Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.058exploits catalogados
35.300CVEs con explotación pública
24.695probados en laboratorio
22.175 exploits
ReferênciaVexDay Proof
Knowledge Base Mod 2.0.2 - 'phpBB' Remote File Inclusion
CVE-2006-2134webappsphp
PHP remote file inclusion vulnerability in /includes/kb_constants.php in Knowledge Base Mod for PHPbb 2.0.2 and earlier
23RIESGO
abrir
ReferênciaVexDay Proof
BIND 9.4.1 < 9.4.2 - Remote DNS Cache Poisoning (Metasploit)
CVE-2008-1447remotemultiple
The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windo
60RIESGO
abrir
ReferênciaVexDay Proof
BIND 9.x - Remote DNS Cache Poisoning
CVE-2008-1447remotemultiple
The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windo
60RIESGO
abrir
ReferênciaVexDay Proof
BIND 9.x - Remote DNS Cache Poisoning
CVE-2008-1447remotemultiple
The DNS protocol, as implemented in (1) BIND 8 and 9 before 9.5.0-P1, 9.4.2-P1, and 9.3.5-P1; (2) Microsoft DNS in Windo
60RIESGO
abrir
Referência
CVE-2010-4791
SQL injection vulnerability in infusions/mg_user_fotoalbum_panel/mg_user_fotoalbum.php in the MG User-Fotoalbum (mg_user
23RIESGO
abrir
Referência
CVE-2010-4795
SQL injection vulnerability in the JS Calendar (com_jscalendar) component 1.5.1 and 1.5.4 for Joomla! allows remote atta
23RIESGO
abrir
Referência
CVE-2010-4797
Multiple SQL injection vulnerabilities in the log-in form in Truworth Flex Timesheet allow remote attackers to execute a
23RIESGO
abrir
Referência
CVE-2010-4798
Directory traversal vulnerability in index.php in OrangeHRM 2.6.0.1 allows remote attackers to include and execute arbit
23RIESGO
abrir
Referência
CVE-2010-4800
SQL injection vulnerability in doadd.php in BaconMap 1.0 allows remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir
Referência
CVE-2010-4800
SQL injection vulnerability in doadd.php in BaconMap 1.0 allows remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir
Referência
CVE-2010-4808
SQL injection vulnerability in index.php in Webmatic allows remote attackers to execute arbitrary SQL commands via the p
23RIESGO
abrir
Referência
CVE-2010-4810
Multiple PHP remote file inclusion vulnerabilities in AR Web Content Manager (AWCM) 2.1 final allow remote attackers to
23RIESGO
abrir
Referência
CVE-2010-4814
SQL injection vulnerability in index1.php in Best Soft Inc. (BSI) Advance Hotel Booking System 1.0 allows remote attacke
23RIESGO
abrir
Referência
CVE-2010-4814
SQL injection vulnerability in index1.php in Best Soft Inc. (BSI) Advance Hotel Booking System 1.0 allows remote attacke
23RIESGO
abrir
Referência
CVE-2010-1980
Directory traversal vulnerability in joomlaflickr.php in the Joomla Flickr (com_joomlaflickr) component 1.0.3 for Joomla
43RIESGO
abrir
Referência
CVE-2019-1003000
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RIESGO
abrir
Referência
CVE-2019-1003000
A sandbox bypass vulnerability exists in Script Security Plugin 1.49 and earlier in src/main/java/org/jenkinsci/plugins/
60RIESGO
abrir
Referência
CVE-2026-18601
GL.iNet GL-MT3000 ovpn-client.so Native Plugin glc ovpn-client.check_config command injection
48RIESGO
abrir
Referência
CVE-2026-18600
GL.iNet GL-MT3000 Network Lua RPC Plugin network network.switch_status command injection
41RIESGO
abrir
Referência
CVE-2026-18599
GL.iNet GL-MT3000 Logread Lua RPC Plugin logread logread.set_config command injection
41RIESGO
abrir
Referência
CVE-2026-18598
GL.iNet GL-MT3000 Logread Lua RPC plugin logread logread.get_system_log command injection
41RIESGO
abrir
ReferênciaVexDay Proof
Smoothflash - 'cid' SQL Injection
CVE-2008-1623webappsphp
SQL injection vulnerability in admin_view_image.php in Smoothflash allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
Referência
CVE-2026-65920
Diffusers Path Traversal via weight_map Arbitrary File Read
33RIESGO
abrir
Referência
CVE-2026-65918
PyTorch torchvision GIF Decoder Out-of-bounds Heap Read
41RIESGO
abrir
Referência
CVE-2026-65702
Vanna 2.0.2 Path Traversal via FileSystemConversationStore
41RIESGO
abrir
Referência
CVE-2026-65701
SoftVC VITS Singing Voice Conversion Path Traversal via /wav2wav Flask Route
48RIESGO
abrir
Referência
CVE-2010-4864
SQL injection vulnerability in the Club Manager (com_clubmanager) component for Joomla! allows remote attackers to execu
23RIESGO
abrir
Referência
CVE-2010-4866
SQL injection vulnerability in index.php in Chipmunk Board 1.3 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
Referência
CVE-2010-4869
SQL injection vulnerability in index.php in DBHcms 1.1.4 allows remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir
Referência
CVE-2010-1045
SQL injection vulnerability in the Productbook (com_productbook) component 1.0.4 for Joomla! allows remote attackers to
23RIESGO
abrir
anteriorpágina 401 / 740siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.