Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.058exploits catalogados
35.300CVEs con explotación pública
24.695probados en laboratorio
22.166 exploits
Referência
CVE-2010-1657
Directory traversal vulnerability in the SmartSite (com_smartsite) component 1.0.0 for Joomla! allows remote attackers t
43RIESGO
abrir
Referência
CVE-2016-4437
CVE-2016-4437CRITICALbajo ataque
Apache Shiro before 1.2.5, when a cipher key has not been configured for the "remember me" feature, allows remote attack
100RIESGO
abrir
Referência
CVE-2010-1658
Directory traversal vulnerability in the Code-Garage NoticeBoard (com_noticeboard) component 1.3 for Joomla! allows remo
43RIESGO
abrir
Referência
CVE-2010-1658
Directory traversal vulnerability in the Code-Garage NoticeBoard (com_noticeboard) component 1.3 for Joomla! allows remo
43RIESGO
abrir
Referência
CVE-2010-1661
Multiple SQL injection vulnerabilities in PHP-Quick-Arcade (PHPQA) 3.0.21 allow remote attackers to execute arbitrary SQ
23RIESGO
abrir
Referência
CVE-2010-1681
Buffer overflow in VISIODWG.DLL before 10.0.6880.4 in Microsoft Office Visio allows user-assisted remote attackers to ex
50RIESGO
abrir
ReferênciaVexDay Proof
phpMyAgenda 3.1 - '/templates/header.php3' Local File Inclusion
CVE-2006-5263webappsphp
Directory traversal vulnerability in templates/header.php3 in phpMyAgenda 3.1 and earlier allows remote attackers to inc
23RIESGO
abrir
Referência
CVE-2019-0552
An elevation of privilege exists in Windows COM Desktop Broker, aka "Windows COM Elevation of Privilege Vulnerability."
23RIESGO
abrir
Referência
CVE-2014-9146
Multiple cross-site scripting (XSS) vulnerabilities in Fiyo CMS 2.0.1.8 allow remote attackers to inject arbitrary web s
23RIESGO
abrir
Referência
CVE-2012-5242
Directory traversal vulnerability in functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to
23RIESGO
abrir
Referência
CVE-2009-4467
misc.php in DeluxeBB 1.3 allows remote attackers to register accounts without a valid email address via a valemail actio
23RIESGO
abrir
Referência
CVE-2009-2327
Cross-site scripting (XSS) vulnerability in add_voting.php in KerviNet Forum 1.1 and earlier allows remote authenticated
23RIESGO
abrir
Referência
CVE-2011-1665
PHPBoost 3.0 stores sensitive information under the web root with insufficient access control, which allows remote attac
23RIESGO
abrir
Referência
CVE-2010-0978
KMSoft Guestbook (aka GBook) 1.0 stores sensitive information under the web root with insufficient access control, which
23RIESGO
abrir
Referência
CVE-2010-0978
KMSoft Guestbook (aka GBook) 1.0 stores sensitive information under the web root with insufficient access control, which
23RIESGO
abrir
ReferênciaVexDay Proof
CaLogic Calendars 1.2.2 - 'CLPath' Remote File Inclusion
CVE-2006-2570webappsphp
PHP remote file inclusion vulnerability in CaLogic Calendars 1.2.2 allows remote attackers to execute arbitrary PHP code
23RIESGO
abrir
Referência
CVE-2019-11504
Zotonic before version 0.47 has mod_admin XSS.
23RIESGO
abrir
Referência
CVE-2019-11504
Zotonic before version 0.47 has mod_admin XSS.
23RIESGO
abrir
ReferênciaVexDay Proof
PageSquid CMS 0.3 Beta - 'index.php' SQL Injection
CVE-2008-2897webappsphp
SQL injection vulnerability in index.php in PageSquid CMS 0.3 Beta allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
Referência
CVE-2016-4669
An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS b
38RIESGO
abrir
Referência
CVE-2016-4669
An issue was discovered in certain Apple products. iOS before 10.1 is affected. macOS before 10.12.1 is affected. tvOS b
38RIESGO
abrir
ReferênciaVexDay Proof
Chicomas 2.0.4 - Database Backup / File Disclosure / Cross-Site Scripting
CVE-2008-5853webappsphp
Chilek Content Management System (aka ChiCoMaS) 2.0.4 and earlier stores sensitive information under the web root with i
23RIESGO
abrir
ReferênciaVexDay Proof
Absolute FAQ Manager 6.0 - Insecure Cookie Handling
CVE-2008-6854webappsphp
Xigla Software Absolute FAQ Manager.NET 6.0 allows remote attackers to bypass authentication and gain administrative acc
23RIESGO
abrir
ReferênciaVexDay Proof
The Gemini Portal 4.7 - Insecure Cookie Handling
CVE-2008-7024webappsphp
admin.php in Arz Development The Gemini Portal 4.7 and earlier allows remote attackers to bypass authentication and gain
23RIESGO
abrir
ReferênciaVexDay Proof
fungamez rc1 - Authentication Bypass / Local File Inclusion
CVE-2009-1489webappsphp
includes/user.php in Fungamez RC1 allows remote attackers to bypass authentication and gain administrative access by set
23RIESGO
abrir
ReferênciaVexDay Proof
Teraway LinkTracker 1.0 - Insecure Cookie Handling
CVE-2009-1617webappsphp
Teraway LinkTracker 1.0 allows remote attackers to bypass authentication and gain administrative access via a userid=1&l
23RIESGO
abrir
Referência
CVE-2018-11671
An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that can add an admin account via index.php
23RIESGO
abrir
Referência
CVE-2010-2689
SQL injection vulnerability in cont_form.php in Internet DM WebDM CMS allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
Referência
CVE-2018-11670
An issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that allows attackers to execute arbitrary
23RIESGO
abrir
Referência
CVE-2018-10312
index.php?m=member&v=pw_reset in WUZHI CMS 4.1.0 allows CSRF to change the password of a common member.
23RIESGO
abrir
anteriorpágina 383 / 739siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.