Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

72.018exploits catalogados
32.219CVEs con explotación pública
1932probados en laboratorio
20.023 exploits
Referência
CVE-2020-9467
Piwigo 2.10.1 has stored XSS via the file parameter in a /ws.php request because of the pwg.images.setInfo function.
28RIESGO
abrir
Referência
CVE-2017-17876
Biometric Shift Employee Management System 3.0 allows remote attackers to bypass intended file-read restrictions via a u
23RIESGO
abrir
Referência
CVE-2020-14461
Zyxel Armor X1 WAP6806 1.00(ABAL.6)C0 devices allow Directory Traversal via the images/eaZy/ URI.
23RIESGO
abrir
Referência
CVE-2022-26521
Abantecart through 1.3.2 allows remote authenticated administrators to execute arbitrary code by uploading an executable
23RIESGO
abrir
Referência
MiniBill 1.22b - config[plugin_dir] Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in MiniBill 2006-07-14 (1.2.2) allow remote attackers to execute arbi
23RIESGO
abrir
Referência
Simple PHP Blog 0.4.7.1 - Remote Command Execution
Directory traversal vulnerability in install05.php in Simple PHP Blog (SPB) 0.4.7.1 and earlier allows remote attackers
23RIESGO
abrir
Referência
CVE-2016-10043
An issue was discovered in Radisys MRF Web Panel (SWMS) 9.0.1. The MSM_MACRO_NAME POST parameter in /swms/ms.cgi was dis
23RIESGO
abrir
Referência
Multiple Vendor - PF Null Pointer Dereference
The pf_test_rule function in OpenBSD Packet Filter (PF), as used in OpenBSD 4.2 through 4.5, NetBSD 5.0 before RC3, MirO
23RIESGO
abrir
Referência
OpenBSD 4.5 - IP datagrams Remote Denial of Service
The pf_test_rule function in OpenBSD Packet Filter (PF), as used in OpenBSD 4.2 through 4.5, NetBSD 5.0 before RC3, MirO
23RIESGO
abrir
Referência
CVE-2012-1010
Unrestricted file upload vulnerability in actions.php in the AllWebMenus plugin before 1.1.8 for WordPress allows remote
23RIESGO
abrir
Referência
CVE-2022-4063
InPost Gallery < 2.1.4.1 - Unauthenticated LFI to RCE
63RIESGO
abrir
Referência
CVE-2026-10812
zilliztech GPTCache Cache Key pre.py BufferedReader.peek weak hash
28RIESGO
abrir
Referência
Shadowed Portal 5.599 - 'root' Remote File Inclusion
PHP remote file inclusion vulnerability in bottom.php in Shadowed Portal 5.599 and earlier allows remote attackers to ex
23RIESGO
abrir
Referência
Mambo Component Security Images 3.0.5 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Security Images (com_securityimages) component 3.0.5 and earlier f
23RIESGO
abrir
Referência
CVE-2018-18793
School Event Management System 1.0 allows Arbitrary File Upload via event/controller.php?action=photos.
23RIESGO
abrir
Referência
CVE-2018-18793
School Event Management System 1.0 allows Arbitrary File Upload via event/controller.php?action=photos.
23RIESGO
abrir
Referência
CVE-2017-7041
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RIESGO
abrir
Referência
Joomla! Component RSfiles 1.0.2 - 'path' File Download
Directory traversal vulnerability in index.php in the RSfiles component (com_rsfiles) 1.0.2 and earlier for Joomla! allo
38RIESGO
abrir
Referência
CVE-2018-18924
The image-upload feature in ProjeQtOr 7.2.5 allows remote attackers to execute arbitrary code by uploading a .shtml file
23RIESGO
abrir
Referência
Alstrasoft e-Friends 4.85 - Remote Command Execution
Directory traversal vulnerability in chat/getStartOptions.php in AlstraSoft E-friends 4.85 allows remote attackers to in
23RIESGO
abrir
Referência
HSRS 1.0 - 'addcode.php' Remote File Inclusion
PHP remote file inclusion vulnerability in addcode.php in HIOX Star Rating System Script (HSRS) 1.0 and earlier allows r
23RIESGO
abrir
Referência
Bubla 0.9.2 - 'bu_dir' Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Vladimir Menshakov buratinable templator (aka bubla) 0.9.1 allow r
23RIESGO
abrir
Referência
CVE-2010-3314
Cross-site scripting (XSS) vulnerability in login.php in EGroupware 1.4.001+.002; 1.6.001+.002 and possibly other versio
23RIESGO
abrir
Referência
FretsWeb 1.2 - Multiple Local File Inclusions
Multiple directory traversal vulnerabilities in FretsWeb 1.2 allow remote attackers to read arbitrary files via director
23RIESGO
abrir
Referência
POWERGAP 2003 - 's0x.php' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in POWERGAP allow remote attackers to execute arbitrary PHP code via
28RIESGO
abrir
Referência
CVE-2010-1475
Directory traversal vulnerability in the Preventive & Reservation (com_preventive) component 1.0.5 for Joomla! allows re
38RIESGO
abrir
Referência
CVE-2010-1475
Directory traversal vulnerability in the Preventive & Reservation (com_preventive) component 1.0.5 for Joomla! allows re
38RIESGO
abrir
Referência
CVE-2010-1722
Directory traversal vulnerability in the Online Market (com_market) component 2.x for Joomla! allows remote attackers to
38RIESGO
abrir
Referência
CVE-2010-1722
Directory traversal vulnerability in the Online Market (com_market) component 2.x for Joomla! allows remote attackers to
38RIESGO
abrir
Referência
CVE-2010-1474
Directory traversal vulnerability in the Sweety Keeper (com_sweetykeeper) component 1.5.x for Joomla! allows remote atta
38RIESGO
abrir
anteriorpágina 154 / 668siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.