Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
75.589exploits catalogados
34.508CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.554GitHub PoC 13.689VulnCheck XDB 8216Nuclei 4223Metasploit 3464✓ solo verificadosrecientespopularesriesgo
21.554 exploits
Referência
CVE-2012-5349
Multiple cross-site scripting (XSS) vulnerabilities in pay.php in the Pay With Tweet plugin before 1.2 allow remote atta
23RIESGO
abrir ↗Referência
CVE-2023-53963
SOUND4 IMPACT/FIRST/PULSE/Eco v2.x Unauthenticated Remote Command Injection
48RIESGO
abrir ↗Referência
CVE-2020-35437
Subrion CMS 4.2.1 is affected by: Cross Site Scripting (XSS) through the avatar[path] parameter in a POST request to the
23RIESGO
abrir ↗Referência
CVE-2015-6965
Multiple cross-site request forgery (CSRF) vulnerabilities in the Contact Form Generator plugin 2.0.1 and earlier for Wo
23RIESGO
abrir ↗Referência
CVE-2015-6965
Multiple cross-site request forgery (CSRF) vulnerabilities in the Contact Form Generator plugin 2.0.1 and earlier for Wo
23RIESGO
abrir ↗Referência
Genexis Platinum 4410 Router 2.1 - UPnP Credential Exposure
UPNP Service listening on port 5555 in Genexis Platinum 4410 Router V2.1 (P4410-V2–1.34H) has an action 'X_GetAccess' wh
23RIESGO
abrir ↗Referência
CVE-2010-1918
SQL injection vulnerability in ask_chat.php in eFront 3.6.2 and earlier allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Referência
CVE-2019-7671
Prima Systems FlexAir, Versions 2.3.38 and prior. Parameters sent to scripts are not properly sanitized before being ret
23RIESGO
abrir ↗Referência
CVE-2017-11785
The Microsoft Windows Kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Wind
23RIESGO
abrir ↗Referência
CVE-2017-8564
Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and
23RIESGO
abrir ↗Referência
CVE-2017-2508
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The
23RIESGO
abrir ↗Referência✓ VexDay Proof
Hitweb 4.2.1 - 'REP_INC' Remote File Inclusion
PHP remote file inclusion vulnerability in genpage-cgi.php in Brian Fraval hitweb 4.2 and possibly earlier versions allo
23RIESGO
abrir ↗Referência✓ VexDay Proof
ACGV News 0.9.1 - 'article.php' Remote File Inclusion
PHP remote file inclusion vulnerability in article.php in ACGV News 0.9.1 and earlier allows remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
Spaminator 1.7 - 'page' Remote File Inclusion
PHP remote file inclusion vulnerability in Login.php in Spaminator 1.7 and earlier allows remote attackers to execute ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpBB Journals System Mod 1.0.2 RC2 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in the Journals System module 1.0.2 (RC2) and earlier for phpBB allow
23RIESGO
abrir ↗Referência✓ VexDay Proof
MyABraCaDaWeb 1.0.3 - 'base' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in MyABraCaDaWeb 1.0.3, when register_globals is enabled, allow remot
23RIESGO
abrir ↗Referência✓ VexDay Proof
Formbankserver 1.9 - 'Name' Remote Denial of Service
formbankcgi.exe in Fersch Formbankserver 1.9, when the PATH_INFO begins with Abfrage, allows remote attackers to cause a
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP 5.2.3 - 'bz2 com_print_typeinfo()' Denial of Service
The com_print_typeinfo function in the bz2 extension in PHP 5.2.3 allows context-dependent attackers to cause a denial o
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP iCalendar 2.24 - Insecure Cookie Handling
PHP iCalendar 2.24 and earlier allows remote attackers to bypass authentication by setting the phpicalendar and phpicale
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component com_Projectfork 2.0.10 - Local File Inclusion
Directory traversal vulnerability in the JoomlaPraise Projectfork (com_projectfork) component 2.0.10 for Joomla! allows
38RIESGO
abrir ↗Referência
CVE-2008-4141
Multiple PHP remote file inclusion vulnerabilities in x10Media x10 Automatic MP3 Script 1.5.5 allow remote attackers to
23RIESGO
abrir ↗Referência
CVE-2009-2325
Directory traversal vulnerability in index.php in Clicknet CMS 2.1 allows remote attackers to read arbitrary files via a
23RIESGO
abrir ↗Referência
CVE-2021-3111
The Express Entries Dashboard in Concrete5 8.5.4 allows stored XSS via the name field of a new data object at an index.p
23RIESGO
abrir ↗Referência
CVE-2021-3111
The Express Entries Dashboard in Concrete5 8.5.4 allows stored XSS via the name field of a new data object at an index.p
23RIESGO
abrir ↗Referência
CVE-2017-7398
D-Link DIR-615 HW: T1 FW:20.09 is vulnerable to Cross-Site Request Forgery (CSRF) vulnerability. This enables an attacke
23RIESGO
abrir ↗Referência
CVE-2012-10046
E-Mail Security Virtual Appliance learn-msg.cgi Command Injection
63RIESGO
abrir ↗Referência
CVE-2012-10046
E-Mail Security Virtual Appliance learn-msg.cgi Command Injection
63RIESGO
abrir ↗Referência
CVE-2012-10046
E-Mail Security Virtual Appliance learn-msg.cgi Command Injection
63RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.