Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
Ocean12 Mailing List Manager Gold - File Disclosure / SQL Injection / Cross-Site Scripting
CVE-2008-5979webappsphp
Cross-site scripting (XSS) vulnerability in default.asp in Ocean12 Mailing List Manager Gold allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
Jetik Emlak ESA 2.0 - Multiple SQL Injections
CVE-2008-5992webappsphp
Multiple SQL injection vulnerabilities in Jetik Emlak Sistem A (ESA) 2.0 allow remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Internet Explorer 6 - 'mshtml.dll' Null Pointer Dereference
CVE-2007-0811doswindows
Microsoft Internet Explorer 6.0 SP1 on Windows 2000, and 6.0 SP2 on Windows XP, allows remote attackers to cause a denia
28RIESGO
abrir
ReferênciaVexDay Proof
QuickTime Player 7.3.1.70 - 'RTSP' Remote Buffer Overflow
CVE-2008-0234remotewindows
Buffer overflow in Apple Quicktime Player 7.3.1.70 and other versions before 7.4.1, when RTSP tunneling is enabled, allo
28RIESGO
abrir
ReferênciaVexDay Proof
webcp 0.5.7 - 'filelocation' Remote File Disclosure
CVE-2008-6002webappsphp
Absolute path traversal vulnerability in sendfile.php in web-cp 0.5.7, when register_globals is enabled, allows remote a
23RIESGO
abrir
ReferênciaVexDay Proof
BookMarks Favourites Script - 'id' SQL Injection
CVE-2008-6007webappsphp
SQL injection vulnerability in view_group.php in QuidaScript BookMarks Favourites Script (APB) allows remote attackers t
23RIESGO
abrir
ReferênciaVexDay Proof
WordPress Plugin Download Manager 0.2 - Arbitrary File Upload
CVE-2008-3362webappsphp
Unrestricted file upload vulnerability in upload.php in the Giulio Ganci Wp Downloads Manager module 0.2 for WordPress a
28RIESGO
abrir
ReferênciaVexDay Proof
SG Real Estate Portal 2.0 - Blind SQL Injection
CVE-2008-6011webappsphp
SQL injection vulnerability in index.php in SG Real Estate Portal 2.0 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
ReferênciaVexDay Proof
SG Real Estate Portal 2.0 - Blind SQL Injection / Local File Inclusion
CVE-2008-6011webappsphp
SQL injection vulnerability in index.php in SG Real Estate Portal 2.0 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
ReferênciaVexDay Proof
phpskelsite 1.4 - Local File Inclusion / Remote File Inclusion / Cross-Site Scripting
CVE-2009-0595webappsphp
PHP remote file inclusion vulnerability in skysilver/login.tpl.php in phpSkelSite 1.4, when register_globals is enabled
28RIESGO
abrir
ReferênciaVexDay Proof
XNova 0.8 sp1 - 'xnova_root_path' Remote File Inclusion
CVE-2008-6022webappsphp
PHP remote file inclusion vulnerability in includes/todofleetcontrol.php in an older version of Xnova, possibly 0.8 sp1,
23RIESGO
abrir
ReferênciaVexDay Proof
XNova 0.8 sp1 - 'xnova_root_path' Remote File Inclusion
CVE-2008-6023webappsphp
PHP remote file inclusion vulnerability in includes/todofleetcontrol.php in a newer version of Xnova, possibly 0.8 sp1,
23RIESGO
abrir
ReferênciaVexDay Proof
Fez 1.3/2.0 RC1 - 'list.php' SQL Injection
CVE-2008-6028webappsphp
SQL injection vulnerability in list.php in University of Queensland Library Fez 1.3 and 2.0 RC1 allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
Agares phpAutoVideo 2.21 - 'articlecat' SQL Injection (1)
CVE-2008-0262webappsphp
SQL injection vulnerability in includes/articleblock.php in Agares PhpAutoVideo 2.21 allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
BuzzyWall 1.3.1 - 'search' SQL Injection
CVE-2008-6029webappsphp
SQL injection vulnerability in search.php in BuzzyWall 1.3.1 and earlier, when magic_quotes_gpc is disabled, allows remo
23RIESGO
abrir
ReferênciaVexDay Proof
WSN Links Free 4.0.34P - 'comments.php' Blind SQL Injection
CVE-2008-6032webappsphp
SQL injection vulnerability in comments.php in WSN Links Free 4.0.34P allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
ReferênciaVexDay Proof
WSN Links 2.20 - 'comments.php' SQL Injection
CVE-2008-6033webappsphp
SQL injection vulnerability in comments.php in WSN Links 2.20 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
PHP-Post 1.0 - Cookie Modification Privilege Escalation
CVE-2006-3772webappsphp
PHP-Post 0.21 and 1.0, and possibly earlier versions, when auto-login is enabled, allows remote attackers to bypass secu
28RIESGO
abrir
ReferênciaVexDay Proof
AvailScript Article Script - 'view.php' SQL Injection
CVE-2008-6037webappsphp
SQL injection vulnerability in view.php in AvailScript Article Script allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
ReferênciaVexDay Proof
DomPHP 0.81 - 'cat' SQL Injection
CVE-2008-6064webappsphp
Multiple SQL injection vulnerabilities in DomPHP 0.81 allow remote attackers to execute arbitrary SQL commands via the c
23RIESGO
abrir
ReferênciaVexDay Proof
TaskFreak! 0.6.1 - SQL Injection
CVE-2008-0270webappsphp
SQL injection vulnerability in index.php in TaskFreak! 0.6.1 and earlier allows remote authenticated users to execute ar
23RIESGO
abrir
ReferênciaVexDay Proof
Total Video Player 1.03 - '.m3u' File Local Buffer Overflow
CVE-2007-0949localwindows
Stack-based buffer overflow in iTinySoft Studio Total Video Player 1.03, and possibly earlier, allows remote attackers t
28RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component JoomlaDate 1.2 - 'user' SQL Injection
CVE-2008-6068webappsphp
SQL injection vulnerability in the JoomlaDate (com_joomladate) component 1.2 for Joomla! allows remote attackers to exec
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component Daily Message 1.0.3 - 'id' SQL Injection
CVE-2008-6076webappsphp
SQL injection vulnerability in the Daily Message (com_dailymessage) 1.0.3 component for Joomla! allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
Simple Customer 1.2 - 'contact.php' SQL Injection
CVE-2008-6081webappsphp
SQL injection vulnerability in contact.php in Simple Customer 1.2 allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir
ReferênciaVexDay Proof
Iamma Simple Gallery 1.0/2.0 - Arbitrary File Upload
CVE-2008-6084webappsphp
Unrestricted file upload vulnerability in pages/download.php in Iamma Simple Gallery 1.0 and 2.0 allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
Camera Life 2.6.2b4 - SQL Injection / Cross-Site Scripting
CVE-2008-6086webappsphp
SQL injection vulnerability in album.php in Camera Life 2.6.2b4 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
ReferênciaVexDay Proof
DigitalHive 2.0 RC2 - 'user_id' SQL Injection
CVE-2008-0290webappsphp
Multiple SQL injection vulnerabilities in Digital Hive 2.0 RC2 and earlier allow (1) remote attackers to execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
RichStrong CMS - 'cat' SQL Injection
CVE-2008-0291webappsasp
SQL injection vulnerability in showproduct.asp in RichStrong CMS allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
ReferênciaVexDay Proof
T-Dreams Job Career Package 3.0 - Insecure Cookie Handling
CVE-2009-1638webappsasp
Techno Dreams Job Career Package 3.0 allows remote attackers to bypass authentication and obtain administrative access b
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.