Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.559exploits catalogados
34.978CVEs con explotación pública
24.695probados en laboratorio
21.899 exploits
Referência
Entrepreneur Dating Script 2.0.1 - 'marital' / 'gender' / 'country' / 'profileid' SQL Injection
CVE-2017-17648webappsphp
Entrepreneur Dating Script 2.0.1 has SQL Injection via the search_result.php marital, gender, country, or profileid para
23RIESGO
abrir
ReferênciaVexDay Proof
Hammer Software MetaGauge 1.0.0.17 - Directory Traversal
CVE-2008-4421remotewindows
Directory traversal vulnerability in MetaGauge 1.0.0.17, and probably other versions before 1.0.3.38, allows remote atta
23RIESGO
abrir
ReferênciaVexDay Proof
ModernBill 4.4.x - Cross-Site Scripting / Remote File Inclusion
CVE-2008-5060webappsphp
Multiple PHP remote file inclusion vulnerabilities in ModernBill 4.4 and earlier allow remote attackers to execute arbit
23RIESGO
abrir
Referência
CVE-2026-11867
Frontend Admin by DynamiApps < 3.29.7 - Subscriber+ Taxonomy Term Creation/Modification/Deletion via Missing Authorization
33RIESGO
abrir
Referência
CVE-2014-8810
SQL injection vulnerability in ajax/mail_functions.php in the WP Symposium plugin before 14.11 for WordPress allows remo
23RIESGO
abrir
Referência
CVE-2014-9305
SQL injection vulnerability in the shortcodeProductsTable function in models/Cart66Ajax.php in the Cart66 Lite plugin be
23RIESGO
abrir
Referência
CVE-2014-9305
SQL injection vulnerability in the shortcodeProductsTable function in models/Cart66Ajax.php in the Cart66 Lite plugin be
23RIESGO
abrir
Referência
CVE-2017-8469
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2,
23RIESGO
abrir
ReferênciaVexDay Proof
Orbit Downloader 2.8.7 - Arbitrary File Deletion
CVE-2009-1064remotewindows
Argument injection vulnerability in orbitmxt.dll 2.1.0.2 in the Orbit Downloader 2.8.7 and earlier ActiveX control allow
23RIESGO
abrir
Referência
CVE-2017-8462
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2,
23RIESGO
abrir
ReferênciaVexDay Proof
FlashChat 4.5.7 - 'aedating4CMS.php' Remote File Inclusion
CVE-2006-4583webappsphp
Multiple PHP remote file inclusion vulnerabilities in FlashChat before 4.6.2 allow remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
R2K Gallery 1.7 - 'galeria.php?lang2' Local File Inclusion
CVE-2007-2642webappsphp
Directory traversal vulnerability in galeria.php in R2K Gallery 1.7 allows remote attackers to read arbitrary files via
23RIESGO
abrir
Referência
CVE-2014-2976
Directory traversal vulnerability in Sixnet SixView Manager 2.4.1 allows remote attackers to read arbitrary files via a
23RIESGO
abrir
Referência
CVE-2026-67184
TinyWeb 0.0.8 Null Pointer Dereference DoS via Malformed HTTP Request
41RIESGO
abrir
Referência
CVE-2023-3049
File Upload in TMT's Lockcell
48RIESGO
abrir
Referência
CVE-2015-4631
Multiple cross-site scripting (XSS) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before
23RIESGO
abrir
Referência
CVE-2015-4631
Multiple cross-site scripting (XSS) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before
23RIESGO
abrir
Referência
CVE-2021-44916
Opmantek Open-AudIT Community 4.2.0 (Fixed in 4.3.0) is affected by a Cross Site Scripting (XSS) vulnerability. If a bad
23RIESGO
abrir
Referência
CVE-2009-4147
The _rtld function in the Run-Time Link-Editor (rtld) in libexec/rtld-elf/rtld.c in FreeBSD 7.1 and 8.0 does not clear t
38RIESGO
abrir
Referência
CVE-2013-2684
Cross-site Scripting (XSS) in Cisco Linksys E4200 1.0.05 Build 7 devices allows remote attackers to inject arbitrary web
23RIESGO
abrir
Referência
CVE-2016-3643
CVE-2016-3643HIGHbajo ataque
SolarWinds Virtualization Manager 6.3.1 and earlier allow local users to gain privileges by leveraging a misconfiguratio
71RIESGO
abrir
Referência
CVE-2016-3643
CVE-2016-3643HIGHbajo ataque
SolarWinds Virtualization Manager 6.3.1 and earlier allow local users to gain privileges by leveraging a misconfiguratio
71RIESGO
abrir
Referência
CVE-2017-6896
Privilege escalation vulnerability on the DIGISOL DG-HR1400 1.00.02 wireless router enables an attacker to escalate from
23RIESGO
abrir
Referência
CVE-2017-6896
Privilege escalation vulnerability on the DIGISOL DG-HR1400 1.00.02 wireless router enables an attacker to escalate from
23RIESGO
abrir
Referência
CVE-2018-20418
index.php?p=admin/actions/entries/save-entry in Craft CMS 3.0.25 allows XSS by saving a new title from the console tab.
23RIESGO
abrir
Referência
CVE-2018-11091
An issue was discovered in MyBiz MyProcureNet 5.0.0. A malicious file can be uploaded to the webserver by an attacker. I
48RIESGO
abrir
ReferênciaVexDay Proof
2WIRE Modems/Routers - 'CRLF' Denial of Service
CVE-2006-4523doshardware
The web-based management interface in 2Wire, Inc. HomePortal and OfficePortal Series modems and routers allows remote at
23RIESGO
abrir
Referência
CVE-2014-9558
Multiple SQL injection vulnerabilities in SmartCMS v.2.
23RIESGO
abrir
Referência
CVE-2015-7346
SQL injection vulnerability in ZCMS 1.1.
23RIESGO
abrir
Referência
CVE-2015-7346
SQL injection vulnerability in ZCMS 1.1.
23RIESGO
abrir
anteriorpágina 358 / 730siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.