Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
22.832 exploits
Referência
CVE-2019-1821
Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
78RIESGO
abrir
ReferênciaVexDay Proof
Battle.net Clan Script 1.5.x - SQL Injection
CVE-2008-2522webappsphp
SQL injection vulnerability in members.php in Battle.net Clan Script for PHP 1.5.3 and earlier, when magic_quotes_gpc is
23RIESGO
abrir
ReferênciaVexDay Proof
QuickUpCMS - Multiple SQL Injections Vulnerabilities
CVE-2008-2530webappsphp
Multiple SQL injection vulnerabilities in Concepts & Solutions QuickUpCMS allow remote attackers to execute arbitrary SQ
23RIESGO
abrir
ReferênciaVexDay Proof
Extreme phpBB 3.0.1 - 'functions.php' Remote File Inclusion
CVE-2007-1105webappsphp
PHP remote file inclusion vulnerability in functions.php in Extreme phpBB (aka phpBB Extreme) 3.0.1 allows remote attack
23RIESGO
abrir
ReferênciaVexDay Proof
Advanced Image Hosting (AIH) 2.1 - SQL Injection
CVE-2008-2536webappsphp
SQL injection vulnerability in out.php in YABSoft Advanced Image Hosting (AIH) Script 2.1 and earlier allows remote atta
23RIESGO
abrir
ReferênciaVexDay Proof
SCO UnixWare Reliant HA 1.1.4 - Local Privilege Escalation
CVE-2008-6558localsco
Untrusted search path vulnerability in (1) hvdisp and (2) rcvm in ReliantHA 1.1.4 in SCO UnixWare 7.1.4 allows local use
23RIESGO
abrir
ReferênciaVexDay Proof
BP Blog 6.0 - 'id' Blind SQL Injection
CVE-2008-2554webappsasp
Multiple SQL injection vulnerabilities in BP Blog 6.0 allow remote attackers to execute arbitrary SQL commands via the (
23RIESGO
abrir
ReferênciaVexDay Proof
Power Phlogger 2.2.5 - 'css_str' SQL Injection
CVE-2008-2562webappsphp
SQL injection vulnerability in edCss.php in PowerPhlogger 2.2.5 and earlier allows remote authenticated users to execute
23RIESGO
abrir
Referência
CVE-2008-2565
Multiple SQL injection vulnerabilities in PHP Address Book 3.1.5 and earlier allow remote attackers to execute arbitrary
23RIESGO
abrir
Referência
CVE-2019-18818
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RIESGO
abrir
Referência
CVE-2019-18818
strapi before 3.0.0-beta.17.5 mishandles password resets within packages/strapi-admin/controllers/Auth.js and packages/s
60RIESGO
abrir
ReferênciaVexDay Proof
Banner Management Script - 'id' SQL Injection
CVE-2008-3749webappsphp
SQL injection vulnerability in tr.php in YourFreeWorld Banner Management Script allows remote attackers to execute arbit
23RIESGO
abrir
ReferênciaVexDay Proof
Angel Lms 7.1 - 'default.asp?id' SQL Injection
CVE-2007-1250webappsasp
SQL injection vulnerability in section/default.asp in ANGEL Learning Management Suite (LMS) 7.1 allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
WEBBDOMAIN Quiz 1.02 - Authentication Bypass
CVE-2008-6626webappsphp
SQL injection vulnerability in getin.php in WEBBDOMAIN Quiz 1.02 and earlier allows remote attackers to execute arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
MercuryBoard 1.1.5 - 'login.php' Blind SQL Injection
CVE-2008-6632webappsphp
SQL injection vulnerability in func/login.php in MercuryBoard 1.1.5 and earlier allows remote attackers to execute arbit
23RIESGO
abrir
Referência
CVE-2022-24716
Path traversal in Icinga Web 2
78RIESGO
abrir
ReferênciaVexDay Proof
PHP-Address Book 3.1.5 - SQL Injection / Cross-Site Scripting
CVE-2008-2565webappsphp
Multiple SQL injection vulnerabilities in PHP Address Book 3.1.5 and earlier allow remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
PHP-Address Book 4.0.x - Multiple SQL Injections
CVE-2008-2565webappsphp
Multiple SQL injection vulnerabilities in PHP Address Book 3.1.5 and earlier allow remote attackers to execute arbitrary
23RIESGO
abrir
Referência
CVE-2018-15708
Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP r
60RIESGO
abrir
ReferênciaVexDay Proof
OxYProject 0.85 - 'edithistory.php' Remote Code Execution
CVE-2008-6651webappsphp
Static code injection vulnerability in edithistory.php in OxYProject OxYBox 0.85 allows remote attackers to inject arbit
23RIESGO
abrir
ReferênciaVexDay Proof
CPCommerce 1.1.0 - 'id_category' SQL Injection
CVE-2007-2890webappsphp
SQL injection vulnerability in category.php in cpCommerce 1.1.0 and earlier allows remote attackers to execute arbitrary
23RIESGO
abrir
Referência
CVE-2014-4977
Multiple SQL injection vulnerabilities in Dell SonicWall Scrutinizer 11.0.1 allow remote authenticated users to execute
60RIESGO
abrir
ReferênciaVexDay Proof
wanewsletter 2.1.3 - Remote File Inclusion
CVE-2007-2969webappsphp
PHP remote file inclusion vulnerability in newsletter.php in WAnewsletter 2.1.3 and earlier allows remote attackers to e
35RIESGO
abrir
ReferênciaVexDay Proof
Inout Search Engine - Remote Code Execution
CVE-2007-2988webappsphp
A certain admin script in Inout Meta Search Engine sends a redirect to the web browser but does not exit when administra
23RIESGO
abrir
Referência
CVE-2017-5521
CVE-2017-5521HIGHbajo ataque
An issue was discovered on NETGEAR R8500, R8300, R7000, R6400, R7300, R7100LG, R6300v2, WNDR3400v3, WNR3500Lv2, R6250, R
100RIESGO
abrir
Referência
CVE-2018-15708
Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP r
60RIESGO
abrir
Referência
CVE-2008-2566
Multiple cross-site scripting (XSS) vulnerabilities in PHP Address Book 3.1.5 and earlier allow remote attackers to inje
23RIESGO
abrir
ReferênciaVexDay Proof
PHP-Address Book 3.1.5 - SQL Injection / Cross-Site Scripting
CVE-2008-2566webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in PHP Address Book 3.1.5 and earlier allow remote attackers to inje
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component SimpleShop 3.4 - SQL Injection
CVE-2008-2568webappsphp
SQL injection vulnerability in the Simple Shop Galore (com_simpleshop) component 3.4 and earlier for Joomla! allows remo
23RIESGO
abrir
ReferênciaVexDay Proof
freeSSHd 1.2.1 - (Authenticated) Remote Stack Overflow (PoC)
CVE-2008-2573doswindows
Stack-based buffer overflow in SFTP in freeSSHd 1.2.1 allows remote authenticated users to execute arbitrary code via a
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.