Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.137exploits catalogados
35.961CVEs con explotación pública
24.695probados en laboratorio
22.640 exploits
ReferênciaVexDay Proof
XZero Community Classifieds 4.95.11 - Remote File Inclusion
CVE-2007-6568webappsphp
PHP remote file inclusion vulnerability in config.inc.php in XZero Community Classifieds 4.95.11 and earlier allows remo
23RIESGO
abrir
Referência
CVE-2012-1260
Cross-site scripting (XSS) vulnerability in cgi-bin/userprefs.cgi in Plixer International Scrutinizer NetFlow & sFlow An
23RIESGO
abrir
Referência
CVE-2020-37027
Sickbeard 0.1 - Remote Command Injection
48RIESGO
abrir
Referência
CVE-2015-5075
Cross-site request forgery (CSRF) vulnerability in X2Engine X2CRM before 5.2 allows remote attackers to hijack the authe
23RIESGO
abrir
Referência
CVE-2010-1467
Multiple PHP remote file inclusion vulnerabilities in openUrgence Vaccin 1.03 allow remote attackers to execute arbitrar
23RIESGO
abrir
Referência
CVE-2017-1000370
The offset2lib patch as used in the Linux Kernel contains a vulnerability that allows a PIE binary to be execve()'ed wit
23RIESGO
abrir
ReferênciaVexDay Proof
FlexPHPNews 0.0.5 - 'newsid' SQL Injection
CVE-2005-1237webappsphp
SQL injection vulnerability in news.php in FlexPHPNews 0.0.3 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
ReferênciaVexDay Proof
XchangeBoard 1.70 - 'boardID' SQL Injection
CVE-2008-3035webappsphp
SQL injection vulnerability in newThread.php in XchangeBoard 1.70 Final and earlier allows remote authenticated users to
23RIESGO
abrir
Referência
CVE-2009-4801
EZ-Blog Beta 1 does not require authentication, which allows remote attackers to create or delete arbitrary posts via re
23RIESGO
abrir
Referência
CVE-2009-4670
admin/delitem.php in RoomPHPlanning 1.6 does not require authentication, which allows remote attackers to (1) delete arb
23RIESGO
abrir
ReferênciaVexDay Proof
Netartmedia Cars Portal 2.0 - SQL Injection
CVE-2008-5310webappsphp
SQL injection vulnerability in image.php in NetArt Media Car Portal 2.0 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
Referência
CVE-2018-18856
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS.
23RIESGO
abrir
Referência
CVE-2018-18856
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS.
23RIESGO
abrir
ReferênciaVexDay Proof
myPHPCalendar 10192000b - 'cal_dir' Remote File Inclusion
CVE-2006-6812webappsphp
Multiple PHP remote file inclusion vulnerabilities in myPHPCalendar 10.1 allow remote attackers to execute arbitrary PHP
23RIESGO
abrir
ReferênciaVexDay Proof
ASP Download 1.03 - Arbitrary Change Administrator Account
CVE-2008-6739webappsasp
Todd Woolums ASP Download management script 1.03 does not require authentication for setupdownload.asp, which allows rem
23RIESGO
abrir
Referência
CVE-2013-2594
SQL injection vulnerability in reports/calldiary.php in Hornbill Supportworks ITSM 1.0.0 through 3.4.14 allows remote at
23RIESGO
abrir
ReferênciaVexDay Proof
Koschtit Image Gallery 1.82 - Multiple Local File Inclusions
CVE-2009-1510webappsphp
Multiple directory traversal vulnerabilities in KoschtIT Image Gallery 1.82 allow remote attackers to include and execut
23RIESGO
abrir
ReferênciaVexDay Proof
MeGaCheatZ 1.1 - Multiple SQL Injections
CVE-2007-6557webappsphp
Multiple SQL injection vulnerabilities in MeGaCheatZ 1.1 allow remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir
ReferênciaVexDay Proof
minimal Gallery 0.8 - Remote File Disclosure
CVE-2008-0259webappsphp
Multiple directory traversal vulnerabilities in _mg/php/mg_thumbs.php in minimal Gallery 0.8 allow remote attackers to r
23RIESGO
abrir
ReferênciaVexDay Proof
DomPHP 0.82 - 'index.php' Local File Inclusion
CVE-2008-0745webappsphp
Directory traversal vulnerability in aides/index.php in DomPHP 0.82 allows remote attackers to include and execute arbit
23RIESGO
abrir
Referência
CVE-2024-36840
SQL Injection vulnerability in Boelter Blue System Management v.1.3 allows a remote attacker to execute arbitrary code a
48RIESGO
abrir
Referência
CVE-2024-36840
SQL Injection vulnerability in Boelter Blue System Management v.1.3 allows a remote attacker to execute arbitrary code a
48RIESGO
abrir
Referência
CVE-2009-2780
Multiple cross-site scripting (XSS) vulnerabilities in 68 Classifieds 4.1 allow remote attackers to inject arbitrary web
23RIESGO
abrir
Referência
CVE-2009-4433
Multiple cross-site scripting (XSS) vulnerabilities in IDevSpot iSupport 1.8 and earlier allow remote attackers to injec
23RIESGO
abrir
Referência
CVE-2014-3934
SQL injection vulnerability in the Submit_News module for PHP-Nuke 8.3 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
Referência
CVE-2026-14821
Quiz And Survey Master < 11.1.5 - Contributor+ Arbitrary Template Deletion
28RIESGO
abrir
Referência
CVE-2023-42628
Stored cross-site scripting (XSS) vulnerability in the Wiki widget in Liferay Portal 7.1.0 through 7.4.3.87, and Liferay
48RIESGO
abrir
Referência
CVE-2023-42629
Stored cross-site scripting (XSS) vulnerability in the manage vocabulary page in Liferay Portal 7.4.2 through 7.4.3.87,
48RIESGO
abrir
Referência
CVE-2015-7889
The SecEmailComposer/EmailComposer application in the Samsung S6 Edge before the October 2015 MR uses weak permissions f
23RIESGO
abrir
Referência
CVE-2015-7889
The SecEmailComposer/EmailComposer application in the Samsung S6 Edge before the October 2015 MR uses weak permissions f
23RIESGO
abrir
anteriorpágina 638 / 755siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.