Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.496exploits catalogados
34.964CVEs con explotación pública
24.695probados en laboratorio
21.899 exploits
ReferênciaVexDay Proof
LBlog 1.05 - 'comments.asp' SQL Injection
CVE-2006-4284webappsasp
SQL injection vulnerability in comments.asp in LBlog 1.05 and earlier allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
ReferênciaVexDay Proof
Fantastic News 2.1.3 - 'script_path' Remote File Inclusion
CVE-2006-4285webappsphp
PHP remote file inclusion vulnerability in news.php in Fantastic News 2.1.3 and earlier allows remote attackers to execu
23RIESGO
abrir
Referência
CVE-2009-4560
SQL injection vulnerability in profile.php in WebLeague 2.2.0 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
NES Game and NES System c108122 - Remote File Inclusion
CVE-2006-4287webappsphp
Multiple PHP remote file inclusion vulnerabilities in NES Game and NES System c108122 and earlier allow remote attackers
28RIESGO
abrir
ReferênciaVexDay Proof
SimpleBlog 2.0 - 'comments.asp' SQL Injection (2)
CVE-2006-4300webappsphp
SQL injection vulnerability in comments.asp in SimpleBlog 2.0 and earlier allows remote attackers to execute arbitrary S
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Internet Explorer 6 - DirectX Media Remote Overflow Denial of Service
CVE-2006-4301doswindows
Microsoft Internet Explorer 6.0 SP1 allows remote attackers to cause a denial of service (crash) via a long Color attrib
35RIESGO
abrir
ReferênciaVexDay Proof
OpenSSL < 0.9.7l/0.9.8d - SSLv2 Client Crash
CVE-2006-4343dosmultiple
The get_server_hello function in the SSLv2 client code in OpenSSL 0.9.7 before 0.9.7l, 0.9.8 before 0.9.8d, and earlier
28RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component Kochsuite 0.9.4 - Remote File Inclusion
CVE-2006-4348webappsphp
PHP remote file inclusion vulnerability in config.kochsuite.php in the Kochsuite (com_kochsuite) 0.9.4 component for Mam
23RIESGO
abrir
Referência
CVE-2009-4561
Multiple SQL injection vulnerabilities in Admin/index.php in WebLeague 2.2.0, when magic_quotes_gpc is disabled, allow r
23RIESGO
abrir
ReferênciaVexDay Proof
Empire CMS 3.7 - 'checklevel.php' Remote File Inclusion
CVE-2006-4354webappsphp
PHP remote file inclusion vulnerability in e/class/CheckLevel.php in Phome Empire CMS 3.7 and earlier allows remote atta
23RIESGO
abrir
ReferênciaVexDay Proof
Integramod Portal 2.x - 'functions_portal.php' Remote File Inclusion
CVE-2006-4368webappsphp
PHP remote file inclusion vulnerability in includes/functions_portal.php in IntegraMOD Portal 2.x and earlier allows rem
23RIESGO
abrir
ReferênciaVexDay Proof
Integramod Portal 2.x - 'functions_portal.php' Remote File Inclusion
CVE-2006-4369webappsphp
Absolute path traversal vulnerability in includes/functions_portal.php in IntegraMOD Portal 2.x and earlier, when magic_
23RIESGO
abrir
ReferênciaVexDay Proof
pSlash 0.7 - 'lvc_include_dir' Remote File Inclusion
CVE-2006-4373webappsphp
PHP remote file inclusion vulnerability in modules/visitors2/include/config.inc.php in pSlash 0.70 allows remote attacke
23RIESGO
abrir
ReferênciaVexDay Proof
PHPCOIN 1.2.3 - 'session_set.php' Remote File Inclusion
CVE-2006-4424webappsphp
PHP remote file inclusion vulnerability in coin_includes/constants.php in phpCOIN 1.2.3 allows remote attackers to execu
23RIESGO
abrir
ReferênciaVexDay Proof
eFiction < 2.0.7 - Remote Admin Authentication Bypass
CVE-2006-4427webappsphp
index.php in eFiction before 2.0.7 allows remote attackers to bypass authentication and gain privileges by setting the (
23RIESGO
abrir
ReferênciaVexDay Proof
Ay System CMS 2.6 - 'main.php' Remote File Inclusion
CVE-2006-4440webappsphp
PHP remote file inclusion vulnerability in main.php in Ay System Solutions CMS 2.6 and earlier allows remote attackers t
23RIESGO
abrir
ReferênciaVexDay Proof
Interact 2.2 - 'CONFIG[base_path]' Remote File Inclusion
CVE-2006-4448webappsphp
Multiple PHP remote file inclusion vulnerabilities in interact 2.2, when register_globals is enabled, allow remote attac
23RIESGO
abrir
ReferênciaVexDay Proof
XChat 2.6.7 (Windows) - Remote Denial of Service
CVE-2006-4455doswindows
Unspecified vulnerability in Xchat 2.6.7 and earlier allows remote attackers to cause a denial of service (crash) via un
23RIESGO
abrir
Referência
CVE-2021-43798
CVE-2021-43798HIGHbajo ataque
Grafana path traversal
100RIESGO
abrir
Referência
CVE-2026-25559
OpenBullet2 0.3.2 Path Traversal via Wordlist Endpoint
41RIESGO
abrir
Referência
CVE-2026-25855
OpenBullet2 0.3.2 Authenticated RCE via FileProxySource Script Upload
41RIESGO
abrir
Referência
CVE-2026-11534
imvks786 student_management_system add.php cross site scripting
33RIESGO
abrir
Referência
CVE-2026-11530
imvks786 student_management_system Login index.ph sql injection
33RIESGO
abrir
Referência14
HTTP/2 Bomb
Apache HTTP Server: mod_http2 denial of service
46RIESGO
abrir
Referência
CVE-2026-11333
tittuvarghese CollegeManagementSystem Student Data Upload Endpoint upload_student_data.php unrestricted upload
33RIESGO
abrir
Referência
CVE-2026-50232
Lyrion Music Server 9.2.0 Stored XSS via Metadata Tags
33RIESGO
abrir
Referência
CVE-2024-0723
freeSSHd denial of service
33RIESGO
abrir
Referência
CVE-2021-22005
CVE-2021-22005CRITICALbajo ataqueransomware
The vCenter Server contains an arbitrary file upload vulnerability in the Analytics service. A malicious actor with netw
100RIESGO
abrir
Referência
CVE-2017-8484
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2,
23RIESGO
abrir
Referência
CVE-2020-5902
CVE-2020-5902CRITICALbajo ataqueransomware
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic
100RIESGO
abrir
anteriorpágina 337 / 730siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.