Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.652exploits catalogados
34.545CVEs con explotación pública
24.695probados en laboratorio
21.581 exploits
ReferênciaVexDay Proof
Magic CMS 4.2.747 - 'mysave.php' Remote File Inclusion
CVE-2007-1393webappsphp
PHP remote file inclusion vulnerability in mysave.php in Magic CMS 4.2.747 allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
Amber Script 1.0 - 'show_content.php?id' Local File Inclusion
CVE-2007-6129webappsphp
Directory traversal vulnerability in scripts/include/show_content.php in Amber Script 1.0 allows remote attackers to inc
23RIESGO
abrir
ReferênciaVexDay Proof
XOOPS mod_gallery Zend_Hash_key + Extract - Remote File Inclusion
CVE-2008-0138webappsphp
PHP remote file inclusion vulnerability in xoopsgallery/init_basic.php in the mod_gallery module for XOOPS, when registe
23RIESGO
abrir
ReferênciaVexDay Proof
FlashBlog 0.31b - Arbitrary File Upload
CVE-2008-2574webappsphp
Unrestricted file upload vulnerability in admin/Editor/imgupload.php in FlashBlog 0.31 beta allows remote attackers to e
23RIESGO
abrir
ReferênciaVexDay Proof
NUVICO DVR NVDV4 / PdvrAtl Module 'PdvrAtl.DLL 1.0.1.25' - Remote Buffer Overflow
CVE-2008-4547remotewindows
Heap-based buffer overflow in the PdvrAtl.PdvrOcx.1 ActiveX control (pdvratl.dll) in DVRHOST Web CMS OCX 1.0.1.25 allows
28RIESGO
abrir
Referência
CVE-2010-4278
operation/agentes/networkmap.php in Pandora FMS before 3.1.1 allows remote authenticated users to execute arbitrary comm
28RIESGO
abrir
Referência
CVE-2017-9812
The reportId parameter of the getReportStatus action method can be abused in the web interface in Kaspersky Anti-Virus f
28RIESGO
abrir
Referência
CVE-2017-9812
The reportId parameter of the getReportStatus action method can be abused in the web interface in Kaspersky Anti-Virus f
28RIESGO
abrir
Referência
CVE-2009-2764
Microsoft Internet Explorer 8.0.7100.0 on Windows 7 RC on the x64 platform allows remote attackers to cause a denial of
28RIESGO
abrir
ReferênciaVexDay Proof
Simplog 0.9.2 - 's' Remote Command Execution
CVE-2006-1776webappsphp
PHP remote file inclusion vulnerability in doc/index.php in Jeremy Ashcraft Simplog 0.9.2 and earlier allows remote atta
28RIESGO
abrir
ReferênciaVexDay Proof
Simplog 0.9.2 - 's' Remote Command Execution
CVE-2006-1779webappsphp
Cross-site scripting (XSS) vulnerability in login.php in Jeremy Ashcraft Simplog 0.9.2 and earlier allows remote attacke
23RIESGO
abrir
Referência
CVE-2018-14418
In Msvod Cms v10, SQL Injection exists via an images/lists?cid= URI.
23RIESGO
abrir
Referência
CVE-2015-3325
SQL injection vulnerability in forum.php in the WP Symposium plugin before 15.4 for WordPress allows remote attackers to
23RIESGO
abrir
Referência
CVE-2017-16953
connoppp.cgi on ZTE ZXDSL 831CII devices does not require HTTP Basic Authentication, which allows remote attackers to mo
28RIESGO
abrir
Referência
CVE-2009-3254
Multiple stack-based buffer overflows in Ultimate Player 1.56 beta allow remote attackers to execute arbitrary code via
23RIESGO
abrir
Referência
CVE-2019-7439
cgi-bin/qcmap_web_cgi on JioFi 4G M2S 1.0.2 devices allows a DoS (Hang) via the mask POST parameter.
23RIESGO
abrir
Referência
CVE-2019-7439
cgi-bin/qcmap_web_cgi on JioFi 4G M2S 1.0.2 devices allows a DoS (Hang) via the mask POST parameter.
23RIESGO
abrir
Referência
CVE-2009-4086
CRLF injection vulnerability in Xerver HTTP Server 4.31 and 4.32 allows remote attackers to inject arbitrary HTTP header
23RIESGO
abrir
ReferênciaVexDay Proof
Monster Top List 1.4.2 - 'functions.php?root_path' Remote File Inclusion
CVE-2006-1781webappsphp
PHP remote file inclusion vulnerability in functions.php in Circle R Monster Top List (MTL) 1.4 allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
opensurveypilot 1.2.1 - Remote File Inclusion
CVE-2007-2166webappsphp
PHP remote file inclusion vulnerability in administration/user/lib/group.inc.php in OpenSurveyPilot (osp) 1.2.1 and earl
23RIESGO
abrir
ReferênciaVexDay Proof
The Personal FTP Server 6.0f - RETR Denial of Service
CVE-2008-4136doswindows
Michael Roth Software Personal FTP Server (PFT) 6.0f allows remote attackers to cause a denial of service (service crash
23RIESGO
abrir
Referência
CVE-2022-4050
JoomSport < 5.2.8 - Unauthenticated SQLi
63RIESGO
abrir
Referência
CVE-2022-4059
Cryptocurrency Widgets Pack < 2.0 - Unauthenticated SQLi
63RIESGO
abrir
Referência
CVE-2017-2474
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS b
23RIESGO
abrir
Referência
CVE-2022-4049
WP User <= 7.0 - Unauthenticated SQLi
63RIESGO
abrir
Referência
CVE-2010-20103
ProFTPD 1.3.3c Backdoor Command Execution
63RIESGO
abrir
Referência
CVE-2010-20103
ProFTPD 1.3.3c Backdoor Command Execution
63RIESGO
abrir
Referência
CVE-2010-20103
ProFTPD 1.3.3c Backdoor Command Execution
63RIESGO
abrir
Referência
CVE-2018-18774
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows XSS via the admin/index.php module parameter.
23RIESGO
abrir
Referência
CVE-2018-18774
CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows XSS via the admin/index.php module parameter.
23RIESGO
abrir
anteriorpágina 219 / 720siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.