Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
22.721 exploits
Referência
CVE-2015-8556
Local privilege escalation vulnerability in the Gentoo QEMU package before 2.5.0-r1.
23RIESGO
abrir
ReferênciaVexDay Proof
XOOPS Module resmanager 1.21 - Blind SQL Injection
CVE-2007-2735webappsphp
SQL injection vulnerability in edit_day.php in the ResManager 1.2.1 and earlier module for Xoops allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
Achievo 1.1.0 - 'config_atkroot' Remote File Inclusion
CVE-2007-2736webappsphp
PHP remote file inclusion vulnerability in index.php in Achievo 1.1.0 allows remote attackers to execute arbitrary PHP c
23RIESGO
abrir
ReferênciaVexDay Proof
Kostenloses Linkmanagementscript - SQL Injection
CVE-2008-2301webappsphp
SQL injection vulnerability in Kostenloses Linkmanagementscript allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
ReferênciaVexDay Proof
Core Image Fun House 2.0 (OSX) - Arbitrary Code Execution (PoC)
CVE-2008-2304dososx
Buffer overflow in Apple Core Image Fun House 2.0 and earlier in CoreImage Examples in Xcode tools before 3.1 allows use
23RIESGO
abrir
ReferênciaVexDay Proof
otscms 2.1.5 - SQL Injection / Cross-Site Scripting
CVE-2007-0847webappsphp
SQL injection vulnerability in mod/PM/reply.php in Open Tibia Server CMS (OTSCMS) 2.1.5 and earlier allows remote attack
23RIESGO
abrir
Referência
CVE-2020-8657
CVE-2020-8657CRITICALbajo ataque
An issue was discovered in EyesOfNetwork 5.3. The installation uses the same API key (hardcoded as EONAPI_KEY in include
100RIESGO
abrir
Referência
File Sharing Wizard 1.5.0 - POST SEH Overflow
CVE-2019-16724remotewindows
File Sharing Wizard 1.5.0 allows a remote attacker to obtain arbitrary code execution by exploiting a Structured Excepti
60RIESGO
abrir
Referência
CVE-2019-16759
CVE-2019-16759CRITICALbajo ataque
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RIESGO
abrir
Referência
CVE-2019-16759
CVE-2019-16759CRITICALbajo ataque
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RIESGO
abrir
Referência
CVE-2019-16759
CVE-2019-16759CRITICALbajo ataque
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RIESGO
abrir
Referência
CVE-2019-16759
CVE-2019-16759CRITICALbajo ataque
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RIESGO
abrir
Referência
CVE-2019-16759
CVE-2019-16759CRITICALbajo ataque
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widge
100RIESGO
abrir
ReferênciaVexDay Proof
PHPFootball 1.6 - SQL Injection
CVE-2008-3387webappsphp
SQL injection vulnerability in show.php in PHPFootball 1.6 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
ReferênciaVexDay Proof
SoftComplex PHP Image Gallery - 'ctg' SQL Injection
CVE-2008-6485webappsphp
SQL injection vulnerability in index.php in SoftComplex PHP Image Gallery allows remote attackers to execute arbitrary S
23RIESGO
abrir
ReferênciaVexDay Proof
DigiAffiliate 1.4 - Authentication Bypass
CVE-2008-6487webappsasp
Multiple SQL injection vulnerabilities in login.asp in Digiappz DigiAffiliate 1.4 and earlier allow remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
OpenX 2.6.3 - 'MAX_type' Local File Inclusion
CVE-2009-0291webappsphp
Directory traversal vulnerability in fc.php in OpenX 2.6.3 allows remote attackers to include and execute arbitrary file
23RIESGO
abrir
Referência
CVE-2021-42362
WordPress Popular Posts <= 5.3.2 Authenticated Arbitrary File Upload
78RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component MyAlbum 1.0 - 'album' SQL Injection
CVE-2008-6489webappsphp
SQL injection vulnerability in MyAlbum component (com_myalbum) 1.0 for Joomla! allows remote attackers to execute arbitr
23RIESGO
abrir
Referência
Froxlor 0.10.29.1 - SQL Injection (Authenticated)
CVE-2021-42325webappsphp
Froxlor through 0.10.29.1 allows SQL injection in Database/Manager/DbManagerMySQL.php via a custom DB name.
28RIESGO
abrir
Referência
CVE-2024-11680
CVE-2024-11680CRITICALbajo ataque
ProjectSend Unauthenticated Configuration Modification
100RIESGO
abrir
Referência
CVE-2024-11680
CVE-2024-11680CRITICALbajo ataque
ProjectSend Unauthenticated Configuration Modification
100RIESGO
abrir
Referência
CVE-2024-11680
CVE-2024-11680CRITICALbajo ataque
ProjectSend Unauthenticated Configuration Modification
100RIESGO
abrir
ReferênciaVexDay Proof
FAQEngine 4.16.03 - 'question.php?questionref' SQL Injection
CVE-2007-2749webappsphp
SQL injection vulnerability in question.php in FAQEngine 4.16.03 and earlier allows remote attackers to execute arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
Build it Fast (bif3) 0.4.1 - Multiple Remote File Inclusions
CVE-2007-2762webappsphp
Multiple PHP remote file inclusion vulnerabilities in Build it Fast (bif3) 0.4.1 allow remote attackers to execute arbit
23RIESGO
abrir
Referência
CVE-2022-26352
CVE-2022-26352CRITICALbajo ataqueransomware
An issue was discovered in the ContentResource API in dotCMS 3.0 through 22.02. Attackers can craft a multipart form req
100RIESGO
abrir
Referência
CVE-2017-16806
The Process function in RemoteTaskServer/WebServer/HttpServer.cs in Ulterius before 1.9.5.0 allows HTTP server directory
60RIESGO
abrir
ReferênciaVexDay Proof
SunLight CMS 5.3 - 'root' Remote File Inclusion
CVE-2007-2774webappsphp
Multiple PHP remote file inclusion vulnerabilities in SunLight CMS 5.3 allow remote attackers to execute arbitrary PHP c
23RIESGO
abrir
ReferênciaVexDay Proof
Ol BookMarks Manager 0.7.4 - SQL Injection
CVE-2007-2817webappsphp
SQL injection vulnerability in read/index.php in ol'bookmarks 0.7.4 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
Referência
CVE-2018-16509
An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handlin
60RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.