Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.620exploits catalogados
35.647CVEs con explotación pública
24.695probados en laboratorio
22.429 exploits
ReferênciaVexDay Proof
iDB 0.2.5pa SVN 243 - 'skin' Local File Inclusion
CVE-2009-1498webappsphp
Directory traversal vulnerability in inc/profilemain.php in Game Maker 2k Internet Discussion Boards (iDB) 0.2.5 Pre-Alp
23RIESGO
abrir
Referência
CVE-2017-6019
An issue was discovered in Schneider Electric Conext ComBox, model 865-1058, all firmware versions prior to V3.03 BN 830
35RIESGO
abrir
Referência
CVE-2019-8387
MASTER IPCAMERA01 3.3.4.2103 devices allow Remote Command Execution, related to the thttpd component.
35RIESGO
abrir
Referência
CVE-2022-21882
CVE-2022-21882HIGHbajo ataqueransomware
Win32k Elevation of Privilege Vulnerability
98RIESGO
abrir
Referência
CVE-2014-7236
Eval injection vulnerability in lib/TWiki/Plugins.pm in TWiki before 6.0.1 allows remote attackers to execute arbitrary
50RIESGO
abrir
Referência
CVE-2014-4114
CVE-2014-4114HIGHbajo ataque
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
100RIESGO
abrir
Referência
CVE-2018-17440
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. They expose an FTP server that serves b
35RIESGO
abrir
Referência
CVE-2017-13872
An issue was discovered in certain Apple products. macOS High Sierra before Security Update 2017-001 is affected. The is
50RIESGO
abrir
Referência
CVE-2017-13872
An issue was discovered in certain Apple products. macOS High Sierra before Security Update 2017-001 is affected. The is
50RIESGO
abrir
Referência
CVE-2015-3042
Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457
35RIESGO
abrir
Referência
CVE-2017-9798
Apache httpd allows remote attackers to read secret data from process memory if the Limit directive can be set in a user
60RIESGO
abrir
Referência
CVE-2009-3343
SQL injection vulnerability in details.asp in HotWeb Rentals allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
Referência
CVE-2023-41425
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RIESGO
abrir
Referência
CVE-2009-2400
SQL injection vulnerability in the PHP (com_php) component for Joomla! allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
Referência
CVE-2009-2402
SQL injection vulnerability in index.php in the forum module in PHPEcho CMS 2.0-rc3 allows remote attackers to execute a
23RIESGO
abrir
Referência
CVE-2009-2423
SQL injection vulnerability in category.php in Ebay Clone 2009 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
Referência
CVE-2019-19609
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RIESGO
abrir
ReferênciaVexDay Proof
Ajax File Browser 3b - 'settings.inc.php?approot' Remote File Inclusion
CVE-2007-4921webappsphp
PHP remote file inclusion vulnerability in _includes/settings.inc.php in Ajax File Browser 3 Beta allows remote attacker
35RIESGO
abrir
ReferênciaVexDay Proof
KwsPHP Module jeuxflash 1.0 - 'id' SQL Injection
CVE-2007-4922webappsphp
SQL injection vulnerability in play.php in the jeuxflash 1.0 module for KwsPHP allows remote authenticated users to exec
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component Joomlaradio 5.0 - Remote File Inclusion
CVE-2007-4923webappsphp
PHP remote file inclusion vulnerability in admin.joomlaradiov5.php in the Joomla Radio 5 (com_joomlaradiov5) component f
35RIESGO
abrir
ReferênciaVexDay Proof
phpFFL 1.24 - 'PHPFFL_FILE_ROOT' Remote File Inclusion
CVE-2007-4934webappsphp
Multiple PHP remote file inclusion vulnerabilities in phpFFL 1.24 allow remote attackers to execute arbitrary PHP code v
28RIESGO
abrir
Referência
CVE-2026-16083
Sipeed PicoClaw LINE Webhook line.go webhook.ParseRequest authentication replay
33RIESGO
abrir
Referência
CVE-2026-16082
Sipeed PicoClaw pipeline_execute.go ExecTool.executeRun toctou
33RIESGO
abrir
Referência
CVE-2026-16081
Sipeed PicoClaw auth.go cross-site request forgery
33RIESGO
abrir
Referência
CVE-2026-16077
AstrBotDevs AstrBot Filesystem Computer-Use Tool fs.py _normalize_rw_path link following
33RIESGO
abrir
Referência
CVE-2026-16076
AstrBotDevs AstrBot API open_api.py OpenApiRoute.chat_send authentication spoofing
33RIESGO
abrir
Referência
CVE-2026-16075
AstrBotDevs AstrBot session-listing Endpoint open_api.py OpenApiRoute.get_chat_sessions authorization
33RIESGO
abrir
Referência
CVE-2013-0807
Cross-site scripting (XSS) vulnerability in the NewSectionPrompt function in include/tool/editing_page.php in gpEasy CMS
23RIESGO
abrir
Referência
CVE-2013-0928
The NetWorker command processor in rrobotd.exe in the Device Manager in EMC AlphaStor 4.0 before build 800 allows remote
50RIESGO
abrir
Referência
CVE-2013-1080
The web server in Novell ZENworks Configuration Management (ZCM) 10.3 and 11.2 before 11.2.4 does not properly perform a
60RIESGO
abrir
anteriorpágina 512 / 748siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.