Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.101exploits catalogados
35.950CVEs con explotación pública
24.695probados en laboratorio
22.640 exploits
ReferênciaVexDay Proof
OpenForum 0.66 Beta - Remote Reset Admin Password
CVE-2008-7066webappsphp
OpenForum 0.66 Beta allows remote attackers to bypass authentication and reset passwords of other users via a direct req
23RIESGO
abrir
ReferênciaVexDay Proof
Ultimate HelpDesk - Cross-Site Scripting / Local File Disclosure
CVE-2006-6381webappsasp
Directory traversal vulnerability in getfile.asp in Ultimate HelpDesk allows remote attackers to read arbitrary files vi
23RIESGO
abrir
ReferênciaVexDay Proof
pivot 1.40.4-7 - Multiple Vulnerabilities
CVE-2009-2134webappsphp
pivot/tb.php in Pivot 1.40.4 and 1.40.7 allows remote attackers to obtain sensitive information via an invalid url param
23RIESGO
abrir
ReferênciaVexDay Proof
ASP-Nuke Community 1.5 - Cookie Privilege Escalation
CVE-2006-7152webappsasp
default.asp in ASP-Nuke Community 1.5 and earlier allows remote attackers to gain privileges by setting certain pseudo c
23RIESGO
abrir
ReferênciaVexDay Proof
McGallery 0.5b - 'download.php' Arbitrary File Download
CVE-2007-1478webappsphp
download.php in McGallery 0.5b allows remote attackers to read arbitrary files and obtain script source code via the fil
23RIESGO
abrir
ReferênciaVexDay Proof
PBLang 4.67.16.a - Remote Code Execution
CVE-2007-3096webappsphp
Directory traversal vulnerability in login.php in PBLang (PBL) 4.67.16.a and earlier, when magic_quotes_gpc is disabled,
23RIESGO
abrir
ReferênciaVexDay Proof
Evilsentinel 1.0.9 - Multiple Vulnerabilities Disable
CVE-2008-0350webappsphp
admin/index.php in Evilsentinel 1.0.9 and earlier sends a redirect to the web browser but does not exit, which allows re
23RIESGO
abrir
ReferênciaVexDay Proof
freePHPgallery 0.6 - Cookie Local File Inclusion
CVE-2008-0818webappsphp
Multiple directory traversal vulnerabilities in freePHPgallery 0.6 allow remote attackers to include and execute arbitra
23RIESGO
abrir
Referência
CVE-2012-5228
Cross-site scripting (XSS) vulnerability in admin/index.php in phplist 2.10.9, 2.10.17, and possibly other versions befo
23RIESGO
abrir
Referência
CVE-2013-10040
ClipBucket <= 2.6 ofc_upload_image.php Arbitrary File Upload RCE
63RIESGO
abrir
Referência
CVE-2013-10040
ClipBucket <= 2.6 ofc_upload_image.php Arbitrary File Upload RCE
63RIESGO
abrir
Referência
CVE-2010-5289
Buffer overflow in the Authenticate method in the INCREDISPOOLERLib.Pop ActiveX control in ImSpoolU.dll in IncrediMail 2
23RIESGO
abrir
Referência
CVE-2017-15730
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.ratings.php.
23RIESGO
abrir
Referência
CVE-2018-7198
October CMS through 1.0.431 allows XSS by entering HTML on the Add Posts page.
23RIESGO
abrir
Referência
CVE-2017-17615
Facebook Clone Script 1.0 has SQL Injection via the friend-profile.php id parameter.
23RIESGO
abrir
Referência
CVE-2017-17615
Facebook Clone Script 1.0 has SQL Injection via the friend-profile.php id parameter.
23RIESGO
abrir
ReferênciaVexDay Proof
iScripts Socialware - 'id' SQL Injection
CVE-2008-1772webappsphp
iScripts SocialWare stores passwords in cleartext in a database, which allows context-dependent attackers to obtain sens
23RIESGO
abrir
Referência
CVE-2014-9243
Multiple cross-site scripting (XSS) vulnerabilities in WebsiteBaker 2.8.3 allow remote attackers to inject arbitrary web
23RIESGO
abrir
Referência
CVE-2013-6058
SQL injection vulnerability in appRain CMF 3.0.2 and earlier allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
Referência
CVE-2013-6058
SQL injection vulnerability in appRain CMF 3.0.2 and earlier allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
Referência
CVE-2018-9092
There is a CSRF vulnerability in mc-admin/conf.php in MiniCMS 1.10 that can change the administrator account password.
23RIESGO
abrir
Referência
CVE-2012-2940
MediaChance Real-DRAW PRO 5.2.4 allows remote attackers to cause a denial of service (application crash) via a crafted (
23RIESGO
abrir
ReferênciaVexDay Proof
BtiTracker 1.4.7 / xbtit 2.0.542 - SQL Injection
CVE-2008-3784webappsphp
SQL injection vulnerability in scrape.php in BtiTracker 1.4.7 and earlier and xBtiTracker 2.0.542 and earlier allows rem
23RIESGO
abrir
ReferênciaVexDay Proof
IndexScript 2.8 - 'cat_id' SQL Injection
CVE-2007-4069webappsphp
SQL injection vulnerability in show_cat.php in IndexScript 2.8 and earlier allows remote attackers to execute arbitrary
23RIESGO
abrir
Referência
CVE-2010-0755
PHP remote file inclusion vulnerability in include/WBmap.php in WikyBlog 1.7.3 rc2 allows remote attackers to execute ar
23RIESGO
abrir
Referência
CVE-2010-0755
PHP remote file inclusion vulnerability in include/WBmap.php in WikyBlog 1.7.3 rc2 allows remote attackers to execute ar
23RIESGO
abrir
Referência
CVE-2016-3053
IBM AIX contains an unspecified vulnerability that would allow a locally authenticated user to obtain root level privile
23RIESGO
abrir
Referência
CVE-2024-22638
liveSite v2019.1 was discovered to contain a remote code execution (RCE) vulenrabiity via the component /livesite/edit_d
48RIESGO
abrir
Referência
CVE-2024-22638
liveSite v2019.1 was discovered to contain a remote code execution (RCE) vulenrabiity via the component /livesite/edit_d
48RIESGO
abrir
Referência
CVE-2003-20001
An issue was discovered on Mitel ICP VoIP 3100 devices. When a remote user attempts to log in via TELNET during the logi
33RIESGO
abrir
anteriorpágina 634 / 755siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.