Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.107exploits catalogados
36.322CVEs con explotación pública
24.695probados en laboratorio
5629 exploits
ReferênciaVexDay Proof
XOOPS Module WF-Snippets 1.02 (c) - Blind SQL Injection
CVE-2007-1962webappsphp
SQL injection vulnerability in index.php in the WF-Snippets 1.02 and earlier module for XOOPS allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
eReservations - Authentication Bypass
CVE-2009-0252webappsasp
Multiple SQL injection vulnerabilities in default.asp in Enthrallweb eReservations allow remote attackers to execute arb
23RIESGO
abrir
ReferênciaVexDay Proof
QuickEStore 8.2 - 'insertorder.cfm' SQL Injection
CVE-2007-3933webappsphp
SQL injection vulnerability in insertorder.cfm in QuickEStore 8.2 and earlier allows remote attackers to execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
Arcadwy Arcade Script - (Authentication Bypass) Insecure Cookie Handling
CVE-2009-1229webappsphp
SQL injection vulnerability in Arcadwy Arcade Script allows remote attackers to execute arbitrary SQL commands via the u
23RIESGO
abrir
ReferênciaVexDay Proof
PHP Real Estate - 'fullnews.php?id' SQL Injection
CVE-2007-6462webappsphp
SQL injection vulnerability in fullnews.php in PHP Real Estate Classifieds allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
Limbo CMS 1.0.4.2 - 'Cuid' cookie Blind SQL Injection
CVE-2008-0734webappsphp
SQL injection vulnerability in class_auth.php in Limbo CMS 1.0.4.2, and possibly earlier versions, allows remote attacke
23RIESGO
abrir
ReferênciaVexDay Proof
YouTube blog 0.1 - Remote File Inclusion / SQL Injection / Cross-Site Scripting
CVE-2008-3307webappsphp
SQL injection vulnerability in todos.php in C. Desseno YouTube Blog (ytb) 0.1 allows remote attackers to execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
Quick and Dirty Blog (qdblog) 0.4 - SQL Injection / Local File Inclusion
CVE-2007-2305webappsphp
Multiple SQL injection vulnerabilities in authenticate.php in Quick and Dirty Blog (QDBlog) 0.4, and possibly earlier, a
23RIESGO
abrir
ReferênciaVexDay Proof
Fuzzylime Forum 1.0 - 'low.php?topic' SQL Injection
CVE-2007-3234webappsphp
SQL injection vulnerability in low.php in Fuzzylime Forum 1.0 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
Vastal I-Tech Freelance Zone - 'coder_id' SQL Injection
CVE-2008-4469webappsphp
SQL injection vulnerability in view_cresume.php in Vastal I-Tech Freelance Zone allows remote attackers to execute arbit
23RIESGO
abrir
ReferênciaVexDay Proof
Netartmedia Blog System - SQL Injection
CVE-2008-5311webappsphp
SQL injection vulnerability in image.php in NetArt Media Blog System 1.5 allows remote attackers to execute arbitrary SQ
23RIESGO
abrir
ReferênciaVexDay Proof
SFS EZ Career - SQL Injection
CVE-2008-6867webappsphp
SQL injection vulnerability in content.php in Scripts For Sites (SFS) EZ Career allows remote attackers to execute arbit
23RIESGO
abrir
ReferênciaVexDay Proof
DigiLeave 1.2 - 'book_id' Blind SQL Injection
CVE-2008-3309webappsasp
SQL injection vulnerability in info_book.asp in DigiLeave 1.2 and earlier allows remote attackers to execute arbitrary S
23RIESGO
abrir
ReferênciaVexDay Proof
Woltlab Burning Board 1.0.2/2.3.6 - 'search.php' SQL Injection (1)
CVE-2007-0388webappsphp
SQL injection vulnerability in search.php in Woltlab Burning Board (wBB) 1.0.2 and earlier, and 2.3.6 and earlier in the
23RIESGO
abrir
ReferênciaVexDay Proof
Crea-Book 1.0 - Admin Access Bypass / Database Disclosure / Code Execution
CVE-2007-2000webappsphp
Multiple SQL injection vulnerabilities in admin/admin.php in Crea-Book 1.0 and earlier allow remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
BluSky CMS - 'news_id' SQL Injection
CVE-2009-1548webappsphp
SQL injection vulnerability in index.php in BluSky CMS allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir
ReferênciaVexDay Proof
ZEELYRICS 2.0 - 'bannerclick.php' SQL Injection
CVE-2008-4717webappsphp
SQL injection vulnerability in bannerclick.php in ZEELYRICS 2.0 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
ReferênciaVexDay Proof
XOOPS module Articles 1.02 - 'print.php?id' SQL Injection
CVE-2007-3311webappsphp
SQL injection vulnerability in print.php in the Articles 1.02 and earlier module for Xoops allows remote attackers to ex
23RIESGO
abrir
ReferênciaVexDay Proof
phpFullAnnu (PFA) 6.0 - SQL Injection
CVE-2007-5068webappsphp
SQL injection vulnerability in index.php in phpFullAnnu (PFA) 6.0 allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir
ReferênciaVexDay Proof
JobSite Professional 2.0 - 'file.php' SQL Injection
CVE-2007-5785webappsphp
SQL injection vulnerability in file.php in JobSite Professional 2.0 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
ReferênciaVexDay Proof
Content Injector 1.53 - 'index.php' SQL Injection
CVE-2007-6394webappsphp
SQL injection vulnerability in index.php in Content Injector 1.53 allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir
ReferênciaVexDay Proof
Autodealers CMS AutOnline - 'id' SQL Injection
CVE-2008-4074webappsphp
SQL injection vulnerability in index.php in Zanfi Autodealers CMS AutOnline allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
LocazoList 2.01a beta5 - 'subcatID' SQL Injection
CVE-2007-0129webappsasp
SQL injection vulnerability in main.asp in LocazoList 2.01a beta5 and earlier allows remote attackers to execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
ThWboard 3.0b2.84-php5 - SQL Injection / Code Execution
CVE-2007-0340webappsphp
SQL injection vulnerability in inc/header.inc.php in ThWboard 3.0b2.84-php5 and earlier allows remote attackers to execu
23RIESGO
abrir
ReferênciaVexDay Proof
WebPortal CMS 0.7.4 - 'download.php' SQL Injection
CVE-2008-4345webappsphp
SQL injection vulnerability in download.php in WebPortal CMS 0.7.4 and earlier allows remote attackers to execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
LightRO CMS 1.0 - 'index.php?projectid' SQL Injection
CVE-2007-0904webappsphp
SQL injection vulnerability in projects.php in LightRO CMS 1.0 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
Injader CMS 2.1.1 - 'id' SQL Injection
CVE-2008-5890webappsphp
SQL injection vulnerability in feeds.php in Injader before 2.1.2 allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
ReferênciaVexDay Proof
XOOPS Module debaser 0.92 - 'genre.php' Blind SQL Injection
CVE-2007-1805webappsphp
SQL injection vulnerability in genre.php in the debaser 0.92 and earlier module for Xoops allows remote attackers to exe
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component live chat - SQL Injection / Open Proxy
CVE-2008-6881webappsphp
Multiple SQL injection vulnerabilities in the Live Chat (com_livechat) component 1.0 for Joomla! allow remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component Phil-a-Form 1.2.0.0 - SQL Injection
CVE-2007-2933webappsphp
SQL injection vulnerability in index.php in the Phil-a-Form (com_philaform) 1.2.0.0 and earlier component for Joomla! al
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.