Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.020exploits catalogados
35.276CVEs con explotación pública
24.695probados en laboratorio
21.899 exploits
Referência
CVE-2021-31166
CVE-2021-31166CRITICALbajo ataque
HTTP Protocol Stack Remote Code Execution Vulnerability
100RIESGO
abrir
Referência
CVE-2023-46604
CVE-2023-46604CRITICALbajo ataqueransomware
Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
100RIESGO
abrir
Referência
CVE-2020-37225
Powie's WHOIS Domain Check 0.9.31 Persistent Cross-Site Scripting
33RIESGO
abrir
Referência
CVE-2020-37224
Joomla J2 JOBS 1.3.0 Authenticated SQL Injection via sortby
41RIESGO
abrir
Referência
CVE-2020-37223
IObit Uninstaller 9.5.0.15 Unquoted Service Path Privilege Escalation
41RIESGO
abrir
Referência
CVE-2020-37222
Kuicms Php EE 2.0 Persistent Cross-Site Scripting via bbs reply
33RIESGO
abrir
Referência
CVE-2020-37221
Atomic Alarm Clock 6.3 Stack Overflow via SEH Unicode
41RIESGO
abrir
Referência
CVE-2020-37220
Huawei HG630 V2 Router Authentication Bypass via Serial Number
41RIESGO
abrir
Referência
CVE-2020-37219
Joomla com_fabrik 3.9.11 Directory Traversal via image.php
41RIESGO
abrir
Referência
CVE-2020-37218
Joomla com_hdwplayer 4.2 SQL Injection via search.php
41RIESGO
abrir
Referência
CVE-2020-37217
Easy2Pilot 7 Cross-Site Request Forgery via admin.php
33RIESGO
abrir
Referência
CVE-2020-37174
WOOF / Products Filter Professional for WooCommerce 1.2.3 Persistent XSS
33RIESGO
abrir
ReferênciaVexDay Proof
aForum 1.32 - 'CommonAbsDir' Remote File Inclusion
CVE-2007-2596webappsphp
PHP remote file inclusion vulnerability in common/func.php in aForum 1.32 and earlier allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
telltarget 1.3.3 - 'tt_docroot' Remote File Inclusion
CVE-2007-2597webappsphp
Multiple PHP remote file inclusion vulnerabilities in telltarget CMS 1.3.3 allow remote attackers to execute arbitrary P
28RIESGO
abrir
ReferênciaVexDay Proof
TutorialCMS 1.00 - 'search.php?search' SQL Injection
CVE-2007-2599webappsphp
Multiple SQL injection vulnerabilities in TutorialCMS (aka Photoshop Tutorials) 1.00 and earlier allow remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
TutorialCMS 1.00 - 'search.php?search' SQL Injection
CVE-2007-2600webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in TutorialCMS (aka Photoshop Tutorials) 1.00 and earlier allow remo
23RIESGO
abrir
ReferênciaVexDay Proof
Miplex2 - 'SmartyFU.class.php' Remote File Inclusion
CVE-2007-2608webappsphp
PHP remote file inclusion vulnerability in lib/smarty/SmartyFU.class.php in Miplex2 Alpha 1 allows remote attackers to e
23RIESGO
abrir
ReferênciaVexDay Proof
PHPLojaFacil 0.1.5 - 'path_local' Remote File Inclusion
CVE-2007-2615webappsphp
Multiple PHP remote file inclusion vulnerabilities in Crie seu PHPLojaFacil 0.1.5 allow remote attackers to execute arbi
23RIESGO
abrir
Referência
CVE-2009-5093
Directory traversal vulnerability in gastbuch.php in Gästebuch (Gastebuch) 1.6 allows remote attackers to read arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
Original 0.11 - 'config.inc.php?x[1]' Remote File Inclusion
CVE-2007-2620webappsphp
PHP remote file inclusion vulnerability in inc/config.inc.php in Jakub Steiner (aka jimmac) original 0.11 allows remote
23RIESGO
abrir
ReferênciaVexDay Proof
NagiosQL 2005 2.00 - 'prepend_adm.php' Remote File Inclusion
CVE-2007-2709webappsphp
PHP remote file inclusion vulnerability in functions/prepend_adm.php in NagiosQL 2005 2.00 allows remote attackers to ex
23RIESGO
abrir
ReferênciaVexDay Proof
Snaps! Gallery 1.4.4 - Remote User Pass Change
CVE-2007-2715webappsphp
Admin/users.php in Snaps! Gallery 1.4.4 allows remote attackers to change arbitrary usernames and passwords via the (1)
28RIESGO
abrir
ReferênciaVexDay Proof
XOOPS Module resmanager 1.21 - Blind SQL Injection
CVE-2007-2735webappsphp
SQL injection vulnerability in edit_day.php in the ResManager 1.2.1 and earlier module for Xoops allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
Achievo 1.1.0 - 'config_atkroot' Remote File Inclusion
CVE-2007-2736webappsphp
PHP remote file inclusion vulnerability in index.php in Achievo 1.1.0 allows remote attackers to execute arbitrary PHP c
23RIESGO
abrir
ReferênciaVexDay Proof
FAQEngine 4.16.03 - 'question.php?questionref' SQL Injection
CVE-2007-2749webappsphp
SQL injection vulnerability in question.php in FAQEngine 4.16.03 and earlier allows remote attackers to execute arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
PHPGlossar 0.8 - 'format_menue' Remote File Inclusion
CVE-2007-2751webappsphp
Multiple PHP remote file inclusion vulnerabilities in PHPGlossar 0.8 allow remote attackers to execute arbitrary PHP cod
23RIESGO
abrir
ReferênciaVexDay Proof
CA BrightStor Backup 11.5.2.0 - 'caloggderd.exe' Denial of Service
CVE-2007-2772doswindows
(1) caloggerd.exe (camt70.dll) and (2) mediasvr.exe (catirpc.dll and rwxdr.dll) in CA BrightStor Backup 11.5.2.0 SP2 all
28RIESGO
abrir
ReferênciaVexDay Proof
CA BrightStor Backup 11.5.2.0 - 'Mediasvr.exe' Denial of Service
CVE-2007-2772doswindows
(1) caloggerd.exe (camt70.dll) and (2) mediasvr.exe (catirpc.dll and rwxdr.dll) in CA BrightStor Backup 11.5.2.0 SP2 all
28RIESGO
abrir
ReferênciaVexDay Proof
Alstrasoft Live Support 1.21 - Admin Credential Retrieve
CVE-2007-2775webappsphp
AlstraSoft Live Support 1.21 sends a redirect to the web browser but does not exit when administrative credentials are m
23RIESGO
abrir
ReferênciaVexDay Proof
Alstrasoft Template Seller Pro 3.25 - Remote Code Execution
CVE-2007-2777webappsphp
Unrestricted file upload vulnerability in admin/addsptemplate.php in AlstraSoft Template Seller Pro 3.25 and earlier all
23RIESGO
abrir
anteriorpágina 351 / 730siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.