Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
76.107exploits catalogados
34.679CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.692GitHub PoC 13.812VulnCheck XDB 8460Nuclei 4233Metasploit 3467✓ solo verificadosrecientespopularesriesgo
21.692 exploits
Referência
CVE-2019-0805
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), ak
23RIESGO
abrir ↗Referência
CVE-2019-0805
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), ak
23RIESGO
abrir ↗Referência✓ VexDay Proof
JV2 Folder Gallery 3.0 - 'download.php' Remote File Disclosure
download.php in Joonas Viljanen JV2 Folder Gallery allows remote attackers to read sensitive files via a relative pathna
23RIESGO
abrir ↗Referência✓ VexDay Proof
Uberghey 0.3.1 - 'FrontPage.php' Remote File Inclusion
PHP remote file inclusion vulnerability in frontpage.php in Uberghey CMS 0.3.1 allows remote attackers to execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
Site-Assistant 0990 - 'paths[version]' Remote File Inclusion
PHP remote file inclusion vulnerability in classes/menu.php in Site-Assistant 0990 and earlier allows remote attackers t
23RIESGO
abrir ↗Referência✓ VexDay Proof
ttCMS 4 - 'ez_sql.php?lib_path' Remote File Inclusion
PHP remote file inclusion vulnerability in lib/db/ez_sql.php in ttCMS 4 and earlier allows remote attackers to execute a
23RIESGO
abrir ↗Referência✓ VexDay Proof
CyBoards PHP Lite 1.21 - 'script_path' Remote File Inclusion
PHP remote file inclusion vulnerability in include/default_header.php in Cyboards PHP Lite 1.21 allows remote attackers
23RIESGO
abrir ↗Referência
CVE-2010-0984
Acidcat CMS 3.5.3 and earlier stores sensitive information under the web root with insufficient access control, which al
23RIESGO
abrir ↗Referência
CVE-2010-0984
Acidcat CMS 3.5.3 and earlier stores sensitive information under the web root with insufficient access control, which al
23RIESGO
abrir ↗Referência✓ VexDay Proof
Sisplet CMS 05.10 - 'site_path' Remote File Inclusion
PHP remote file inclusion vulnerability in main/forum/komentar.php in OneClick CMS (aka Sisplet CMS) 05.10 and earlier a
23RIESGO
abrir ↗Referência
CVE-2010-1431
SQL injection vulnerability in templates_export.php in Cacti 0.8.7e and earlier allows remote attackers to execute arbit
23RIESGO
abrir ↗Referência✓ VexDay Proof
Sendcard 3.4.1 - 'sendcard.php?form' Local File Inclusion
Directory traversal vulnerability in sendcard.php in Sendcard 3.4.1 and earlier allows remote attackers to read arbitrar
23RIESGO
abrir ↗Referência✓ VexDay Proof
6ALBlog - 'newsid' SQL Injection
PHP remote file inclusion vulnerability in admin/index.php in 6ALBlog allows remote authenticated administrators to exec
23RIESGO
abrir ↗Referência✓ VexDay Proof
XOOPS 2.0.18 - Local File Inclusion / URL Redirecting
Directory traversal vulnerability in htdocs/install/index.php in XOOPS 2.0.18 allows remote attackers to include and exe
23RIESGO
abrir ↗Referência✓ VexDay Proof
Web Slider 0.6 - Insecure Cookie/Authentication Handling
Admin.php in Web Slider 0.6 allows remote attackers to bypass authentication and gain privileges by setting the admin co
23RIESGO
abrir ↗Referência✓ VexDay Proof
txtSQL 2.2 Final - 'startup.php' Remote File Inclusion
PHP remote file inclusion vulnerability in examples/txtSQLAdmin/startup.php in txtSQL 2.2 Final allows remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
PhpBlock a8.5 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in PhpBlock A8.5 allow remote attackers to execute arbitrary PHP code
23RIESGO
abrir ↗Referência
CVE-2018-0752
The Windows Kernel API in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709
23RIESGO
abrir ↗Referência
CVE-2018-0748
The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and
23RIESGO
abrir ↗Referência
CVE-2022-1631
Users Account Pre-Takeover or Users Account Takeover. in microweber/microweber
33RIESGO
abrir ↗Referência
CVE-2010-4612
Multiple SQL injection vulnerabilities in index.php in Hycus CMS 1.0.3, when magic_quotes_gpc is disabled, allow remote
23RIESGO
abrir ↗Referência✓ VexDay Proof
JiRo's FAQ Manager eXperience 1.0 - 'fID' SQL Injection
SQL injection vulnerability in read.asp in JiRo's FAQ Manager eXperience 1.0 allows remote attackers to execute arbitrar
23RIESGO
abrir ↗Referência✓ VexDay Proof
Black Ice Software Inc Barcode SDK - 'BITiff.ocx' Remote Buffer Overflow (2)
Stack-based buffer overflow in the BITIFF.BITiffCtrl.1 ActiveX control in BITiff.ocx 10.9.3.0 in Black Ice Barcode SDK 5
28RIESGO
abrir ↗Referência
CVE-2022-21371
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Web Container). Supported ve
78RIESGO
abrir ↗Referência
CVE-2010-1267
Multiple directory traversal vulnerabilities in WebMaid CMS 0.2-6 Beta and earlier allow remote attackers to read arbitr
23RIESGO
abrir ↗Referência
CVE-2010-1267
Multiple directory traversal vulnerabilities in WebMaid CMS 0.2-6 Beta and earlier allow remote attackers to read arbitr
23RIESGO
abrir ↗Referência
CVE-2009-4698
Multiple SQL injection vulnerabilities in the Qas (aka Quas) module for XOOPS Celepar allow remote attackers to execute
23RIESGO
abrir ↗Referência
CVE-2009-4698
Multiple SQL injection vulnerabilities in the Qas (aka Quas) module for XOOPS Celepar allow remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
asp-project 1.0 - Insecure Cookie Method
Asp Project Management 1.0 allows remote attackers to bypass authentication and gain administrative access by setting th
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.