Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.056exploits catalogados
35.925CVEs con explotación pública
24.695probados en laboratorio
22.600 exploits
ReferênciaVexDay Proof
AJ Auction - Authentication Bypass
CVE-2008-6966webappsphp
AJ Square AJ Auction Pro Platinum Skin #1 sends a redirect but does not exit when it is called directly, which allows re
23RIESGO
abrir
Referência
CVE-2026-40521
FrontAccounting < 2.4.20 Path Traversal RCE via attachment upload
41RIESGO
abrir
ReferênciaVexDay Proof
Enthrallweb eClassifieds 1.0 - Remote User Pass Change
CVE-2006-6822webappsasp
myprofile.asp in Enthrallweb eClassifieds does not properly validate the MM_recordId parameter during profile updates, w
23RIESGO
abrir
ReferênciaVexDay Proof
Tuned Studios Templates - Local File Inclusion
CVE-2008-0231webappsphp
Multiple directory traversal vulnerabilities in index.php in Tuned Studios (1) Subwoofer, (2) Freeze Theme, (3) Orange C
23RIESGO
abrir
Referência
CVE-2012-6044
M-Player 0.4 allows remote attackers to cause a denial of service (crash) via a crafted MP3 file.
23RIESGO
abrir
Referência
CVE-2018-7176
FrontAccounting 2.4.3 suffers from a CSRF flaw, which leads to adding a user account via admin/users.php (aka the "add u
23RIESGO
abrir
Referência
CVE-2013-6936
Multiple SQL injection vulnerabilities in ajaxfs.php in the Ajax forum stat (Ajaxfs) Plugin 2.0 for MyBB (aka MyBulletin
23RIESGO
abrir
Referência
CVE-2013-6936
Multiple SQL injection vulnerabilities in ajaxfs.php in the Ajax forum stat (Ajaxfs) Plugin 2.0 for MyBB (aka MyBulletin
23RIESGO
abrir
Referência
CVE-2017-9415
Cross-site request forgery (CSRF) vulnerability in subsonic 6.1.1 allows remote attackers with knowledge of the target u
23RIESGO
abrir
Referência
CVE-2012-10040
Openfiler v2.x NetworkCard Command Execution
63RIESGO
abrir
Referência
CVE-2012-10040
Openfiler v2.x NetworkCard Command Execution
63RIESGO
abrir
Referência
CVE-2012-10040
Openfiler v2.x NetworkCard Command Execution
63RIESGO
abrir
Referência
CVE-2009-4927
WB News 2.1.2 allows remote attackers to bypass authentication and gain administrative access via a modified WBNEWS cook
23RIESGO
abrir
Referência
CVE-2026-14547
Estatik Real Estate Plugin < 4.3.3 - Unauthenticated Arbitrary-Recipient Mail Relay via Request Form
33RIESGO
abrir
ReferênciaVexDay Proof
mini-pub 0.3 - File Disclosure / Code Execution
CVE-2008-5581webappsphp
PHP remote file inclusion vulnerability in mini-pub.php/front-end/img.php in mini-pub 0.3 allows remote attackers to exe
23RIESGO
abrir
ReferênciaVexDay Proof
CFAGCMS 1 - Remote File Inclusion
CVE-2008-5922webappsphp
Multiple PHP remote file inclusion vulnerabilities in themes/default/index.php in Cant Find A Gaming CMS (CFAGCMS) 1 all
23RIESGO
abrir
Referência
CVE-2010-1720
SQL injection vulnerability in the Q-Personel (com_qpersonel) component 1.0.2 and earlier for Joomla! allows remote atta
23RIESGO
abrir
Referência
CVE-2015-3315
Automatic Bug Reporting Tool (ABRT) allows local users to read, change the ownership of, or have other unspecified impac
43RIESGO
abrir
ReferênciaVexDay Proof
basebuilder 2.0.1 - 'main.inc.php' Remote File Inclusion
CVE-2008-6036webappsphp
PHP remote file inclusion vulnerability in main.inc.php in BaseBuilder 2.0.1 and earlier allows remote attackers to exec
23RIESGO
abrir
Referência
CVE-2013-0249
Stack-based buffer overflow in the Curl_sasl_create_digest_md5_message function in lib/curl_sasl.c in curl and libcurl 7
28RIESGO
abrir
Referência
CVE-2010-3603
Cross-site request forgery (CSRF) vulnerability in the file manager service (Services/FileService.ashx) in mojoPortal 2.
23RIESGO
abrir
Referência
CVE-2010-3603
Cross-site request forgery (CSRF) vulnerability in the file manager service (Services/FileService.ashx) in mojoPortal 2.
23RIESGO
abrir
Referência
CVE-2026-13500
antlr ANTLR4 Grammar Action Block OutputFile.java code injection
33RIESGO
abrir
Referência
CVE-2018-14497
Tenda D152 ADSL routers allow XSS via a crafted SSID.
23RIESGO
abrir
Referência
CVE-2018-0901
The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Serve
23RIESGO
abrir
Referência
CVE-2010-1725
SQL injection vulnerability in offers_buy.php in Alibaba Clone Platinum allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
Referência
CVE-2010-1725
SQL injection vulnerability in offers_buy.php in Alibaba Clone Platinum allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
Referência
CVE-2026-16603
Content Protector (Passster) < 4.3.6 - Unauthenticated Category-Locked Content Disclosure via Core REST API
41RIESGO
abrir
Referência
CVE-2010-1726
SQL injection vulnerability in offers_buy.php in EC21 Clone 3.0 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
Referência
CVE-2009-4825
8pixel.net Blog 4 stores sensitive information under the web root with insufficient access control, which allows remote
23RIESGO
abrir
anteriorpágina 629 / 754siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.