Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.020exploits catalogados
35.276CVEs con explotación pública
24.695probados en laboratorio
21.899 exploits
Referência
CVE-2009-4854
addons/import.php in TalkBack 2.3.14 allows remote attackers to execute arbitrary commands via the result parameter.
23RIESGO
abrir
ReferênciaVexDay Proof
TurnkeyForms Web Hosting Directory - Multiple Vulnerabilities
CVE-2008-6939webappsphp
TurnkeyForms Web Hosting Directory allows remote attackers to bypass authentication and (1) gain administrative privileg
23RIESGO
abrir
ReferênciaVexDay Proof
DBGuestbook 1.1 - 'dbs_base_path' Remote File Inclusion
CVE-2007-1165webappsphp
Multiple PHP remote file inclusion vulnerabilities in DBGuestbook 1.1 allow remote attackers to execute arbitrary PHP co
23RIESGO
abrir
Referência
CVE-2011-4807
Directory traversal vulnerability in main.php in phpAlbum 0.4.1.16 and earlier allows remote attackers to read arbitrary
23RIESGO
abrir
Referência
CVE-2006-5191
PHP remote file inclusion vulnerability in includes/functions_static_topics.php in the Nivisec Static Topics module for
23RIESGO
abrir
Referência
CVE-2019-8390
qdPM 9.1 suffers from Cross-site Scripting (XSS) in the search[keywords] parameter.
38RIESGO
abrir
Referência
CVE-2019-13236
In system/workplace/ in Alkacon OpenCms 10.5.4 and 10.5.5, there are multiple Reflected and Stored XSS issues in the man
23RIESGO
abrir
Referência
CVE-2019-8390
qdPM 9.1 suffers from Cross-site Scripting (XSS) in the search[keywords] parameter.
38RIESGO
abrir
Referência
CVE-2010-5032
SQL injection vulnerability in the BF Quiz (com_bfquiztrial) component before 1.3.1 for Joomla! allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
phpTrafficA 1.4.2 - 'pageid' SQL Injection
CVE-2007-3425webappsphp
Directory traversal vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to include arbit
23RIESGO
abrir
ReferênciaVexDay Proof
k_fileManager 1.2 - 'dwl_include_path' Remote File Inclusion
CVE-2006-3987webappsphp
Multiple PHP remote file inclusion vulnerabilities in index.php in Knusperleicht FileManager 1.2 and earlier allow remot
23RIESGO
abrir
Referência
CVE-2020-25820
BigBlueButton before 2.2.7 allows remote authenticated users to read local files and conduct SSRF attacks via an uploade
28RIESGO
abrir
Referência
CVE-2018-14592
The CWJoomla CW Article Attachments PRO extension before 2.0.7 and CW Article Attachments FREE extension before 1.0.6 fo
23RIESGO
abrir
ReferênciaVexDay Proof
EasyNews 40tr - SQL Injection / Cross-Site Scripting / Local File Inclusion
CVE-2008-1651webappsphp
Directory traversal vulnerability in admin/login.php in EasyNews 4.0 allows remote attackers to include and execute arbi
23RIESGO
abrir
ReferênciaVexDay Proof
gapicms 9.0.2 - 'dirDepth' Remote File Inclusion
CVE-2008-3183webappsphp
PHP remote file inclusion vulnerability in ktmlpro/includes/ktedit/toolbar.php in gapicms 9.0.2 allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
HIOX Random Ad 1.3 - Remote File Inclusion
CVE-2008-3401webappsphp
PHP remote file inclusion vulnerability in hioxRandomAd.php in HIOX Random Ad (HRA) 1.3 allows remote attackers to execu
23RIESGO
abrir
ReferênciaVexDay Proof
Hotel Reservation System - 'city.asp' Blind SQL Injection
CVE-2008-4204webappsasp
SQL injection vulnerability in city.asp in SoftAcid Hotel Reservation System (HRS) allows remote attackers to execute ar
23RIESGO
abrir
ReferênciaVexDay Proof
Attachmax Dolphin 2.1.0 - Multiple Vulnerabilities
CVE-2008-4207webappsphp
Attachmax Dolphin 2.1.0 and earlier does not properly protect info.php in the main folder, which allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Windows Server - Code Execution (PoC) (MS08-067)
CVE-2008-4250CRITICALbajo ataquedoswindows
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 20
100RIESGO
abrir
Referência
CVE-2012-2905
Artiphp CMS 5.5.0 Neo (r422) stores database backups with predictable names under the web root with insufficient access
23RIESGO
abrir
Referência
CVE-2017-8912
CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated administrators to execute arbitrary PHP code via the code para
41RIESGO
abrir
Referência
CVE-2018-6364
SQL Injection exists in Multilanguage Real Estate MLM Script through 3.0 via the /product-list.php srch parameter.
23RIESGO
abrir
Referência
CVE-2018-6364
SQL Injection exists in Multilanguage Real Estate MLM Script through 3.0 via the /product-list.php srch parameter.
23RIESGO
abrir
ReferênciaVexDay Proof
WFTPD Explorer Pro 1.0 - Remote Heap Overflow (PoC)
CVE-2007-6473doswindows
Heap-based buffer overflow in Texas Imperial Software WFTPD Pro Explorer 1.0 allows remote FTP servers to execute arbitr
23RIESGO
abrir
Referência
CVE-2009-4222
phpBazar 2.1.1fix and earlier does not require administrative authentication for admin/admin.php, which allows remote at
23RIESGO
abrir
Referência
CVE-2010-4901
Multiple cross-site scripting (XSS) vulnerabilities in char_map.php in MySource Matrix 3.28.3 allow remote attackers to
23RIESGO
abrir
Referência
CVE-2015-6101
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
23RIESGO
abrir
Referência
CVE-2019-20354
The web application component of piSignage before 2.6.4 allows a remote attacker (authenticated as a low-privilege user)
23RIESGO
abrir
ReferênciaVexDay Proof
Stash 1.0.3 - Multiple SQL Injections
CVE-2008-4080webappsphp
SQL injection vulnerability in Stash 1.0.3, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
ExBB Italiano 0.2 - exbb[home_path] Remote File Inclusion
CVE-2006-4488webappsphp
PHP remote file inclusion vulnerability in modules/userstop/userstop.php in ExBB Italia 0.2 and earlier, when register_g
23RIESGO
abrir
anteriorpágina 359 / 730siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.