Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
75.904exploits catalogados
34.599CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.624GitHub PoC 13.727VulnCheck XDB 8410Nuclei 4233Metasploit 3467✓ solo verificadosrecientespopularesriesgo
21.624 exploits
Referência
CVE-2009-3171
Multiple cross-site scripting (XSS) vulnerabilities in Anantasoft Gazelle CMS 1.0 and earlier allow remote attackers to
23RIESGO
abrir ↗Referência
CVE-2022-44900
A directory traversal vulnerability in the SevenZipFile.extractall() function of the python library py7zr v0.20.0 and ea
48RIESGO
abrir ↗Referência✓ VexDay Proof
open-medium.CMS 0.25 - '404.php' Remote File Inclusion
PHP remote file inclusion vulnerability in 404.php in open-medium.CMS 0.25 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
ASP Stats Generator 2.1.1 - SQL Injection
Direct static code injection vulnerability in ASP Stats Generator before 2.1.2 allows remote authenticated attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
Apple iOS 4.0.3 - DPAP Server Denial of Service
The Digital Photo Access Protocol (DPAP) server for iPhoto 4.0.3 allows remote attackers to cause a denial of service (c
23RIESGO
abrir ↗Referência✓ VexDay Proof
Simple Customer 1.3 - Arbitrary Change Admin Password
profile.php in Simple Customer 1.3 does not require administrative authentication, which allows remote attackers to chan
23RIESGO
abrir ↗Referência
CVE-2009-2337
SQL injection vulnerability in includes/module/book/index.inc.php in w3b|cms Gaestebuch Guestbook Module 3.0.0, when mag
23RIESGO
abrir ↗Referência
CVE-2011-5218
SQL injection vulnerability in DotA OpenStats 1.3.9 and earlier allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗Referência
CVE-2019-2721
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th
23RIESGO
abrir ↗Referência
CVE-2019-13529
An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform action
41RIESGO
abrir ↗Referência
CVE-2009-2606
ASP Football Pool 2.3 stores sensitive information under the web root with insufficient access control, which allows rem
23RIESGO
abrir ↗Referência
CVE-2009-2602
R2 Newsletter Lite, Pro, and Stats stores sensitive information under the web root with insufficient access control, whi
23RIESGO
abrir ↗Referência
CVE-2009-4545
Logoshows BBS 2.0 stores sensitive information under the web root with insufficient access control, which allows remote
23RIESGO
abrir ↗Referência
CVE-2022-47870
A Cross Site Scripting (XSS) vulnerability in the web SQL monitor login page in Redgate SQL Monitor 12.1.31.893 allows r
33RIESGO
abrir ↗Referência
CVE-2010-0725
Cross-site scripting (XSS) vulnerability in showimg.php in Arab Cart 1.0.2.0 allows remote attackers to inject arbitrary
23RIESGO
abrir ↗Referência
CVE-2010-0725
Cross-site scripting (XSS) vulnerability in showimg.php in Arab Cart 1.0.2.0 allows remote attackers to inject arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP-Nuke NukeAI Module 3b - 'util.php' Remote File Inclusion
Direct static code injection vulnerability in util.php in the NukeAI 0.0.3 Beta module for PHP-Nuke, aka Program E is an
23RIESGO
abrir ↗Referência✓ VexDay Proof
P-News 1.16/1.17 - 'user.dat' Remote Password Disclosure
P-News 1.16 and 1.17 store sensitive information under the web root with insufficient access control, which allows remot
23RIESGO
abrir ↗Referência✓ VexDay Proof
MiniBB 2.2 - Cross-Site Scripting / SQL Injection / Full Path Disclosure
miniBB 2.2, and possibly earlier, when register_globals is enabled, allows remote attackers to obtain the full path via
23RIESGO
abrir ↗Referência✓ VexDay Proof
CMS NetCat 3.12 - Multiple Vulnerabilities
Multiple CRLF injection vulnerabilities in AIST NetCat 3.12 and earlier allow remote attackers to have an unknown impact
23RIESGO
abrir ↗Referência✓ VexDay Proof
Liberum Help Desk 0.97.3 - SQL Injection / File Disclosure
Doug Luxem Liberum Help Desk 0.97.3 stores db/helpdesk2000.mdb under the web root with insufficient access control, whic
23RIESGO
abrir ↗Referência✓ VexDay Proof
template creature - SQL Injection / File Disclosure
ASP Template Creature stores sensitive information under the web root with insufficient access control, which allows rem
23RIESGO
abrir ↗Referência✓ VexDay Proof
Rapid Classified 3.1 - Database Disclosure
Rapid Classified 3.1 and 3.15 stores sensitive information under the web root with insufficient access control, which al
23RIESGO
abrir ↗Referência✓ VexDay Proof
Iamma Simple Gallery 1.0/2.0 - Arbitrary File Upload
Unrestricted file upload vulnerability in pages/download.php in Iamma Simple Gallery 1.0 and 2.0 allows remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
ColdFusion Scripts Red_Reservations - Database Disclosure
The Red_Reservations script for ColdFusion stores sensitive information under the web root with insufficient access cont
23RIESGO
abrir ↗Referência✓ VexDay Proof
ASP User Engine .NET - Remote Database Disclosure
ASP User Engine.NET stores sensitive information under the web root with insufficient access control, which allows remot
23RIESGO
abrir ↗Referência✓ VexDay Proof
Ocean12 FAQ Manager Pro - Database Disclosure
Ocean12 FAQ Manager Pro stores sensitive data under the web root with insufficient access control, which allows remote a
23RIESGO
abrir ↗Referência
CVE-2024-53537
An issue in OpenPanel v0.3.4 to v0.2.1 allows attackers to execute a directory traversal in File Actions of File Manager
48RIESGO
abrir ↗Referência
CVE-2007-6135
Cross-site scripting (XSS) vulnerability in phpslideshow.php in PHPSlideShow 0.9.9.2, and possibly earlier, allows remot
23RIESGO
abrir ↗Referência
CVE-2014-8995
SQL injection vulnerability in Maarch LetterBox 2.8 allows remote attackers to execute arbitrary SQL commands via the Us
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.