Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.559exploits catalogados
34.978CVEs con explotación pública
24.695probados en laboratorio
21.899 exploits
ReferênciaVexDay Proof
Netbutikker 4 - SQL Injection
CVE-2008-2504webappsphp
Multiple SQL injection vulnerabilities in Simpel Side Netbutik 1 through 4 allow remote attackers to execute arbitrary S
23RIESGO
abrir
Referência
CVE-2015-5520
Cross-site scripting (XSS) vulnerability in the Users module in Orchard 1.7.3 through 1.8.2 and 1.9.x before 1.9.1 allow
23RIESGO
abrir
Referência
CVE-2015-5520
Cross-site scripting (XSS) vulnerability in the Users module in Orchard 1.7.3 through 1.8.2 and 1.9.x before 1.9.1 allow
23RIESGO
abrir
Referência
CVE-2015-2507
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
23RIESGO
abrir
Referência
CVE-2009-4563
Cross-site request forgery (CSRF) vulnerability in zp-core/admin-options.php in Zenphoto 1.2.5 allows remote attackers t
23RIESGO
abrir
Referência
CVE-2017-6979
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS
23RIESGO
abrir
Referência
CVE-2026-66730
facil.io 0.6.0 - 0.7.6 Infinite Loop DoS via Multipart MIME Body Parser
41RIESGO
abrir
Referência
CVE-2012-1024
Directory traversal vulnerability in file in Enigma2 Webinterface 1.5rc1 and 1.5beta4 allows remote attackers to read ar
23RIESGO
abrir
Referência
CVE-2009-4729
Multiple cross-site scripting (XSS) vulnerabilities in x10 Adult Media Script 1.7 allow remote attackers to inject arbit
23RIESGO
abrir
Referência
CVE-2017-11176
The mq_notify function in the Linux kernel through 4.11.9 does not set the sock pointer to NULL upon entry into the retr
23RIESGO
abrir
Referência
CVE-2016-4315
Cross-site request forgery (CSRF) vulnerability in WSO2 Carbon 4.4.5 allows remote attackers to hijack the authenticatio
23RIESGO
abrir
Referência
CVE-2016-4315
Cross-site request forgery (CSRF) vulnerability in WSO2 Carbon 4.4.5 allows remote attackers to hijack the authenticatio
23RIESGO
abrir
Referência
CVE-2008-6888
Cross-site scripting (XSS) vulnerability in signup.asp in Pre Classified Listings 1.0 allows remote attackers to inject
23RIESGO
abrir
Referência
CVE-2016-1000123
Unauthenticated SQL Injection in Huge-IT Video Gallery v1.0.9 for Joomla
23RIESGO
abrir
ReferênciaVexDay Proof
LunarPoll 1.0 - 'show.php?PollDir' Remote File Inclusion
CVE-2007-0298webappsphp
PHP remote file inclusion vulnerability in show.php in LunarPoll, when register_globals is enabled, allows remote attack
23RIESGO
abrir
Referência
CVE-2010-1312
Directory traversal vulnerability in the iJoomla News Portal (com_news_portal) component 1.5.x for Joomla! allows remote
43RIESGO
abrir
Referência
CVE-2010-1313
Directory traversal vulnerability in the Seber Cart (com_sebercart) component 1.0.0.12 and 1.0.0.13 for Joomla!, when ma
38RIESGO
abrir
Referência
CVE-2010-1314
Directory traversal vulnerability in the Highslide JS (com_hsconfig) component 1.5 and 2.0.9 for Joomla! allows remote a
43RIESGO
abrir
ReferênciaVexDay Proof
Sciurus Hosting Panel - Remote Code Injection
CVE-2007-6082webappsphp
Direct static code injection vulnerability in acp/savenews.php in Sciurus Hosting Panel, possibly 2.0.3, allows remote a
23RIESGO
abrir
ReferênciaVexDay Proof
Gradman 0.1.3 - 'agregar_info.php' Local File Inclusion
CVE-2008-0361webappsphp
Directory traversal vulnerability in agregar_info.php in GradMan 0.1.3 and earlier allows remote attackers to include an
23RIESGO
abrir
Referência
CVE-2022-29851
documentconverter in OX App Suite through 7.10.6, in a non-default configuration with ghostscript, allows OS Command Inj
48RIESGO
abrir
Referência
CVE-2017-17721
CWEBNET/WOSummary/List in ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows SQL injection via the tradestatus, assetno, ass
23RIESGO
abrir
Referência
CVE-2017-17721
CWEBNET/WOSummary/List in ZUUSE BEIMS ContractorWeb .NET 5.18.0.0 allows SQL injection via the tradestatus, assetno, ass
23RIESGO
abrir
Referência
CVE-2016-0143
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, W
23RIESGO
abrir
Referência
CVE-2020-9371
Stored XSS exists in the Appointment Booking Calendar plugin before 1.3.35 for WordPress. In the cpabc_appointments.php
23RIESGO
abrir
Referência
CVE-2016-7384
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 3
23RIESGO
abrir
Referência
CVE-2017-8471
Microsoft Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Server 2012 and R2,
23RIESGO
abrir
ReferênciaVexDay Proof
GeBlog 0.1 (Windows) - GLOBALS[tplname] Local File Inclusion
CVE-2007-1577webappsphp
Directory traversal vulnerability in index.php in GeBlog 0.1 allows remote attackers to include and execute arbitrary lo
23RIESGO
abrir
ReferênciaVexDay Proof
Libc - 'libc:fts_*()' Local Denial of Service
CVE-2009-0537dosbsd
Integer overflow in the fts_build function in fts.c in libc in (1) OpenBSD 4.4 and earlier and (2) Microsoft Interix 6.0
23RIESGO
abrir
ReferênciaVexDay Proof
PostNuke pnFlashGames Module 1.5 - SQL Injection
CVE-2007-2427webappsphp
SQL injection vulnerability in index.php in the pnFlashGames 1.5 module for PostNuke allows remote attackers to execute
23RIESGO
abrir
anteriorpágina 365 / 730siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.