Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.056exploits catalogados
35.925CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.458Referência 22.640GitHub PoC 14.392VulnCheck XDB 8755Nuclei 4333Metasploit 3478✓ solo verificadosrecientespopularesriesgo
22.600 exploits
Referência
CVE-2009-4760
Winn ASP Guestbook 1.01 Beta stores sensitive information under the web root with insufficient access control, which all
23RIESGO
abrir ↗Referência
CVE-2016-4205
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acro
28RIESGO
abrir ↗Referência
CVE-2009-4799
Diskos CMS 6.x stores sensitive information under the web root with insufficient access control, which allows remote att
23RIESGO
abrir ↗Referência
CVE-2026-71969
OP-TEE OS 4.10.0 Buffer Underwrite via RSA NOPAD Encrypt/Decrypt Operations
41RIESGO
abrir ↗Referência
CVE-2023-31698
Bludit v3.14.1 is vulnerable to Stored Cross Site Scripting (XSS) via SVG file on site logo. NOTE: the product's securit
23RIESGO
abrir ↗Referência
CVE-2012-6568
Buffer overflow in the back-end component in Huawei UTPS 1.0 allows local users to gain privileges via a long IDS_PLUGIN
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP Webquest 2.6 - Get Database Credentials
PHP Webquest 2.6 allows remote attackers to retrieve database credentials via a direct request to admin/backup_phpwebque
23RIESGO
abrir ↗Referência
CVE-2012-6584
Multiple SQL injection vulnerabilities in MYRE Realty Manager allow remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗Referência✓ VexDay Proof
Nukedit 4.9.8 - Remote Database Disclosure
Nukedit 4.9.8 stores sensitive information under the web root with insufficient access control, which allows remote atta
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joovili 3.1.4 - Insecure Cookie Handling
Joovili 3.1.4 allows remote attackers to bypass authentication and gain privileges as other users, including the adminis
23RIESGO
abrir ↗Referência✓ VexDay Proof
TurnkeyForms Entertainment Portal 2.0 - Insecure Cookie Handling
TurnkeyForms Entertainment Portal 2.0 allows remote attackers to bypass authentication and gain administrative access by
23RIESGO
abrir ↗Referência✓ VexDay Proof
Free PHP VX Guestbook 1.06 - Insecure Cookie Handling
Free PHP VX Guestbook 1.06 allows remote attackers to bypass authentication and gain administrative access by setting th
23RIESGO
abrir ↗Referência
CVE-2014-1206
SQL injection vulnerability in the password reset page in Open Web Analytics (OWA) before 1.5.5 allows remote attackers
23RIESGO
abrir ↗Referência
CVE-2010-1604
Multiple SQL injection vulnerabilities in admin_login.php in NCT Jobs Portal Script allow remote attackers to execute ar
23RIESGO
abrir ↗Referência
CVE-2009-3423
login.php in Zenas PaoLink 1.0, when register_globals is enabled, allows remote attackers to bypass authentication and g
23RIESGO
abrir ↗Referência
CVE-2019-12745
out/out.UsrMgr.php in SeedDMS before 5.1.11 allows Stored Cross-Site Scripting (XSS) via the name field.
23RIESGO
abrir ↗Referência✓ VexDay Proof
shibby shop 2.2 - Multiple Vulnerabilities
SQL injection vulnerability in default.asp in sHibby sHop 2.2 and earlier allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗Referência
CVE-2013-3524
SQL injection vulnerability in popupnewsitem/ in the Pop Up News module 2.0 and possibly earlier for phpVMS allows remot
23RIESGO
abrir ↗Referência✓ VexDay Proof
shibby shop 2.2 - Multiple Vulnerabilities
sHibby sHop 2.2 and earlier stores sensitive information under the web root with insufficient access control, which allo
23RIESGO
abrir ↗Referência
CVE-2018-10366
An issue was discovered in the Users (aka Front-end user management) plugin 1.4.5 for October CMS. XSS exists in the nam
23RIESGO
abrir ↗Referência
CVE-2008-5943
Multiple directory traversal vulnerabilities in NavBoard 16 (2.6.0) allow remote attackers to include and execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
PhpCommander 3.0 - 'upload' Remote Code Execution
Directory traversal vulnerability in SZEWO PhpCommander 3.0 and earlier allows remote attackers to include and execute a
23RIESGO
abrir ↗Referência✓ VexDay Proof
Ninja Blog 4.8 - Remote Information Disclosure
Directory traversal vulnerability in entries/index.php in Ninja Blog 4.8, when magic_quotes_gpc is disabled, allows remo
23RIESGO
abrir ↗Referência✓ VexDay Proof
Polaring 0.04.03 - 'general.php' Remote File Inclusion
PHP remote file inclusion vulnerability in view/general.php in Kristian Niemi Polaring 00.04.03 and earlier allows remot
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpYabs 0.1.2 - 'Azione' Remote File Inclusion
PHP remote file inclusion vulnerability in moduli/libri/index.php in phpyabs 0.1.2 allows remote attackers to execute ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
WebBuilder 2.0 - 'StageLoader.php' Remote File Inclusion
PHP remote file inclusion vulnerability in library/StageLoader.php in WebBuilder 2.0 and earlier allows remote attackers
23RIESGO
abrir ↗Referência✓ VexDay Proof
Webavis 0.1.1 - 'class.php?root' Remote File Inclusion
PHP remote file inclusion vulnerability in class/class.php in Webavis 0.1.1 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
LimeSurvey 1.52 - 'language.php' Remote File Inclusion
PHP remote file inclusion vulnerability in classes/core/language.php in LimeSurvey 1.5.2 and earlier allows remote attac
23RIESGO
abrir ↗Referência
CVE-2014-5520
SQL injection vulnerability in XRMS CRM, possibly 1.99.2, allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗Referência
CVE-2022-40797
Roxy Fileman 1.4.6 allows Remote Code Execution via a .phar upload, because the default FORBIDDEN_UPLOADS value in conf.
48RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.