Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.231exploits catalogados
35.420CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.451Referência 22.266GitHub PoC 14.131VulnCheck XDB 8635Nuclei 4274Metasploit 3474✓ solo verificadosrecientespopularesriesgo
22.266 exploits
Referência
CVE-2014-4716
Cross-site request forgery (CSRF) vulnerability in Thomson TWG87OUIR allows remote attackers to hijack the authenticatio
23RIESGO
abrir ↗Referência✓ VexDay Proof
LearnLoop 2.0beta7 - 'sFilePath' Remote File Disclosure
Directory traversal vulnerability in include/file_download.php in LearnLoop 2.0 beta7 allows remote attackers to read ar
23RIESGO
abrir ↗Referência
CVE-2018-13032
ECESSA ShieldLink SL175EHQ 10.7.4 devices have CSRF to add superuser accounts via the cgi-bin/pl_web.cgi/util_configlogi
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPortal 1.2 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in sablonlar/gunaysoft/gunaysoft.php in PHPortal 1.2 Beta allow remot
23RIESGO
abrir ↗Referência✓ VexDay Proof
Pritlog 0.4 - 'Filename' Remote File Disclosure
Directory traversal vulnerability in index.php in Pritlog 0.4 and earlier, when magic_quotes_gpc is disabled, allows rem
23RIESGO
abrir ↗Referência
CVE-2022-29727
Survey Sparrow Enterprise Survey Software 2022 has a Stored cross-site scripting (XSS) vulnerability in the Signup param
23RIESGO
abrir ↗Referência
CVE-2012-5099
Cross-site scripting (XSS) vulnerability in list.php in PHPB2B 4.1 and earlier allows remote attackers to inject arbitra
23RIESGO
abrir ↗Referência
CVE-2016-6255
Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to write to arbitrary files in the webroot via a P
28RIESGO
abrir ↗Referência
CVE-2016-6256
SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML
23RIESGO
abrir ↗Referência
CVE-2016-6256
SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML
23RIESGO
abrir ↗Referência
Veeam ONE Reporter 9.5.0.3201 - Multiple Cross-Site Request Forgery
Veeam ONE Reporter 9.5.0.3201 allows CSRF.
23RIESGO
abrir ↗Referência
PilusCart 1.4.1 - Cross-Site Request Forgery (Add Admin)
PilusCart 1.4.1 is vulnerable to index.php?module=users&action=newUser CSRF, leading to the addition of a new user as ad
23RIESGO
abrir ↗Referência
CVE-2016-6277
NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.B
100RIESGO
abrir ↗Referência
CVE-2012-1260
Cross-site scripting (XSS) vulnerability in cgi-bin/userprefs.cgi in Plixer International Scrutinizer NetFlow & sFlow An
23RIESGO
abrir ↗Referência✓ VexDay Proof
FlexPHPNews 0.0.5 - 'newsid' SQL Injection
SQL injection vulnerability in news.php in FlexPHPNews 0.0.3 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗Referência
CVE-2010-1467
Multiple PHP remote file inclusion vulnerabilities in openUrgence Vaccin 1.03 allow remote attackers to execute arbitrar
23RIESGO
abrir ↗Referência
CVE-2017-1000370
The offset2lib patch as used in the Linux Kernel contains a vulnerability that allows a PIE binary to be execve()'ed wit
23RIESGO
abrir ↗Referência✓ VexDay Proof
myPHPCalendar 10192000b - 'cal_dir' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in myPHPCalendar 10.1 allow remote attackers to execute arbitrary PHP
23RIESGO
abrir ↗Referência
CVE-2009-4801
EZ-Blog Beta 1 does not require authentication, which allows remote attackers to create or delete arbitrary posts via re
23RIESGO
abrir ↗Referência
CVE-2009-4670
admin/delitem.php in RoomPHPlanning 1.6 does not require authentication, which allows remote attackers to (1) delete arb
23RIESGO
abrir ↗Referência✓ VexDay Proof
MeGaCheatZ 1.1 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in MeGaCheatZ 1.1 allow remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir ↗Referência
CVE-2016-6434
Cisco Firepower Management Center 6.0.1 has hardcoded database credentials, which allows local users to obtain sensitive
23RIESGO
abrir ↗Referência
CVE-2018-18856
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS.
23RIESGO
abrir ↗Referência
CVE-2018-18856
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS.
23RIESGO
abrir ↗Referência✓ VexDay Proof
minimal Gallery 0.8 - Remote File Disclosure
Multiple directory traversal vulnerabilities in _mg/php/mg_thumbs.php in minimal Gallery 0.8 allow remote attackers to r
23RIESGO
abrir ↗Referência✓ VexDay Proof
DomPHP 0.82 - 'index.php' Local File Inclusion
Directory traversal vulnerability in aides/index.php in DomPHP 0.82 allows remote attackers to include and execute arbit
23RIESGO
abrir ↗Referência✓ VexDay Proof
XchangeBoard 1.70 - 'boardID' SQL Injection
SQL injection vulnerability in newThread.php in XchangeBoard 1.70 Final and earlier allows remote authenticated users to
23RIESGO
abrir ↗Referência✓ VexDay Proof
Netartmedia Cars Portal 2.0 - SQL Injection
SQL injection vulnerability in image.php in NetArt Media Car Portal 2.0 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.