Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.056exploits catalogados
35.925CVEs con explotación pública
24.695probados en laboratorio
22.600 exploits
Referência
CVE-2017-5264
Versions of Nexpose prior to 6.4.66 fail to adequately validate the source of HTTP requests intended for the Automated A
23RIESGO
abrir
Referência
CVE-2012-2442
Buffer overflow in the Video Manager in Nokia PC Suite 7.1.180.64 and earlier allows remote attackers to cause a denial
23RIESGO
abrir
Referência
CVE-2012-2442
Buffer overflow in the Video Manager in Nokia PC Suite 7.1.180.64 and earlier allows remote attackers to cause a denial
23RIESGO
abrir
ReferênciaVexDay Proof
Multi-Page Comment System 1.1.0 - Insecure Cookie Handling
CVE-2008-2293webappsphp
admin.php in Multi-Page Comment System (MPCS) 1.0 and 1.1 allows remote attackers to bypass authentication and gain priv
23RIESGO
abrir
Referência
CVE-2019-14346
Internal/Views/config.php in Schben Adive 2.0.7 allows admin/config CSRF to change a user password.
23RIESGO
abrir
Referência
CVE-2009-3912
Directory traversal vulnerability in index.php in TFTgallery 0.13 allows remote attackers to read arbitrary files via a
23RIESGO
abrir
Referência
CVE-2012-5863
Sinapsi eSolar OS Command Injection
53RIESGO
abrir
Referência
CVE-2009-3123
Directory traversal vulnerability in gallery/gallery.php in Wap-Motor before 18.1 allows remote attackers to read arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
Galatolo Web Manager 1.0 - SQL Injection
CVE-2008-2700webappsphp
SQL injection vulnerability in view.php in Galatolo WebManager 1.0 and earlier allows remote attackers to execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
WebCreator 0.2.6-rc3 - 'moddir' Remote File Inclusion
CVE-2007-1459webappsphp
Multiple PHP remote file inclusion vulnerabilities in WebCreator 0.2.6-rc3 and earlier allow remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
AyeView 2.20 - Invalid Bitmap Header Parsing Crash
CVE-2008-5937doswindows
AyeView 2.20 allows user-assisted attackers to cause a denial of service (memory consumption or application crash) via a
23RIESGO
abrir
ReferênciaVexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
CVE-2007-6502webappsasp
Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to obtain sensitive information via (1)
23RIESGO
abrir
ReferênciaVexDay Proof
Gravy Media Photo Host 1.0.8 - Local File Disclosure
CVE-2009-2184webappsphp
Absolute path traversal vulnerability in forcedownload.php in Gravy Media Photo Host 1.0.8 allows remote attackers to re
23RIESGO
abrir
Referência
CVE-2009-3151
Directory traversal vulnerability in actions/downloadFile.php in Ultrize TimeSheet 1.2.2 allows remote attackers to read
23RIESGO
abrir
Referência
CVE-2018-11443
The parameter q is affected by Cross-site Scripting in jobcard-ongoing.php in EasyService Billing 1.0.
23RIESGO
abrir
Referência
CVE-2026-33829
Windows Snipping Tool Spoofing Vulnerability
33RIESGO
abrir
ReferênciaVexDay Proof
JShop 1.x < 2.x - 'xPage' Local File Inclusion
CVE-2008-1624webappsphp
Directory traversal vulnerability in v2demo/page.php in Jshop Server 1.x through 2.x allows remote attackers to include
23RIESGO
abrir
Referência
CVE-2017-6331
Prior to SEP 14 RU1 Symantec Endpoint Protection product can encounter an issue of Tamper-Protection Bypass, which is a
23RIESGO
abrir
Referência
CVE-2009-4748
SQL injection vulnerability in mycategoryorder.php in the My Category Order plugin 2.8 and earlier for WordPress allows
23RIESGO
abrir
Referência
CVE-2009-4748
SQL injection vulnerability in mycategoryorder.php in the My Category Order plugin 2.8 and earlier for WordPress allows
23RIESGO
abrir
ReferênciaVexDay Proof
UBBCentral UBB.Threads 6.4.x < 6.5.2 - 'thispath' Remote File Inclusion
CVE-2006-2568webappsphp
PHP remote file inclusion vulnerability in addpost_newpoll.php in UBB.threads 6.4 through 6.5.2 and 6.5.1.1 (trial) allo
23RIESGO
abrir
ReferênciaVexDay Proof
VidShare Pro - Arbitrary File Upload
CVE-2009-1750webappsphp
Unrestricted file upload vulnerability in VidSharePro allows remote authenticated users to execute arbitrary code by upl
23RIESGO
abrir
Referência
CVE-2015-1517
SQL injection vulnerability in Piwigo before 2.7.4, when all filters are activated, allows remote authenticated users to
23RIESGO
abrir
Referência
CVE-2010-0967
Multiple directory traversal vulnerabilities in Geekhelps ADMP 1.01, when magic_quotes_gpc is disabled, allow remote att
23RIESGO
abrir
Referência
CVE-2024-27620
An issue in Ladder v.0.0.1 thru v.0.0.21 allows a remote attacker to obtain sensitive information via a crafted request
41RIESGO
abrir
Referência
CVE-2010-1475
Directory traversal vulnerability in the Preventive & Reservation (com_preventive) component 1.0.5 for Joomla! allows re
38RIESGO
abrir
ReferênciaVexDay Proof
Sisfo Kampus 2006 - 'dwoprn.php?f' Arbitrary File Download
CVE-2007-4895webappsphp
Directory traversal vulnerability in dwoprn.php in Sisfo Kampus 2006 (Semarang 3) allows remote attackers to read arbitr
23RIESGO
abrir
Referência
CVE-2026-74843
Wavlink WN531P3/WN535M1 Export Pingortrace CGI export_pingortrace.cgi strcpy stack-based overflow
48RIESGO
abrir
ReferênciaVexDay Proof
AlkalinePHP 0.77.35 - 'adduser.php' Arbitrary Add Admin
CVE-2008-2346webappsphp
AlkalinePHP 0.77.35 and earlier allows remote attackers to bypass authentication and gain administrative access by creat
23RIESGO
abrir
Referência
CVE-2014-2022
SQL injection vulnerability in includes/api/4/breadcrumbs_create.php in vBulletin 4.2.2, 4.2.1, 4.2.0 PL2, and earlier a
23RIESGO
abrir
anteriorpágina 620 / 754siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.