Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
Simple CMS 1.0.3 - 'area' SQL Injection
CVE-2008-0835webappsphp
SQL injection vulnerability in indexen.php in Simple CMS 1.0.3 and earlier allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component com_clasifier - 'cat_id' SQL Injection
CVE-2008-0842webappsphp
SQL injection vulnerability in index.php in the Classifier (com_clasifier) component for Joomla! allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component com_pccookbook - 'user_id' SQL Injection
CVE-2008-0844webappsphp
SQL injection vulnerability in index.php in the PccookBook (com_pccookbook) component for Joomla! allows remote attacker
23RIESGO
abrir
ReferênciaVexDay Proof
Now SMS/Mms Gateway 5.5 - Remote Buffer Overflow
CVE-2008-0871remotewindows
Multiple stack-based buffer overflows in Now SMS/MMS Gateway 2007.06.27 and earlier allow remote attackers to execute ar
50RIESGO
abrir
ReferênciaVexDay Proof
PORAR WebBoard - 'question.asp' SQL Injection
CVE-2008-1039webappsasp
SQL injection vulnerability in question.asp in PORAR WEBBOARD allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
Centreon 1.4.2.3 - 'get_image.php' Remote File Disclosure
CVE-2008-1119webappsphp
Directory traversal vulnerability in include/doc/get_image.php in Centreon 1.4.2.3 and earlier allows remote attackers t
23RIESGO
abrir
ReferênciaVexDay Proof
Podcast Generator 1.0 Beta 2 - Remote File Inclusion / File Disclosure
CVE-2008-1124webappsphp
Multiple PHP remote file inclusion vulnerabilities in Podcast Generator 1.0 BETA 2 and earlier allow remote attackers to
28RIESGO
abrir
ReferênciaVexDay Proof
Mambo Component garyscookbook 1.1.1 - SQL Injection
CVE-2008-1137webappsphp
SQL injection vulnerability in the Garys Cookbook (com_garyscookbook) 1.1.1 and earlier component for Mambo and Joomla!
23RIESGO
abrir
ReferênciaVexDay Proof
DESlock+ < 3.2.6 - Local Kernel Ring0 link list zero SYSTEM
CVE-2008-1139localwindows
DESlock+ 3.2.6 and earlier, when DLMFENC.sys 1.0.0.26 and DLMFDISK.sys 1.2.0.27 are present, allows local users to gain
23RIESGO
abrir
ReferênciaVexDay Proof
DESlock+ < 3.2.6 - 'DLMFDISK.sy's Local kernel Ring0 SYSTEM
CVE-2008-1140localwindows
DLMFDISK.sys 1.2.0.27 in DESlock+ 3.2.6 and earlier allows local users to gain privileges via a certain DLKFDISK_IOCTL r
23RIESGO
abrir
ReferênciaVexDay Proof
DESlock+ < 3.2.6 - 'LIST' Local Kernel Memory Leak
CVE-2008-1141localwindows
Memory leak in DLMFENC.sys 1.0.0.26 in DESlock+ 3.2.6 and earlier allows local users to cause a denial of service (kerne
23RIESGO
abrir
ReferênciaVexDay Proof
phpArcadeScript 3.0RC2 - 'userid' SQL Injection
CVE-2008-1163webappsphp
SQL injection vulnerability in index.php in phpArcadeScript 1.0 through 3.0 RC2 allows remote attackers to execute arbit
23RIESGO
abrir
ReferênciaVexDay Proof
phpComasy 0.8 - 'mod_project_id' SQL Injection
CVE-2008-1164webappsphp
SQL injection vulnerability in index.php in phpComasy 0.8 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
ReferênciaVexDay Proof
phpBB Mod FileBase 2.0 - 'id' SQL Injection
CVE-2008-1305webappsphp
SQL injection vulnerability in filebase.php in the Filebase mod for phpBB allows remote attackers to execute arbitrary S
23RIESGO
abrir
ReferênciaVexDay Proof
Bloo 1.00 - Multiple SQL Injections
CVE-2008-1313webappsphp
Multiple SQL injection vulnerabilities in index.php in Bloo 1.00 and earlier allow remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
EasyCalendar 4.0tr - Multiple Vulnerabilities
CVE-2008-1345webappsphp
Cross-site scripting (XSS) vulnerability in plugins/calendar/calendar_backend.php in MyioSoft EasyCalendar 4.0tr and ear
23RIESGO
abrir
ReferênciaVexDay Proof
EasyGallery 5.0tr - Multiple Vulnerabilities
CVE-2008-1346webappsphp
SQL injection vulnerability in staticpages/easygallery/index.php in MyioSoft EasyGallery 5.0tr and earlier allows remote
23RIESGO
abrir
ReferênciaVexDay Proof
EasyGallery 5.0tr - Multiple Vulnerabilities
CVE-2008-1347webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in staticpages/easygallery/index.php in MyioSoft EasyGallery 5.0tr a
23RIESGO
abrir
ReferênciaVexDay Proof
Fully Modded phpBB - 'kb.php' SQL Injection
CVE-2008-1350webappsphp
SQL injection vulnerability in kb.php in Fully Modded phpBB (phpbbfm) 80220 allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
XOOPS Module tutorials 2.1b - 'printpage.php' SQL Injection
CVE-2008-1351webappsphp
SQL injection vulnerability in the Tutorials 2.1b module for XOOPS allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
ReferênciaVexDay Proof
KAPhotoservice - 'album.asp' SQL Injection
CVE-2008-1426webappsasp
SQL injection vulnerability in album.asp in KAPhotoservice allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
ReferênciaVexDay Proof
Limbo CMS 1.0.4.2 - 'sql.php' Remote File Inclusion
CVE-2006-2142webappsphp
PHP remote file inclusion vulnerability in classes/adodbt/sql.php in Limbo CMS 1.04 and earlier allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
Knowledge Base Mod 2.0.2 - 'phpBB' Remote File Inclusion
CVE-2006-2134webappsphp
PHP remote file inclusion vulnerability in /includes/kb_constants.php in Knowledge Base Mod for PHPbb 2.0.2 and earlier
23RIESGO
abrir
ReferênciaVexDay Proof
BIND 9.4.1 < 9.4.2 - Remote DNS Cache Poisoning (Metasploit)
CVE-2008-1447remotemultiple
The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windo
60RIESGO
abrir
ReferênciaVexDay Proof
BIND 9.x - Remote DNS Cache Poisoning
CVE-2008-1447remotemultiple
The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windo
60RIESGO
abrir
ReferênciaVexDay Proof
BIND 9.x - Remote DNS Cache Poisoning
CVE-2008-1447remotemultiple
The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windo
60RIESGO
abrir
ReferênciaVexDay Proof
Smoothflash - 'cid' SQL Injection
CVE-2008-1623webappsphp
SQL injection vulnerability in admin_view_image.php in Smoothflash allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
ReferênciaVexDay Proof
PHP-Fusion module Expanded Calendar 2.x - SQL Injection
CVE-2007-5187webappsphp
SQL injection vulnerability in infusions/calendar_events_panel/show_single.php in the Expanded Calendar 2.x module for P
23RIESGO
abrir
ReferênciaVexDay Proof
MusicBox 2.3.7 - 'artistId' SQL Injection
CVE-2008-2125webappsphp
SQL injection vulnerability in viewalbums.php in Musicbox 2.3.6 and 2.3.7 allows remote attackers to execute arbitrary S
23RIESGO
abrir
ReferênciaVexDay Proof
PHPMyInventory 2.8 - 'global.inc.php' Remote File Inclusion
CVE-2007-3270webappsphp
PHP remote file inclusion vulnerability in Includes/global.inc.php in phpMyInventory 2.8 allows remote attackers to exec
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.