Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.724exploits catalogados
35.724CVEs con explotación pública
24.695probados en laboratorio
22.429 exploits
ReferênciaVexDay Proof
Pictures Rating - 'index.php?msgid' SQL Injection
CVE-2007-3881webappsphp
SQL injection vulnerability in index.php in Pictures Rating (Picture Rating) allows remote attackers to execute arbitrar
23RIESGO
abrir
Referência
CVE-2007-3808
SQL injection vulnerability in includes/search.php in paFileDB 3.6 allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
Referência
CVE-2017-17637
Car Rental Script 2.0.4 has SQL Injection via the countrycode1.php val parameter.
23RIESGO
abrir
ReferênciaVexDay Proof
Data Dynamics ActiveBar - ActiveX 'actbar3.ocx 3.1' Insecure Methods
CVE-2007-3883remotewindows
The Data Dynamics ActiveBar ActiveX control (actbar3.ocx) 3.2 and earlier allows remote attackers to create or overwrite
23RIESGO
abrir
Referência
CVE-2017-17638
Groupon Clone Script 3.01 has SQL Injection via the city_ajax.php state_id parameter.
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft DirectX SAMI File Parsing - Remote Stack Overflow
CVE-2007-3901remotewindows
Stack-based buffer overflow in the DirectShow Synchronized Accessible Media Interchange (SAMI) parser in quartz.dll for
50RIESGO
abrir
Referência
CVE-2017-17638
Groupon Clone Script 3.01 has SQL Injection via the city_ajax.php state_id parameter.
23RIESGO
abrir
ReferênciaVexDay Proof
A-shop 0.70 - Remote File Deletion
CVE-2007-3937webappsasp
Multiple SQL injection vulnerabilities in A-shop 0.70 and earlier allow remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
ReferênciaVexDay Proof
LinkedIn Toolbar 3.0.2.1098 - Remote Buffer Overflow
CVE-2007-3955remotewindows
Buffer overflow in the IEToolbar.IEContextMenu.1 ActiveX control in LinkedInIEToolbar.dll in the LinkedIn Toolbar 3.0.2.
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Windows Explorer - '.GIF' Image Denial of Service
CVE-2007-3958doswindows
Microsoft Windows Explorer (explorer.exe) allows user-assisted remote attackers to cause a denial of service via a certa
28RIESGO
abrir
ReferênciaVexDay Proof
PHP 4.4.7/5.2.3 - MySQL/MySQLi 'Safe_Mode' Bypass
CVE-2007-3997localmultiple
The (1) MySQL and (2) MySQLi extensions in PHP 4 before 4.4.8, and PHP 5 before 5.2.4, allow remote attackers to bypass
28RIESGO
abrir
Referência
CVE-2026-9348
Edimax EW-7438RPn webs mp stack-based overflow
41RIESGO
abrir
Referência
CVE-2017-17641
Resume Clone Script 2.0.5 has SQL Injection via the preview.php id parameter.
23RIESGO
abrir
ReferênciaVexDay Proof
VMware Inc 6.0.0 - CreateProcess Remote Code Execution
CVE-2007-4155remotewindows
Absolute path traversal vulnerability in a certain ActiveX control in vielib.dll in EMC VMware 6.0.0 allows remote attac
23RIESGO
abrir
ReferênciaVexDay Proof
AuraCMS Forum Module - SQL Injection
CVE-2007-4171webappsphp
SQL injection vulnerability in komentar.php in the Forum Module for auraCMS (Modul Forum Sederhana) allows remote attack
23RIESGO
abrir
ReferênciaVexDay Proof
paBugs 2.0 Beta 3 - 'main.php?cid' SQL Injection
CVE-2007-4183webappsphp
SQL injection vulnerability in main.php in paBugs 2.0 Beta 3 and earlier allows remote attackers to execute arbitrary SQ
23RIESGO
abrir
ReferênciaVexDay Proof
Envolution 1.1.0 - 'topic' SQL Injection
CVE-2007-4253webappsphp
SQL injection vulnerability in the News module in modules.php in Envolution 1.1.0 and earlier allows remote attackers to
23RIESGO
abrir
Referência
CVE-2017-17642
Basic Job Site Script 2.0.5 has SQL Injection via the keyword parameter to /job.
23RIESGO
abrir
ReferênciaVexDay Proof
YNP Portal System 2.2.0 - 'showpage.cgi p' Remote File Disclosure
CVE-2007-4256webappscgi
Directory traversal vulnerability in showpage.cgi in YNP Portal System 2.2.0 allows remote attackers to read arbitrary f
23RIESGO
abrir
Referência
CVE-2017-17642
Basic Job Site Script 2.0.5 has SQL Injection via the keyword parameter to /job.
23RIESGO
abrir
ReferênciaVexDay Proof
Live for Speed S1/S2/Demo - '.ply' Local Buffer Overflow
CVE-2007-4257localwindows
Multiple buffer overflows in Live for Speed (LFS) S1 and S2 allow user-assisted remote attackers to execute arbitrary co
23RIESGO
abrir
ReferênciaVexDay Proof
Live for Speed S1/S2/Demo - '.spr' Local Buffer Overflow
CVE-2007-4257localwindows
Multiple buffer overflows in Live for Speed (LFS) S1 and S2 allow user-assisted remote attackers to execute arbitrary co
23RIESGO
abrir
Referência
CVE-2017-17643
FS Lynda Clone 1.0 has SQL Injection via the keywords parameter to tutorial/.
23RIESGO
abrir
ReferênciaVexDay Proof
Prozilla Pub Site Directory - 'Directory.php?cat' SQL Injection
CVE-2007-4258webappsphp
SQL injection vulnerability in directory.php in Prozilla Pub Site Directory allows remote attackers to execute arbitrary
23RIESGO
abrir
Referência
CVE-2017-17643
FS Lynda Clone 1.0 has SQL Injection via the keywords parameter to tutorial/.
23RIESGO
abrir
ReferênciaVexDay Proof
FrontAccounting 1.12 build 31 - Remote File Inclusion
CVE-2007-4279webappsphp
PHP remote file inclusion vulnerability in config.php in FrontAccounting 1.12 Build 31 allows remote attackers to execut
45RIESGO
abrir
ReferênciaVexDay Proof
PHP Blue Dragon CMS 3.0.0 - SQL Injection
CVE-2007-4312webappsphp
SQL injection vulnerability in index.php in Php Blue Dragon CMS 3.0.0 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
ReferênciaVexDay Proof
Prozilla Webring Website Script - 'category.php?cat' SQL Injection
CVE-2007-4362webappsphp
SQL injection vulnerability in category.php in Prozilla Webring allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
Referência
CVE-2017-17645
Bus Booking Script 1.0 has SQL Injection via the txtname parameter to admin/index.php.
23RIESGO
abrir
ReferênciaVexDay Proof
IBM Rational ClearQuest - Web Authentication Bypass / SQL Injection
CVE-2007-4368webappscgi
SQL injection vulnerability in /main in IBM Rational ClearQuest (CQ) Web 7.0.0.0-IFIX02 and 7.0.0.1 allows remote attack
23RIESGO
abrir
anteriorpágina 542 / 748siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.