Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
76.569exploits catalogados
34.981CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.899GitHub PoC 13.965VulnCheck XDB 8542Nuclei 4248Metasploit 3472✓ solo verificadosrecientespopularesriesgo
21.899 exploits
Referência✓ VexDay Proof
AllMyGuests 0.4.1 - 'cfg_serverpath' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in AllMyGuests 0.4.1 and earlier allow remote attackers to execute ar
23RIESGO
abrir ↗Referência
CVE-2019-12460
Web Port 1.19.1 allows XSS via the /access/setup type parameter.
23RIESGO
abrir ↗Referência✓ VexDay Proof
Webfwlog 0.92 - 'debug.php' Remote File Disclosure
include/debug.php in Webfwlog 0.92 and earlier, when register_globals is enabled, allows remote attackers to obtain sour
23RIESGO
abrir ↗Referência✓ VexDay Proof
68 Classifieds 4.0 - 'category.php' SQL Injection
SQL injection vulnerability in category.php in 68 Classifieds 4.0.1 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir ↗Referência✓ VexDay Proof
IMGallery 2.5 - Multiple SQL Injections
Multiple SQL injection vulnerabilities in IMGallery 2.5, when magic_quotes_gpc is disabled, allow remote attackers to ex
23RIESGO
abrir ↗Referência✓ VexDay Proof
plusphp url shortening software 1.6 - Remote File Inclusion
PHP remote file inclusion vulnerability in plus.php in plusPHP Short URL Multi-User Script 1.6 allows remote attackers t
23RIESGO
abrir ↗Referência
CVE-2012-4344
Cross-site scripting (XSS) vulnerability in Ipswitch WhatsUp Gold 15.02 allows remote attackers to inject arbitrary web
23RIESGO
abrir ↗Referência✓ VexDay Proof
Claroline E-Learning 1.75 - 'ldap.inc.php' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Claroline 1.7.5 allow remote attackers to execute arbitrary PHP co
23RIESGO
abrir ↗Referência
CVE-2012-2156
Multiple cross-site scripting (XSS) vulnerabilities in Plume CMS 1.2.4 and earlier allow remote attackers to inject arbi
23RIESGO
abrir ↗Referência
CVE-2025-2749
Kentico Xperience <= 13.0.178 Staging Media File Upload Authenticated RCE
71RIESGO
abrir ↗Referência✓ VexDay Proof
newsmanager 2.0 - Remote File Inclusion / File Disclosure / SQL Injection
PHP remote file inclusion vulnerability in ch_readalso.php in News Manager 2.0 allows remote attackers to execute arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
MeltingIce File System 1.0 - Arbitrary Add User
MeltingIce File System 1.0 allows remote attackers to bypass application authentication, create new user accounts, and e
23RIESGO
abrir ↗Referência✓ VexDay Proof
CMS WebManager-Pro - Multiple SQL Injections
Multiple SQL injection vulnerabilities in index.php in CMS WebManager-Pro allow remote attackers to execute arbitrary SQ
23RIESGO
abrir ↗Referência✓ VexDay Proof
How2ASP.net WebBoard 4.1 - SQL Injection
SQL injection vulnerability in showQAnswer.asp in How2ASP.net Webboard 4.1 allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
Konqueror 3.5.9 - 'color'/'bgcolor' Multiple Remote Crash Vulnerabilities
The HTML parser in KDE Konqueror 3.5.9 allows remote attackers to cause a denial of service (application crash) via (1)
23RIESGO
abrir ↗Referência
CVE-2010-1296
Multiple buffer overflows in Adobe Photoshop CS4 before 11.0.2 allow user-assisted remote attackers to execute arbitrary
28RIESGO
abrir ↗Referência
CVE-2009-2223
Directory traversal vulnerability in locms/smarty.php in LightOpenCMS 0.1 allows remote attackers to include and execute
23RIESGO
abrir ↗Referência
CVE-2015-1725
Buffer overflow in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows S
23RIESGO
abrir ↗Referência
CVE-2018-4090
An issue was discovered in certain Apple products. iOS before 11.2.5 is affected. macOS before 10.13.3 is affected. tvOS
23RIESGO
abrir ↗Referência
CVE-2019-19230
An unsafe deserialization vulnerability exists in CA Release Automation (Nolio) 6.6 with the DataManagement component th
48RIESGO
abrir ↗Referência
CVE-2015-3933
Multiple SQL injection vulnerabilities in inc/lib/User.class.php in MetalGenix GeniXCMS before 0.0.3-patch allow remote
23RIESGO
abrir ↗Referência
CVE-2015-5066
Multiple cross-site scripting (XSS) vulnerabilities in the MetalGenix GeniXCMS 0.0.3 allow remote attackers to inject ar
23RIESGO
abrir ↗Referência
CVE-2015-5066
Multiple cross-site scripting (XSS) vulnerabilities in the MetalGenix GeniXCMS 0.0.3 allow remote attackers to inject ar
23RIESGO
abrir ↗Referência
CVE-2019-1148
Microsoft Graphics Component Information Disclosure Vulnerability
33RIESGO
abrir ↗Referência✓ VexDay Proof
PHP recommend 1.3 - Authentication Bypass / Remote File Inclusion / Code Injection
admin.php in Frax.dk Php Recommend 1.3 and earlier does not require authentication when the user password is changed, wh
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mambo Module galleria 1.0b - Remote File Inclusion
PHP remote file inclusion vulnerability in galleria.html.php in Galleria Mambo Module 1.0 and earlier for Mambo allows r
23RIESGO
abrir ↗Referência
CVE-2007-2792
SQL injection vulnerability in the Yet another Newsletter Component (aka YaNC or com_yanc) component before 1.5 beta 3 f
23RIESGO
abrir ↗Referência
CVE-2007-2792
SQL injection vulnerability in the Yet another Newsletter Component (aka YaNC or com_yanc) component before 1.5 beta 3 f
23RIESGO
abrir ↗Referência
CVE-2020-15038
The SeedProd coming-soon plugin before 5.1.1 for WordPress allows XSS.
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.