Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.559exploits catalogados
34.978CVEs con explotación pública
24.695probados en laboratorio
21.899 exploits
Referência
CVE-2013-5312
Multiple cross-site scripting (XSS) vulnerabilities in Vastal I-Tech phpVID 1.2.3 allow remote attackers to inject arbit
23RIESGO
abrir
Referência
CVE-2013-5312
Multiple cross-site scripting (XSS) vulnerabilities in Vastal I-Tech phpVID 1.2.3 allow remote attackers to inject arbit
23RIESGO
abrir
Referência
CVE-2013-4898
Unrestricted file upload vulnerability in the user profile page feature in the Timeline Plugin 4.2.5p9 for SocialEngine
23RIESGO
abrir
Referência
CVE-2018-17382
SQL Injection exists in the Jobs Factory 2.0.4 component for Joomla! via the filter_letter parameter.
23RIESGO
abrir
Referência
CVE-2018-17382
SQL Injection exists in the Jobs Factory 2.0.4 component for Joomla! via the filter_letter parameter.
23RIESGO
abrir
Referência
CVE-2018-18763
SaltOS 3.1 r8126 allows action=ajax&query=numbers&page=usuarios&action2=[SQL] SQL Injection.
23RIESGO
abrir
Referência
CVE-2026-15206
SMS Alert Order Notifications – WooCommerce < 3.9.8 - Unauthenticated Account Takeover via Unbound OTP Verification in Signup-with-Mobile
41RIESGO
abrir
Referência
CVE-2026-15151
Five Star Restaurant Reservations < 2.7.23 - Booking Manager+ Missing Authorization via rtb_reset_notifications
41RIESGO
abrir
Referência
CVE-2023-39026
Directory Traversal vulnerability in FileMage Gateway Windows Deployments v.1.10.8 and before allows a remote attacker t
43RIESGO
abrir
Referência
CVE-2020-6756
languageOptions.php in Rasilient PixelStor 5000 K:4.0.1580-20150629 (KDI Version) allows unauthenticated attackers to re
53RIESGO
abrir
Referência
CVE-2015-6568
Wolf CMS before 0.8.3.1 allows unrestricted file rename and PHP Code Execution because admin/plugin/file_manager/browse/
28RIESGO
abrir
Referência
CVE-2015-6568
Wolf CMS before 0.8.3.1 allows unrestricted file rename and PHP Code Execution because admin/plugin/file_manager/browse/
28RIESGO
abrir
ReferênciaVexDay Proof
D-Bus Daemon < 1.2.4 - 'libdbus' Denial of Service
CVE-2008-3834dosmultiple
The dbus_signature_validate function in the D-bus library (libdbus) before 1.2.4 allows remote attackers to cause a deni
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component ionFiles 4.4.2 - File Disclosure
CVE-2008-6080webappsphp
Directory traversal vulnerability in download.php in the ionFiles (com_ionfiles) 4.4.2 component for Joomla! allows remo
43RIESGO
abrir
Referência
CVE-2014-5201
SQL injection vulnerability in the Gallery Objects plugin 0.4 for WordPress allows remote attackers to execute arbitrary
23RIESGO
abrir
Referência
CVE-2014-9224
Cross-site scripting (XSS) vulnerability in the ajaxswing webui in the Management Console server in the management serve
23RIESGO
abrir
Referência
CVE-2010-1352
Directory traversal vulnerability in the JOOFORGE Jutebox (com_jukebox) component 1.0 and 1.7 for Joomla! allows remote
43RIESGO
abrir
Referência
CVE-2010-0288
A typo in the administrator permission check in the ACL Manager plugin (plugins/acl/ajax.php) in DokuWiki before 2009-12
28RIESGO
abrir
Referência
CVE-2010-1353
Directory traversal vulnerability in the LoginBox Pro (com_loginbox) component for Joomla! allows remote attackers to re
43RIESGO
abrir
Referência
CVE-2010-1354
Directory traversal vulnerability in the VJDEO (com_vjdeo) component 1.0 and 1.0.1 for Joomla! allows remote attackers t
43RIESGO
abrir
Referência
CVE-2020-23839
A Reflected Cross-Site Scripting (XSS) vulnerability in GetSimple CMS v3.3.16, in the admin/index.php login portal webpa
28RIESGO
abrir
Referência
CVE-2020-35754
OpenSolution Quick.CMS < 6.7 and Quick.Cart < 6.7 allow an authenticated user to perform code injection (and consequentl
28RIESGO
abrir
Referência
CVE-2012-4768
Cross-site scripting (XSS) vulnerability in the Download Monitor plugin before 3.3.5.9 for WordPress allows remote attac
43RIESGO
abrir
Referência
CVE-2016-6754
A remote code execution vulnerability in Webview in Android 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x before 2016-
23RIESGO
abrir
Referência
CVE-2012-3996
TikiWiki CMS/Groupware 8.3 and earlier allows remote attackers to obtain the installation path via a direct request to (
23RIESGO
abrir
Referência
CVE-2012-3996
TikiWiki CMS/Groupware 8.3 and earlier allows remote attackers to obtain the installation path via a direct request to (
23RIESGO
abrir
ReferênciaVexDay Proof
PHP 5.2.4 ionCube - 'ioncube_read_file' Safe Mode / disable_functions Bypass
CVE-2007-5447localwindows
ioncube_loader_win_5.2.dll in the ionCube Loader 6.5 extension for PHP 5.2.4 does not follow safe_mode and disable_funct
23RIESGO
abrir
ReferênciaVexDay Proof
BulletProof FTP Client - '.bps' Local Stack Overflow (PoC)
CVE-2008-5754doswindows
Stack-based buffer overflow in BulletProof FTP Client allows user-assisted attackers to execute arbitrary code via a .bp
23RIESGO
abrir
Referência
CVE-2019-19363
An issue was discovered in Ricoh (including Savin and Lanier) Windows printer drivers prior to 2020 that allows attacker
38RIESGO
abrir
Referência
CVE-2021-31950
Microsoft SharePoint Server Spoofing Vulnerability
41RIESGO
abrir
anteriorpágina 328 / 730siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.