Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.620exploits catalogados
35.647CVEs con explotación pública
24.695probados en laboratorio
22.429 exploits
ReferênciaVexDay Proof
Online Keyword Research Tool - 'download.php' File Disclosure
CVE-2008-6335webappsphp
Directory traversal vulnerability in download.php in eMetrix Online Keyword Research Tool allows remote attackers to rea
23RIESGO
abrir
ReferênciaVexDay Proof
Text Lines Rearrange Script - 'Filename' File Disclosure
CVE-2008-6336webappsphp
Directory traversal vulnerability in download.php in Text Lines Rearrange Script 1.0, when register_globals is enabled,
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component Volunteer 2.0 - SQL Injection
CVE-2008-6337webappsphp
SQL injection vulnerability in the Volunteer Management System (com_volunteer) module 2.0 for Joomla! allows remote atta
23RIESGO
abrir
ReferênciaVexDay Proof
SolarCMS 0.53.8 - 'Forum' Remote Cookies Disclosure
CVE-2008-6345webappsphp
SQL injection vulnerability in Forum.php in SolarCMS 0.53.8 and 1.0 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component ongumatimesheet20 4b - Remote File Inclusion
CVE-2008-6347webappsphp
PHP remote file inclusion vulnerability in lib/onguma.class.php in the Onguma Time Sheet (com_ongumatimesheet20) 2.0 4b
28RIESGO
abrir
ReferênciaVexDay Proof
DevelopItEasy Photo Gallery 1.2 - SQL Injection
CVE-2008-6348webappsphp
Multiple SQL injection vulnerabilities in DevelopItEasy Photo Gallery 1.2 allow remote attackers to execute arbitrary SQ
23RIESGO
abrir
ReferênciaVexDay Proof
TurnkeyForms Business Survey Pro 1.0 - 'id' SQL Injection
CVE-2008-6349webappsphp
SQL injection vulnerability in survey_results_text.php in TurnkeyForms Business Survey Pro 1.0 allows remote attackers t
23RIESGO
abrir
Referência
CVE-2019-8943
WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can
60RIESGO
abrir
Referência
CVE-2019-8943
WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can
60RIESGO
abrir
Referência
CVE-2019-8943
WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can
60RIESGO
abrir
Referência
CVE-2019-8943
WordPress through 5.0.3 allows Path Traversal in wp_crop_image(). An attacker (who has privileges to crop an image) can
60RIESGO
abrir
Referência
CVE-2023-31069
An issue was discovered in TSplus Remote Access through 16.0.2.14. Credentials are stored as cleartext within the HTML s
23RIESGO
abrir
ReferênciaVexDay Proof
Drake CMS 0.4.11 - Blind SQL Injection
CVE-2008-6475webappsphp
SQL injection vulnerability in the guestbook component (components/guestbook/guestbook.php) in Drake CMS 0.4.11 and earl
23RIESGO
abrir
Referência
CVE-2018-11138
CVE-2018-11138CRITICALbajo ataqueransomware
The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by
100RIESGO
abrir
Referência
CVE-2012-0391
CVE-2012-0391CRITICALbajo ataque
The ExceptionDelegator component in Apache Struts before 2.2.3.1 interprets parameter values as OGNL expressions during
100RIESGO
abrir
ReferênciaVexDay Proof
Mumbo Jumbo Media OP4 - Blind SQL Injection
CVE-2008-6477webappsphp
SQL injection vulnerability in Mumbo Jumbo Media OP4 allows remote attackers to execute arbitrary SQL commands via the i
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component versioning 1.0.2 - 'id' SQL Injection
CVE-2008-6481webappsphp
SQL injection vulnerability in the Versioning component (com_versioning) 1.0.2 in Joomla! and Mambo allows remote attack
23RIESGO
abrir
Referência
TSPlus 16.0.0.0 - Remote Work Insecure Credential storage
CVE-2023-31069remotewindows
An issue was discovered in TSplus Remote Access through 16.0.2.14. Credentials are stored as cleartext within the HTML s
23RIESGO
abrir
Referência
CVE-2023-31468
An issue was discovered in Inosoft VisiWin 7 through 2022-2.1 (Runtime RT7.3 RC3 20221209.5). The "%PROGRAMFILES(X86)%\I
41RIESGO
abrir
Referência
CVE-2017-12629
Remote code execution occurs in Apache Solr before 7.1 with Apache Lucene before 7.1 by exploiting XXE in conjunction wi
60RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component Flash Tree Gallery 1.0 - Remote File Inclusion
CVE-2008-6482webappsphp
PHP remote file inclusion vulnerability in admin.treeg.php in the Flash Tree Gallery (com_treeg) component 1.0 for Jooml
28RIESGO
abrir
Referência
CVE-2015-8556
Local privilege escalation vulnerability in the Gentoo QEMU package before 2.5.0-r1.
28RIESGO
abrir
ReferênciaVexDay Proof
Geeklog 2 - 'BaseView.php' Remote File Inclusion
CVE-2007-0810webappsphp
PHP remote file inclusion vulnerability in MVCnPHP/BaseView.php in GeekLog 2 and earlier allows remote attackers to exec
23RIESGO
abrir
ReferênciaVexDay Proof
Woltlab Burning Board Lite 1.0.2pl3e - 'pms.php' SQL Injection
CVE-2007-0812webappsphp
SQL injection vulnerability in pms.php in Woltlab Burning Board (wBB) Lite 1.0.2pl3e and earlier allows remote authentic
23RIESGO
abrir
ReferênciaVexDay Proof
Mole Group Taxi Calc Dist Script - Authentication Bypass
CVE-2008-6484webappsphp
SQL injection vulnerability in login.php in Mole Group Taxi Map Script (aka Taxi Calc Dist Script) allows remote attacke
23RIESGO
abrir
Referência
CVE-2019-1821
Cisco Prime Infrastructure and Evolved Programmable Network Manager Remote Code Execution Vulnerabilities
78RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component MyAlbum 1.0 - 'album' SQL Injection
CVE-2008-6489webappsphp
SQL injection vulnerability in MyAlbum component (com_myalbum) 1.0 for Joomla! allows remote attackers to execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
FLABER 1.1 RC1 - Remote Command Execution
CVE-2008-6490webappsphp
function/update_xml.php in FLABER 1.1 and earlier allows remote attackers to overwrite arbitrary files by specifying the
23RIESGO
abrir
Referência
CVE-2024-11680
CVE-2024-11680CRITICALbajo ataque
ProjectSend Unauthenticated Configuration Modification
100RIESGO
abrir
Referência
CVE-2024-11680
CVE-2024-11680CRITICALbajo ataque
ProjectSend Unauthenticated Configuration Modification
100RIESGO
abrir
anteriorpágina 509 / 748siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.