Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.058exploits catalogados
35.300CVEs con explotación pública
24.695probados en laboratorio
22.166 exploits
Referência
CVE-2014-1206
SQL injection vulnerability in the password reset page in Open Web Analytics (OWA) before 1.5.5 allows remote attackers
23RIESGO
abrir
Referência
CVE-2010-1604
Multiple SQL injection vulnerabilities in admin_login.php in NCT Jobs Portal Script allow remote attackers to execute ar
23RIESGO
abrir
Referência
CVE-2009-3423
login.php in Zenas PaoLink 1.0, when register_globals is enabled, allows remote attackers to bypass authentication and g
23RIESGO
abrir
Referência
CVE-2019-12745
out/out.UsrMgr.php in SeedDMS before 5.1.11 allows Stored Cross-Site Scripting (XSS) via the name field.
23RIESGO
abrir
Referência
CVE-2013-3524
SQL injection vulnerability in popupnewsitem/ in the Pop Up News module 2.0 and possibly earlier for phpVMS allows remot
23RIESGO
abrir
ReferênciaVexDay Proof
WebBuilder 2.0 - 'StageLoader.php' Remote File Inclusion
CVE-2007-0703webappsphp
PHP remote file inclusion vulnerability in library/StageLoader.php in WebBuilder 2.0 and earlier allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
Somery 0.4.6 - 'skin_dir' Remote File Inclusion
CVE-2007-0704webappsphp
PHP remote file inclusion vulnerability in install.php in Somery 0.4.6 allows remote attackers to execute arbitrary PHP
23RIESGO
abrir
Referência
CVE-2018-10366
An issue was discovered in the Users (aka Front-end user management) plugin 1.4.5 for October CMS. XSS exists in the nam
23RIESGO
abrir
Referência
CVE-2008-5943
Multiple directory traversal vulnerabilities in NavBoard 16 (2.6.0) allow remote attackers to include and execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
Webavis 0.1.1 - 'class.php?root' Remote File Inclusion
CVE-2007-2943webappsphp
PHP remote file inclusion vulnerability in class/class.php in Webavis 0.1.1 allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
SQLiteWebAdmin 0.1 - 'tpl.inc.php' Remote File Inclusion
CVE-2006-4102webappsphp
PHP remote file inclusion vulnerability in tpl.inc.php in Falko Timme and Till Brehm SQLiteWebAdmin 0.1 and earlier allo
23RIESGO
abrir
Referência
CVE-2016-4230
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows
35RIESGO
abrir
Referência
CVE-2016-4264
The Office Open XML (OOXML) feature in Adobe ColdFusion 10 before Update 21 and 11 before Update 10 allows remote attack
35RIESGO
abrir
ReferênciaVexDay Proof
LimeSurvey 1.52 - 'language.php' Remote File Inclusion
CVE-2007-5573webappsphp
PHP remote file inclusion vulnerability in classes/core/language.php in LimeSurvey 1.5.2 and earlier allows remote attac
23RIESGO
abrir
ReferênciaVexDay Proof
shibby shop 2.2 - Multiple Vulnerabilities
CVE-2008-2872webappsphp
SQL injection vulnerability in default.asp in sHibby sHop 2.2 and earlier allows remote attackers to execute arbitrary S
23RIESGO
abrir
ReferênciaVexDay Proof
PhpCommander 3.0 - 'upload' Remote Code Execution
CVE-2006-4636webappsphp
Directory traversal vulnerability in SZEWO PhpCommander 3.0 and earlier allows remote attackers to include and execute a
23RIESGO
abrir
ReferênciaVexDay Proof
shibby shop 2.2 - Multiple Vulnerabilities
CVE-2008-2873webappsphp
sHibby sHop 2.2 and earlier stores sensitive information under the web root with insufficient access control, which allo
23RIESGO
abrir
ReferênciaVexDay Proof
Polaring 0.04.03 - 'general.php' Remote File Inclusion
CVE-2006-5078webappsphp
PHP remote file inclusion vulnerability in view/general.php in Kristian Niemi Polaring 00.04.03 and earlier allows remot
23RIESGO
abrir
ReferênciaVexDay Proof
paBugs 2.0 Beta 3 - 'class.mysql.php' Remote File Inclusion
CVE-2006-5079webappsphp
PHP remote file inclusion vulnerability in class.mysql.php in Matt Humphrey paBugs 2.0 Beta 3 and earlier allows remote
23RIESGO
abrir
ReferênciaVexDay Proof
Ninja Blog 4.8 - Remote Information Disclosure
CVE-2009-0325webappsphp
Directory traversal vulnerability in entries/index.php in Ninja Blog 4.8, when magic_quotes_gpc is disabled, allows remo
23RIESGO
abrir
ReferênciaVexDay Proof
phpYabs 0.1.2 - 'Azione' Remote File Inclusion
CVE-2009-0639webappsphp
PHP remote file inclusion vulnerability in moduli/libri/index.php in phpyabs 0.1.2 allows remote attackers to execute ar
23RIESGO
abrir
Referência
CVE-2010-2622
SQL injection vulnerability in the Joomanager component, possibly 1.1.1, for Joomla! allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
TorrentFlux 2.2 - 'maketorrent.php' Remote Command Execution
CVE-2006-6599webappsphp
maketorrent.php in TorrentFlux 2.2 allows remote authenticated users to execute arbitrary commands via shell metacharact
23RIESGO
abrir
ReferênciaVexDay Proof
project alumni 1.0.9 - 'index.php?act' Local File Inclusion
CVE-2007-6184webappsphp
Directory traversal vulnerability in index.php in Project Alumni 1.0.9 allows remote attackers to include and execute ar
23RIESGO
abrir
ReferênciaVexDay Proof
Power Editor 2.0 - Remote File Disclosure / Edit
CVE-2008-2116webappsphp
Multiple directory traversal vulnerabilities in editor.php in ScriptsEZ.net Power Editor 2.0 allow remote attackers to r
23RIESGO
abrir
ReferênciaVexDay Proof
AJ HYIP ACME - 'news.php' SQL Injection
CVE-2008-2893webappsphp
SQL injection vulnerability in news.php in AJ Square aj-hyip (aka AJ HYIP Acme) allows remote attackers to execute arbit
23RIESGO
abrir
Referência
CVE-2026-58460
react-native-receive-sharing-intent Path Traversal via _display_name
41RIESGO
abrir
ReferênciaVexDay Proof
PPA Gallery 1.0 - 'functions.inc.php' Remote File Inclusion
CVE-2006-5165webappsphp
PHP remote file inclusion vulnerability in inc/functions.inc.php in Skrypty PPA Gallery 1.0 and earlier allows remote at
23RIESGO
abrir
Referência
CVE-2016-4655
CVE-2016-4655MEDIUMbajo ataque
The kernel in Apple iOS before 9.3.5 allows attackers to obtain sensitive information from memory via a crafted app.
90RIESGO
abrir
ReferênciaVexDay Proof
Docebo 3.5.0.3 - 'lib.regset.php' Command Execution
CVE-2008-7154webappsphp
Docebo 3.5.0.3 and earlier allows remote attackers to obtain sensitive information via a direct request to (1) class/cla
23RIESGO
abrir
anteriorpágina 382 / 739siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.