Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.313exploits catalogados
34.834CVEs con explotación pública
24.695probados en laboratorio
21.797 exploits
ReferênciaVexDay Proof
Aardvark Topsites PHP 4.2.2 - 'lostpw.php' Remote File Inclusion
CVE-2006-2149webappsphp
PHP remote file inclusion vulnerability in sources/lostpw.php in Aardvark Topsites PHP 4.2.2 and earlier, when register_
23RIESGO
abrir
ReferênciaVexDay Proof
Phpjobscheduler 3.0 - 'installed_config_file' File Inclusion
CVE-2006-5928webappsphp
Multiple PHP remote file inclusion vulnerabilities in Phpjobscheduler 3.0 allow remote attackers to execute arbitrary PH
23RIESGO
abrir
ReferênciaVexDay Proof
RsGallery2 < 1.11.2 - 'rsgallery.html.php' File Inclusion
CVE-2006-6962webappsphp
PHP remote file inclusion vulnerability in rsgallery2.html.php in the RS Gallery2 component (com_rsgallery2) 1.11.2 for
23RIESGO
abrir
Referência
CVE-2013-3535
Multiple cross-site scripting (XSS) vulnerabilities in CMSLogik 1.2.0 and 1.2.1 allow remote attackers to inject arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
CMS Faethon 2.2 Ultimate - Remote File Inclusion / Cross-Site Scripting
CVE-2008-2127webappsphp
Cross-site scripting (XSS) vulnerability in search.php in CMS Faethon 2.2 Ultimate allows remote attackers to inject arb
23RIESGO
abrir
Referência
CVE-2014-4312
Multiple cross-site scripting (XSS) vulnerabilities in Epicor Enterprise 7.4 before FS74SP6_HotfixTL054181 allow remote
23RIESGO
abrir
Referência
CVE-2014-4312
Multiple cross-site scripting (XSS) vulnerabilities in Epicor Enterprise 7.4 before FS74SP6_HotfixTL054181 allow remote
23RIESGO
abrir
ReferênciaVexDay Proof
Galleristic 1.0 - 'cat' SQL Injection
CVE-2008-2129webappsphp
SQL injection vulnerability in index.php in Galleristic 1.0, when magic_quotes_gpc is disabled, allows remote attackers
23RIESGO
abrir
Referência
CVE-2015-8284
SeaWell Networks Spectrum SDC 02.05.00 allows remote viewer users to perform administrative functions.
23RIESGO
abrir
Referência
CVE-2015-8284
SeaWell Networks Spectrum SDC 02.05.00 allows remote viewer users to perform administrative functions.
23RIESGO
abrir
Referência
CVE-2018-9245
The Ericsson-LG iPECS NMS A.1Ac login portal has a SQL injection vulnerability in the User ID and password fields that a
23RIESGO
abrir
Referência
CVE-2015-2878
Multiple cross-site request forgery (CSRF) vulnerabilities in Hexis HawkEye G 3.0.1.4912 allow remote attackers to hijac
23RIESGO
abrir
Referência
CVE-2009-2787
Directory traversal vulnerability in include/reputation/rep_profile.php in the Reputation plugin 2.2.4, 2.2.3, 2.0.4, an
23RIESGO
abrir
Referência
CVE-2009-2787
Directory traversal vulnerability in include/reputation/rep_profile.php in the Reputation plugin 2.2.4, 2.2.3, 2.0.4, an
23RIESGO
abrir
Referência
CVE-2018-4230
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "NVIDIA Grap
23RIESGO
abrir
Referência
CVE-2022-0847
CVE-2022-0847HIGHbajo ataque
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
Referência
CVE-2012-0984
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS before 2.5.5 allow remote attackers to inject arbitrary web
23RIESGO
abrir
Referência
CVE-2012-0984
Multiple cross-site scripting (XSS) vulnerabilities in XOOPS before 2.5.5 allow remote attackers to inject arbitrary web
23RIESGO
abrir
Referência
CVE-2022-0847
CVE-2022-0847HIGHbajo ataque
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
Referência
CVE-2012-1124
SQL injection vulnerability in search.php in phxEventManager 2.0 beta 5 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
Referência
CVE-2012-6667
Cross-site scripting (XSS) vulnerability in vbshout.php in DragonByte Technologies vBShout module for vBulletin allows r
23RIESGO
abrir
ReferênciaVexDay Proof
PHPMyInventory 2.8 - 'global.inc.php' Remote File Inclusion
CVE-2007-3270webappsphp
PHP remote file inclusion vulnerability in Includes/global.inc.php in phpMyInventory 2.8 allows remote attackers to exec
23RIESGO
abrir
Referência
CVE-2018-7703
Cross-site scripting (XSS) vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote attackers to inject arbitr
23RIESGO
abrir
Referência
CVE-2013-7136
The UPC Ireland Cisco EPC 2425 router (aka Horizon Box) does not have a sufficiently large number of possible WPA-PSK pa
23RIESGO
abrir
Referência
CVE-2017-12954
The gig::Region::GetSampleFromWavePool function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial of
23RIESGO
abrir
Referência
CVE-2017-12953
The gig::Instrument::UpdateRegionKeyTable function in gig.cpp in libgig 4.0.0 allows remote attackers to cause a denial
23RIESGO
abrir
ReferênciaVexDay Proof
WordPress Plugin Wordspew - SQL Injection
CVE-2008-0682webappsphp
SQL injection vulnerability in wordspew-rss.php in the Wordspew plugin before 3.72 for Wordpress allows remote attackers
23RIESGO
abrir
Referência
CVE-2014-6312
Cross-site request forgery (CSRF) vulnerability in the Login Widget With Shortcode (login-sidebar-widget) plugin before
23RIESGO
abrir
ReferênciaVexDay Proof
PostcardMentor - 'cat_fldAuto' SQL Injection
CVE-2008-2132webappsasp
SQL injection vulnerability in step1.asp in Systementor PostcardMentor allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
Referência
CVE-2014-6242
Multiple SQL injection vulnerabilities in the All In One WP Security & Firewall plugin before 3.8.3 for WordPress allow
23RIESGO
abrir
anteriorpágina 301 / 727siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.