Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.058exploits catalogados
35.300CVEs con explotación pública
24.695probados en laboratorio
22.166 exploits
Referência
CVE-2015-2223
Multiple cross-site scripting (XSS) vulnerabilities in the web-based console management interface in Palo Alto Networks
23RIESGO
abrir
Referência
CVE-2018-16061
Mitsubishi Electric Europe B.V. SmartRTU devices allow XSS via the username parameter or PATH_INFO to login.php.
23RIESGO
abrir
ReferênciaVexDay Proof
Jinzora 2.1 - 'media.php' Remote File Inclusion
CVE-2006-7130webappsphp
PHP remote file inclusion vulnerability in backend/primitives/cache/media.php in Jinzora 2.1 and earlier allows remote a
23RIESGO
abrir
Referência
CVE-2026-3301
Totolink N300RH Web Management cstecgi.cgi setWebWlanIdx os command injection
48RIESGO
abrir
Referência
CVE-2017-15284
Cross-Site Scripting exists in OctoberCMS 1.0.425 (aka Build 425), allowing a least privileged user to upload an SVG fil
23RIESGO
abrir
Referência
CVE-2017-15284
Cross-Site Scripting exists in OctoberCMS 1.0.425 (aka Build 425), allowing a least privileged user to upload an SVG fil
23RIESGO
abrir
Referência
CVE-2019-11419
vcodec2_hls_filter in libvoipCodec_v7a.so in the WeChat application through 7.0.3 for Android allows attackers to cause
23RIESGO
abrir
Referência
CVE-2009-4834
lib.php in Zeroboard 4.1 pl7 allows remote attackers to execute arbitrary PHP code via a crafted parameter name, possibl
23RIESGO
abrir
ReferênciaVexDay Proof
PHP-Nuke Module PostGuestbook 0.6.1 - 'tpl_pgb_moddir' Remote File Inclusion
CVE-2007-1372webappsphp
PHP remote file inclusion vulnerability in styles/internal/header.php in the PostGuestbook 0.6.1 module for PHP-Nuke all
23RIESGO
abrir
Referência
CVE-2019-17220
Rocket.Chat before 2.1.0 allows XSS via a URL on a ![title] line.
23RIESGO
abrir
ReferênciaVexDay Proof
mxBB Module FAQ & RULES 2.0.0 - Remote File Inclusion
CVE-2007-2493webappsphp
PHP remote file inclusion vulnerability in faq.php in the FAQ & RULES 2.0.0 and earlier module for mxBB allows remote at
23RIESGO
abrir
Referência
WeChat for Android 7.0.4 - 'vcodec2_hls_filter' Denial of Service
CVE-2019-11419dosandroid
vcodec2_hls_filter in libvoipCodec_v7a.so in the WeChat application through 7.0.3 for Android allows attackers to cause
23RIESGO
abrir
ReferênciaVexDay Proof
DeluxeBB 1.2 - Multiple Vulnerabilities
CVE-2008-2194webappsphp
SQL injection vulnerability in forums.php in DeluxeBB 1.2 and earlier allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
ReferênciaVexDay Proof
phpDatingClub 3.7 - 'website.php' Local File Inclusion
CVE-2008-3179webappsphp
Directory traversal vulnerability in website.php in Web 2 Business (W2B) phpDatingClub (aka Dating Club) 3.7 allows remo
23RIESGO
abrir
ReferênciaVexDay Proof
cPanel 11.x - Cross-Site Scripting / Local File Inclusion
CVE-2008-6926webappsphp
Directory traversal vulnerability in autoinstall4imagesgalleryupgrade.php in the Fantastico De Luxe Module for cPanel al
23RIESGO
abrir
Referência
CVE-2010-4969
SQL injection vulnerability in articlesdetails.php in BrotherScripts (BS) Business Directory allows remote attackers to
23RIESGO
abrir
Referência
CVE-2010-2034
Directory traversal vulnerability in the Percha Image Attach (com_perchaimageattach) component 1.1 for Joomla! allows re
43RIESGO
abrir
Referência
CVE-2020-13118
An issue was discovered in Mikrotik-Router-Monitoring-System through 2018-10-22. SQL Injection exists in check_community
23RIESGO
abrir
Referência
CVE-2010-2035
Directory traversal vulnerability in the Percha Gallery (com_perchagallery) component 1.6 Beta for Joomla! allows remote
43RIESGO
abrir
Referência
CVE-2014-8690
Multiple cross-site scripting (XSS) vulnerabilities in Exponent CMS before 2.1.4 patch 6, 2.2.x before 2.2.3 patch 9, an
23RIESGO
abrir
Referência
CVE-2014-8690
Multiple cross-site scripting (XSS) vulnerabilities in Exponent CMS before 2.1.4 patch 6, 2.2.x before 2.2.3 patch 9, an
23RIESGO
abrir
ReferênciaVexDay Proof
Quake 3 Engine 1.32b - 'R_RemapShader()' Remote Client Buffer Overflow
CVE-2006-2236remotelinux
Buffer overflow in the Quake 3 Engine, as used by (1) ET 2.60, (2) Return to Castle Wolfenstein 1.41, and (3) Quake III
23RIESGO
abrir
Referência
CVE-2026-15368
Profile Builder < 3.16.4 - Unauthenticated Account Takeover via Auto-Login After Registration
41RIESGO
abrir
Referência
CVE-2026-15244
HUSKY - Products Filter Professional for WooCommerce < 1.4.1 - Shop Manager+ Local File Inclusion via meta_filter search_view
41RIESGO
abrir
ReferênciaVexDay Proof
MiniBB 2.0.5 - 'Language' Local File Inclusion
CVE-2007-3272webappsphp
Directory traversal vulnerability in index.php in MiniBB 2.0.5 allows remote attackers to read arbitrary files via a ..
23RIESGO
abrir
Referência
CVE-2016-1915
Multiple cross-site scripting (XSS) vulnerabilities in BlackBerry Enterprise Server 12 (BES12) Self-Service before 12.4
23RIESGO
abrir
ReferênciaVexDay Proof
EMO Realty Manager - 'ida' SQL Injection
CVE-2008-2265webappsphp
SQL injection vulnerability in news.php in EMO Realty Manager allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
Referência
CVE-2026-10551
Breeze Cache < 2.5.6 - Unauthenticated Stored XSS via Minify Library
33RIESGO
abrir
ReferênciaVexDay Proof
phpBB User Viewed Posts Tracker 1.0 - Remote File Inclusion
CVE-2006-5223webappsphp
PHP remote file inclusion vulnerability in includes/functions_user_viewed_posts.php in the Nivisec User Viewed Posts Tra
23RIESGO
abrir
Referência
CVE-2017-15957
my_profile.php in Ingenious School Management System 2.3.0 allows a student or teacher to upload an arbitrary file.
23RIESGO
abrir
anteriorpágina 377 / 739siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.