-based buffer overflows in Microsoft Visual Basic 6 allow user-assisted remote attackers to cause a denial
35RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Visual Basic 6.0 Project - Description Stack Overflow (PoC)
CVE-2007-2884doswindows
Multiple stack-based buffer overflows in Microsoft Visual Basic 6 allow user-assisted remote attackers to cause a denial
35RIESGO
abrir
ReferênciaVexDay Proof
UltraISO 8.6.2.2011 - '.cue/'.bin' Local Buffer Overflow (PoC)
CVE-2007-2888doswindows
Stack-based buffer overflow in UltraISO 8.6.2.2011 and earlier allows user-assisted remote attackers to execute arbitrar
50RIESGO
abrir
ReferênciaVexDay Proof
Battle.net Clan Script 1.5.x - SQL Injection
CVE-2008-2522webappsphp
SQL injection vulnerability in members.php in Battle.net Clan Script for PHP 1.5.3 and earlier, when magic_quotes_gpc is
23RIESGO
abrir
ReferênciaVexDay Proof
QuickUpCMS - Multiple SQL Injections Vulnerabilities
CVE-2008-2530webappsphp
Multiple SQL injection vulnerabilities in Concepts & Solutions QuickUpCMS allow remote attackers to execute arbitrary SQ
23RIESGO
abrir
ReferênciaVexDay Proof
Extreme phpBB 3.0.1 - 'functions.php' Remote File Inclusion
CVE-2007-1105webappsphp
PHP remote file inclusion vulnerability in functions.php in Extreme phpBB (aka phpBB Extreme) 3.0.1 allows remote attack
23RIESGO
abrir
ReferênciaVexDay Proof
Advanced Image Hosting (AIH) 2.1 - SQL Injection
CVE-2008-2536webappsphp
SQL injection vulnerability in out.php in YABSoft Advanced Image Hosting (AIH) Script 2.1 and earlier allows remote atta
23RIESGO
abrir
ReferênciaVexDay Proof
SCO UnixWare Reliant HA 1.1.4 - Local Privilege Escalation
CVE-2008-6558localsco
Untrusted search path vulnerability in (1) hvdisp and (2) rcvm in ReliantHA 1.1.4 in SCO UnixWare 7.1.4 allows local use
23RIESGO
abrir
ReferênciaVexDay Proof
BP Blog 6.0 - 'id' Blind SQL Injection
CVE-2008-2554webappsasp
Multiple SQL injection vulnerabilities in BP Blog 6.0 allow remote attackers to execute arbitrary SQL commands via the (
23RIESGO
abrir
ReferênciaVexDay Proof
Power Phlogger 2.2.5 - 'css_str' SQL Injection
CVE-2008-2562webappsphp
SQL injection vulnerability in edCss.php in PowerPhlogger 2.2.5 and earlier allows remote authenticated users to execute
23RIESGO
abrir
ReferênciaVexDay Proof
Banner Management Script - 'id' SQL Injection
CVE-2008-3749webappsphp
SQL injection vulnerability in tr.php in YourFreeWorld Banner Management Script allows remote attackers to execute arbit
23RIESGO
abrir
ReferênciaVexDay Proof
Angel Lms 7.1 - 'default.asp?id' SQL Injection
CVE-2007-1250webappsasp
SQL injection vulnerability in section/default.asp in ANGEL Learning Management Suite (LMS) 7.1 allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
WEBBDOMAIN Quiz 1.02 - Authentication Bypass
CVE-2008-6626webappsphp
SQL injection vulnerability in getin.php in WEBBDOMAIN Quiz 1.02 and earlier allows remote attackers to execute arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
MercuryBoard 1.1.5 - 'login.php' Blind SQL Injection
CVE-2008-6632webappsphp
SQL injection vulnerability in func/login.php in MercuryBoard 1.1.5 and earlier allows remote attackers to execute arbit
23RIESGO
abrir
ReferênciaVexDay Proof
PHP-Address Book 3.1.5 - SQL Injection / Cross-Site Scripting
CVE-2008-2565webappsphp
Multiple SQL injection vulnerabilities in PHP Address Book 3.1.5 and earlier allow remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
PHP-Address Book 4.0.x - Multiple SQL Injections
CVE-2008-2565webappsphp
Multiple SQL injection vulnerabilities in PHP Address Book 3.1.5 and earlier allow remote attackers to execute arbitrary
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.