Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.772exploits catalogados
35.760CVEs con explotación pública
24.695probados en laboratorio
22.492 exploits
Referência
CVE-2023-4547
SPA-Cart eCommerce CMS search cross site scripting
55RIESGO
abrir
Referência
CVE-2017-9232
Juju before 1.25.12, 2.0.x before 2.0.4, and 2.1.x before 2.1.3 uses a UNIX domain socket without setting appropriate pe
50RIESGO
abrir
Referência
CVE-2021-40875
Improper Access Control in Gurock TestRail versions < 7.2.0.3014 resulted in sensitive information exposure. A threat ac
50RIESGO
abrir
Referência
CVE-2009-0182
Buffer overflow in VUPlayer 2.49 and earlier allows user-assisted attackers to execute arbitrary code via a long URL in
50RIESGO
abrir
Referência
CVE-2025-48828
Certain vBulletin versions might allow attackers to execute arbitrary PHP code by abusing Template Conditionals in the t
75RIESGO
abrir
ReferênciaVexDay Proof
Bitweaver 2.6 - 'saveFeed()' Remote Code Execution
CVE-2009-1669webappsphp
The smarty_function_math function in libs/plugins/function.math.php in Smarty 2.6.22 allows context-dependent attackers
28RIESGO
abrir
Referência
CVE-2013-3563
Stack-based buffer overflow in db_netserver in Lianja SQL Server before 1.0.0RC5.2 allows remote attackers to cause a de
50RIESGO
abrir
ReferênciaVexDay Proof
Xitami Web Server 2.5 - 'If-Modified-Since' Remote Buffer Overflow
CVE-2007-5067remotewindows
Multiple buffer overflows in iMatix Xitami Web Server 2.5c2 allow remote attackers to execute arbitrary code via a long
60RIESGO
abrir
ReferênciaVexDay Proof
DM FileManager 3.9.2 - Authentication Bypass
CVE-2009-1741webappsphp
Multiple SQL injection vulnerabilities in login.php in DM FileManager 3.9.2, when magic_quotes_gpc is disabled, allow re
23RIESGO
abrir
ReferênciaVexDay Proof
DGNews 3.0 Beta - 'id' SQL Injection
CVE-2009-1746webappsphp
SQL injection vulnerability in berita.php in Dian Gemilang DGNews 3.0 Beta allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
Softbiz Classifieds PLUS - 'id' SQL Injection
CVE-2007-5122webappsphp
SQL injection vulnerability in store_info.php in SoftBiz Classifieds PLUS allows remote attackers to execute arbitrary S
23RIESGO
abrir
Referência
CVE-2009-3054
SQL injection vulnerability in the Artetics.com Art Portal (com_artportal) component 1.0 for Joomla! allows remote attac
23RIESGO
abrir
Referência
CVE-2009-3062
SQL injection vulnerability in message_box.php in OSI Codes PHP Live! 3.3 allows remote attackers to execute arbitrary S
23RIESGO
abrir
Referência
CVE-2009-3063
SQL injection vulnerability in the Game Server (com_gameserver) component 1.0 for Joomla! allows remote attackers to exe
23RIESGO
abrir
Referência
CVE-2009-3115
SolarWinds TFTP Server 9.2.0.111 and earlier allows remote attackers to cause a denial of service (service stop) via a c
28RIESGO
abrir
Referência
CVE-2009-3150
SQL injection vulnerability in index.php in Multi Website 1.5 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
Referência
CVE-2016-3976
CVE-2016-3976HIGHbajo ataque
Directory traversal vulnerability in SAP NetWeaver AS Java 7.1 through 7.5 allows remote attackers to read arbitrary fil
83RIESGO
abrir
Referência
CVE-2019-17026
CVE-2019-17026HIGHbajo ataque
Incorrect alias information in IonMonkey JIT compiler for setting array elements could lead to a type confusion. We are
83RIESGO
abrir
ReferênciaVexDay Proof
MaxCMS 2.0 - '/inc/ajax.asp' SQL Injection
CVE-2009-1764webappsasp
SQL injection vulnerability in inc/ajax.asp in MaxCMS 2.0 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
Referência
CVE-2018-15812
DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expect
50RIESGO
abrir
Referência
CVE-2019-9692
class.showtime2_image.php in CMS Made Simple (CMSMS) before 2.2.10 does not ensure that a watermark file has a standard
50RIESGO
abrir
Referência
CVE-2019-9692
class.showtime2_image.php in CMS Made Simple (CMSMS) before 2.2.10 does not ensure that a watermark file has a standard
50RIESGO
abrir
Referência
CVE-2009-3320
Cross-site scripting (XSS) vulnerability in scrivi.php in Zenas PaoLink (aka Pao-Link) 1.0 allows remote attackers to in
23RIESGO
abrir
Referência
CVE-2009-3331
Multiple PHP remote file inclusion vulnerabilities in DDL CMS 1.0 allow remote attackers to execute arbitrary PHP code v
23RIESGO
abrir
Referência
CVE-2009-3336
SQL injection vulnerability in auction_details.php in PHP Pro Bid allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir
ReferênciaVexDay Proof
Vortex Portal 1.0.42 - Remote File Inclusion
CVE-2007-5842webappsphp
Multiple PHP remote file inclusion vulnerabilities in Vortex Portal 1.0.42 allow remote attackers to execute arbitrary P
35RIESGO
abrir
Referência
CVE-2010-0219
Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products
60RIESGO
abrir
Referência
CVE-2019-6444
An issue was discovered in NTPsec before 1.1.3. process_control() in ntp_control.c has a stack-based buffer over-read be
35RIESGO
abrir
Referência
CVE-2017-0202
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. The vulnerabi
35RIESGO
abrir
Referência
CVE-2023-4708
Infosoftbd Clcknshop GET Parameter all sql injection
45RIESGO
abrir
anteriorpágina 530 / 750siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.