Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.313exploits catalogados
34.834CVEs con explotación pública
24.695probados en laboratorio
21.797 exploits
ReferênciaVexDay Proof
Ktools Photostore 3.5.1 - 'gid' SQL Injection
CVE-2008-6647webappsphp
SQL injection vulnerability in gallery.php in Ktools PhotoStore 3.4.3 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
Referência
CVE-2009-2123
Multiple SQL injection vulnerabilities in Elvin 1.2.0 allow remote attackers to execute arbitrary SQL commands via the (
23RIESGO
abrir
Referência
CVE-2009-3967
SQL injection vulnerability in browse.php in Ed Charkow SuperCharged Linking allows remote attackers to execute arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
elvin bts 1.2.0 - Multiple Vulnerabilities
CVE-2009-2123webappsphp
Multiple SQL injection vulnerabilities in Elvin 1.2.0 allow remote attackers to execute arbitrary SQL commands via the (
23RIESGO
abrir
ReferênciaVexDay Proof
Zip Store Chat 4.0/5.0 - Authentication Bypass
CVE-2009-2142webappsphp
Multiple SQL injection vulnerabilities in admin/index.asp in Zip Store Chat 4.0 and 5.0 allow remote attackers to execut
23RIESGO
abrir
Referência
CVE-2010-3026
Cross-site request forgery (CSRF) vulnerability in application/modules/admin/controllers/users.php in Tomaz Muraus Open
23RIESGO
abrir
Referência
CVE-2010-4911
SQL injection vulnerability in classi/detail.php in PHP Classifieds Ads allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
w-Agora 4.2.1 - 'cat' SQL Injection
CVE-2007-6647webappsphp
SQL injection vulnerability in index.php in w-Agora 4.2.1 and earlier allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
ReferênciaVexDay Proof
XOOPS Module eEmpregos - 'cid' SQL Injection
CVE-2008-0874webappsphp
SQL injection vulnerability in index.php in the eEmpregos module for XOOPS allows remote attackers to execute arbitrary
23RIESGO
abrir
Referência
CVE-2009-3117
SQL injection vulnerability in category.php in Snow Hall Silurus System 1.0 allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
Prozilla Freelancers - 'project' SQL Injection
CVE-2008-1864webappsphp
SQL injection vulnerability in project.php in Prozilla Freelancers allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
ReferênciaVexDay Proof
Netious CMS 0.4 - 'pageid' SQL Injection
CVE-2008-2461webappsphp
SQL injection vulnerability in index.php in Netious CMS 0.4 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir
ReferênciaVexDay Proof
MojoClassifieds 2.0 - Blind SQL Injection
CVE-2008-3382webappscgi
SQL injection vulnerability in mojoClassified.cgi in MojoClassifieds 2.0 allows remote attackers to execute arbitrary SQ
23RIESGO
abrir
ReferênciaVexDay Proof
Living Local Website - 'listtest.php' SQL Injection
CVE-2008-3943webappsphp
SQL injection vulnerability in listtest.php in eZoneScripts Living Local 1.1 allows remote attackers to execute arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
EsFaq 2.0 - 'idcat' SQL Injection
CVE-2008-3952webappsphp
SQL injection vulnerability in questions.php in EsFaq 2.0 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
ReferênciaVexDay Proof
Vastal I-Tech Cosmetics Zone - 'cat_id' SQL Injection
CVE-2008-4466webappsphp
SQL injection vulnerability in view_products_cat.php in Vastal I-Tech Cosmetics Zone allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
Shahrood - Blind SQL Injection
CVE-2008-5003webappsphp
SQL injection vulnerability in ndetail.php in Shahrood allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir
Referência
CVE-2009-4933
Multiple SQL injection vulnerabilities in login.php in EZ Webitor allow remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
ReferênciaVexDay Proof
Nitrotech 0.0.3a - Remote File Inclusion / SQL Injection
CVE-2008-5333webappsphp
SQL injection vulnerability in members.php in NitroTech 0.0.3a allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
Active Photo Gallery 6.2 - Authentication Bypass
CVE-2008-5641webappsphp
SQL injection vulnerability in account.asp in Active Photo Gallery 6.2 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
eDNews 2.0 - SQL Injection
CVE-2008-5820webappsphp
SQL injection vulnerability in eDNews_view.php in eDreamers eDNews 2 allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component mydyngallery 1.4.2 - SQL Injection
CVE-2008-5957webappsphp
SQL injection vulnerability in the Mydyngallery (com_mydyngallery) component 1.4.2 for Joomla! allows remote attackers t
23RIESGO
abrir
ReferênciaVexDay Proof
Ocean12 Membership Manager Pro - Authentication Bypass
CVE-2008-6390webappsphp
SQL injection vulnerability in login.asp in Ocean12 Membership Manager Pro allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
Easy Photo Gallery 2.1 - Cross-Site Scripting / File Disclosure/Bypass / SQL Injection
CVE-2008-6989webappsphp
SQL injection vulnerability in gallery.php in Easy Photo Gallery (aka Ezphotogallery) 2.1 allows remote attackers to exe
23RIESGO
abrir
Referência
CVE-2011-4811
SQL injection vulnerability in pokaz_podkat.php in BestShopPro allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
Referência
CVE-2023-29689
PyroCMS 3.9 contains a remote code execution (RCE) vulnerability that can be exploited through a server-side template in
35RIESGO
abrir
Referência
CVE-2009-5003
SQL injection vulnerability in click.php in e-soft24 Banner Exchange Script 1.0 allows remote attackers to execute arbit
23RIESGO
abrir
Referência
CVE-2009-5003
SQL injection vulnerability in click.php in e-soft24 Banner Exchange Script 1.0 allows remote attackers to execute arbit
23RIESGO
abrir
Referência
CVE-2006-3822
SQL injection vulnerability in index.php in GeodesicSolutions GeoAuctions Enterprise 1.0.6 allows remote attackers to ex
23RIESGO
abrir
ReferênciaVexDay Proof
chernobiLe Portal 1.0 - 'default.asp' SQL Injection
CVE-2007-0582webappsasp
SQL injection vulnerability in default.asp in ChernobiLe 1.0 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
anteriorpágina 309 / 727siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.