Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.207exploits catalogados
36.011CVEs con explotación pública
24.695probados en laboratorio
22.657 exploits
Referência
CVE-2009-4552
Cross-site scripting (XSS) vulnerability in the Survey Pro module for Miniweb 2.0 allows remote attackers to inject arbi
23RIESGO
abrir
Referência
CVE-2010-2700
Cross-site scripting (XSS) vulnerability in index.php in Edge PHP Clickbank Affiliate Marketplace Script (CBQuick) allow
23RIESGO
abrir
Referência
CVE-2009-3420
Multiple cross-site scripting (XSS) vulnerabilities in index.php in the Publisher module 2.0 for Miniweb allow remote at
23RIESGO
abrir
Referência
CVE-2007-3812
SQL injection vulnerability in forums.php in CMScout 1.23 and earlier allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
Referência
CVE-2007-3812
SQL injection vulnerability in forums.php in CMScout 1.23 and earlier allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
Referência
CVE-2014-7822
The implementation of certain splice_write file operations in the Linux kernel before 3.16 does not enforce a restrictio
23RIESGO
abrir
ReferênciaVexDay Proof
MyFWB 1.0 - 'index.php' SQL Injection
CVE-2008-5097webappsphp
SQL injection vulnerability in index.php in MyFWB 1.0 allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir
Referência
CVE-2024-13980
H3C Intelligent Management Center (iMC) /byod/index.xhtml RCE
48RIESGO
abrir
Referência
CVE-2024-13980
H3C Intelligent Management Center (iMC) /byod/index.xhtml RCE
48RIESGO
abrir
Referência
CVE-2024-13980
H3C Intelligent Management Center (iMC) /byod/index.xhtml RCE
48RIESGO
abrir
Referência
CVE-2024-13980
H3C Intelligent Management Center (iMC) /byod/index.xhtml RCE
48RIESGO
abrir
Referência
CVE-2009-2894
Multiple SQL injection vulnerabilities in Ebay Clone 2009 allow remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir
Referência
CVE-2009-0445
SQL injection vulnerability in index.php in Dreampics Gallery Builder allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
Referência
CVE-2010-0720
SQL injection vulnerability in news.php in Erotik Auktionshaus allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
Referência
CVE-2010-0720
SQL injection vulnerability in news.php in Erotik Auktionshaus allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
Referência
CVE-2010-4619
SQL injection vulnerability in profil.php in Mafya Oyun Scrpti (aka Mafia Game Script) allows remote attackers to execut
23RIESGO
abrir
Referência
WonderCMS 3.1.3 - 'Menu' Persistent Cross-Site Scripting
CVE-2020-29469webappsphp
WonderCMS 3.1.3 is affected by cross-site scripting (XSS) in the Menu component. This vulnerability can allow an attacke
23RIESGO
abrir
Referência
OpenCart 3.0.3.6 - 'Profile Image' Stored Cross-Site Scripting (Authenticated)
CVE-2020-29471webappsphp
OpenCart 3.0.3.6 is affected by cross-site scripting (XSS) in the Profile Image. An admin can upload a profile image as
23RIESGO
abrir
Referência
CVE-2010-2681
PHP remote file inclusion vulnerability in the SEF404x (com_sef) component for Joomla! allows remote attackers to execut
23RIESGO
abrir
ReferênciaVexDay Proof
DCFM Blog 0.9.4 - SQL Injection
CVE-2008-2671webappsphp
SQL injection vulnerability in comments.php in DCFM Blog 0.9.4 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
Referência
CVE-2009-4349
Cross-site request forgery (CSRF) vulnerability in administration/administrators.php in Link Up Gold 5.0 allows remote a
23RIESGO
abrir
Referência
CVE-2009-4349
Cross-site request forgery (CSRF) vulnerability in administration/administrators.php in Link Up Gold 5.0 allows remote a
23RIESGO
abrir
ReferênciaVexDay Proof
PHP-Nuke Module My_eGallery 2.7.9 - SQL Injection
CVE-2008-7038webappsphp
SQL injection vulnerability in the My_eGallery module for PHP-Nuke allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
ReferênciaVexDay Proof
BigACE 2.5 - SQL Injection
CVE-2009-1778webappsphp
SQL injection vulnerability in the new user registration feature in BigACE CMS 2.5, when magic_quotes_gpc is disabled, a
23RIESGO
abrir
Referência
CVE-2004-1689
sudoedit (aka sudo -e) in sudo 1.6.8 opens a temporary file with root privileges, which allows local users to read arbit
23RIESGO
abrir
Referência
CVE-2010-4906
SQL injection vulnerability in zp-core/full-image.php in Zenphoto 1.3 and 1.3.1.2 allows remote attackers to execute arb
23RIESGO
abrir
Referência
CVE-2010-2682
Directory traversal vulnerability in the Realtyna Translator (com_realtyna) component 1.0.15 for Joomla! allows remote a
43RIESGO
abrir
Referência
CVE-2016-0846
libs/binder/IMemory.cpp in the IMemory Native Interface in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.
23RIESGO
abrir
ReferênciaVexDay Proof
See-Commerce 1.0.625 - 'owimg.php3' Remote File Inclusion
CVE-2006-4121webappsphp
PHP remote file inclusion vulnerability in owimg.php3 in See-Commerce 1.0.625 and earlier allows remote attackers to exe
23RIESGO
abrir
ReferênciaVexDay Proof
eNdonesia 8.4 - '/mod.php/friend.php/admin.php' Multiple Vulnerabilities
CVE-2006-6873webappsphp
Multiple SQL injection vulnerabilities in mod.php in eNdonesia 8.4 allow remote attackers to execute arbitrary SQL comma
23RIESGO
abrir
anteriorpágina 663 / 756siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.