Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.066exploits catalogados
34.679CVEs con explotación pública
24.695probados en laboratorio
21.692 exploits
Referência
CVE-2022-45709
IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple command injection vulnerabilities via the pEnable, pLev
48RIESGO
abrir
Referência
CVE-2014-8577
Multiple cross-site scripting (XSS) vulnerabilities in Croogo before 2.1.0 allow remote attackers to inject arbitrary we
23RIESGO
abrir
Referência
CVE-2014-8577
Multiple cross-site scripting (XSS) vulnerabilities in Croogo before 2.1.0 allow remote attackers to inject arbitrary we
23RIESGO
abrir
Referência
CVE-2017-2353
An issue was discovered in certain Apple products. macOS before 10.12.3 is affected. The issue involves the "Bluetooth"
23RIESGO
abrir
Referência
CVE-2017-13865
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RIESGO
abrir
Referência
CVE-2017-2456
An issue was discovered in certain Apple products. iOS before 10.3 is affected. macOS before 10.12.4 is affected. tvOS b
23RIESGO
abrir
Referência
CVE-2012-1009
NetSarang Xlpd 4 Build 0100 and NetSarang Xmanager Enterprise 4 Build 0186 allow remote attackers to cause a denial of s
23RIESGO
abrir
Referência
CVE-2025-25034
SugarCRM PHP Deserialization RCE
63RIESGO
abrir
Referência
CVE-2025-25034
SugarCRM PHP Deserialization RCE
63RIESGO
abrir
Referência
CVE-2021-3294
CASAP Automated Enrollment System 1.0 is affected by cross-site scripting (XSS) in users.php. An attacker can steal a co
23RIESGO
abrir
Referência
CVE-2009-3666
Cross-site scripting (XSS) vulnerability in index.php in Nullam Blog 0.1.2 allows remote attackers to inject arbitrary w
23RIESGO
abrir
ReferênciaVexDay Proof
Mambo Component mambelfish 1.1 - Remote File Inclusion
CVE-2006-4270webappsphp
PHP remote file inclusion vulnerability in mambelfish.class.php in the mambelfish component (com_mambelfish) 1.1 and ear
23RIESGO
abrir
ReferênciaVexDay Proof
Somery 0.4.6 - 'skin_dir' Remote File Inclusion
CVE-2006-4669webappsphp
PHP remote file inclusion vulnerability in admin/system/include.php in Somery 0.4.6 and earlier, when register_globals i
23RIESGO
abrir
ReferênciaVexDay Proof
Aardvark Topsites PHP 4.2.2 - 'path' Remote File Inclusion
CVE-2006-7026webappsphp
PHP remote file inclusion vulnerability in sources/join.php in Aardvark Topsites PHP 4.2.2 and earlier, when register_gl
23RIESGO
abrir
ReferênciaVexDay Proof
QuickTalk forum 1.3 - 'lang' Local File Inclusion
CVE-2007-3505webappsphp
Multiple directory traversal vulnerabilities in QuickTalk forum 1.3 allow remote attackers to include and execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
Acidcat CMS 3.4.1 - Multiple Vulnerabilities
CVE-2008-1992webappsphp
Acidcat CMS 3.4.1 does not properly restrict access to (1) default_mail_aspemail.asp, (2) default_mail_cdosys.asp or (3)
23RIESGO
abrir
ReferênciaVexDay Proof
PHP weather 2.2.2 - Local File Inclusion / Cross-Site Scripting
CVE-2008-5770webappsphp
Cross-site scripting (XSS) vulnerability in config/make_config.php in PHP Weather 2.2.2 allows remote attackers to injec
23RIESGO
abrir
ReferênciaVexDay Proof
EZ Publish < 3.9.5/3.10.1/4.0.1 - Privilege Escalation
CVE-2008-6844webappsphp
The registration view (/user/register) in eZ Publish 3.5.6 and earlier, and possibly other versions before 3.9.5, 3.10.1
23RIESGO
abrir
ReferênciaVexDay Proof
Mambo Component MMP 1.2 - Remote File Inclusion
CVE-2006-4203webappsphp
PHP remote file inclusion vulnerability in help.mmp.php in the MMP Component (com_mmp) 1.2 and earlier for Mambo allows
23RIESGO
abrir
Referência
CVE-2008-4601
Cross-site scripting (XSS) vulnerability in the login feature in Habari CMS 0.5.1 allows remote attackers to inject arbi
23RIESGO
abrir
Referência
CVE-2010-2316
Multiple cross-site scripting (XSS) vulnerabilities in default.asp in WmsCms 2.0 and earlier allow remote attackers to i
23RIESGO
abrir
Referência
CVE-2018-19135
ClipperCMS 1.3.3 does not have CSRF protection on its kcfinder file upload (enabled by default). This can be used by an
23RIESGO
abrir
Referência
CVE-2018-7449
SEGGER FTP Server for Windows before 3.22a allows remote attackers to cause a denial of service (daemon crash) via an in
23RIESGO
abrir
Referência
CVE-2010-2458
Cross-site scripting (XSS) vulnerability in video.php in 2daybiz Video Community Portal Script 1.0 allows remote attacke
23RIESGO
abrir
ReferênciaVexDay Proof
AEP SmartGate 4.3b - 'GET' Arbitrary File Download
CVE-2006-5596remotewindows
Directory traversal vulnerability in the SSL server in AEP Smartgate 4.3b allows remote attackers to download arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
EasyNews PRO News Publishing 4.0 - Password Disclosure
CVE-2006-6866webappsphp
STphp EasyNews PRO 4.0 stores sensitive information under the web root with insufficient access control, which allows re
23RIESGO
abrir
Referência
CVE-2021-24719
Enfold Theme < 4.8.4 - Reflected Cross-Site Scripting (XSS)
23RIESGO
abrir
Referência
CVE-2012-10021
D-Link DIR-605L Captcha Handling Buffer Overflow
63RIESGO
abrir
Referência
CVE-2012-10021
D-Link DIR-605L Captcha Handling Buffer Overflow
63RIESGO
abrir
Referência
CVE-2012-10021
D-Link DIR-605L Captcha Handling Buffer Overflow
63RIESGO
abrir
anteriorpágina 282 / 724siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.