Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.008exploits catalogados
34.638CVEs con explotación pública
24.695probados en laboratorio
21.662 exploits
Referência
CVE-2012-10040
Openfiler v2.x NetworkCard Command Execution
63RIESGO
abrir
Referência
CVE-2009-4927
WB News 2.1.2 allows remote attackers to bypass authentication and gain administrative access via a modified WBNEWS cook
23RIESGO
abrir
Referência
CVE-2002-1230
NetDDE Agent on Windows NT 4.0, 4.0 Terminal Server Edition, Windows 2000, and Windows XP allows local users to execute
23RIESGO
abrir
ReferênciaVexDay Proof
Redaxo 3.2 - 'INCLUDE_PATH' Remote File Inclusion
CVE-2006-2843webappsphp
PHP remote file inclusion vulnerability in Redaxo 2.7.4 allows remote attackers to execute arbitrary PHP code via a URL
23RIESGO
abrir
ReferênciaVexDay Proof
Redaxo 3.2 - 'INCLUDE_PATH' Remote File Inclusion
CVE-2006-2844webappsphp
Multiple PHP remote file inclusion vulnerabilities in Redaxo 3.0 allow remote attackers to execute arbitrary PHP code vi
23RIESGO
abrir
ReferênciaVexDay Proof
Redaxo 3.2 - 'INCLUDE_PATH' Remote File Inclusion
CVE-2006-2845webappsphp
PHP remote file inclusion vulnerability in Redaxo 3.0 up to 3.2 allows remote attackers to execute arbitrary PHP code vi
23RIESGO
abrir
ReferênciaVexDay Proof
WebspotBlogging 3.0.1 - 'path' Remote File Inclusion
CVE-2006-2860webappsphp
PHP remote file inclusion vulnerability in Webspotblogging 3.0.1 allows remote attackers to execute arbitrary PHP code v
28RIESGO
abrir
ReferênciaVexDay Proof
CS-Cart 1.3.3 - 'classes_dir' Remote File Inclusion
CVE-2006-2863webappsphp
PHP remote file inclusion vulnerability in class.cs_phpmailer.php in CS-Cart 1.3.3 allows remote attackers to execute ar
23RIESGO
abrir
ReferênciaVexDay Proof
mini-pub 0.3 - File Disclosure / Code Execution
CVE-2008-5581webappsphp
PHP remote file inclusion vulnerability in mini-pub.php/front-end/img.php in mini-pub 0.3 allows remote attackers to exe
23RIESGO
abrir
ReferênciaVexDay Proof
CFAGCMS 1 - Remote File Inclusion
CVE-2008-5922webappsphp
Multiple PHP remote file inclusion vulnerabilities in themes/default/index.php in Cant Find A Gaming CMS (CFAGCMS) 1 all
23RIESGO
abrir
ReferênciaVexDay Proof
basebuilder 2.0.1 - 'main.inc.php' Remote File Inclusion
CVE-2008-6036webappsphp
PHP remote file inclusion vulnerability in main.inc.php in BaseBuilder 2.0.1 and earlier allows remote attackers to exec
23RIESGO
abrir
Referência
CVE-2014-9113
CCH Wolters Kluwer ProSystem fx Engagement (aka PFX Engagement) 7.1 and earlier uses weak permissions (Authenticated Use
23RIESGO
abrir
Referência
CVE-2014-9113
CCH Wolters Kluwer ProSystem fx Engagement (aka PFX Engagement) 7.1 and earlier uses weak permissions (Authenticated Use
23RIESGO
abrir
Referência
CVE-2012-1049
Multiple cross-site scripting (XSS) vulnerabilities in ManageEngine ADManager Plus 5.2 Build 5210 allow remote attackers
23RIESGO
abrir
Referência
CVE-2011-10026
Spreecommerce < 0.50.x API RCE
63RIESGO
abrir
Referência
CVE-2011-10026
Spreecommerce < 0.50.x API RCE
63RIESGO
abrir
Referência
CVE-2023-33383
Shelly 4PM Pro four-channel smart switch 0.11.0 allows an attacker to trigger a BLE out of bounds read fault condition t
23RIESGO
abrir
Referência
CVE-2014-3868
Multiple SQL injection vulnerabilities in ZeusCart 4.x.
23RIESGO
abrir
Referência
CVE-2010-1064
Erolife AjxGaleri VT stores sensitive information under the web root with insufficient access control, which allows remo
23RIESGO
abrir
Referência
CVE-2010-1064
Erolife AjxGaleri VT stores sensitive information under the web root with insufficient access control, which allows remo
23RIESGO
abrir
Referência
CVE-2010-1066
AR Web Content Manager (AWCM) 2.1 stores sensitive information under the web root with insufficient access control, whic
23RIESGO
abrir
Referência
CVE-2009-0760
Team Board 1.x and 2.x stores sensitive information under the web root with insufficient access control, which allows re
23RIESGO
abrir
Referência
CVE-2015-2803
SQL injection vulnerability in mod1/index.php in the Akronymmanager (sb_akronymmanager) extension before 7.0.0 for TYPO3
23RIESGO
abrir
Referência
CVE-2015-2803
SQL injection vulnerability in mod1/index.php in the Akronymmanager (sb_akronymmanager) extension before 7.0.0 for TYPO3
23RIESGO
abrir
Referência
CVE-2013-6872
SQL injection vulnerability in managetimetracker.php in Collabtive before 1.2 allows remote authenticated users to execu
23RIESGO
abrir
Referência
CVE-2013-6872
SQL injection vulnerability in managetimetracker.php in Collabtive before 1.2 allows remote authenticated users to execu
23RIESGO
abrir
ReferênciaVexDay Proof
BlueShoes Framework 4.6 - Remote File Inclusion
CVE-2006-2864webappsphp
Multiple PHP remote file inclusion vulnerabilities in BlueShoes Framework 4.6 allow remote attackers to execute arbitrar
28RIESGO
abrir
Referência
CVE-2010-5055
SQL injection vulnerability in index.php in Almnzm 2.1 allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir
Referência
CVE-2010-5055
SQL injection vulnerability in index.php in Almnzm 2.1 allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir
ReferênciaVexDay Proof
Claroline 1.7.6 - 'includePath' Remote Code Execution
CVE-2006-2868webappsphp
Multiple PHP remote file inclusion vulnerabilities in Claroline 1.7.6 allow remote attackers to execute arbitrary PHP co
28RIESGO
abrir
anteriorpágina 278 / 723siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.