Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

80.095exploits catalogados
36.945CVEs con explotación pública
24.695probados en laboratorio
80.095 exploits
Exploit-DB
tPanel 2009 - Authentication Bypass
CVE-2017-15974webappsphp30 oct 2017
tPanel 2009 allows SQL injection for Authentication Bypass via 'or 1=1 or ''=' to login.php.
23RIESGO
abrir
Exploit-DB
iProject Management System 1.0 - 'ID' SQL Injection
CVE-2017-15961webappsphp30 oct 2017
iProject Management System 1.0 allows SQL Injection via the ID parameter to index.php.
23RIESGO
abrir
Exploit-DB
MyBuilder Clone 1.0 - 'subcategory' SQL Injection
CVE-2017-15968webappsphp30 oct 2017
MyBuilder Clone 1.0 allows SQL Injection via the phpsqlsearch_genxml.php subcategory parameter.
23RIESGO
abrir
Exploit-DB
Protected Links - SQL Injection
CVE-2017-15977webappsphp30 oct 2017
Protected Links - Expiring Download Links 1.0 allows SQL Injection via the username parameter.
23RIESGO
abrir
Exploit-DB
Php Inventory - Arbitrary File Upload
CVE-2017-15990webappsphp30 oct 2017
Php Inventory & Invoice Management System allows Arbitrary File Upload via dashboard/edit_myaccountdetail/.
23RIESGO
abrir
Exploit-DB
MyMagazine 1.0 - 'id' SQL Injection
CVE-2017-15983webappsphp30 oct 2017
MyMagazine Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editing
23RIESGO
abrir
Exploit-DB
News 1.0 - SQL Injection
CVE-2017-15982webappsphp30 oct 2017
Dynamic News Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for form editi
23RIESGO
abrir
Exploit-DB
SoftDatepro Dating Social Network 1.3 - SQL Injection
CVE-2017-15972webappsphp30 oct 2017
SoftDatepro Dating Social Network 1.3 allows SQL Injection via the viewprofile.php profid parameter, the viewmessage.php
23RIESGO
abrir
Exploit-DB
Mailing List Manager Pro 3.0 - SQL Injection
CVE-2017-15967webappsphp30 oct 2017
Mailing List Manager Pro 3.0 allows SQL Injection via the edit parameter to admin/users in a sort=login action, or the e
23RIESGO
abrir
Exploit-DB
Online Exam Test Application - 'sort' SQL Injection
CVE-2017-15989webappsphp30 oct 2017
Online Exam Test Application allows SQL Injection via the resources.php sort parameter in a category action.
23RIESGO
abrir
Exploit-DB
Vastal I-Tech Dating Zone 0.9.9 - 'product_id' SQL Injection
CVE-2017-15975webappsphp30 oct 2017
Vastal I-Tech Dating Zone 0.9.9 allows SQL Injection via the 'product_id' to add_to_cart.php, a different vulnerability
23RIESGO
abrir
Exploit-DB
Zomato Clone Script - 'resid' SQL Injection
CVE-2017-15993webappsphp30 oct 2017
Zomato Clone Script allows SQL Injection via the restaurant-menu.php resid parameter.
23RIESGO
abrir
Exploit-DB
Nice PHP FAQ Script - 'nice_theme' SQL Injection
CVE-2017-15988webappsphp30 oct 2017
Nice PHP FAQ Script allows SQL Injection via the index.php nice_theme parameter, a different vulnerability than CVE-2008
23RIESGO
abrir
Exploit-DB
Fake Magazine Cover Script - SQL Injection
CVE-2017-15987webappsphp30 oct 2017
Fake Magazine Cover Script allows SQL Injection via the rate.php value parameter or the content.php id parameter.
23RIESGO
abrir
GitHub PoC
skyformat99/dnsmasq-2.4.1-fix-CVE-2017-14491
CVE-2017-1449130 oct 2017
Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execut
45RIESGO
abrir
Exploit-DB
PG All Share Video 1.0 - SQL Injection
CVE-2017-15969webappsphp30 oct 2017
PG All Share Video 1.0 allows SQL Injection via the PATH_INFO to search/tag, friends/index, users/profile, or video_cata
23RIESGO
abrir
Exploit-DB
PHP CityPortal 2.0 - SQL Injection
CVE-2017-15970webappsphp30 oct 2017
PHP CityPortal 2.0 allows SQL Injection via the nid parameter to index.php in a page=news action, or the cat parameter.
23RIESGO
abrir
Exploit-DB
CmsLite 1.4 - 'S' SQL Injection
CVE-2017-15984webappsphp30 oct 2017
Creative Management System (CMS) Lite 1.4 allows SQL Injection via the S parameter to index.php.
23RIESGO
abrir
Exploit-DB
Same Sex Dating Software Pro 1.0 - SQL Injection
CVE-2017-15971webappsphp30 oct 2017
Same Sex Dating Software Pro 1.0 allows SQL Injection via the viewprofile.php profid parameter, the viewmessage.php send
23RIESGO
abrir
Exploit-DB
US Zip Codes Database - 'state' SQL Injection
CVE-2017-15980webappsphp30 oct 2017
US Zip Codes Database Script 1.0 allows SQL Injection via the state parameter.
23RIESGO
abrir
Exploit-DB
D-Park Pro 1.0 - SQL Injection
CVE-2017-15958webappsphp30 oct 2017
D-Park Pro Domain Parking Script 1.0 allows SQL Injection via the username to admin/loginform.php.
23RIESGO
abrir
Exploit-DB
CPA Lead Reward Script - SQL Injection
CVE-2017-15986webappsphp30 oct 2017
CPA Lead Reward Script allows SQL Injection via the username parameter.
23RIESGO
abrir
Exploit-DB
Shareet - 'photo' SQL Injection
CVE-2017-15979webappsphp30 oct 2017
Shareet - Photo Sharing Social Network 1.0 allows SQL Injection via the photo parameter.
23RIESGO
abrir
Exploit-DB
Basic B2B Script - SQL Injection
CVE-2017-15985webappsphp30 oct 2017
Basic B2B Script allows SQL Injection via the product_view1.php pid or id parameter.
23RIESGO
abrir
Exploit-DB
Newspaper 1.0 - SQL Injection
CVE-2017-15981webappsphp30 oct 2017
Responsive Newspaper Magazine & Blog CMS 1.0 allows SQL Injection via the id parameter to admin/admin_process.php for fo
23RIESGO
abrir
Exploit-DB
Ingenious 2.3.0 - Arbitrary File Upload
CVE-2017-15957webappsphp30 oct 2017
my_profile.php in Ingenious School Management System 2.3.0 allows a student or teacher to upload an arbitrary file.
23RIESGO
abrir
GitHub PoC
This is the Apache Struts CVE-2017-5638 struts 2 vulnerability. The same CVE that resulted in the equifax database breach.
CVE-2017-5638CRITICALbajo ataqueransomware30 oct 2017
The Jakarta Multipart parser in Apache Struts 2 2.3.x before 2.3.32 and 2.5.x before 2.5.10.1 has incorrect exception ha
100RIESGO
abrir
Exploit-DB
Job Board Script - 'nice_theme' SQL Injection
CVE-2017-15964webappsphp30 oct 2017
Job Board Script Software allows SQL Injection via the PATH_INFO to a /job-details URI.
23RIESGO
abrir
Exploit-DB
ZeeBuddy 2x - 'groupid' SQL Injection
CVE-2017-15976webappsphp30 oct 2017
ZeeBuddy 2x allows SQL Injection via the admin/editadgroup.php groupid parameter, a different vulnerability than CVE-200
23RIESGO
abrir
Exploit-DB
AROX School ERP PHP Script - 'id' SQL Injection
CVE-2017-15978webappsphp30 oct 2017
AROX School ERP PHP Script 1.0 allows SQL Injection via the office_admin/ id parameter.
23RIESGO
abrir
anteriorpágina 945 / 2670siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.