Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.620exploits catalogados
35.647CVEs con explotación pública
24.695probados en laboratorio
22.429 exploits
ReferênciaVexDay Proof
Camera Life 2.6.2b4 - SQL Injection / Cross-Site Scripting
CVE-2008-6086webappsphp
SQL injection vulnerability in album.php in Camera Life 2.6.2b4 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
ReferênciaVexDay Proof
Informium 0.12.0 - 'common-menu.php' Remote File Inclusion
CVE-2006-2818webappsphp
PHP remote file inclusion vulnerability in common-menu.php in Cameron McKay Informium 0.12.0 allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
Redaxo 3.2 - 'INCLUDE_PATH' Remote File Inclusion
CVE-2006-2844webappsphp
Multiple PHP remote file inclusion vulnerabilities in Redaxo 3.0 allow remote attackers to execute arbitrary PHP code vi
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component Joomtracker 1.01 - SQL Injection
CVE-2008-6088webappsphp
SQL injection vulnerability in the Joomtracker (com_joomtracker) 1.01 module for Joomla! allows remote attackers to exec
23RIESGO
abrir
ReferênciaVexDay Proof
e107 Plugin ZoGo-Shop 1.15.4 - 'product' SQL Injection
CVE-2008-6114webappsphp
SQL injection vulnerability in product_details.php in the Mytipper Zogo-shop 1.15.4 plugin for e107 allows remote attack
23RIESGO
abrir
ReferênciaVexDay Proof
Wikiwig 4.1 - 'wk_lang.php' Remote File Inclusion
CVE-2006-2888webappsphp
PHP remote file inclusion vulnerability in _wk/wk_lang.php in Wikiwig 4.1 and earlier allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
Limbo CMS Module event 1.0 - Remote File Inclusion
CVE-2006-6800webappsphp
PHP remote file inclusion in eventcal/mod_eventcal.php in the event module 1.0 for Limbo CMS allows remote attackers to
23RIESGO
abrir
Referência
CVE-2019-9194
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
60RIESGO
abrir
Referência
CVE-2019-9194
elFinder before 2.1.48 has a command injection vulnerability in the PHP connector.
60RIESGO
abrir
Referência
CVE-2023-33246
CVE-2023-33246CRITICALbajo ataque
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RIESGO
abrir
Referência
CVE-2023-33246
CVE-2023-33246CRITICALbajo ataque
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RIESGO
abrir
Referência104
CVE-2023-33246 RocketMQ RCE Detect By Version and Exploit
CVE-2023-33246CRITICALbajo ataque
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
100RIESGO
abrir
Referência
CVE-2026-10815
LakshayD02 Hostel-Management-System-PHP Admin Dashboard index.php authorization
33RIESGO
abrir
Referência
CVE-2026-10814
milvus-io milvus Grantee ID Hash kv_catalog.go weak hash
28RIESGO
abrir
Referência
CVE-2026-10812
zilliztech GPTCache Cache Key pre.py BufferedReader.peek weak hash
28RIESGO
abrir
Referência
CVE-2023-46747
CVE-2023-46747CRITICALbajo ataqueransomware
BIG-IP Configuration utility unauthenticated remote code execution vulnerability
100RIESGO
abrir
Referência
CVE-2019-25745
WordPress Plugin Google Review Slider 6.1 SQL Injection via tid
41RIESGO
abrir
ReferênciaVexDay Proof
AdMan 1.1.20070907 - 'campaignId' SQL Injection
CVE-2008-6156webappsphp
SQL injection vulnerability in editCampaign.php in AdMan 1.1.20070907 allows remote authenticated users to execute arbit
23RIESGO
abrir
Referência
CVE-2019-25735
AllPlayer 7.4 Local Buffer Overflow via SEH Unicode
41RIESGO
abrir
ReferênciaVexDay Proof
Bux.to Clone Script - Insecure Cookie Handling
CVE-2008-6162webappsphp
Bux.to Clone script allows remote attackers to bypass authentication and gain administrative access by setting the logge
23RIESGO
abrir
Referência
CVE-2019-25734
Contact Form by WD 1.13.1 CSRF to Local File Inclusion
33RIESGO
abrir
Referência
CVE-2024-11954
Pimcore Search Document cross site scripting
33RIESGO
abrir
Referência
CVE-2024-12344
TP-Link VN020 F3v(T) FTP USER Command memory corruption
33RIESGO
abrir
Referência
CVE-2008-6209
SQL injection vulnerability in view_product.php in Vastal I-Tech Software Zone allows remote attackers to execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
Vastal I-Tech Software Zone - 'cat_id' SQL Injection
CVE-2008-6209webappsphp
SQL injection vulnerability in view_product.php in Vastal I-Tech Software Zone allows remote attackers to execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
Dream4 Koobi 4.4/5.4 - gallery SQL Injection
CVE-2008-6210webappsphp
SQL injection vulnerability in index.php in dream4 Koobi 4.4 and 5.4 allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir
Referência
CVE-2015-4852
CVE-2015-4852CRITICALbajo ataque
The WLS Security component in Oracle WebLogic Server 10.3.6.0, 12.1.2.0, 12.1.3.0, and 12.2.1.0 allows remote attackers
100RIESGO
abrir
ReferênciaVexDay Proof
Harlandscripts Pro Traffic One - 'mypage.php' SQL Injection
CVE-2008-6213webappsphp
SQL injection vulnerability in mypage.php in Harlandscripts Pro Traffic One allows remote attackers to execute arbitrary
23RIESGO
abrir
Referência
CVE-2015-1497
radexecd.exe in Persistent Systems Radia Client Automation (RCA) 7.9, 8.1, 9.0, and 9.1 allows remote attackers to execu
60RIESGO
abrir
Referência
CVE-2014-3871
Multiple SQL injection vulnerabilities in register.php in Geodesic Solutions GeoCore MAX 7.3.3 (formerly GeoClassifieds
23RIESGO
abrir
anteriorpágina 504 / 748siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.