Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.459Referência 22.721GitHub PoC 14.946VulnCheck XDB 8829Nuclei 4350Metasploit 3489✓ solo verificadosrecientespopularesriesgo
22.721 exploits
Referência✓ VexDay Proof
Joomla! Component MyAlbum 1.0 - 'album' SQL Injection
SQL injection vulnerability in MyAlbum component (com_myalbum) 1.0 for Joomla! allows remote attackers to execute arbitr
23RIESGO
abrir ↗Referência
Froxlor 0.10.29.1 - SQL Injection (Authenticated)
Froxlor through 0.10.29.1 allows SQL injection in Database/Manager/DbManagerMySQL.php via a custom DB name.
28RIESGO
abrir ↗Referência✓ VexDay Proof
FAQEngine 4.16.03 - 'question.php?questionref' SQL Injection
SQL injection vulnerability in question.php in FAQEngine 4.16.03 and earlier allows remote attackers to execute arbitrar
23RIESGO
abrir ↗Referência✓ VexDay Proof
Build it Fast (bif3) 0.4.1 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Build it Fast (bif3) 0.4.1 allow remote attackers to execute arbit
23RIESGO
abrir ↗Referência
CVE-2022-26352
An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form req
100RIESGO
abrir ↗Referência
CVE-2017-16806
The Process function in RemoteTaskServer/WebServer/HttpServer.cs in Ulterius before 1.9.5.0 allows HTTP server directory
60RIESGO
abrir ↗Referência✓ VexDay Proof
SunLight CMS 5.3 - 'root' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in SunLight CMS 5.3 allow remote attackers to execute arbitrary PHP c
23RIESGO
abrir ↗Referência✓ VexDay Proof
Ol BookMarks Manager 0.7.4 - SQL Injection
SQL injection vulnerability in read/index.php in ol'bookmarks 0.7.4 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗Referência
CVE-2018-16509
An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handlin
60RIESGO
abrir ↗Referência
CVE-2018-3810
Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unau
60RIESGO
abrir ↗Referência
CVE-2009-3023
Buffer overflow in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 6.0 allows remote authen
60RIESGO
abrir ↗Referência✓ VexDay Proof
IMGallery 2.5 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in IMGallery 2.5, when magic_quotes_gpc is disabled, allow remote attackers to ex
23RIESGO
abrir ↗Referência
CVE-2015-8556
Local privilege escalation vulnerability in the Gentoo QEMU package before 2.5.0-r1.
23RIESGO
abrir ↗Referência
CVE-2017-15222
Buffer Overflow vulnerability in Ayukov NFTPD 2.0 and earlier allows remote attackers to execute arbitrary code.
50RIESGO
abrir ↗Referência
CVE-2012-1784
SQL injection vulnerability in MyJobList 0.1.3 allows remote attackers to execute arbitrary SQL commands via the eid par
23RIESGO
abrir ↗Referência
CVE-2017-3599
Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Pluggable Auth). Supported versions t
45RIESGO
abrir ↗Referência
CVE-2018-11776
Apache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullN
100RIESGO
abrir ↗Referência
CVE-2017-0146
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir ↗Referência✓ VexDay Proof
PHPRaider 1.0.7 - 'PHPbb3.functions.php' Remote File Inclusion
PHP remote file inclusion vulnerability in authentication/phpbb3/phpbb3.functions.php in phpRaider 1.0.7 and 1.0.7a, whe
23RIESGO
abrir ↗Referência
CVE-2022-44268
ImageMagick 7.1.0-49 is vulnerable to Information Disclosure. When it parses a PNG image (e.g., for resize), the resulti
55RIESGO
abrir ↗Referência✓ VexDay Proof
Xomol CMS 1.2 - Authentication Bypass / Local File Inclusion
SQL injection vulnerability in index.php in Xomol CMS 1.20071213, when magic_quotes_gpc is disabled, allows remote attac
23RIESGO
abrir ↗Referência
Ericsson Network Location MPS GMPC21 - Remote Code Execution (RCE) (Metasploit)
In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file
23RIESGO
abrir ↗Referência✓ VexDay Proof
RoomPHPlanning 1.5 - Arbitrary Add Admin
admin/userform.php in RoomPHPlanning 1.5 does not require administrative credentials, which allows remote authenticated
23RIESGO
abrir ↗Referência
CVE-2019-17558
Apache Solr 5.0.0 to Apache Solr 8.3.1 are vulnerable to a Remote Code Execution through the VelocityResponseWriter. A V
100RIESGO
abrir ↗Referência✓ VexDay Proof
Netbutikker 4 - SQL Injection
Multiple SQL injection vulnerabilities in Simpel Side Netbutik 1 through 4 allow remote attackers to execute arbitrary S
23RIESGO
abrir ↗Referência
CVE-2024-13160
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up
100RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.