Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.445exploits catalogados
34.432CVEs con explotación pública
24.695probados en laboratorio
21.497 exploits
Referência
CVE-2021-43339
In Ericsson Network Location before 2021-07-31, it is possible for an authenticated attacker to inject commands via file
23RIESGO
abrir
ReferênciaVexDay Proof
Simple PHP Blog 0.4.7.1 - Remote Command Execution
CVE-2006-1243webappsphp
Directory traversal vulnerability in install05.php in Simple PHP Blog (SPB) 0.4.7.1 and earlier allows remote attackers
23RIESGO
abrir
Referência
CVE-2009-4985
SQL injection vulnerability in browse.php in Accessories Me PHP Affiliate Script 1.4 allows remote attackers to execute
23RIESGO
abrir
Referência
CVE-2010-4231
Directory traversal vulnerability in the web-based administration interface on the Camtron CMNC-200 Full HD IP Camera an
43RIESGO
abrir
Referência
CVE-2020-9467
Piwigo 2.10.1 has stored XSS via the file parameter in a /ws.php request because of the pwg.images.setInfo function.
28RIESGO
abrir
Referência
CVE-2017-17876
Biometric Shift Employee Management System 3.0 allows remote attackers to bypass intended file-read restrictions via a u
23RIESGO
abrir
Referência
CVE-2020-14461
Zyxel Armor X1 WAP6806 1.00(ABAL.6)C0 devices allow Directory Traversal via the images/eaZy/ URI.
23RIESGO
abrir
Referência
CVE-2022-26521
Abantecart through 1.3.2 allows remote authenticated administrators to execute arbitrary code by uploading an executable
23RIESGO
abrir
Referência
CVE-2016-10043
An issue was discovered in Radisys MRF Web Panel (SWMS) 9.0.1. The MSM_MACRO_NAME POST parameter in /swms/ms.cgi was dis
23RIESGO
abrir
Referência
CVE-2012-1010
Unrestricted file upload vulnerability in actions.php in the AllWebMenus plugin before 1.1.8 for WordPress allows remote
23RIESGO
abrir
Referência
CVE-2022-4063
InPost Gallery < 2.1.4.1 - Unauthenticated LFI to RCE
63RIESGO
abrir
Referência
CVE-2026-10812
zilliztech GPTCache Cache Key pre.py BufferedReader.peek weak hash
28RIESGO
abrir
ReferênciaVexDay Proof
MiniBill 1.22b - config[plugin_dir] Remote File Inclusion
CVE-2006-4489webappsphp
Multiple PHP remote file inclusion vulnerabilities in MiniBill 2006-07-14 (1.2.2) allow remote attackers to execute arbi
23RIESGO
abrir
ReferênciaVexDay Proof
Fundanemt 2.2.0 - 'spellcheck.php' Remote Code Execution
CVE-2007-2935webappsphp
core/spellcheck/spellcheck.php in Fundanemt before 2.2.0.1 allows remote attackers to execute arbitrary commands via she
23RIESGO
abrir
Referência
CVE-2018-18793
School Event Management System 1.0 allows Arbitrary File Upload via event/controller.php?action=photos.
23RIESGO
abrir
Referência
CVE-2018-18793
School Event Management System 1.0 allows Arbitrary File Upload via event/controller.php?action=photos.
23RIESGO
abrir
Referência
CVE-2017-7041
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RIESGO
abrir
Referência
CVE-2018-18924
The image-upload feature in ProjeQtOr 7.2.5 allows remote attackers to execute arbitrary code by uploading a .shtml file
23RIESGO
abrir
Referência
CVE-2010-3314
Cross-site scripting (XSS) vulnerability in login.php in EGroupware 1.4.001+.002; 1.6.001+.002 and possibly other versio
23RIESGO
abrir
Referência
CVE-2010-1722
Directory traversal vulnerability in the Online Market (com_market) component 2.x for Joomla! allows remote attackers to
38RIESGO
abrir
Referência
CVE-2010-1722
Directory traversal vulnerability in the Online Market (com_market) component 2.x for Joomla! allows remote attackers to
38RIESGO
abrir
Referência
CVE-2010-1474
Directory traversal vulnerability in the Sweety Keeper (com_sweetykeeper) component 1.5.x for Joomla! allows remote atta
38RIESGO
abrir
Referência
CVE-2010-1474
Directory traversal vulnerability in the Sweety Keeper (com_sweetykeeper) component 1.5.x for Joomla! allows remote atta
38RIESGO
abrir
Referência
CVE-2016-10277
An elevation of privilege vulnerability in the Motorola bootloader could enable a local malicious application to execute
23RIESGO
abrir
ReferênciaVexDay Proof
Shadowed Portal 5.599 - 'root' Remote File Inclusion
CVE-2006-4826webappsphp
PHP remote file inclusion vulnerability in bottom.php in Shadowed Portal 5.599 and earlier allows remote attackers to ex
23RIESGO
abrir
ReferênciaVexDay Proof
Mambo Component Security Images 3.0.5 - Remote File Inclusion
CVE-2006-5048webappsphp
Multiple PHP remote file inclusion vulnerabilities in Security Images (com_securityimages) component 3.0.5 and earlier f
23RIESGO
abrir
ReferênciaVexDay Proof
HSRS 1.0 - 'addcode.php' Remote File Inclusion
CVE-2006-6154webappsphp
PHP remote file inclusion vulnerability in addcode.php in HIOX Star Rating System Script (HSRS) 1.0 and earlier allows r
23RIESGO
abrir
ReferênciaVexDay Proof
Bubla 0.9.2 - 'bu_dir' Multiple Remote File Inclusions
CVE-2006-6867webappsphp
Multiple PHP remote file inclusion vulnerabilities in Vladimir Menshakov buratinable templator (aka bubla) 0.9.1 allow r
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component RSfiles 1.0.2 - 'path' File Download
CVE-2007-4504webappsphp
Directory traversal vulnerability in index.php in the RSfiles component (com_rsfiles) 1.0.2 and earlier for Joomla! allo
38RIESGO
abrir
ReferênciaVexDay Proof
FretsWeb 1.2 - Multiple Local File Inclusions
CVE-2009-2109webappsphp
Multiple directory traversal vulnerabilities in FretsWeb 1.2 allow remote attackers to read arbitrary files via director
23RIESGO
abrir
anteriorpágina 157 / 717siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.