Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.137exploits catalogados
35.961CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.458Referência 22.657GitHub PoC 14.424VulnCheck XDB 8773Nuclei 4340Metasploit 3485✓ solo verificadosrecientespopularesriesgo
22.657 exploits
Referência
CVE-2017-0115
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers
28RIESGO
abrir ↗Referência
CVE-2015-6516
SQL injection vulnerability in cygnux.org sysPass 1.0.9 and earlier allows remote authenticated users to execute arbitra
23RIESGO
abrir ↗Referência
CVE-2009-2218
Multiple PHP remote file inclusion vulnerabilities in phpCollegeExchange 0.1.5c, when register_globals is enabled, allow
23RIESGO
abrir ↗Referência
CVE-2009-3359
Multiple cross-site scripting (XSS) vulnerabilities in Match Agency BiZ 1.0 allow remote attackers to inject arbitrary w
23RIESGO
abrir ↗Referência
CVE-2009-3186
Multiple cross-site scripting (XSS) vulnerabilities in VideoGirls BiZ allow remote attackers to inject arbitrary web scr
23RIESGO
abrir ↗Referência✓ VexDay Proof
Angelo-Emlak 1.0 - Multiple SQL Injections
Cross-site scripting (XSS) vulnerability in hpz/admin/Default.asp in Angelo-Emlak 1.0 allows remote attackers to inject
23RIESGO
abrir ↗Referência
CVE-2009-3715
Multiple SQL injection vulnerabilities in scr_login.php in MCshoutbox 1.1, when magic_quotes_gpc is disabled, allow remo
23RIESGO
abrir ↗Referência✓ VexDay Proof
W1L3D4 philboard 1.2 - Blind SQL Injection / Cross-Site Scripting
Cross-site scripting (XSS) vulnerability in search.asp in W1L3D4 Philboard 1.14 and 1.2 allows remote attackers to injec
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpcrs 2.06 - 'importFunction' Local File Inclusion
Directory traversal vulnerability in frame.php in phpcrs 2.06 and earlier, when magic_quotes_gpc is disabled, allows rem
23RIESGO
abrir ↗Referência
CVE-2018-18858
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS.
23RIESGO
abrir ↗Referência
CVE-2018-18858
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS.
23RIESGO
abrir ↗Referência✓ VexDay Proof
Yet Another NOCC 0.1.0 - Local File Inclusion
Directory traversal vulnerability in check_lang.php in Yet Another NOCC (YANOCC) 0.1.0 and earlier allows remote attacke
23RIESGO
abrir ↗Referência✓ VexDay Proof
LiveCMS 3.4 - 'categoria.php?cid' SQL Injection
Cross-site scripting (XSS) vulnerability in LiveCMS 3.4 and earlier allows remote attackers to inject arbitrary web scri
23RIESGO
abrir ↗Referência✓ VexDay Proof
Dokeos 1.8.4 - Arbitrary File Upload
Unrestricted file upload vulnerability in the "My productions" component for main/auth/profile.php (aka the "My profile"
23RIESGO
abrir ↗Referência
CVE-2015-6517
Cross-site request forgery (CSRF) vulnerability in phpLiteAdmin 1.1 allows remote attackers to hijack the authentication
23RIESGO
abrir ↗Referência
RAD SecFlow-1v SF_0290_2.3.01.26 - Persistent Cross-Site Scripting
A vulnerability in the web-based management interface of RAD SecFlow-1v through 2020-05-21 could allow an authenticated
23RIESGO
abrir ↗Referência✓ VexDay Proof
Barracuda Spam Firewall 3.5.11.020 Model 600 - SQL Injection
SQL injection vulnerability in index.cgi in the Account View page in Barracuda Spam Firewall (BSF) before 3.5.12.007 all
23RIESGO
abrir ↗Referência
CVE-2015-6567
Wolf CMS before 0.8.3.1 allows unrestricted file upload and PHP Code Execution because admin/plugin/file_manager/browse/
28RIESGO
abrir ↗Referência✓ VexDay Proof
EntertainmentScript 1.4.0 - 'page.php' Local File Inclusion
Directory traversal vulnerability in page.php in EntertainmentScript 1.4.0 allows remote attackers to include and execut
23RIESGO
abrir ↗Referência
CVE-2022-33098
Magnolia CMS v6.2.19 was discovered to contain a cross-site scripting (XSS) vulnerability via the Edit Contact function.
35RIESGO
abrir ↗Referência
CVE-2018-5211
PHP Melody version 2.7.1 suffer from SQL Injection Time-based attack on the page ajax.php with the parameter playlist.
23RIESGO
abrir ↗Referência
CVE-2014-3414
Cross-site request forgery (CSRF) vulnerability in Sharetronix before 3.4 allows remote attackers to hijack the authenti
23RIESGO
abrir ↗Referência✓ VexDay Proof
FubarForum 1.5 - 'index.php' Local File Inclusion
Directory traversal vulnerability in index.php in chaozz@work FubarForum 1.5 allows remote attackers to include and exec
23RIESGO
abrir ↗Referência
CVE-2013-6826
cgi-bin/module//sysmanager/admin/SYSAdminUserDialog in Fortinet FortiAnalyzer before 5.0.5 does not properly validate th
23RIESGO
abrir ↗Referência✓ VexDay Proof
Minishowcase 09b136 - 'lang' Local File Inclusion
Directory traversal vulnerability in libraries/general.init.php in Minishowcase Image Gallery 09b136, when register_glob
23RIESGO
abrir ↗Referência
CVE-2018-14894
CyberArk Endpoint Privilege Manager 10.2.1.603 and earlier allows an attacker (who is able to edit permissions of a file
23RIESGO
abrir ↗Referência
CVE-2012-5343
Cross-site scripting (XSS) vulnerability in admin/login.php in Limny 3.0.1 allows remote attackers to inject arbitrary w
23RIESGO
abrir ↗Referência
CVE-2010-2122
Directory traversal vulnerability in the SimpleDownload (com_simpledownload) component before 0.9.6 for Joomla! allows r
43RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.