Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.313exploits catalogados
34.834CVEs con explotación pública
24.695probados en laboratorio
21.797 exploits
ReferênciaVexDay Proof
SerWeb 2.0.0 dev1 2007-02-20 - Multiple Local/Remote File Inclusion Vulnerabilities
CVE-2007-6290webappsphp
Multiple directory traversal vulnerabilities in js/get_js.php in SERWeb 2.0.0 dev1 and earlier allow remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
Maian Guestbook 3.2 - Insecure Cookie Handling
CVE-2008-3320webappsphp
admin/index.php in Maian Guestbook 3.2 and earlier allows remote attackers to bypass authentication and gain administrat
23RIESGO
abrir
ReferênciaVexDay Proof
Silentum LoginSys 1.0.0 - Insecure Cookie Handling
CVE-2008-6763webappsphp
login2.php in Silentum LoginSys 1.0.0 allows remote attackers to bypass authentication and obtain access to an arbitrary
23RIESGO
abrir
Referência
CVE-2024-4620
ArForms < 6.6 - Unauthenticated RCE
63RIESGO
abrir
Referência
CVE-2021-43701
CSZ CMS 1.2.9 has a Time and Boolean-based Blind SQL Injection vulnerability in the endpoint /admin/export/getcsv/articl
23RIESGO
abrir
Referência
CVE-2011-0018
The email function in manage_sql.c in OpenVAS Manager 1.0.x through 1.0.3 and 2.0.x through 2.0rc2 allows remote authent
23RIESGO
abrir
Referência
CVE-2012-5335
Directory traversal vulnerability in Tiny Server 1.1.5 allows remote authenticated users to read arbitrary files via a .
23RIESGO
abrir
Referência
CVE-2021-46416
Insecure direct object reference in SUNNY TRIPOWER 5.0 Firmware version 3.10.16.R leads to unauthorized user groups acce
33RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component MooFAQ (com_moofaq) - Local File Inclusion
CVE-2009-2015webappsphp
Directory traversal vulnerability in includes/file_includer.php in the Ideal MooFAQ (com_moofaq) component 1.0 for Jooml
38RIESGO
abrir
Referência
CVE-2016-10079
SAPlpd through 7400.3.11.33 in SAP GUI 7.40 on Windows has a Denial of Service vulnerability (service crash) with a long
23RIESGO
abrir
Referência
CVE-2006-5190
Multiple cross-site scripting (XSS) vulnerabilities in osCommerce 2.2 Milestone 2 Update 060817 allow remote attackers t
23RIESGO
abrir
Referência
CVE-2010-0707
Cross-site request forgery (CSRF) vulnerability in add_user.php in Employee Timeclock Software 0.99 allows remote attack
23RIESGO
abrir
Referência
CVE-2026-24061
CVE-2026-24061CRITICALbajo ataque
telnetd in GNU Inetutils through 2.7 allows remote authentication bypass via a "-f root" value for the USER environment
100RIESGO
abrir
Referência
CVE-2018-4386
Multiple memory corruption issues were addressed with improved memory handling. This issue affected versions prior to iO
23RIESGO
abrir
Referência
CVE-2009-3318
Directory traversal vulnerability in the Roland Breedveld Album (com_album) component 1.14 for Joomla! allows remote att
38RIESGO
abrir
ReferênciaVexDay Proof
Opencart 1.1.8 - 'route' Local File Inclusion
CVE-2009-1621webappsphp
Directory traversal vulnerability in index.php in OpenCart 1.1.8 allows remote attackers to read arbitrary files via a .
23RIESGO
abrir
Referência
CVE-2019-12137
Typora 0.9.9.24.6 on macOS allows directory traversal, for execution of arbitrary programs, via a file:/// or ../ substr
23RIESGO
abrir
Referência
CVE-2016-6503
The CORBA IDL dissectors in Wireshark 2.x before 2.0.5 on 64-bit Windows platforms do not properly interact with Visual
23RIESGO
abrir
Referência
CVE-2017-5227
QNAP QTS before 4.2.4 Build 20170313 allows local users to obtain sensitive Domain Administrator password information by
23RIESGO
abrir
Referência
CVE-2016-3717
The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to read arbitrary files vi
28RIESGO
abrir
ReferênciaVexDay Proof
Boonex Dolphin 6.1.2 - Multiple Remote File Inclusions
CVE-2008-3167webappsphp
Multiple PHP remote file inclusion vulnerabilities in BoonEx Dolphin 6.1.2, when register_globals is enabled, allow remo
23RIESGO
abrir
Referência
CVE-2009-3272
Stack consumption vulnerability in WebKit.dll in WebKit in Apple Safari 3.2.3, and possibly other versions before 4.1.2,
23RIESGO
abrir
Referência
CVE-2018-12589
Polaris Office 2017 8.1 allows attackers to execute arbitrary code via a Trojan horse puiframeworkproresenu.dll file in
28RIESGO
abrir
Referência
CVE-2018-12589
Polaris Office 2017 8.1 allows attackers to execute arbitrary code via a Trojan horse puiframeworkproresenu.dll file in
28RIESGO
abrir
Referência
CVE-2009-4987
admin/header.php in Scripteen Free Image Hosting Script 2.3 allows remote attackers to bypass authentication and gain ad
23RIESGO
abrir
Referência
CVE-2010-1217
Directory traversal vulnerability in the JE Form Creator (com_jeformcr) component for Joomla!, when magic_quotes_gpc is
38RIESGO
abrir
Referência
CVE-2010-1217
Directory traversal vulnerability in the JE Form Creator (com_jeformcr) component for Joomla!, when magic_quotes_gpc is
38RIESGO
abrir
Referência
CVE-2015-3300
Multiple cross-site scripting (XSS) vulnerabilities in the TheCartPress eCommerce Shopping Cart (aka The Professional Wo
23RIESGO
abrir
Referência
CVE-2009-2694
The msn_slplink_process_msg function in libpurple/protocols/msn/slplink.c in libpurple, as used in Pidgin (formerly Gaim
28RIESGO
abrir
Referência
CVE-2009-3717
Heap-based buffer overflow in LucVil PatPlayer 3.9 allows remote attackers to cause a denial of service (crash) or execu
23RIESGO
abrir
anteriorpágina 308 / 727siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.