Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.066exploits catalogados
34.679CVEs con explotación pública
24.695probados en laboratorio
21.662 exploits
Referência
CVE-2012-4772
SQL injection vulnerability in register/ in Subrion CMS before 2.2.3 allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir
Referência
CVE-2009-2784
Multiple directory traversal vulnerabilities in dit.cms 1.3, when register_globals is enabled, allow remote attackers to
23RIESGO
abrir
Referência
CVE-2008-6495
Cross-site scripting (XSS) vulnerability in index.php in Fritz Berger yet another php photo album - next generation (yap
23RIESGO
abrir
ReferênciaVexDay Proof
Web//News 1.4 - 'parser.php' Remote File Inclusion (1)
CVE-2006-5100webappsphp
PHP remote file inclusion vulnerability in parse/parser.php in WEB//NEWS (aka webnews) 1.4 and earlier allows remote att
23RIESGO
abrir
ReferênciaVexDay Proof
MiniBill 20061010 - 'menu_builder.php' File Inclusion
CVE-2006-5620webappsphp
PHP remote file inclusion vulnerability in include/menu_builder.php in MiniBILL 2006-10-10 (1.2.3) and earlier, when reg
23RIESGO
abrir
ReferênciaVexDay Proof
PHP Upload Center 2.0 - 'activate.php' File Inclusion
CVE-2006-6360webappsphp
PHP remote file inclusion vulnerability in activate.php in PHP Upload Center 2.0 allows remote attackers to execute arbi
23RIESGO
abrir
ReferênciaVexDay Proof
CandyPress eCommerce suite 4.1.1.26 - Multiple Vulnerabilities
CVE-2008-0547webappsasp
Cross-site scripting (XSS) vulnerability in admin/utilities_ConfigHelp.asp in CandyPress (CP) 4.1.1.26, and probably ear
23RIESGO
abrir
ReferênciaVexDay Proof
WholeHogSoftware Ware Support - Insecure Cookie Handling
CVE-2009-0460webappsphp
Whole Hog Ware Support 1.x allows remote attackers to bypass authentication and obtain administrative access via an inte
23RIESGO
abrir
Referência
CVE-2010-2115
SolarWinds TFTP Server 10.4.0.10 allows remote attackers to cause a denial of service (no new connections) via a crafted
50RIESGO
abrir
Referência
CVE-2014-8810
SQL injection vulnerability in ajax/mail_functions.php in the WP Symposium plugin before 14.11 for WordPress allows remo
23RIESGO
abrir
Referência
CVE-2010-2122
Directory traversal vulnerability in the SimpleDownload (com_simpledownload) component before 0.9.6 for Joomla! allows r
43RIESGO
abrir
Referência
CVE-2014-9305
SQL injection vulnerability in the shortcodeProductsTable function in models/Cart66Ajax.php in the Cart66 Lite plugin be
23RIESGO
abrir
Referência
CVE-2014-9305
SQL injection vulnerability in the shortcodeProductsTable function in models/Cart66Ajax.php in the Cart66 Lite plugin be
23RIESGO
abrir
Referência
CVE-2010-2122
Directory traversal vulnerability in the SimpleDownload (com_simpledownload) component before 0.9.6 for Joomla! allows r
43RIESGO
abrir
Referência
CVE-2017-8469
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2,
23RIESGO
abrir
Referência
CVE-2017-8462
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2,
23RIESGO
abrir
Referência
CVE-2017-8482
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2,
23RIESGO
abrir
Referência
CVE-2017-8478
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2,
23RIESGO
abrir
Referência
CVE-2014-2976
Directory traversal vulnerability in Sixnet SixView Manager 2.4.1 allows remote attackers to read arbitrary files via a
23RIESGO
abrir
ReferênciaVexDay Proof
FlashChat 4.5.7 - 'aedating4CMS.php' Remote File Inclusion
CVE-2006-4583webappsphp
Multiple PHP remote file inclusion vulnerabilities in FlashChat before 4.6.2 allow remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
R2K Gallery 1.7 - 'galeria.php?lang2' Local File Inclusion
CVE-2007-2642webappsphp
Directory traversal vulnerability in galeria.php in R2K Gallery 1.7 allows remote attackers to read arbitrary files via
23RIESGO
abrir
ReferênciaVexDay Proof
SkyFex Client 1.0 - ActiveX 'Start()' Method Remote Stack Overflow
CVE-2007-6605doswindows
Buffer overflow in a certain ActiveX control in SkyFexClient.ocx 1.0.2.77 in SkyFex Client 1.0 allows remote attackers t
23RIESGO
abrir
ReferênciaVexDay Proof
Orbit Downloader 2.8.7 - Arbitrary File Deletion
CVE-2009-1064remotewindows
Argument injection vulnerability in orbitmxt.dll 2.1.0.2 in the Orbit Downloader 2.8.7 and earlier ActiveX control allow
23RIESGO
abrir
Referência
CVE-2023-3049
File Upload in TMT's Lockcell
48RIESGO
abrir
Referência
CVE-2015-4631
Multiple cross-site scripting (XSS) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before
23RIESGO
abrir
Referência
CVE-2015-4631
Multiple cross-site scripting (XSS) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before
23RIESGO
abrir
ReferênciaVexDay Proof
snap - seccomp BBlacklist for TIOCSTI can be Circumvented
CVE-2019-7303MEDIUMdoslinux
Snapd seccomp filter TIOCSTI ioctl bypass
33RIESGO
abrir
Referência
CVE-2021-44916
Opmantek Open-AudIT Community 4.2.0 (Fixed in 4.3.0) is affected by a Cross Site Scripting (XSS) vulnerability. If a bad
23RIESGO
abrir
Referência
CVE-2009-4147
The _rtld function in the Run-Time Link-Editor (rtld) in libexec/rtld-elf/rtld.c in FreeBSD 7.1 and 8.0 does not clear t
38RIESGO
abrir
Referência
CVE-2013-2684
Cross-site Scripting (XSS) in Cisco Linksys E4200 1.0.05 Build 7 devices allows remote attackers to inject arbitrary web
23RIESGO
abrir
anteriorpágina 277 / 723siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.