Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.008exploits catalogados
34.638CVEs con explotación pública
24.695probados en laboratorio
21.662 exploits
Referência
CVE-2021-24383
WP Google Maps < 8.1.12 - Authenticated Stored Cross-Site Scripting (XSS)
23RIESGO
abrir
Referência
CVE-2010-3206
Multiple PHP remote file inclusion vulnerabilities in DiY-CMS 1.0 allow remote attackers to execute arbitrary PHP code v
23RIESGO
abrir
Referência
CVE-2010-3206
Multiple PHP remote file inclusion vulnerabilities in DiY-CMS 1.0 allow remote attackers to execute arbitrary PHP code v
23RIESGO
abrir
ReferênciaVexDay Proof
FdWeB Espace Membre 2.01 - 'path' Remote File Inclusion
CVE-2007-0301webappsphp
PHP remote file inclusion vulnerability in _admin/admin_menu.php in FdWeB Espace Membre 2.1 and earlier allows remote at
23RIESGO
abrir
ReferênciaVexDay Proof
Mutant 0.9.2 - 'mutant_functions.php' Remote File Inclusion
CVE-2007-1961webappsphp
PHP remote file inclusion vulnerability in mutant_functions.php in the Mutant 0.9.2 portal for phpBB 2.2 allows remote a
23RIESGO
abrir
ReferênciaVexDay Proof
Expow 0.8 - 'autoindex.php?cfg_file' Remote File Inclusion
CVE-2007-2302webappsphp
PHP remote file inclusion vulnerability in autoindex.php in Expow 0.8 allows remote attackers to execute arbitrary PHP c
23RIESGO
abrir
ReferênciaVexDay Proof
NewsSync for phpBB 1.5.0rc6 - Remote File Inclusion
CVE-2007-3136webappsphp
PHP remote file inclusion vulnerability in inc/nuke_include.php in newsSync 1.5.0rc6 allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
MyCMS 0.9.8 - Remote Command Execution (2)
CVE-2007-3585webappsphp
PHP remote file inclusion vulnerability in games.php in MyCMS 0.9.8 and earlier allows remote attackers to execute arbit
23RIESGO
abrir
ReferênciaVexDay Proof
CandyPress eCommerce suite 4.1.1.26 - Multiple Vulnerabilities
CVE-2008-0737webappsasp
SQL injection vulnerability in admin/utilities_ConfigHelp.asp in CandyPress (CP) 4.1.1.26, and other 4.x and 3.x version
23RIESGO
abrir
ReferênciaVexDay Proof
Gregarius 0.5.4 - SQL Injection
CVE-2008-3374webappsphp
SQL injection vulnerability in ajax.php in Gregarius 0.5.4 and earlier allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
Motorola Wimax modem CPEi300 - File Disclosure / Cross-Site Scripting
CVE-2009-0392remotehardware
Directory traversal vulnerability in sysconf.cgi in Motorola Wimax modem CPEi300 allows remote authenticated users to re
23RIESGO
abrir
ReferênciaVexDay Proof
WholeHogSoftware Ware Support - Authentication Bypass
CVE-2009-0458webappsphp
Multiple SQL injection vulnerabilities in admin/login_submit.php in Whole Hog Ware Support 1.x allow remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
WebPortal CMS 0.8b - Multiple Local/Remote File Inclusions
CVE-2009-1444webappsphp
PHP remote file inclusion vulnerability in indexk.php in WebPortal CMS 0.8-beta allows remote attackers to execute arbit
23RIESGO
abrir
Referência
CVE-2010-3204
Multiple PHP remote file inclusion vulnerabilities in Pecio CMS 2.0.5 allow remote attackers to execute arbitrary PHP co
23RIESGO
abrir
Referência
CVE-2010-3204
Multiple PHP remote file inclusion vulnerabilities in Pecio CMS 2.0.5 allow remote attackers to execute arbitrary PHP co
23RIESGO
abrir
Referência
CVE-2010-3210
Multiple PHP remote file inclusion vulnerabilities in Multi-lingual E-Commerce System 0.2 allow remote attackers to exec
23RIESGO
abrir
Referência
CVE-2009-4796
Multiple SQL injection vulnerabilities in the ExecuteQueries function in private/system/classes/listfactory.class.php in
23RIESGO
abrir
Referência
CVE-2010-2922
SQL injection vulnerability in default.asp in AKY Blog allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir
Referência
CVE-2010-2922
SQL injection vulnerability in default.asp in AKY Blog allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir
Referência
CVE-2010-4865
SQL injection vulnerability in the JE Guestbook (com_jeguestbook) component 1.0 for Joomla! allows remote attackers to e
23RIESGO
abrir
Referência
CVE-2012-10027
WordPress Plugin WP-Property <= 1.35.0 PHP File Upload
63RIESGO
abrir
Referência
CVE-2012-10027
WordPress Plugin WP-Property <= 1.35.0 PHP File Upload
63RIESGO
abrir
Referência
CVE-2012-10027
WordPress Plugin WP-Property <= 1.35.0 PHP File Upload
63RIESGO
abrir
ReferênciaVexDay Proof
Electronic Engineering Tool (EE TOOL) 0.4.1 - Remote File Inclusion
CVE-2006-5623webappsphp
PHP remote file inclusion vulnerability in ip.inc.php in Electronic Engineering Tool (EE Tool) 0.4-1 and earlier allows
23RIESGO
abrir
ReferênciaVexDay Proof
gtcatalog 0.9.1 - 'index.php' Remote File Inclusion
CVE-2006-5923webappsphp
PHP remote file inclusion vulnerability in index.php in Chris Mac gtcatalog (aka GimeScripts Shopping Catalog) 0.9.1 and
23RIESGO
abrir
ReferênciaVexDay Proof
MySource CMS 2.16.2 - 'init_mysource.php' Remote File Inclusion
CVE-2006-5672webappsphp
PHP remote file inclusion vulnerability in web/init_mysource.php in MySource CMS 2.16.2 and earlier allows remote attack
23RIESGO
abrir
ReferênciaVexDay Proof
CNStats 2.9 - 'who_r.php?bj' Remote File Inclusion
CVE-2007-2086webappsphp
Multiple PHP remote file inclusion vulnerabilities in CNStats 2.9 allow remote attackers to execute arbitrary PHP code v
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component MosReporter 0.9.3 - Remote File Inclusion
CVE-2006-6051webappsphp
PHP remote file inclusion vulnerability in reporter.logic.php in the MosReporter (com_reporter) component for Mambo and
23RIESGO
abrir
ReferênciaVexDay Proof
Flip 3.0 - Remote Admin Creation
CVE-2007-5062webappsphp
account.php in Adam Scheinberg Flip 3.0 and earlier allows remote attackers to create administrative accounts via the un
23RIESGO
abrir
ReferênciaVexDay Proof
Verlihub Control Panel 1.7.x - Local File Inclusion
CVE-2007-5321webappsphp
Directory traversal vulnerability in index.php in Verlihub Control Panel (VHCP) 1.7 and earlier allows remote attackers
23RIESGO
abrir
anteriorpágina 272 / 723siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.