Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

82.202exploits catalogados
38.443CVEs con explotación pública
24.695probados en laboratorio
24.695 exploits
Referência✓ VexDay Proof
Blog:CMS 4.2.1b - SQL Injection / Cross-Site Scripting
CVE-2008-0360—webappsphp
Multiple SQL injection vulnerabilities in BLOG:CMS 4.2.1b allow remote attackers to execute arbitrary SQL commands via (
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component com_doc - SQL Injection
CVE-2008-0772—webappsphp
SQL injection vulnerability in index.php in the com_doc component for Joomla! and Mambo allows remote attackers to execu
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP-Nuke Module EasyContent - 'page_id' SQL Injection
CVE-2008-0880—webappsphp
SQL injection vulnerability in modules.php in the EasyContent module for PHP-Nuke allows remote attackers to execute arb
23RIESGO
abrir ↗
Referência✓ VexDay Proof
vShare YouTube Clone 2.6 - 'tid' SQL Injection
CVE-2008-2223—webappsphp
SQL injection vulnerability in group_posts.php in vShare YouTube Clone 2.6 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗
Referência✓ VexDay Proof
easyTrade 2.x - 'id' SQL Injection
CVE-2008-2790—webappsphp
SQL injection vulnerability in detail.php in MountainGrafix easyTrade 2.x allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗
Referência✓ VexDay Proof
CilemNews System 1.1 - 'yazdir.asp' haber_id SQL Injection
CVE-2006-0961—webappsasp
SQL injection vulnerability in yazdir.asp in Cilem Hiber 1.1 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗
Referência✓ VexDay Proof
FlashGet 1.9 - 'FTP PWD Response' Remote Buffer Overflow (PoC)
CVE-2008-4321—doswindows
Buffer overflow in FlashGet (formerly JetCar) FTP 1.9 allows remote FTP servers to execute arbitrary code via a long res
23RIESGO
abrir ↗
Referência✓ VexDay Proof
celerbb 0.0.2 - Multiple Vulnerabilities
CVE-2009-0851—webappsphp
Multiple SQL injection vulnerabilities in CelerBB 0.0.2, when magic_quotes_gpc is disabled, allow remote attackers to ex
23RIESGO
abrir ↗
Referência✓ VexDay Proof
MiaCMS 4.6.5 - Multiple SQL Injections
CVE-2008-3785—webappsphp
Multiple SQL injection vulnerabilities in the com_content component in MiaCMS 4.6.5 allow remote attackers to execute ar
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Invision Power Board 2.1.4 - Register Users Denial of Service
CVE-2006-0888—dosmultiple
index.php in Invision Power Board (IPB) 2.0.1, with Code Confirmation disabled, allows remote attackers to cause an unsp
23RIESGO
abrir ↗
Referência✓ VexDay Proof
openEngine 2.0 beta4 - Remote File Inclusion
CVE-2008-4329—webappsphp
PHP remote file inclusion vulnerability in cms/system/openengine.php in openEngine 2.0 beta4 and earlier allows remote a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Woltlab Burning Board Lite 1.0.2 - 'decode_cookie()' SQL Injection
CVE-2006-6237—webappsphp
SQL injection vulnerability in the decode_cookie function in thread.php in Woltlab Burning Board Lite 1.0.2 allows remot
23RIESGO
abrir ↗
Referência✓ VexDay Proof
GeekLog 1.4.0sr3 - '_CONF[path]' Remote File Inclusion
CVE-2006-6225—webappsphp
Multiple PHP remote file inclusion vulnerabilities in GeekLog 1.4 allow remote attackers to execute arbitrary code via a
23RIESGO
abrir ↗
Referência✓ VexDay Proof
4Images 1.7.1 - Local File Inclusion / Remote Code Execution
CVE-2006-0899—webappsphp
Directory traversal vulnerability in index.php in 4Images 1.7.1 and earlier allows remote attackers to read and include
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Mambo Component 'com_a6mambocredits' 1.0.0 - Remote File Inclusion
CVE-2006-4288—webappsphp
PHP remote file inclusion vulnerability in admin.a6mambocredits.php in the a6mambocredits component (com_a6mambocredits)
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Basic PHP Events Lister 1.0 - SQL Injection
CVE-2008-6464—webappsphp
SQL injection vulnerability in event.php in Mevin Productions Basic PHP Events Lister 1.0 allows remote attackers to exe
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Discuz! 5.0.0 GBK - SQL Injection / Admin Credentials Disclosure
CVE-2006-5561—webappsphp
SQL injection vulnerability in admincp.php in Discuz! GBK 5.0.0 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗
Referência✓ VexDay Proof
DigiRez 3.4 - 'book_id' SQL Injection
CVE-2007-0128—webappsasp
SQL injection vulnerability in info_book.asp in Digirez 3.4 and earlier allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Liberum Help Desk 0.97.3 - SQL Injection
CVE-2006-6160—webappsasp
SQL injection vulnerability in details.asp in Doug Luxem Liberum Help Desk 0.97.3 and earlier allows remote attackers to
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Admbook 1.2.2 - 'x-forwarded-for' Remote Command Execution
CVE-2006-0852—webappsphp
Direct static code injection vulnerability in write.php in Admbook 1.2.2 and earlier allows remote attackers to execute
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Gonafish LinksCaffePRO 4.5 - 'index.php' SQL Injection
CVE-2008-4202—webappsphp
SQL injection vulnerability in index.php in Gonafish LinksCaffePRO 4.5 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Drinks Complete Website 2.1.0 - 'drinkid' SQL Injection
CVE-2008-5169—webappsphp
SQL injection vulnerability in drinks/drink.php in Drinks Complete Website 2.1.0 allows remote attackers to execute arbi
23RIESGO
abrir ↗
Referência✓ VexDay Proof
SFS EZ HotScripts-like Site - 'cid' SQL Injection
CVE-2008-6243—webappsphp
SQL injection vulnerability in showcategory.php in Scripts For Sites (SFS) Hotscripts-like Site allows remote attackers
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Joomla! Component MyContent 1.1.13 - Blind SQL Injection
CVE-2008-6430—webappsphp
SQL injection vulnerability in the MyContent (com_mycontent) component 1.1.13 for Joomla! allows remote attackers to exe
23RIESGO
abrir ↗
Referência✓ VexDay Proof
ilchClan 1.05g - 'tid' SQL Injection
CVE-2006-0851—webappsphp
SQL injection vulnerability in the forum module of ilchClan 1.05g and earlier allows remote attackers to execute arbitra
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Sisfo Kampus 0.8 - Remote File Inclusion / Download
CVE-2006-6137—webappsphp
Multiple PHP remote file inclusion vulnerabilities in Sisfo Kampus 0.8 allow remote attackers to execute arbitrary PHP c
23RIESGO
abrir ↗
Referência✓ VexDay Proof
fipsGallery 1.5 - 'index1.asp' SQL Injection
CVE-2006-6117—webappsasp
SQL injection vulnerability in index1.asp in fipsGallery 1.5 and earlier allows remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗
Referência✓ VexDay Proof
WEBBDOMAIN Webshop 1.02 - Authentication Bypass
CVE-2008-6627—webappsphp
SQL injection vulnerability in getin.php in WEBBDOMAIN WebShop 1.2, 1.1, 1.02, and earlier allows remote attackers to ex
23RIESGO
abrir ↗
Referência✓ VexDay Proof
PHP Dir Submit - Authentication Bypass
CVE-2009-1787—webappsphp
Multiple SQL injection vulnerabilities in PHP Dir Submit (aka WebsiteSubmitter and Submitter Script) allow remote attack
23RIESGO
abrir ↗
Referência✓ VexDay Proof
Vastal I-Tech Freelance Zone - 'coder_id' SQL Injection
CVE-2008-4469—webappsphp
SQL injection vulnerability in view_cresume.php in Vastal I-Tech Freelance Zone allows remote attackers to execute arbit
23RIESGO
abrir ↗
← anteriorpágina 816 / 824siguiente →

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.