Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.151exploits catalogados
35.370CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.451Referência 22.233GitHub PoC 14.119VulnCheck XDB 8617Nuclei 4257Metasploit 3474✓ solo verificadosrecientespopularesriesgo
22.175 exploits
Referência
CVE-2016-6434
Cisco Firepower Management Center 6.0.1 has hardcoded database credentials, which allows local users to obtain sensitive
23RIESGO
abrir ↗Referência
CVE-2018-18856
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS.
23RIESGO
abrir ↗Referência
CVE-2018-18856
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS.
23RIESGO
abrir ↗Referência✓ VexDay Proof
minimal Gallery 0.8 - Remote File Disclosure
Multiple directory traversal vulnerabilities in _mg/php/mg_thumbs.php in minimal Gallery 0.8 allow remote attackers to r
23RIESGO
abrir ↗Referência✓ VexDay Proof
DomPHP 0.82 - 'index.php' Local File Inclusion
Directory traversal vulnerability in aides/index.php in DomPHP 0.82 allows remote attackers to include and execute arbit
23RIESGO
abrir ↗Referência✓ VexDay Proof
XchangeBoard 1.70 - 'boardID' SQL Injection
SQL injection vulnerability in newThread.php in XchangeBoard 1.70 Final and earlier allows remote authenticated users to
23RIESGO
abrir ↗Referência✓ VexDay Proof
Netartmedia Cars Portal 2.0 - SQL Injection
SQL injection vulnerability in image.php in NetArt Media Car Portal 2.0 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Referência✓ VexDay Proof
ASP Download 1.03 - Arbitrary Change Administrator Account
Todd Woolums ASP Download management script 1.03 does not require authentication for setupdownload.asp, which allows rem
23RIESGO
abrir ↗Referência✓ VexDay Proof
Koschtit Image Gallery 1.82 - Multiple Local File Inclusions
Multiple directory traversal vulnerabilities in KoschtIT Image Gallery 1.82 allow remote attackers to include and execut
23RIESGO
abrir ↗Referência
CVE-2009-3199
Uebimiau Webmail 3.2.0-2.0 stores sensitive information under the web root with insufficient access control, which allow
23RIESGO
abrir ↗Referência
CVE-2018-8811
Cross-site request forgery (CSRF) vulnerability in system/workplace/admin/accounts/user_role.jsp in OpenCMS 10.5.3 allow
23RIESGO
abrir ↗Referência
CVE-2018-5370
BizLogic xnami 1.0 has XSS via the comment parameter in an addComment action to the /media/ajax URI.
23RIESGO
abrir ↗Referência
CVE-2018-5370
BizLogic xnami 1.0 has XSS via the comment parameter in an addComment action to the /media/ajax URI.
23RIESGO
abrir ↗Referência✓ VexDay Proof
Seditio CMS 121 - SQL Injection
SQL injection vulnerability in plugins/search/search.php in Neocrome Seditio CMS 121 and earlier allows remote attackers
23RIESGO
abrir ↗Referência
CVE-2009-0611
Multiple cross-site scripting (XSS) vulnerabilities in qfsearch/AdminServlet in QuickFinder Server in Novell Open Enterp
23RIESGO
abrir ↗Referência
CVE-2018-6224
A lack of cross-site request forgery (CSRF) protection vulnerability in Trend Micro Email Encryption Gateway 5.5 could a
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPmotion 2.0 - 'update_profile.php' Arbitrary File Upload
SQL injection vulnerability in play.php in PHPmotion 2.0 and earlier allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir ↗Referência
CVE-2021-43009
A Cross Site Scripting (XSS) vulnerability exists in OpServices OpMon through 9.11 via the search parameter in the reque
23RIESGO
abrir ↗Referência
CVE-2010-1999
Directory traversal vulnerability in scr/soustab.php in OpenMairie Opencatalogue 1.024, when register_globals is enabled
23RIESGO
abrir ↗Referência✓ VexDay Proof
cf shopkart 5.2.2 - SQL Injection / File Disclosure
CF Shopkart 5.2.2 stores cfshopkart52.mdb under the web root with insufficient access control, which allows remote attac
23RIESGO
abrir ↗Referência
CVE-2012-4282
SQL injection vulnerability in photo.php in Trombinoscope 3.5 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência
CVE-2011-5229
SQL injection vulnerability in quickstart/profile/index.php in the Forum module in appRain CMF 0.1.5 allows remote attac
23RIESGO
abrir ↗Referência
CVE-2012-1673
SQL injection vulnerability in loginscript.php in e-ticketing allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência
CVE-2012-1672
SQL injection vulnerability in getcity.php in Hotel Booking Portal 0.1 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Referência
CVE-2013-3537
Multiple SQL injection vulnerabilities in todooforum.php in Todoo Forum 2.0 allow remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência
CVE-2013-3531
SQL injection vulnerability in meneger.php in RadioCMS 2.2 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗Referência
CVE-2016-6601
Directory traversal vulnerability in the file download functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows rem
60RIESGO
abrir ↗Referência
CVE-2016-6601
Directory traversal vulnerability in the file download functionality in ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows rem
60RIESGO
abrir ↗Referência
CVE-2012-1018
Cross-site scripting (XSS) vulnerability in includes/convert.php in D-Mack Media Currency Converter (mod_currencyconvert
23RIESGO
abrir ↗Referência
CVE-2016-6603
ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to bypass authentication and impersonate arbitrary users v
45RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.