Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
WebEyes Guest Book 3 - 'yorum.asp?mesajid' SQL Injection
CVE-2009-1950webappsasp
SQL injection vulnerability in yorum.asp in WebEyes Guest Book 3 allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
ReferênciaVexDay Proof
propertymax pro free - SQL Injection / Cross-Site Scripting
CVE-2009-1951webappsphp
Cross-site scripting (XSS) vulnerability in index.php in PropertyMax Pro FREE 0.3 allows remote attackers to inject arbi
23RIESGO
abrir
ReferênciaVexDay Proof
propertymax pro free - SQL Injection / Cross-Site Scripting
CVE-2009-1952webappsphp
Multiple SQL injection vulnerabilities in the administrative login feature in PropertyMax Pro FREE 0.3, when magic_quote
23RIESGO
abrir
ReferênciaVexDay Proof
Apache mod_dav / svn - Remote Denial of Service
CVE-2009-1955dosmultiple
The expat XML parser in the apr_xml_* interface in xml/apr_xml.c in Apache APR-util before 1.3.7, as used in the mod_dav
35RIESGO
abrir
ReferênciaVexDay Proof
Dokuwiki 2009-02-14 - Local File Inclusion
CVE-2009-1960webappsphp
inc/init.php in DokuWiki 2009-02-14, rc2009-02-06, and rc2009-01-30, when register_globals is enabled, allows remote att
28RIESGO
abrir
ReferênciaVexDay Proof
Dokuwiki 2009-02-14 - Temporary/Remote File Inclusion
CVE-2009-1960webappsphp
inc/init.php in DokuWiki 2009-02-14, rc2009-02-06, and rc2009-01-30, when register_globals is enabled, allows remote att
28RIESGO
abrir
ReferênciaVexDay Proof
Password Protector SD 1.3.1 - Insecure Cookie Handling
CVE-2009-2003webappsphp
Ascad Networks Password Protector SD 1.3.1 allows remote attackers to bypass authentication and gain administrative acce
23RIESGO
abrir
ReferênciaVexDay Proof
Family Connections CMS 1.9 - SQL Injection
CVE-2009-2010webappsphp
Multiple SQL injection vulnerabilities in Haudenschilt Family Connections CMS (FCMS) 1.9 and earlier allow remote authen
23RIESGO
abrir
ReferênciaVexDay Proof
Worldweaver DX Studio Player < 3.0.29.1 Firefox plugin - Command Injection
CVE-2009-2011remotewindows
Worldweaver DX Studio Player 3.0.29.0, 3.0.22.0, 3.0.12.0, and probably other versions before 3.0.29.1, when used as a p
50RIESGO
abrir
ReferênciaVexDay Proof
Virtue Book Store - 'cid' SQL Injection
CVE-2009-2017webappsphp
SQL injection vulnerability in products.php in Virtue Book Store allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
ReferênciaVexDay Proof
virtue news - SQL Injection / Cross-Site Scripting
CVE-2009-2019webappsphp
SQL injection vulnerability in news_detail.php in Virtue News Manager allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
ReferênciaVexDay Proof
Virtue Classifieds - 'category' SQL Injection
CVE-2009-2021webappsphp
SQL injection vulnerability in search.php in Virtue Classifieds allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
ReferênciaVexDay Proof
PHPCollegeExchange 0.1.5c - 'listing_view.php?itemnr' SQL Injection
CVE-2009-2096webappsphp
SQL injection vulnerability in house/listing_view.php in phpCollegeExchange 0.1.5c allows remote attackers to execute ar
23RIESGO
abrir
ReferênciaVexDay Proof
PHPortal 1 - 'topicler.php?id' SQL Injection
CVE-2009-2098webappsphp
SQL injection vulnerability in topicler.php in phPortal 1.0 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir
ReferênciaVexDay Proof
2532/Gigs 1.2.2 Stable - Remote Authentication Bypass
CVE-2008-6907webappsphp
Multiple SQL injection vulnerabilities in checkuser.php in 2532designs 2532|Gigs 1.2.2 Stable, when magic_quotes_gpc is
23RIESGO
abrir
ReferênciaVexDay Proof
Zeeways Shaadi Clone 2.0 - Authentication Bypass (1)
CVE-2008-6912webappsphp
Zeeways SHAADICLONE 2.0 allows remote attackers to bypass authentication and gain administrative privileges via a direct
23RIESGO
abrir
ReferênciaVexDay Proof
impleo music Collection 2.0 - SQL Injection / Cross-Site Scripting
CVE-2009-2154webappsphp
SQL injection vulnerability in admin/login.php in Impleo Music Collection 2.0, when magic_quotes_gpc is disabled, allows
23RIESGO
abrir
ReferênciaVexDay Proof
ScriptsFeed (SF) Recipes Listing Portal - Arbitrary File Upload
CVE-2008-6943webappsphp
Unrestricted file upload vulnerability in ScriptsFeed Recipes Listing Portal allows remote authenticated users to execut
23RIESGO
abrir
ReferênciaVexDay Proof
DD-WRT HTTPd Daemon/Service - Remote Command Execution
CVE-2008-6975remotehardware
Multiple cross-site request forgery (CSRF) vulnerabilities in apply.cgi in DD-WRT 24 sp2 allow remote attackers to hijac
23RIESGO
abrir
ReferênciaVexDay Proof
aspwebalbum 3.2 - Arbitrary File Upload / SQL Injection / Cross-Site Scripting
CVE-2008-6977webappsphp
Cross-site scripting (XSS) vulnerability in album.asp in Full Revolution aspWebAlbum 3.2 allows remote attackers to inje
23RIESGO
abrir
ReferênciaVexDay Proof
Fuzzylime CMS 3.03a - Local Inclusion / Arbitrary File Corruption
CVE-2009-2177webappsphp
code/display.php in fuzzylime (cms) 3.03a and earlier, when magic_quotes_gpc is disabled, allows remote attackers to con
23RIESGO
abrir
ReferênciaVexDay Proof
Quicksilver Forums 1.4.2 (Windows) - Remote Code Execution
CVE-2008-7064webappsphp
Directory traversal vulnerability in the get_lang function in global.php in Quicksilver Forums 1.4.2 and earlier, as use
23RIESGO
abrir
ReferênciaVexDay Proof
chipmunk topsites - Authentication Bypass / Cross-Site Scripting
CVE-2008-7071webappsphp
SQL injection vulnerability in authenticate.php in Chipmunk Topsites allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir
ReferênciaVexDay Proof
phpDatingClub 3.7 - SQL Injection / Cross-Site Scripting Injection
CVE-2009-2179webappsphp
SQL injection vulnerability in search.php in phpDatingClub 3.7 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
pc4 Uploader 10.0 - Remote File Disclosure
CVE-2009-2180webappsphp
Multiple directory traversal vulnerabilities in upfiles/index.php in Pc4 Uploader 10.0 and earlier allow remote attacker
23RIESGO
abrir
ReferênciaVexDay Proof
Nero ShowTime 5.0.15.0 - '.m3u' Playlist File Remote Buffer Overflow (PoC)
CVE-2008-7079doswindows
Buffer overflow in Nero ShowTime 5.0.15.0 allows remote attackers to cause a denial of service (crash) and possibly exec
23RIESGO
abrir
ReferênciaVexDay Proof
ReVou Twitter Clone - Authentication Bypass
CVE-2008-7083webappsphp
Multiple SQL injection vulnerabilities in ReVou Micro Blogging Twitter clone allow remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
HockeySTATS Online 2.0 - Multiple SQL Injections
CVE-2008-7085webappsphp
Multiple SQL injection vulnerabilities in TheHockeyStop HockeySTATS Online 2.0 Basic and Advanced allow remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
ESET Smart Security 3.0.667.0 - Privilege Escalation (PoC)
CVE-2008-7107doswindows
easdrv.sys in ESET Smart Security 3.0.667.0 allows local users to cause a denial of service (crash) via a crafted IOCTL
23RIESGO
abrir
ReferênciaVexDay Proof
iFdate 2.0.3 - SQL Injection
CVE-2008-7114webappsphp
SQL injection vulnerability in members_search.php in iFusion Services iFdate 2.0.3 and earlier allows remote attackers t
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.