Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.008exploits catalogados
34.638CVEs con explotación pública
24.695probados en laboratorio
21.662 exploits
Referência
CVE-2010-3029
SQL injection vulnerability in statistics.php in PHPKick 0.8 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
Referência
CVE-2017-7571
public/rolechangeadmin in Faveo 1.9.3 allows CSRF. The impact is obtaining admin privileges.
23RIESGO
abrir
Referência
CVE-2018-19138
WSTMart 2.0.7 has CSRF via the index.php/admin/staffs/add.html URI.
23RIESGO
abrir
Referência
CVE-2023-25439
Stored Cross Site Scripting (XSS) vulnerability in Square Pig FusionInvoice 2023-1.0, allows attackers to execute arbitr
33RIESGO
abrir
Referência
CVE-2018-12090
There is unauthenticated reflected cross-site scripting (XSS) in LAMS before 3.1 that allows a remote attacker to introd
23RIESGO
abrir
Referência
CVE-2012-4927
SQL injection vulnerability in Limesurvey (a.k.a PHPSurveyor) before 1.91+ Build 120224 and earlier allows remote attack
23RIESGO
abrir
Referência
CVE-2012-4927
SQL injection vulnerability in Limesurvey (a.k.a PHPSurveyor) before 1.91+ Build 120224 and earlier allows remote attack
23RIESGO
abrir
Referência
CVE-2009-3171
Multiple cross-site scripting (XSS) vulnerabilities in Anantasoft Gazelle CMS 1.0 and earlier allow remote attackers to
23RIESGO
abrir
Referência
CVE-2022-44900
A directory traversal vulnerability in the SevenZipFile.extractall() function of the python library py7zr v0.20.0 and ea
48RIESGO
abrir
ReferênciaVexDay Proof
open-medium.CMS 0.25 - '404.php' Remote File Inclusion
CVE-2006-2683webappsphp
PHP remote file inclusion vulnerability in 404.php in open-medium.CMS 0.25 allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
ASP Stats Generator 2.1.1 - SQL Injection
CVE-2006-3184webappsasp
Direct static code injection vulnerability in ASP Stats Generator before 2.1.2 allows remote authenticated attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
Apple iOS 4.0.3 - DPAP Server Denial of Service
CVE-2008-0830dosios
The Digital Photo Access Protocol (DPAP) server for iPhoto 4.0.3 allows remote attackers to cause a denial of service (c
23RIESGO
abrir
ReferênciaVexDay Proof
Simple Customer 1.3 - Arbitrary Change Admin Password
CVE-2009-1637webappsphp
profile.php in Simple Customer 1.3 does not require administrative authentication, which allows remote attackers to chan
23RIESGO
abrir
Referência
CVE-2009-2337
SQL injection vulnerability in includes/module/book/index.inc.php in w3b|cms Gaestebuch Guestbook Module 3.0.0, when mag
23RIESGO
abrir
Referência
CVE-2011-5218
SQL injection vulnerability in DotA OpenStats 1.3.9 and earlier allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
Referência
CVE-2019-2721
Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions th
23RIESGO
abrir
Referência
CVE-2019-13529
An attacker could send a malicious link to an authenticated operator, which may allow remote attackers to perform action
41RIESGO
abrir
Referência
CVE-2009-2606
ASP Football Pool 2.3 stores sensitive information under the web root with insufficient access control, which allows rem
23RIESGO
abrir
Referência
CVE-2009-2602
R2 Newsletter Lite, Pro, and Stats stores sensitive information under the web root with insufficient access control, whi
23RIESGO
abrir
Referência
CVE-2009-4545
Logoshows BBS 2.0 stores sensitive information under the web root with insufficient access control, which allows remote
23RIESGO
abrir
Referência
CVE-2022-47870
A Cross Site Scripting (XSS) vulnerability in the web SQL monitor login page in Redgate SQL Monitor 12.1.31.893 allows r
33RIESGO
abrir
Referência
CVE-2010-0725
Cross-site scripting (XSS) vulnerability in showimg.php in Arab Cart 1.0.2.0 allows remote attackers to inject arbitrary
23RIESGO
abrir
Referência
CVE-2010-0725
Cross-site scripting (XSS) vulnerability in showimg.php in Arab Cart 1.0.2.0 allows remote attackers to inject arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
PHP-Nuke NukeAI Module 3b - 'util.php' Remote File Inclusion
CVE-2006-6255webappsphp
Direct static code injection vulnerability in util.php in the NukeAI 0.0.3 Beta module for PHP-Nuke, aka Program E is an
23RIESGO
abrir
ReferênciaVexDay Proof
P-News 1.16/1.17 - 'user.dat' Remote Password Disclosure
CVE-2006-6888webappsphp
P-News 1.16 and 1.17 store sensitive information under the web root with insufficient access control, which allows remot
23RIESGO
abrir
ReferênciaVexDay Proof
MiniBB 2.2 - Cross-Site Scripting / SQL Injection / Full Path Disclosure
CVE-2008-2028webappsphp
miniBB 2.2, and possibly earlier, when register_globals is enabled, allows remote attackers to obtain the full path via
23RIESGO
abrir
ReferênciaVexDay Proof
CMS NetCat 3.12 - Multiple Vulnerabilities
CVE-2008-5730webappsphp
Multiple CRLF injection vulnerabilities in AIST NetCat 3.12 and earlier allow remote attackers to have an unknown impact
23RIESGO
abrir
ReferênciaVexDay Proof
Liberum Help Desk 0.97.3 - SQL Injection / File Disclosure
CVE-2008-6057webappsphp
Doug Luxem Liberum Help Desk 0.97.3 stores db/helpdesk2000.mdb under the web root with insufficient access control, whic
23RIESGO
abrir
ReferênciaVexDay Proof
template creature - SQL Injection / File Disclosure
CVE-2008-5951webappsphp
ASP Template Creature stores sensitive information under the web root with insufficient access control, which allows rem
23RIESGO
abrir
ReferênciaVexDay Proof
Rapid Classified 3.1 - Database Disclosure
CVE-2008-6388webappsphp
Rapid Classified 3.1 and 3.15 stores sensitive information under the web root with insufficient access control, which al
23RIESGO
abrir
anteriorpágina 262 / 723siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.