Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
22.721 exploits
Referência
CVE-2023-0904
SourceCodester Employee Task Management System task-details.php sql injection
33RIESGO
abrir
Referência
CVE-2008-5970
SQL injection vulnerability in profile_social.php in i-Net Solution Orkut Clone allows remote authenticated users to exe
23RIESGO
abrir
Referência47
Unauthenticated RCE on CraftCMS when PHP `register_argc_argv` config setting is enabled
CVE-2024-56145CRITICALbajo ataque
RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cms
100RIESGO
abrir
Referência
CVE-2016-7288
The scripting engines in Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (m
35RIESGO
abrir
ReferênciaVexDay Proof
PHP iCalendar 2.24 - 'cookie_language' Local File Inclusion / Arbitrary File Upload
CVE-2008-5968webappsphp
Directory traversal vulnerability in print.php in PHP iCalendar 2.24 and earlier allows remote attackers to include and
23RIESGO
abrir
Referência
CVE-2026-19823
Tenda W20E QoS Rule Deletion delQos formQOSRuleDel stack-based overflow
41RIESGO
abrir
Referência
CVE-2026-19822
Tenda W20E QoS Edit editQos lstAdd stack-based overflow
41RIESGO
abrir
ReferênciaVexDay Proof
AllMyGuests 0.4.1 - 'AMG_id' SQL Injection
CVE-2008-1961webappsphp
SQL injection vulnerability in index.php in Voice Of Web AllMyGuests 0.4.1 allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
Aterr 0.9.1 - PHP5 Local File Inclusion
CVE-2008-1962webappsphp
Multiple directory traversal vulnerabilities in Aterr 0.9.1 allow remote attackers to include and execute arbitrary loca
23RIESGO
abrir
Referência
CVE-2019-9082
CVE-2019-9082HIGHbajo ataque
ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public/
100RIESGO
abrir
ReferênciaVexDay Proof
Acidcat CMS 3.4.1 - Multiple Vulnerabilities
CVE-2008-1990webappsphp
Multiple SQL injection vulnerabilities in Acidcat CMS 3.4.1 allow remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
ReferênciaVexDay Proof
Watchfire Appscan 7.0 - ActiveX Multiple Insecure Methods
CVE-2008-2015remotewindows
Multiple absolute path traversal vulnerabilities in certain ActiveX controls in WatchFire AppScan 7.0 allow remote attac
23RIESGO
abrir
Referência
CVE-2021-40964
A Path Traversal vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to
23RIESGO
abrir
Referência
CVE-2019-0230
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lea
60RIESGO
abrir
Referência
CVE-2019-0230
Apache Struts 2.0.0 to 2.5.20 forced double OGNL evaluation, when evaluated on raw user input in tag attributes, may lea
60RIESGO
abrir
Referência
CVE-2026-19812
TOTOLINK A800R product.so cstecgi.cgi UploadCustomModule stack-based overflow
41RIESGO
abrir
Referência
CVE-2021-41318
In Progress WhatsUp Gold prior to version 21.1.0, an application endpoint failed to adequately sanitize malicious input.
23RIESGO
abrir
Referência
CVE-2026-19811
TOTOLINK A800R firewall.so cstecgi.cgi setIpQosRules stack-based overflow
41RIESGO
abrir
Referência
CVE-2026-18039
Essential Addons for Elementor < 6.7.2 - Unauthenticated Privilege Escalation via Custom Profile Field Mass Assignment
41RIESGO
abrir
Referência
CVE-2026-16739
Epeken All Kurir <= 2.1.2 - Unauthenticated Order Payment Confirmation Forgery
33RIESGO
abrir
Referência
CVE-2017-3248
Vulnerability in the Oracle WebLogic Server component of Oracle Fusion Middleware (subcomponent: Core Components). Suppo
60RIESGO
abrir
ReferênciaVexDay Proof
Uploader & Downloader 3.0 - 'id_user' SQL Injection
CVE-2006-6716webappsphp
SQL injection vulnerability in administration/administre2.php in Eric GUILLAUME uploader&downloader 3 allows remote atta
23RIESGO
abrir
ReferênciaVexDay Proof
Bandwebsite 1.5 - 'LOGIN' Remote Add Admin
CVE-2006-6722webappsphp
Bandwebsite (aka Bandsite portal system) 1.5 allows remote attackers to create administrative accounts via a direct requ
23RIESGO
abrir
ReferênciaVexDay Proof
Megabbs Forum 2.2 - SQL Injection / Cross-Site Scripting
CVE-2008-2023webappsasp
Multiple SQL injection vulnerabilities in PD9 Software MegaBBS 2.2 allow remote attackers to execute arbitrary SQL comma
23RIESGO
abrir
ReferênciaVexDay Proof
MiniBB 2.2 - Cross-Site Scripting / SQL Injection / Full Path Disclosure
CVE-2008-2024webappsphp
Cross-site scripting (XSS) vulnerability in index.php in miniBB 2.2, and possibly earlier, when register_globals is enab
23RIESGO
abrir
Referência
CVE-2025-34028
CVE-2025-34028CRITICALbajo ataque
Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal
100RIESGO
abrir
Referência21
watchtowrlabs/watchTowr-vs-Commvault-PreAuth-RCE-CVE-2025-34028
CVE-2025-34028CRITICALbajo ataque
Commvault Command Center Innovation Release <= 11.38.25 Unathenticated Install Package Path Traversal
100RIESGO
abrir
Referência
Payara Micro Community 5.2021.6 - Directory Traversal
CVE-2021-41381webappsmultiple
Payara Micro Community 5.2021.6 and below allows Directory Traversal.
50RIESGO
abrir
Referência
CVE-2023-1671
CVE-2023-1671CRITICALbajo ataque
A pre-auth command injection vulnerability in the warn-proceed handler of Sophos Web Appliance older than version 4.3.10
100RIESGO
abrir
Referência
CVE-2019-7256
CVE-2019-7256CRITICALbajo ataque
Linear eMerge E3-Series devices allow Command Injections.
100RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.