Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.231exploits catalogados
35.420CVEs con explotación pública
24.695probados en laboratorio
22.266 exploits
Referência
CVE-2026-2686
SECCN Dingcheng G10 session_login.cgi qq os command injection
48RIESGO
abrir
Referência
CVE-2022-29727
Survey Sparrow Enterprise Survey Software 2022 has a Stored cross-site scripting (XSS) vulnerability in the Signup param
23RIESGO
abrir
Referência
CVE-2012-5099
Cross-site scripting (XSS) vulnerability in list.php in PHPB2B 4.1 and earlier allows remote attackers to inject arbitra
23RIESGO
abrir
Referência
CVE-2016-6255
Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to write to arbitrary files in the webroot via a P
28RIESGO
abrir
Referência
CVE-2016-6256
SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML
23RIESGO
abrir
Referência
CVE-2016-6256
SAP Business One for Android 1.2.3 allows remote attackers to conduct XML External Entity (XXE) attacks via crafted XML
23RIESGO
abrir
Referência
Veeam ONE Reporter 9.5.0.3201 - Multiple Cross-Site Request Forgery
CVE-2019-11569webappsashx
Veeam ONE Reporter 9.5.0.3201 allows CSRF.
23RIESGO
abrir
Referência
PilusCart 1.4.1 - Cross-Site Request Forgery (Add Admin)
CVE-2019-9769webappsphp
PilusCart 1.4.1 is vulnerable to index.php?module=users&action=newUser CSRF, leading to the addition of a new user as ad
23RIESGO
abrir
Referência
CVE-2016-6277
CVE-2016-6277HIGHbajo ataque
NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.B
100RIESGO
abrir
Referência
CVE-2012-1260
Cross-site scripting (XSS) vulnerability in cgi-bin/userprefs.cgi in Plixer International Scrutinizer NetFlow & sFlow An
23RIESGO
abrir
Referência
CVE-2020-37027
Sickbeard 0.1 - Remote Command Injection
48RIESGO
abrir
ReferênciaVexDay Proof
FlexPHPNews 0.0.5 - 'newsid' SQL Injection
CVE-2005-1237webappsphp
SQL injection vulnerability in news.php in FlexPHPNews 0.0.3 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
Referência
CVE-2010-1467
Multiple PHP remote file inclusion vulnerabilities in openUrgence Vaccin 1.03 allow remote attackers to execute arbitrar
23RIESGO
abrir
Referência
CVE-2017-1000370
The offset2lib patch as used in the Linux Kernel contains a vulnerability that allows a PIE binary to be execve()'ed wit
23RIESGO
abrir
ReferênciaVexDay Proof
myPHPCalendar 10192000b - 'cal_dir' Remote File Inclusion
CVE-2006-6812webappsphp
Multiple PHP remote file inclusion vulnerabilities in myPHPCalendar 10.1 allow remote attackers to execute arbitrary PHP
23RIESGO
abrir
Referência
CVE-2009-4801
EZ-Blog Beta 1 does not require authentication, which allows remote attackers to create or delete arbitrary posts via re
23RIESGO
abrir
Referência
CVE-2009-4670
admin/delitem.php in RoomPHPlanning 1.6 does not require authentication, which allows remote attackers to (1) delete arb
23RIESGO
abrir
ReferênciaVexDay Proof
MeGaCheatZ 1.1 - Multiple SQL Injections
CVE-2007-6557webappsphp
Multiple SQL injection vulnerabilities in MeGaCheatZ 1.1 allow remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir
Referência
CVE-2016-6434
Cisco Firepower Management Center 6.0.1 has hardcoded database credentials, which allows local users to obtain sensitive
23RIESGO
abrir
Referência
CVE-2018-18856
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS.
23RIESGO
abrir
Referência
CVE-2018-18856
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS.
23RIESGO
abrir
ReferênciaVexDay Proof
minimal Gallery 0.8 - Remote File Disclosure
CVE-2008-0259webappsphp
Multiple directory traversal vulnerabilities in _mg/php/mg_thumbs.php in minimal Gallery 0.8 allow remote attackers to r
23RIESGO
abrir
ReferênciaVexDay Proof
DomPHP 0.82 - 'index.php' Local File Inclusion
CVE-2008-0745webappsphp
Directory traversal vulnerability in aides/index.php in DomPHP 0.82 allows remote attackers to include and execute arbit
23RIESGO
abrir
ReferênciaVexDay Proof
XchangeBoard 1.70 - 'boardID' SQL Injection
CVE-2008-3035webappsphp
SQL injection vulnerability in newThread.php in XchangeBoard 1.70 Final and earlier allows remote authenticated users to
23RIESGO
abrir
ReferênciaVexDay Proof
Netartmedia Cars Portal 2.0 - SQL Injection
CVE-2008-5310webappsphp
SQL injection vulnerability in image.php in NetArt Media Car Portal 2.0 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
ASP Download 1.03 - Arbitrary Change Administrator Account
CVE-2008-6739webappsasp
Todd Woolums ASP Download management script 1.03 does not require authentication for setupdownload.asp, which allows rem
23RIESGO
abrir
ReferênciaVexDay Proof
Koschtit Image Gallery 1.82 - Multiple Local File Inclusions
CVE-2009-1510webappsphp
Multiple directory traversal vulnerabilities in KoschtIT Image Gallery 1.82 allow remote attackers to include and execut
23RIESGO
abrir
Referência
CVE-2009-2337
SQL injection vulnerability in includes/module/book/index.inc.php in w3b|cms Gaestebuch Guestbook Module 3.0.0, when mag
23RIESGO
abrir
Referência
CVE-2011-5218
SQL injection vulnerability in DotA OpenStats 1.3.9 and earlier allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
Referência
CVE-2019-2721
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th
23RIESGO
abrir
anteriorpágina 419 / 743siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.