Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.107exploits catalogados
34.679CVEs con explotación pública
24.695probados en laboratorio
21.692 exploits
Referência
CVE-2014-5090
admin/options/logs.php in Status2k allows remote authenticated administrators to execute arbitrary commands via shell me
23RIESGO
abrir
ReferênciaVexDay Proof
IntelliTamper 2.07 - '.map' Local Arbitrary Code Execution (1)
CVE-2006-2494localwindows
Stack-based buffer overflow in IntelliTamper 2.07 allows remote attackers to execute arbitrary code via a crafted .map f
23RIESGO
abrir
ReferênciaVexDay Proof
Million Dollar Text Links 1.0 - Arbitrary Authentication Bypass
CVE-2009-1582webappsphp
Million Dollar Text Links 1.0 does not properly restrict administrator access to admin.home.php, which allows remote att
23RIESGO
abrir
Referência
CVE-2017-6547
Cross-site scripting (XSS) vulnerability in httpd on ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC
23RIESGO
abrir
ReferênciaVexDay Proof
Gizzar 03162002 - 'index.php' Remote File Inclusion
CVE-2006-6526webappsphp
PHP remote file inclusion vulnerability in index.php in Gizzar 03162002 and earlier allows remote attackers to execute a
23RIESGO
abrir
Referência
CVE-2010-4858
Directory traversal vulnerability in team.rc5-72.php in DNET Live-Stats 0.8 allows remote attackers to read arbitrary fi
23RIESGO
abrir
Referência
CVE-2010-4858
Directory traversal vulnerability in team.rc5-72.php in DNET Live-Stats 0.8 allows remote attackers to read arbitrary fi
23RIESGO
abrir
ReferênciaVexDay Proof
ACGVclick 0.2.0 - 'path' Remote File Inclusion
CVE-2007-0577webappsphp
PHP remote file inclusion vulnerability in function.inc.php in ACGVclick 0.2.0 and earlier allows remote attackers to ex
23RIESGO
abrir
ReferênciaVexDay Proof
phpBB MOD Forum picture and META tags 1.7 - Remote File Inclusion
CVE-2007-1818webappsphp
PHP remote file inclusion vulnerability in MOD_forum_fields_parse.php in the Forum picture and META tags 1.7 module for
23RIESGO
abrir
Referência
CVE-2016-6772
An elevation of privilege vulnerability in Wi-Fi could enable a local malicious application to execute arbitrary code wi
23RIESGO
abrir
Referência
CVE-2009-4424
SQL injection vulnerability in results.php in the Pyrmont plugin 2 for WordPress allows remote attackers to execute arbi
23RIESGO
abrir
Referência
CVE-2009-4424
SQL injection vulnerability in results.php in the Pyrmont plugin 2 for WordPress allows remote attackers to execute arbi
23RIESGO
abrir
ReferênciaVexDay Proof
YAAP 1.5 - '__autoload()' Remote File Inclusion
CVE-2007-2664webappsphp
PHP remote file inclusion vulnerability in includes/common.php in Yaap 1.5 and earlier allows remote attackers to execut
23RIESGO
abrir
ReferênciaVexDay Proof
Scallywag - 'template.php?path' Remote File Inclusion
CVE-2007-2900webappsphp
Multiple PHP remote file inclusion vulnerabilities in Scallywag 2005-04-25 allow remote attackers to execute arbitrary P
23RIESGO
abrir
ReferênciaVexDay Proof
phpBB Mod OpenID 0.2.0 - 'BBStore.php' Remote File Inclusion
CVE-2007-5173webappsphp
PHP remote file inclusion vulnerability in includes/openid/Auth/OpenID/BBStore.php in phpBB Openid 0.2.0 allows remote a
23RIESGO
abrir
ReferênciaVexDay Proof
Flat PHP Board 1.2 - Multiple Vulnerabilities
CVE-2007-6397webappsphp
Multiple directory traversal vulnerabilities in index.php in Flat PHP Board 1.2 and earlier allow remote attackers to (1
23RIESGO
abrir
ReferênciaVexDay Proof
NmnNewsletter 1.0.7 - 'output' Remote File Inclusion
CVE-2007-6585webappsphp
PHP remote file inclusion vulnerability in confirmUnsubscription.php in NmnNewsletter 1.0.7 allows remote attackers to e
23RIESGO
abrir
ReferênciaVexDay Proof
Cyberfolio 7.12 - 'rep' Remote File Inclusion
CVE-2008-2228webappsphp
PHP remote file inclusion vulnerability in portfolio/commentaires/derniers_commentaires.php in Cyberfolio 7.12, when reg
23RIESGO
abrir
Referência
CVE-2015-1428
Multiple SQL injection vulnerabilities in Sefrengo before 1.6.2 allow (1) remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
Referência
CVE-2014-3442
Winamp 5.666 and earlier allows remote attackers to cause a denial of service (memory corruption and crash) via a malfor
23RIESGO
abrir
Referência
CVE-2015-7569
SQL injection vulnerability in "yeager/y.php/tab_USERLIST" in Yeager CMS 1.2.1 allows local users to execute arbitrary S
23RIESGO
abrir
Referência
CVE-2015-7569
SQL injection vulnerability in "yeager/y.php/tab_USERLIST" in Yeager CMS 1.2.1 allows local users to execute arbitrary S
23RIESGO
abrir
Referência
CVE-2010-2312
SQL injection vulnerability in index.php in HauntmAx Haunted House Directory Listing CMS allows remote attackers to exec
23RIESGO
abrir
Referência
CVE-2019-0805
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), ak
23RIESGO
abrir
Referência
CVE-2019-0805
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), ak
23RIESGO
abrir
ReferênciaVexDay Proof
JV2 Folder Gallery 3.0 - 'download.php' Remote File Disclosure
CVE-2007-0329webappsphp
download.php in Joonas Viljanen JV2 Folder Gallery allows remote attackers to read sensitive files via a relative pathna
23RIESGO
abrir
ReferênciaVexDay Proof
Uberghey 0.3.1 - 'FrontPage.php' Remote File Inclusion
CVE-2007-0359webappsphp
PHP remote file inclusion vulnerability in frontpage.php in Uberghey CMS 0.3.1 allows remote attackers to execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
Site-Assistant 0990 - 'paths[version]' Remote File Inclusion
CVE-2007-0867webappsphp
PHP remote file inclusion vulnerability in classes/menu.php in Site-Assistant 0990 and earlier allows remote attackers t
23RIESGO
abrir
ReferênciaVexDay Proof
ttCMS 4 - 'ez_sql.php?lib_path' Remote File Inclusion
CVE-2007-1708webappsphp
PHP remote file inclusion vulnerability in lib/db/ez_sql.php in ttCMS 4 and earlier allows remote attackers to execute a
23RIESGO
abrir
ReferênciaVexDay Proof
CyBoards PHP Lite 1.21 - 'script_path' Remote File Inclusion
CVE-2007-1983webappsphp
PHP remote file inclusion vulnerability in include/default_header.php in Cyboards PHP Lite 1.21 allows remote attackers
23RIESGO
abrir
anteriorpágina 283 / 724siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.