Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.533exploits catalogados
35.607CVEs con explotación pública
24.695probados en laboratorio
22.407 exploits
ReferênciaVexDay Proof
pPIM 1.01 - 'notes.php' Local File Inclusion
CVE-2008-4528webappsphp
Directory traversal vulnerability in notes.php in Phlatline's Personal Information Manager (pPIM) 1.01 allows remote att
23RIESGO
abrir
ReferênciaVexDay Proof
asiCMS alpha 0.208 - Multiple Remote File Inclusions
CVE-2008-4529webappsphp
Multiple PHP remote file inclusion vulnerabilities in asiCMS alpha 0.208 allow remote attackers to execute arbitrary PHP
23RIESGO
abrir
ReferênciaVexDay Proof
Absolute Poll Manager XE 4.1 - 'xlacomments.asp' SQL Injection
CVE-2008-4569webappsasp
SQL injection vulnerability in xlacomments.asp in XIGLA Software Absolute Poll Manager XE 4.1 allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
Ayco Okul Portali - 'linkid' SQL Injection
CVE-2008-4574webappsasp
SQL injection vulnerability in default.asp in Ayco Okul Portali allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
ReferênciaVexDay Proof
Chilkat FTP ActiveX 2.0 - 'ChilkatCert.dll' Insecure Method
CVE-2008-4583remotewindows
Insecure method vulnerability in the Chilkat FTP 2.0 ActiveX component (ChilkatCert.dll) allows remote attackers to over
23RIESGO
abrir
ReferênciaVexDay Proof
Macrovision FlexNet DownloadManager - Insecure Methods
CVE-2008-4587remotewindows
Insecure method vulnerability in the MSVNClientDownloadManager61Lib.DownloadManager.1 ActiveX control (ISDM.exe 6.1.100.
28RIESGO
abrir
ReferênciaVexDay Proof
PHPWebGallery 1.3.4 - Cross-Site Scripting / Local File Inclusion
CVE-2008-4591webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in admin/include/isadmin.inc.php in PhpWebGallery 1.3.4 allow remote
23RIESGO
abrir
ReferênciaVexDay Proof
CafeEngine - Multiple SQL Injections
CVE-2008-4605webappsphp
SQL injection vulnerability in CafeEngine allows remote attackers to execute arbitrary SQL commands via the id parameter
23RIESGO
abrir
Referência
CVE-2026-19195
V-Secure Jingyun Antivirus Kernel Driver ZyArk.sys access control
41RIESGO
abrir
ReferênciaVexDay Proof
CCLeague Pro 1.2 - Insecure Cookie Authentication
CVE-2008-5123webappsphp
SQL injection vulnerability in admin.php in CCleague Pro 1.2 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
Referência
CVE-2026-19193
Jiangmin Antivirus Minifilter Port kvcore.sys MessageNotifyCallback access control
41RIESGO
abrir
Referência
CVE-2026-19108
MZ Automation libiec61850 URCB Revalidation reporting.c deleteDataSetValuesShadowBuffer use after free
33RIESGO
abrir
Referência
CVE-2025-15674
Content Protector (Passster) < 4.3.7 - Contributor+ Protected Content Disclosure via Core REST API
28RIESGO
abrir
Referência
CVE-2026-16620
WPC Name Your Price for WooCommerce < 2.2.5 - Unauthenticated Price Manipulation via Select Mode
41RIESGO
abrir
Referência
CVE-2026-16619
miniOrange 2FA < 6.2.8 - 2FA Bypass via Unlimited Second-Factor Attempts
41RIESGO
abrir
Referência
CVE-2026-19062
chiuwingyan house selectall.action sql injection
33RIESGO
abrir
Referência
CVE-2026-16067
Event Booking Manager for WooCommerce (Pro) < 5.0.3 - Unauthenticated Payment Bypass via Client-Controlled Ticket Price
33RIESGO
abrir
Referência
CVE-2026-15256
Ninja Forms < 3.14.10 - Unauthenticated Arbitrary Shortcode Execution via Query-String Populated Field Default
33RIESGO
abrir
Referência
CVE-2026-17032
Supsystic Multiple Pro Plugins - Backdoor via Compromised Vendor Update Server
48RIESGO
abrir
Referência
CVE-2026-13342
Security Optimizer – The All-In-One Protection Plugin < 1.6.5 - Login Access IP Allowlist Bypass via post_password
33RIESGO
abrir
Referência
CVE-2026-15149
WP Hotel Booking < 2.3.3 - Unauthenticated Payment Bypass via Price Manipulation
33RIESGO
abrir
Referência
CVE-2026-15208
RegistrationMagic < 6.0.9.5 - Unauthenticated Payment Bypass via Amount-Blind PayPal Verification
33RIESGO
abrir
ReferênciaVexDay Proof
Pro Chat Rooms 3.0.3 - SQL Injection
CVE-2008-5070webappsphp
SQL injection vulnerability in Pro Chat Rooms 3.0.3, when magic_quotes_gpc is disabled, allows remote attackers to execu
23RIESGO
abrir
Referência
CVE-2018-6888
An issue was discovered in Typesetter 5.1. The User Permissions page (aka Admin/Users) suffers from critical flaw of Cro
23RIESGO
abrir
ReferênciaVexDay Proof
Yoxel 1.23beta - 'itpm_estimate.php' Remote Code Execution
CVE-2008-5071webappsphp
Multiple eval injection vulnerabilities in itpm_estimate.php in Yoxel 1.23beta and earlier allow remote authenticated us
23RIESGO
abrir
ReferênciaVexDay Proof
Deterministic Network Enhancer - 'dne2000.sys' Kernel Ring0 SYSTEM
CVE-2008-5121localwindows
dne2000.sys in Citrix Deterministic Network Enhancer (DNE) 2.21.7.233 through 3.21.7.17464, as used in (1) Cisco VPN Cli
23RIESGO
abrir
Referência
CVE-2018-6892
An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sy
60RIESGO
abrir
ReferênciaVexDay Proof
Orca 2.0/2.0.2 - 'params.php?gConf[dir][layouts]' Remote File Inclusion
CVE-2008-5167webappsphp
PHP remote file inclusion vulnerability in layout/default/params.php in Boonex Orca 2.0 and 2.0.2, when register_globals
23RIESGO
abrir
ReferênciaVexDay Proof
Tips Complete Website 1.2.0 - 'tipid' SQL Injection
CVE-2008-5168webappsphp
SQL injection vulnerability in tip.php in Tips Complete Website 1.2.0 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
ReferênciaVexDay Proof
Cheats Complete Website 1.1.1 - 'itemID' SQL Injection
CVE-2008-5170webappsphp
SQL injection vulnerability in item.php in Cheats Complete Website 1.1.1 allows remote attackers to execute arbitrary SQ
23RIESGO
abrir
anteriorpágina 492 / 747siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.