Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.343exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
PEEL CMS 3.x - Admin Hash Extraction / Arbitrary File Upload
CVE-2008-1495webappsphp
Unrestricted file upload vulnerability in administrer/produits.php in PEEL, possibly 3.x and earlier, allows remote auth
23RIESGO
abrir
ReferênciaVexDay Proof
NetWin Surgemail 3.8k4-4 - IMAP (Authenticated) Remote LIST Universal
CVE-2008-1498remotewindows
Stack-based buffer overflow in the IMAP service in NetWin Surgemail 3.8k4-4 and earlier allows remote authenticated user
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component custompages 1.1 - Remote File Inclusion
CVE-2008-1505webappsphp
PHP remote file inclusion vulnerability in the SSTREAMTV custompages (com_custompages) 1.1 and earlier component for Joo
35RIESGO
abrir
ReferênciaVexDay Proof
Danneo CMS 0.5.1 - Blind SQL Injection
CVE-2008-1513webappsphp
SQL injection vulnerability in index.php in Danneo CMS 0.5.1 and earlier, when the Referers statistics option is enabled
23RIESGO
abrir
ReferênciaVexDay Proof
PHP-Nuke Platinum 7.6.b.5 - 'dynamic_titles.php' SQL Injection
CVE-2008-1539webappsphp
SQL injection vulnerability in includes/dynamic_titles.php in PHP-Nuke Platinum 7.6.b.5 allows remote attackers to execu
23RIESGO
abrir
ReferênciaVexDay Proof
RunCMS Module Photo 3.02 - 'cid' SQL Injection
CVE-2008-1551webappsphp
SQL injection vulnerability in viewcat.php in the Photo 3.02 module for RunCMS allows remote attackers to execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
TopperMod 2.0 - SQL Injection
CVE-2008-1554webappsphp
SQL injection vulnerability in account/index.php in TopperMod 2.0, when magic_quotes_gpc is disabled, allows remote atta
23RIESGO
abrir
ReferênciaVexDay Proof
D-Link DWL-2000AP 2.11 - ARP Flood Remote Denial of Service
CVE-2006-6538doshardware
D-LINK DWL-2000AP+ firmware 2.11 allows remote attackers to cause (1) a denial of service (device reset) via a flood of
23RIESGO
abrir
ReferênciaVexDay Proof
MPlayer 1.0 rc2 - 'sdpplin_parse()' Array Indexing Buffer Overflow (PoC)
CVE-2008-1558doslinux
Uncontrolled array index in the sdpplin_parse function in stream/realrtsp/sdpplin.c in MPlayer 1.0 rc2 allows remote att
28RIESGO
abrir
ReferênciaVexDay Proof
Fantastic News 2.1.4 - 'news.php' SQL Injection
CVE-2006-6542webappsphp
SQL injection vulnerability in news.php in Fantastic News 2.1.4 and earlier allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component Alphacontent 2.5.8 - 'id' SQL Injection
CVE-2008-1559webappsphp
SQL injection vulnerability in the Bernard Gilly AlphaContent (com_alphacontent) 2.5.8 component for Joomla! allows remo
23RIESGO
abrir
ReferênciaVexDay Proof
Aperto Blog 0.1.1 - Local File Inclusion / SQL Injection
CVE-2008-5775webappsphp
SQL injection vulnerability in categories.php in Aperto Blog 0.1.1 allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
ReferênciaVexDay Proof
CadeNix - SQL Injection
CVE-2008-5777webappsphp
SQL injection vulnerability in index.php in CadeNix allows remote attackers to execute arbitrary SQL commands via the ci
23RIESGO
abrir
ReferênciaVexDay Proof
PostNuke 0.764 - Blind SQL Injection
CVE-2008-1591webappsphp
The pnVarPrepForStore function in PostNuke 0.764 and earlier skips input sanitization when magic_quotes_runtime is enabl
23RIESGO
abrir
ReferênciaVexDay Proof
iGaming CMS 1.5 - Multiple SQL Injections
CVE-2008-5841webappsphp
Multiple SQL injection vulnerabilities in iGaming 1.5 and earlier allow remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Plugin tinybrowser 1.5.12 - Arbitrary File Upload / Execution
CVE-2011-4908webappsphp
TinyBrowser plugin for Joomla! before 1.5.13 allows arbitrary file upload via upload.php.
50RIESGO
abrir
ReferênciaVexDay Proof
EasyNews 40tr - SQL Injection / Cross-Site Scripting / Local File Inclusion
CVE-2008-1650webappsphp
SQL injection vulnerability in dynamicpages/index.php in EasyNews 4.0 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
ReferênciaVexDay Proof
Prediction Football 1.x - 'matchid' SQL Injection
CVE-2008-1732webappsphp
SQL injection vulnerability in showpredictionsformatch.php in Prediction Football 1.x allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
LiveCart 1.1.1 - 'id' Blind SQL Injection
CVE-2008-1750webappsphp
SQL injection vulnerability in Integry Systems LiveCart 1.1.1 and earlier allows remote attackers to execute arbitrary S
23RIESGO
abrir
ReferênciaVexDay Proof
KwsPHP Module ConcoursPhoto 2.0 - 'C_ID' SQL Injection
CVE-2008-1758webappsphp
SQL injection vulnerability in the ConcoursPhoto module for KwsPHP allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
ReferênciaVexDay Proof
Akamai Download Manager < 2.2.3.7 - ActiveX Remote Download
CVE-2008-1770remotewindows
CRLF injection vulnerability in Akamai Download Manager ActiveX control before 2.2.3.6 allows remote attackers to force
28RIESGO
abrir
ReferênciaVexDay Proof
BosClassifieds 3.0 - 'index.php' SQL Injection
CVE-2008-1838webappsphp
SQL injection vulnerability in BosClassifieds Classified Ads System 3.0 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
CDNetworks Nefficient Download - 'NeffyLauncher.dll' Code Execution
CVE-2008-1886remotewindows
The NeffyLauncher 1.0.5 ActiveX control (NeffyLauncher.dll) in CDNetworks Nefficient Download uses weak cryptography for
23RIESGO
abrir
ReferênciaVexDay Proof
LaserNet CMS 1.5 - SQL Injection
CVE-2008-1913webappsphp
SQL injection vulnerability in index.php in Lasernet CMS 1.5 and 1.11, when magic_quotes_gpc is disabled, allows remote
23RIESGO
abrir
ReferênciaVexDay Proof
BlogWorx 1.0 - 'id' SQL Injection
CVE-2008-1915webappsphp
SQL injection vulnerability in view.asp in DevWorx BlogWorx 1.0 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
ReferênciaVexDay Proof
5th Avenue Shopping Cart - 'category_id' SQL Injection
CVE-2008-1921webappsphp
SQL injection vulnerability in store_pages/category_list.php in 5th Avenue Shopping Cart 1.2 trial edition allows remote
23RIESGO
abrir
ReferênciaVexDay Proof
Zune Software - ActiveX Arbitrary File Overwrite
CVE-2008-1933remotewindows
Absolute path traversal vulnerability in a certain ActiveX control in Zune allows user-assisted remote attackers to over
28RIESGO
abrir
ReferênciaVexDay Proof
Crazy Goomba 1.2.1 - 'id' SQL Injection
CVE-2008-1934webappsphp
SQL injection vulnerability in commentaires.php in Crazy Goomba 1.2.1 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
ReferênciaVexDay Proof
Classifieds Caffe - 'cat_id' SQL Injection
CVE-2008-1936webappsphp
SQL injection vulnerability in index.php in Classifieds Caffe allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
Web Calendar 4.1 - Blind SQL Injection
CVE-2008-1954webappsphp
SQL injection vulnerability in one_day.php in Web Calendar Pro 4.1 and earlier allows remote attackers to execute arbitr
23RIESGO
abrir
página 1 / 188siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.