Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.866exploits catalogados
35.812CVEs con explotación pública
24.695probados en laboratorio
22.573 exploits
Referência
CVE-2008-2186
Cross-site scripting (XSS) vulnerability in index.php in Chilek Content Management System (aka ChiCoMaS) 2.0.4 allows re
23RIESGO
abrir
Referência
CVE-2019-18418
clonos.php in ClonOS WEB control panel 19.09 allows remote attackers to gain full access via change password requests be
23RIESGO
abrir
Referência
CVE-2017-1000405
The Linux Kernel versions 2.6.38 through 4.14 have a problematic use of pmd_mkdirty() in the touch_pmd() function inside
23RIESGO
abrir
ReferênciaVexDay Proof
WebCards 1.3 - SQL Injection
CVE-2008-4878webappsphp
Unrestricted file upload vulnerability in the "Add Image Macro" feature in WebCards 1.3 allows remote authenticated admi
23RIESGO
abrir
Referência
CVE-2016-4316
Multiple cross-site scripting (XSS) vulnerabilities in WSO2 Carbon 4.4.5 allow remote attackers to inject arbitrary web
23RIESGO
abrir
ReferênciaVexDay Proof
work system E-Commerce 3.0.5 - Remote File Inclusion
CVE-2007-1423webappsphp
Multiple PHP remote file inclusion vulnerabilities in WORK system e-commerce 3.0.5 and earlier allow remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
Viewpoint Media Player for IE 3.2 - Remote Stack Overflow (PoC)
CVE-2007-5911doswindows
Multiple stack-based buffer overflows in the AxMetaStream ActiveX control in AxMetaStream.dll 3.3.2.26 in Viewpoint Medi
23RIESGO
abrir
Referência
CVE-2010-4971
Cross-site scripting (XSS) vulnerability in VideoWhisper PHP 2 Way Video Chat component for Joomla! allows remote attack
23RIESGO
abrir
Referência
CVE-2010-4972
SQL injection vulnerability in index.php in YPNinc JokeScript allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
Referência
CVE-2018-11339
An XSS issue was discovered in Frappe ERPNext v11.x.x-develop b1036e5 via a comment.
23RIESGO
abrir
Referência
CVE-2017-6550
Multiple SQL injection vulnerabilities in Kinsey Infor-Lawson (formerly ESBUS) allow remote attackers to execute arbitra
23RIESGO
abrir
Referência
CVE-2017-6550
Multiple SQL injection vulnerabilities in Kinsey Infor-Lawson (formerly ESBUS) allow remote attackers to execute arbitra
23RIESGO
abrir
Referência
CVE-2017-9126
The quicktime_read_dref_table function in dref.c in libquicktime 1.2.4 allows remote attackers to cause a denial of serv
23RIESGO
abrir
Referência
CVE-2010-4875
Cross-site scripting (XSS) vulnerability in vodpod-video-gallery/vodpod_gallery_thumbs.php in the Vodpod Video Gallery P
23RIESGO
abrir
Referência
CVE-2017-9412
The unpack_read_samples function in frontend/get_audio.c in LAME 3.99.5 allows remote attackers to cause a denial of ser
23RIESGO
abrir
ReferênciaVexDay Proof
GameCMS Lite 1.0 - 'systemId' SQL Injection
CVE-2008-2225webappsphp
SQL injection vulnerability in index.php in gameCMS Lite 1.0 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
Referência
CVE-2015-2248
Cross-site request forgery (CSRF) vulnerability in the user portal in Dell SonicWALL Secure Remote Access (SRA) products
23RIESGO
abrir
ReferênciaVexDay Proof
docmint 2.0 - '/engine/require.php' Remote File Inclusion
CVE-2006-5240webappsphp
PHP remote file inclusion vulnerability in engine/require.php in Docmint 2.0 and earlier, when register_globals is enabl
23RIESGO
abrir
ReferênciaVexDay Proof
PHPQuickGallery 1.9 - 'textFile' Remote File Inclusion
CVE-2006-6044webappsphp
PHP remote file inclusion vulnerability in gallery_top.inc.php in PHPQuickGallery 1.9 and earlier allows remote attacker
23RIESGO
abrir
ReferênciaVexDay Proof
phpBB Tweaked 3 - 'phpbb_root_path' Remote File Inclusion
CVE-2007-0680webappsphp
PHP remote file inclusion vulnerability in includes/functions.php in Phpbb Tweaked 3 and earlier allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
phpBB Module SupaNav 1.0.0 - 'link_main.php' Remote File Inclusion
CVE-2007-3935webappsphp
PHP remote file inclusion vulnerability in link_main.php in the SupaNav 1.0.0 module for phpBB allows remote attackers t
23RIESGO
abrir
Referência
CVE-2017-17590
FS Stackoverflow Clone 1.0 has SQL Injection via the /question keywords parameter.
23RIESGO
abrir
Referência
CVE-2017-17590
FS Stackoverflow Clone 1.0 has SQL Injection via the /question keywords parameter.
23RIESGO
abrir
Referência
CVE-2012-4891
Cross-site scripting (XSS) vulnerability in fw/index2.do in ManageEngine Firewall Analyzer 7.2 allows remote attackers t
23RIESGO
abrir
ReferênciaVexDay Proof
Technote 7.2 - Remote File Inclusion
CVE-2009-0441webappsphp
PHP remote file inclusion vulnerability in skin_shop/standard/2_view_body/body_default.php in TECHNOTE 7.2, when registe
23RIESGO
abrir
Referência
CVE-2015-2680
Cross-site request forgery (CSRF) vulnerability in MetalGenix GeniXCMS before 0.0.2 allows remote attackers to hijack th
23RIESGO
abrir
ReferênciaVexDay Proof
ravennuke 2.3.0 - Multiple Vulnerabilities
CVE-2009-0678webappsphp
images/captcha.php in RavenNuke 2.30 allows remote attackers to obtain sensitive information via an aFonts array paramet
23RIESGO
abrir
Referência
CVE-2014-9605
WebUpgrade in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass aut
23RIESGO
abrir
Referência
CVE-2015-2508
The Adobe Type Manager Library in Microsoft Windows 10 allows local users to gain privileges via a crafted application,
23RIESGO
abrir
Referência
CVE-2011-4714
Directory traversal vulnerability in Virtual Vertex Muster before 6.20 allows remote attackers to read arbitrary files v
23RIESGO
abrir
anteriorpágina 579 / 753siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.