Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.055exploits catalogados
35.925CVEs con explotación pública
24.695probados en laboratorio
22.600 exploits
ReferênciaVexDay Proof
OTSCMS 2.1.3 - Multiple Remote File Inclusions
CVE-2006-5547webappsphp
PHP remote file inclusion vulnerability in OTSCMS/OTSCMS.php in Open Tibia Server Content Management System (OTSCMS) 1.0
23RIESGO
abrir
ReferênciaVexDay Proof
OTSCMS 2.1.3 - Multiple Remote File Inclusions
CVE-2006-5548webappsphp
PHP remote file inclusion vulnerability in OTSCMS/OTSCMS.php in Open Tibia Server Content Management System (OTSCMS) 2.0
23RIESGO
abrir
ReferênciaVexDay Proof
RevilloC MailServer 1.x - 'RCPT TO' Remote Denial of Service
CVE-2006-5552doswindows
Multiple heap-based buffer overflows in RevilloC MailServer 1.21 and earlier allow remote attackers to cause a denial of
23RIESGO
abrir
ReferênciaVexDay Proof
Imageview 5 - '/Cookie/index.php' Local/Remote File Inclusion
CVE-2006-5554webappsphp
Directory traversal vulnerability in index.php in Imageview 5 allows remote attackers to read or execute arbitrary local
23RIESGO
abrir
ReferênciaVexDay Proof
Nero ShowTime 5.0.15.0 - '.m3u' Playlist File Remote Buffer Overflow (PoC)
CVE-2008-7079doswindows
Buffer overflow in Nero ShowTime 5.0.15.0 allows remote attackers to cause a denial of service (crash) and possibly exec
23RIESGO
abrir
ReferênciaVexDay Proof
ReVou Twitter Clone - Authentication Bypass
CVE-2008-7083webappsphp
Multiple SQL injection vulnerabilities in ReVou Micro Blogging Twitter clone allow remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
HockeySTATS Online 2.0 - Multiple SQL Injections
CVE-2008-7085webappsphp
Multiple SQL injection vulnerabilities in TheHockeyStop HockeySTATS Online 2.0 Basic and Advanced allow remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
Maian Greetings 2.1 - Insecure Cookie Handling
CVE-2008-7086webappsphp
Maian Greetings 2.1 allows remote attackers to bypass authentication and gain administrative privileges by setting the m
23RIESGO
abrir
ReferênciaVexDay Proof
PhotoPost vBGallery 2.4.2 - Arbitrary File Upload
CVE-2008-7088webappsphp
Unrestricted file upload vulnerability in upload.php in PhotoPost vBGallery 2.4.2 allows remote authenticated users to e
23RIESGO
abrir
ReferênciaVexDay Proof
Pligg CMS 9.9.0 - Cross-Site Scripting / Local File Inclusion / SQL Injection
CVE-2008-7090webappsphp
Multiple directory traversal vulnerabilities in Pligg 9.9 and earlier allow remote attackers to (1) determine the existe
23RIESGO
abrir
ReferênciaVexDay Proof
Pligg CMS 9.9.0 - Cross-Site Scripting / Local File Inclusion / SQL Injection
CVE-2008-7091webappsphp
Multiple SQL injection vulnerabilities in Pligg 9.9 and earlier allow remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
Referência
CVE-2011-1556
SQL injection vulnerability in plugins/pdfClasses/pdfgen.php in Andy's PHP Knowledgebase (Aphpkb) 0.95.4 allows remote a
23RIESGO
abrir
Referência
CVE-2011-1565
Directory traversal vulnerability in IGSSdataServer.exe 9.00.00.11063 and earlier in 7-Technologies Interactive Graphica
50RIESGO
abrir
Referência
CVE-2011-1670
Cross-site scripting (XSS) vulnerability in actions/add.php in InTerra Blog Machine 1.84, and possibly earlier versions,
23RIESGO
abrir
Referência
CVE-2015-0936
Ceragon FibeAir IP-10 have a default SSH public key in the authorized_keys file for the mateidu user, which allows remot
60RIESGO
abrir
Referência
CVE-2009-4751
SQL injection vulnerability in anzeiger/start.php in Swinger Club Portal allows remote attackers to execute arbitrary SQ
23RIESGO
abrir
Referência
CVE-2009-4752
PHP remote file inclusion vulnerability in anzeiger/start.php in Swinger Club Portal allows remote attackers to execute
23RIESGO
abrir
Referência
CVE-2013-4864
MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to send HTTP requests to intranet servers via the url
23RIESGO
abrir
Referência
CVE-2013-4864
MiCasaVerde VeraLite with firmware 1.5.408 allows remote attackers to send HTTP requests to intranet servers via the url
23RIESGO
abrir
Referência
CVE-2013-4865
Cross-site request forgery (CSRF) vulnerability in upgrade_step2.sh in MiCasaVerde VeraLite with firmware 1.5.408 allows
23RIESGO
abrir
Referência
CVE-2013-5045
Microsoft Internet Explorer 10 and 11 allows local users to bypass the Protected Mode protection mechanism, and conseque
43RIESGO
abrir
ReferênciaVexDay Proof
BaoFeng - ActiveX 'OnBeforeVideoDownload()' Remote Buffer Overflow
CVE-2009-1612remotewindows
Stack-based buffer overflow in the MPS.StormPlayer.1 ActiveX control in mps.dll 3.9.4.27 in Baofeng Storm allows remote
50RIESGO
abrir
Referência
CVE-2026-9523
Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform getCalcmeterDetailDayListTree sql injection
33RIESGO
abrir
Referência
CVE-2009-4756
Stack-based buffer overflow in TraktorBeatport.exe 1.0.0.283 in Beatport Player 1.0.0.0 allows remote attackers to execu
23RIESGO
abrir
Referência
CVE-2022-41082
CVE-2022-41082HIGHbajo ataqueransomware
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
Referência
CVE-2025-59287
CVE-2025-59287CRITICALbajo ataque
Windows Server Update Service (WSUS) Remote Code Execution Vulnerability
100RIESGO
abrir
Referência
CVE-2011-4106
TimThumb (timthumb.php) before 2.0 does not validate the entire source with the domain white list, which allows remote a
28RIESGO
abrir
Referência
CVE-2025-32432
CVE-2025-32432CRITICALbajo ataque
Craft CMS Allows Remote Code Execution
100RIESGO
abrir
ReferênciaVexDay Proof
Easy Scripts Answer and Question Script - Multiple Vulnerabilities
CVE-2009-1664webappsphp
myaccount.php in Easy Scripts Answer and Question Script does not verify the original password before changing passwords
23RIESGO
abrir
Referência
CVE-2015-1130
CVE-2015-1130HIGHbajo ataque
The XPC implementation in Admin Framework in Apple OS X before 10.10.3 allows local users to bypass authentication and o
86RIESGO
abrir
anteriorpágina 605 / 754siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.