Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.202exploits catalogados
38.443CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
AShop Deluxe 4.x - 'catalogue.php' SQL Injection
CVE-2008-3136—webappsphp
SQL injection vulnerability in catalogue.php in AShop Deluxe 4.x allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SmartPPC Pay Per Click Script - 'idDirectory' Blind SQL Injection (1)
CVE-2008-3152—webappsphp
SQL injection vulnerability in directory.php in SmartPPC and SmartPPC Pro allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SmartPPC Pay Per Click Script - 'idDirectory' Blind SQL Injection (2)
CVE-2008-3152—webappsphp
SQL injection vulnerability in directory.php in SmartPPC and SmartPPC Pro allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Agares phpAutoVideo 2.21 - 'articlecat' SQL Injection (2)
CVE-2008-0262—webappsphp
SQL injection vulnerability in includes/articleblock.php in Agares PhpAutoVideo 2.21 allows remote attackers to execute
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Pligg CMS 9.9.0 - 'story.php' SQL Injection
CVE-2008-3366—webappsphp
SQL injection vulnerability in story.php in Pligg CMS Beta 9.9.0 allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Maian Uploader 4.0 - Insecure Cookie Handling
CVE-2008-3321—webappsphp
admin/index.php in Maian Uploader 4.0 and earlier allows remote attackers to bypass authentication and gain administrati
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ShopCartDx 4.30 - 'pid' SQL Injection
CVE-2008-3346—webappsphp
SQL injection vulnerability in product_detail.php in ShopCart DX allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Camera Life 2.6.2 - 'id' SQL Injection
CVE-2008-3355—webappsphp
SQL injection vulnerability in sitemap.xml.php in Camera Life 2.6.2 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Gregarius 0.5.4 - SQL Injection
CVE-2008-3374—webappsphp
SQL injection vulnerability in ajax.php in Gregarius 0.5.4 and earlier allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Referência✓ VexDay Proof
phpMyRealty 2.0.0 - 'location' SQL Injection
CVE-2008-3445—webappsphp
SQL injection vulnerability in index.php in phpMyRealty (PMR) 2.0.0 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗
Referência✓ VexDay Proof
F-PROT AntiVirus 6.2.1.4252 - Malformed Archive Infinite Loop Denial of Service
CVE-2008-3447—dosmultiple
The scanning engine in F-Prot Antivirus 6.2.1 4252 allows remote attackers to cause a denial of service (infinite loop)
23RIESGO
abrir ↗
Referência✓ VexDay Proof
eNdonesia 8.4 (Calendar Module) - SQL Injection
CVE-2008-3452—webappsphp
SQL injection vulnerability in the Calendar module in eNdonesia 8.4 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Bandwebsite 1.5 - 'LOGIN' Remote Add Admin
CVE-2006-6722—webappsphp
Bandwebsite (aka Bandsite portal system) 1.5 allows remote attackers to create administrative accounts via a direct requ
23RIESGO
abrir ↗
Referência✓ VexDay Proof
JaxUltraBB 2.0 - 'delete.php' Remote Auto Deface
CVE-2006-5511—webappsphp
Direct static code injection vulnerability in delete.php in JaxUltraBB (JUBB) 2.0, when register_globals is enabled, all
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SQLiteWebAdmin 0.1 - 'tpl.inc.php' Remote File Inclusion
CVE-2006-4102—webappsphp
PHP remote file inclusion vulnerability in tpl.inc.php in Falko Timme and Till Brehm SQLiteWebAdmin 0.1 and earlier allo
23RIESGO
abrir ↗
Referência✓ VexDay Proof
RealPlayer 10.5 - ActiveX Control Denial of Service
CVE-2006-6759—doswindows
A certain ActiveX control in rpau3260.dll in RealNetworks RealPlayer 10.5 allows remote attackers to cause a denial of s
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SuperNET Shop 1.0 - SQL Injection
CVE-2008-6204—webappsasp
Multiple SQL injection vulnerabilities in SuperNET Shop 1.0 and earlier allow remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component Tech Article 1.x - SQL Injection
CVE-2008-6050—webappsphp
SQL injection vulnerability in the Tech Articles (com_tech_article) 1.0 component for Joomla! allows remote attackers to
23RIESGO
abrir ↗
Referência✓ VexDay Proof
open NewsLetter 2.5 - Multiple Vulnerabilities (2)
CVE-2006-6785—webappsphp
The (1) settings.php and (2) subscribers.php scripts in Open Newsletter 2.5 and earlier do not exit when authentication
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Crafty Syntax Live Help 2.14.6 - 'department' SQL Injection
CVE-2008-3845—webappsphp
Multiple SQL injection vulnerabilities in Crafty Syntax Live Help (CSLH) 2.14.6 and earlier allow remote attackers to ex
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CMME 1.12 - Local File Inclusion / Cross-Site Scripting / Cross-Site Request Forgery/Download Backup/Make Directory
CVE-2008-3923—webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in statistics.php in Content Management Made Easy (CMME) 1.12 allow
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Vastal I-Tech Shaadi Zone 1.0.9 - 'tage' SQL Injection
CVE-2008-3953—webappsphp
SQL injection vulnerability in keyword_search_action.php in Vastal I-Tech Shaadi Zone 1.0.9 allows remote attackers to e
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Microsoft Windows - SmbRelay3 NTLM Replay (MS08-068)
CVE-2008-4037—remotewindows
Microsoft Windows 2000 Gold through SP4, XP Gold through SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 20
50RIESGO
abrir ↗
Referência✓ VexDay Proof
Kolifa.net Download Script 1.2 - 'id' SQL Injection
CVE-2008-4054—webappsphp
SQL injection vulnerability in indir.php in Kolifa.net Download Script 1.2 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ActiveBuyandSell 6.2 - 'buyersend.asp?catid' SQL Injection
CVE-2005-2062—webappsasp
Multiple SQL injection vulnerabilities in ActiveBuyAndSell 6.2 allow remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Microsoft Windows Explorer - '.zip' Denial of Service
CVE-2008-4323—doswindows
Windows Explorer in Microsoft Windows XP SP3 allows user-assisted attackers to cause a denial of service (application cr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Atomic Photo Album 1.1.0pre4 - Blind SQL Injection
CVE-2008-4335—webappsphp
SQL injection vulnerability in album.php in Atomic Photo Album (APA) 1.1.0pre4 allows remote attackers to execute arbitr
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MyBlog 0.9.8 - Insecure Cookie Handling
CVE-2008-4341—webappsphp
add.php in MyBlog 0.9.8 and earlier allows remote attackers to bypass authentication and gain administrative access by s
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CMS Buzz - 'id' SQL Injection
CVE-2008-4374—webappsphp
SQL injection vulnerability in index.php in CMS Buzz allows remote attackers to execute arbitrary SQL commands via the i
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Creator CMS 5.0 - 'sideid' SQL Injection
CVE-2008-4377—webappsasp
SQL injection vulnerability in index.asp in Creative Mind Creator CMS 5.0 allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗
← anteriorpágina 815 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.