Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.058exploits catalogados
35.300CVEs con explotación pública
24.695probados en laboratorio
22.166 exploits
ReferênciaVexDay Proof
Tuned Studios Templates - Local File Inclusion
CVE-2008-0231webappsphp
Multiple directory traversal vulnerabilities in index.php in Tuned Studios (1) Subwoofer, (2) Freeze Theme, (3) Orange C
23RIESGO
abrir
Referência
CVE-2018-15884
RICOH MP C4504ex devices allow HTML Injection via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter.
23RIESGO
abrir
Referência
CVE-2018-15884
RICOH MP C4504ex devices allow HTML Injection via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter.
23RIESGO
abrir
Referência
CVE-2009-4118
The StartServiceCtrlDispatcher function in the cvpnd service (cvpnd.exe) in Cisco VPN client for Windows before 5.0.06.0
23RIESGO
abrir
Referência
CVE-2018-16252
FsPro Labs Event Log Explorer 4.6.1.2115 has ".elx" FileType XML External Entity Injection.
23RIESGO
abrir
Referência
CVE-2019-13657
CA Performance Management 3.5.x, 3.6.x before 3.6.9, and 3.7.x before 3.7.4 have a default credential vulnerability that
48RIESGO
abrir
Referência
CVE-2019-13657
CA Performance Management 3.5.x, 3.6.x before 3.6.9, and 3.7.x before 3.7.4 have a default credential vulnerability that
48RIESGO
abrir
Referência
CVE-2013-7193
Multiple SQL injection vulnerabilities in C2C Forward Auction Creator 2.0 allow remote attackers to execute arbitrary SQ
23RIESGO
abrir
Referência
CVE-2026-40521
FrontAccounting < 2.4.20 Path Traversal RCE via attachment upload
41RIESGO
abrir
ReferênciaVexDay Proof
gnopaste 0.5.3 - 'common.php' Remote File Inclusion
CVE-2006-2834webappsphp
PHP remote file inclusion vulnerability in includes/common.php in gnopaste 0.5.3 and earlier allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
BigACE 2.4 - Multiple Remote File Inclusions
CVE-2008-2520webappsphp
Multiple PHP remote file inclusion vulnerabilities in BigACE 2.4, when register_globals is enabled, allow remote attacke
23RIESGO
abrir
ReferênciaVexDay Proof
Family Connections CMS 1.4 - Multiple SQL Injections
CVE-2008-2901webappsphp
Multiple SQL injection vulnerabilities in Haudenschilt Family Connections CMS (FCMS) 1.4 allow remote authenticated user
23RIESGO
abrir
ReferênciaVexDay Proof
Mini Blog 1.0.1 - 'index.php' Multiple Local File Inclusions
CVE-2008-5594webappsphp
Multiple directory traversal vulnerabilities in index.php in Mini Blog 1.0.1 allow remote attackers to include and execu
23RIESGO
abrir
ReferênciaVexDay Proof
AJ Auction - Authentication Bypass
CVE-2008-6966webappsphp
AJ Square AJ Auction Pro Platinum Skin #1 sends a redirect but does not exit when it is called directly, which allows re
23RIESGO
abrir
ReferênciaVexDay Proof
PHP-Nuke Module eBoard 1.0.7 - GLOBALS[name] Local File Inclusion
CVE-2007-1934webappsphp
Directory traversal vulnerability in member.php in the eBoard 1.0.7 module for PHP-Nuke allows remote attackers to inclu
23RIESGO
abrir
Referência
CVE-2012-5228
Cross-site scripting (XSS) vulnerability in admin/index.php in phplist 2.10.9, 2.10.17, and possibly other versions befo
23RIESGO
abrir
ReferênciaVexDay Proof
IndexScript 2.8 - 'cat_id' SQL Injection
CVE-2007-4069webappsphp
SQL injection vulnerability in show_cat.php in IndexScript 2.8 and earlier allows remote attackers to execute arbitrary
23RIESGO
abrir
Referência
CVE-2013-10040
ClipBucket <= 2.6 ofc_upload_image.php Arbitrary File Upload RCE
63RIESGO
abrir
Referência
CVE-2013-10040
ClipBucket <= 2.6 ofc_upload_image.php Arbitrary File Upload RCE
63RIESGO
abrir
Referência
CVE-2010-5289
Buffer overflow in the Authenticate method in the INCREDISPOOLERLib.Pop ActiveX control in ImSpoolU.dll in IncrediMail 2
23RIESGO
abrir
ReferênciaVexDay Proof
iScripts Socialware - 'id' SQL Injection
CVE-2008-1772webappsphp
iScripts SocialWare stores passwords in cleartext in a database, which allows context-dependent attackers to obtain sens
23RIESGO
abrir
Referência
CVE-2017-15730
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.ratings.php.
23RIESGO
abrir
Referência
CVE-2018-7198
October CMS through 1.0.431 allows XSS by entering HTML on the Add Posts page.
23RIESGO
abrir
Referência
CVE-2017-17615
Facebook Clone Script 1.0 has SQL Injection via the friend-profile.php id parameter.
23RIESGO
abrir
Referência
CVE-2017-17615
Facebook Clone Script 1.0 has SQL Injection via the friend-profile.php id parameter.
23RIESGO
abrir
Referência
CVE-2014-9243
Multiple cross-site scripting (XSS) vulnerabilities in WebsiteBaker 2.8.3 allow remote attackers to inject arbitrary web
23RIESGO
abrir
Referência
CVE-2013-6058
SQL injection vulnerability in appRain CMF 3.0.2 and earlier allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
Referência
CVE-2013-6058
SQL injection vulnerability in appRain CMF 3.0.2 and earlier allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
Referência
CVE-2010-1714
Directory traversal vulnerability in the Arcade Games (com_arcadegames) component 1.0 for Joomla! allows remote attacker
43RIESGO
abrir
Referência
CVE-2018-9092
There is a CSRF vulnerability in mc-admin/conf.php in MiniCMS 1.10 that can change the administrator account password.
23RIESGO
abrir
anteriorpágina 381 / 739siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.