Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.313exploits catalogados
34.834CVEs con explotación pública
24.695probados en laboratorio
21.797 exploits
ReferênciaVexDay Proof
PHPbbBook 1.3 - 'bbcode.php?l' Local File Inclusion
CVE-2009-0442webappsphp
Directory traversal vulnerability in bbcode.php in PHPbbBook 1.3 and 1.3h allows remote attackers to include and execute
23RIESGO
abrir
Referência
CVE-2016-1610
Directory traversal vulnerability in the email-template feature in Novell Filr before 1.2 Security Update 3 and 2.0 befo
28RIESGO
abrir
Referência
CVE-2026-67611
OpenEMR 8.2.0 OAuth2 Password Grant Authentication Bypass via SMART Configuration
38RIESGO
abrir
ReferênciaVexDay Proof
RunCMS 1.5.2 - 'debug_show.php' SQL Injection
CVE-2007-2538webappsphp
SQL injection vulnerability in class/debug/debug_show.php in RunCms 1.5.2 and earlier allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
Elecard AVC HD Player - '.XPL' Stack Buffer Overflow (SEH) (PoC)
CVE-2009-1356doswindows
Stack-based buffer overflow in Elecard AVC HD Player allows remote attackers to execute arbitrary code via a long MP3 fi
23RIESGO
abrir
Referência
CVE-2009-4757
Stack-based buffer overflow in BrotherSoft EW-MusicPlayer 0.8 allows remote attackers to cause a denial of service (appl
23RIESGO
abrir
Referência
CVE-2026-67610
OpenEMR 8.2.0 OAuth2 Dynamic Client Registration Unauthorized FHIR Access
38RIESGO
abrir
Referência
CVE-2026-18605
CheckMAL AppCheck Pro Kernel Mini-Filter Driver AppCheckD.sys uncontrolled search path
38RIESGO
abrir
ReferênciaVexDay Proof
QuickTicket 1.5 - 'qti_usr.php' SQL Injection
CVE-2007-3539webappsphp
Multiple SQL injection vulnerabilities in QuickTicket 1.2 build:20070621 and QuickTalk Forum 1.3 allow remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Visual 6 - 'VDT70.dll NotSafe' Remote Stack Overflow
CVE-2007-4254remotewindows
Stack-based buffer overflow in a certain ActiveX control in VDT70.DLL in Microsoft Visual Database Tools Database Design
28RIESGO
abrir
Referência
CVE-2026-39932
OpenEMR 8.2.0 Remote Code Execution via CategoryTree eval() Injection
45RIESGO
abrir
Referência
CVE-2026-18601
GL.iNet GL-MT3000 ovpn-client.so Native Plugin glc ovpn-client.check_config command injection
45RIESGO
abrir
Referência
CVE-2026-18600
GL.iNet GL-MT3000 Network Lua RPC Plugin network network.switch_status command injection
38RIESGO
abrir
Referência
CVE-2017-13855
An issue was discovered in certain Apple products. iOS before 11.2 is affected. macOS before 10.13.2 is affected. tvOS b
23RIESGO
abrir
Referência
CVE-2026-18599
GL.iNet GL-MT3000 Logread Lua RPC Plugin logread logread.set_config command injection
38RIESGO
abrir
Referência
CVE-2026-18598
GL.iNet GL-MT3000 Logread Lua RPC plugin logread logread.get_system_log command injection
38RIESGO
abrir
Referência
CVE-2016-9488
ManageEngine Applications Manager versions 12 and 13 suffer from remote SQL injection vulnerabilities
23RIESGO
abrir
Referência
CVE-2016-9488
ManageEngine Applications Manager versions 12 and 13 suffer from remote SQL injection vulnerabilities
23RIESGO
abrir
Referência
CVE-2015-3325
SQL injection vulnerability in forum.php in the WP Symposium plugin before 15.4 for WordPress allows remote attackers to
23RIESGO
abrir
Referência
CVE-2017-16952
KMPlayer 4.2.2.4 allows remote attackers to cause a denial of service via a crafted NSV file.
23RIESGO
abrir
Referência
CVE-2019-3759
The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 cont
33RIESGO
abrir
Referência
CVE-2014-4613
Cross-site request forgery (CSRF) vulnerability in the administration panel in Piwigo before 2.6.2 allows remote attacke
23RIESGO
abrir
Referência
CVE-2014-4613
Cross-site request forgery (CSRF) vulnerability in the administration panel in Piwigo before 2.6.2 allows remote attacke
23RIESGO
abrir
ReferênciaVexDay Proof
Magic CMS 4.2.747 - 'mysave.php' Remote File Inclusion
CVE-2007-1393webappsphp
PHP remote file inclusion vulnerability in mysave.php in Magic CMS 4.2.747 allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
Amber Script 1.0 - 'show_content.php?id' Local File Inclusion
CVE-2007-6129webappsphp
Directory traversal vulnerability in scripts/include/show_content.php in Amber Script 1.0 allows remote attackers to inc
23RIESGO
abrir
ReferênciaVexDay Proof
XOOPS mod_gallery Zend_Hash_key + Extract - Remote File Inclusion
CVE-2008-0138webappsphp
PHP remote file inclusion vulnerability in xoopsgallery/init_basic.php in the mod_gallery module for XOOPS, when registe
23RIESGO
abrir
ReferênciaVexDay Proof
FlashBlog 0.31b - Arbitrary File Upload
CVE-2008-2574webappsphp
Unrestricted file upload vulnerability in admin/Editor/imgupload.php in FlashBlog 0.31 beta allows remote attackers to e
23RIESGO
abrir
ReferênciaVexDay Proof
NUVICO DVR NVDV4 / PdvrAtl Module 'PdvrAtl.DLL 1.0.1.25' - Remote Buffer Overflow
CVE-2008-4547remotewindows
Heap-based buffer overflow in the PdvrAtl.PdvrOcx.1 ActiveX control (pdvratl.dll) in DVRHOST Web CMS OCX 1.0.1.25 allows
28RIESGO
abrir
Referência
CVE-2022-4050
JoomSport < 5.2.8 - Unauthenticated SQLi
63RIESGO
abrir
Referência
CVE-2022-4059
Cryptocurrency Widgets Pack < 2.0 - Unauthenticated SQLi
63RIESGO
abrir
anteriorpágina 319 / 727siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.