Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.449exploits catalogados
35.552CVEs con explotación pública
24.695probados en laboratorio
22.332 exploits
ReferênciaVexDay Proof
PortalApp 4.0 - SQL Injection / Cross-Site Scripting / Authentication Bypass
CVE-2008-4614webappsasp
PortalApp 4.0 does not require authentication for (1) forums.asp and (2) content.asp, which allows remote attackers to c
23RIESGO
abrir
Referência
Joomla! Component JEXTN Membership 3.1.0 - 'usr_plan' SQL Injection
CVE-2018-6577webappsphp
SQL Injection exists in the JEXTN Membership 3.1.0 component for Joomla! via the usr_plan parameter in a view=myplans&ta
23RIESGO
abrir
ReferênciaVexDay Proof
phpFastNews 1.0.0 - Insecure Cookie Handling
CVE-2008-4622webappsphp
The isLoggedIn function in fastnews-code.php in phpFastNews 1.0.0 allows remote attackers to bypass authentication and g
23RIESGO
abrir
ReferênciaVexDay Proof
Fast Click SQL 1.1.7 Lite - 'init.php' Remote File Inclusion
CVE-2008-4624webappsphp
PHP remote file inclusion vulnerability in init.php in Fast Click SQL Lite 1.1.7, when register_globals is enabled, allo
23RIESGO
abrir
ReferênciaVexDay Proof
WordPress Plugin st_newsletter - 'stnl_iframe.php' SQL Injection
CVE-2008-4625webappsphp
SQL injection vulnerability in stnl_iframe.php in the ShiftThis Newsletter (st_newsletter) plugin for WordPress allows r
23RIESGO
abrir
Referência
Joomla! Component JEXTN Reverse Auction 3.1.0 - SQL Injection
CVE-2018-6579webappsphp
SQL Injection exists in the JEXTN Reverse Auction 3.1.0 component for Joomla! via a view=products&uid= request.
23RIESGO
abrir
ReferênciaVexDay Proof
Yappa-ng 2.3.3-beta0 - 'album' Local File Inclusion
CVE-2008-4626webappsphp
Directory traversal vulnerability in index.php in Fritz Berger yet another php photo album - next generation (yappa-ng)
23RIESGO
abrir
ReferênciaVexDay Proof
WBB Plugin rGallery 1.09 - 'itemID' Blind SQL Injection
CVE-2008-4627webappsphp
SQL injection vulnerability in the rGallery plugin 1.09 for WoltLab Burning Board (WBB) allows remote attackers to execu
23RIESGO
abrir
ReferênciaVexDay Proof
miniBloggie 1.0 - 'del.php' Blind SQL Injection
CVE-2008-4628webappsphp
SQL injection vulnerability in del.php in myWebland miniBloggie 1.0 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
ReferênciaVexDay Proof
mystats - 'hits.php' Multiple Vulnerabilities
CVE-2008-4643webappsphp
SQL injection vulnerability in hits.php in myWebland myStats allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
ReferênciaVexDay Proof
PHPWebGallery 1.7.2 - Session Hijacking / Code Execution
CVE-2008-4645webappsphp
plugins/event_tracer/event_list.php in PhpWebGallery 1.7.2 and earlier allows remote authenticated administrators to exe
23RIESGO
abrir
Referência
CVE-2026-19246
HKUDS nanobot Provider-returned Image URL image_generation.py _download_image_data_url server-side request forgery
33RIESGO
abrir
Referência
CVE-2026-19245
HKUDS nanobot Login-shell Environment shell.py ExecTool._prepare_command information disclosure
33RIESGO
abrir
ReferênciaVexDay Proof
Philips VOIP841 Firmware 1.0.4.800 - Multiple Vulnerabilities
CVE-2008-4874remotehardware
The web component in Philips Electronics VOIP841 DECT Phone with firmware 1.0.4.50 and 1.0.4.80 has a back door "service
23RIESGO
abrir
ReferênciaVexDay Proof
YourFreeWorld Reminder Service - SQL Injection
CVE-2008-4881webappsphp
SQL injection vulnerability in tr.php in YourFreeWorld Reminder Service Script allows remote attackers to execute arbitr
23RIESGO
abrir
Referência
CVE-2018-6789
CVE-2018-6789CRITICALbajo ataqueransomware
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RIESGO
abrir
ReferênciaVexDay Proof
YourFreeWorld Blog Blaster - 'tr.php' SQL Injection
CVE-2008-4883webappsphp
SQL injection vulnerability in tr.php in YourFreeWorld Blog Blaster Script allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
YourFreeWorld Classifieds Hosting - SQL Injection
CVE-2008-4884webappsphp
SQL injection vulnerability in tr.php in YourFreeWorld Classifieds Hosting Script allows remote attackers to execute arb
23RIESGO
abrir
ReferênciaVexDay Proof
YourFreeWorld Scrolling Text Ads - SQL Injection
CVE-2008-4885webappsphp
SQL injection vulnerability in tr1.php in YourFreeWorld Scrolling Text Ads Script allows remote attackers to execute arb
23RIESGO
abrir
ReferênciaVexDay Proof
NetRisk 2.0 - Cross-Site Scripting / SQL Injection
CVE-2008-4888webappsphp
Cross-site scripting (XSS) vulnerability in error.php in NetRisk 2.0 and earlier allows remote attackers to inject arbit
23RIESGO
abrir
ReferênciaVexDay Proof
YourFreeWorld Downline Builder - 'tr.php' SQL Injection
CVE-2008-4895webappsphp
SQL injection vulnerability in tr.php in YourFreeWorld Downline Builder allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
Logz podcast CMS 1.3.1 - 'art' SQL Injection
CVE-2008-4897webappsphp
SQL injection vulnerability in fichiers/add_url.php in Logz podcast CMS 1.3.1, when magic_quotes_gpc is disabled, allows
23RIESGO
abrir
ReferênciaVexDay Proof
YourFreeWorld Classifieds Blaster - SQL Injection
CVE-2008-4900webappsphp
SQL injection vulnerability in tr.php in YourFreeWorld Classifieds Blaster Script allows remote attackers to execute arb
23RIESGO
abrir
ReferênciaVexDay Proof
Article Publisher PRO 1.5 - Authentication Bypass
CVE-2008-4901webappsphp
SQL injection vulnerability in admin/admin.php in Article Publisher Pro 1.5 allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
Article Publisher PRO - 'userid' SQL Injection
CVE-2008-4902webappsphp
SQL injection vulnerability in contact_author.php in Article Publisher Pro 1.5 allows remote attackers to execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
RX Maxsoft - 'fotoID' SQL Injection
CVE-2008-4912webappsphp
SQL injection vulnerability in popup_img.php in the fotogalerie module in RS MAXSOFT allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
Visagesoft eXPert PDF ViewerX - 'VSPDFViewerX.ocx' File Overwrite
CVE-2008-4919remotewindows
Insecure method vulnerability in VISAGESOFT eXPert PDF Viewer X ActiveX control (VSPDFViewerX.ocx) 3.0.990.0 allows remo
23RIESGO
abrir
ReferênciaVexDay Proof
DjVu - ActiveX Control 3.0 ImageURL Property Overflow
CVE-2008-4922remotewindows
Buffer overflow in the DjVu ActiveX Control 3.0 for Microsoft Office (DjVu_ActiveX_MSOffice.dll) allows remote attackers
50RIESGO
abrir
ReferênciaVexDay Proof
MW6 Aztec - ActiveX 'Aztec.dll' Remote Insecure Method
CVE-2008-4923remotewindows
Multiple insecure method vulnerabilities in MW6 Technologies Aztec ActiveX control (AZTECLib.MW6Aztec, Aztec.dll) 3.0.0.
23RIESGO
abrir
ReferênciaVexDay Proof
MW6 Barcode - ActiveX 'Barcode.dll' Insecure Method
CVE-2008-4924remotewindows
Multiple insecure method vulnerabilities in MW6 Technologies 1D Barcode ActiveX control (BARCODELib.MW6Barcode, Barcode.
23RIESGO
abrir
anteriorpágina 483 / 745siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.