Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.008exploits catalogados
34.638CVEs con explotación pública
24.695probados en laboratorio
21.624 exploits
Referência
CVE-2017-11785
The Microsoft Windows Kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Wind
23RIESGO
abrir
Referência
CVE-2017-8564
Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and
23RIESGO
abrir
Referência
CVE-2017-2508
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The
23RIESGO
abrir
ReferênciaVexDay Proof
Hitweb 4.2.1 - 'REP_INC' Remote File Inclusion
CVE-2006-4113webappsphp
PHP remote file inclusion vulnerability in genpage-cgi.php in Brian Fraval hitweb 4.2 and possibly earlier versions allo
23RIESGO
abrir
ReferênciaVexDay Proof
ACGV News 0.9.1 - 'article.php' Remote File Inclusion
CVE-2006-4638webappsphp
PHP remote file inclusion vulnerability in article.php in ACGV News 0.9.1 and earlier allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
Spaminator 1.7 - 'page' Remote File Inclusion
CVE-2006-4158webappsphp
PHP remote file inclusion vulnerability in Login.php in Spaminator 1.7 and earlier allows remote attackers to execute ar
23RIESGO
abrir
ReferênciaVexDay Proof
phpBB Journals System Mod 1.0.2 RC2 - Remote File Inclusion
CVE-2006-5306webappsphp
Multiple PHP remote file inclusion vulnerabilities in the Journals System module 1.0.2 (RC2) and earlier for phpBB allow
23RIESGO
abrir
ReferênciaVexDay Proof
MyABraCaDaWeb 1.0.3 - 'base' Remote File Inclusion
CVE-2006-4719webappsphp
Multiple PHP remote file inclusion vulnerabilities in MyABraCaDaWeb 1.0.3, when register_globals is enabled, allow remot
23RIESGO
abrir
ReferênciaVexDay Proof
Formbankserver 1.9 - 'Name' Remote Denial of Service
CVE-2006-6910doswindows
formbankcgi.exe in Fersch Formbankserver 1.9, when the PATH_INFO begins with Abfrage, allows remote attackers to cause a
23RIESGO
abrir
ReferênciaVexDay Proof
PHP 5.2.3 - 'bz2 com_print_typeinfo()' Denial of Service
CVE-2007-3790dosmultiple
The com_print_typeinfo function in the bz2 extension in PHP 5.2.3 allows context-dependent attackers to cause a denial o
23RIESGO
abrir
ReferênciaVexDay Proof
PHP iCalendar 2.24 - Insecure Cookie Handling
CVE-2008-5840webappsphp
PHP iCalendar 2.24 and earlier allows remote attackers to bypass authentication by setting the phpicalendar and phpicale
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component com_Projectfork 2.0.10 - Local File Inclusion
CVE-2009-2100webappsphp
Directory traversal vulnerability in the JoomlaPraise Projectfork (com_projectfork) component 2.0.10 for Joomla! allows
38RIESGO
abrir
ReferênciaVexDay Proof
Campsite 3.3.0 RC1 - Multiple Remote File Inclusions
CVE-2009-2182webappsphp
Multiple PHP remote file inclusion vulnerabilities in Campsite 3.3.0 RC1 allow remote attackers to execute arbitrary PHP
23RIESGO
abrir
Referência
CVE-2020-26808
SAP AS ABAP(DMIS), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 a
48RIESGO
abrir
Referência
CVE-2023-28285
Microsoft Office Remote Code Execution Vulnerability
41RIESGO
abrir
Referência
CVE-2018-4241
An issue was discovered in certain Apple products. iOS before 11.4 is affected. macOS before 10.13.5 is affected. tvOS b
23RIESGO
abrir
Referência
CVE-2009-4251
Stack-based buffer overflow in Jasc Paint Shop Pro 8.10 (aka Corel Paint Shop Pro) allows user-assisted remote attackers
23RIESGO
abrir
Referência
CVE-2016-8018
Cross-site request forgery (CSRF) vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier)
23RIESGO
abrir
Referência
CVE-2010-5025
Cross-site scripting (XSS) vulnerability in manage/main.php in CuteSITE CMS 1.2.3 and 1.5.0 allows remote attackers to i
23RIESGO
abrir
Referência
CVE-2018-17996
LayerBB before 1.1.3 allows CSRF for adding a user via admin/new_user.php, deleting a user via admin/members.php/delete_
23RIESGO
abrir
Referência
CVE-2018-17996
LayerBB before 1.1.3 allows CSRF for adding a user via admin/new_user.php, deleting a user via admin/members.php/delete_
23RIESGO
abrir
Referência
CVE-2017-8927
Buffer overflow in Larson VizEx Reader 9.7.5 allows attackers to cause a denial of service or possibly have unspecified
23RIESGO
abrir
Referência
CVE-2009-4542
Cross-site scripting (XSS) vulnerability in newticket.php in IsolSoft Support Center 2.5 allows remote attackers to inje
23RIESGO
abrir
ReferênciaVexDay Proof
Cartweaver 2.16.11 - 'ProdID' SQL Injection
CVE-2006-2046webappscgi
Multiple SQL injection vulnerabilities in Application Dynamics Cartweaver ColdFusion 2.16.11 and earlier allow remote at
23RIESGO
abrir
ReferênciaVexDay Proof
OPENi-CMS 1.0.1beta - 'config' Remote File Inclusion
CVE-2006-4750webappsphp
PHP remote file inclusion vulnerability in openi-admin/base/fileloader.php in OPENi-CMS 1.0.1, and possibly earlier, all
23RIESGO
abrir
ReferênciaVexDay Proof
KGB 1.9 - 'sesskglogadmin.php' Local File Inclusion
CVE-2007-0337webappsphp
Directory traversal vulnerability in sesskglogadmin.php in KGB 1.9 and earlier allows remote attackers to include and ex
23RIESGO
abrir
ReferênciaVexDay Proof
Aktueldownload Haber scripti - 'id' SQL Injection
CVE-2007-1015webappsasp
SQL injection vulnerability in HaberDetay.asp in Aktueldownload Haber script allows remote attackers to execute arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
F3Site 2.1 - Remote Code Execution
CVE-2007-0763webappsphp
Cross-site scripting (XSS) vulnerability in the news comment functionality in F3Site 2.1 and earlier allows remote attac
23RIESGO
abrir
ReferênciaVexDay Proof
PHP-Nuke Module AddressBook 1.2 - Local File Inclusion
CVE-2007-1720webappsphp
Directory traversal vulnerability in addressbook.php in the Addressbook 1.2 module for PHP-Nuke allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
public media manager 1.3 - Remote File Inclusion
CVE-2007-5149webappsphp
PHP remote file inclusion vulnerability in NewsCMS/news/newstopic_inc.php in North Country Public Radio Public Media Man
23RIESGO
abrir
anteriorpágina 252 / 721siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.