Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.151exploits catalogados
35.370CVEs con explotación pública
24.695probados en laboratorio
22.233 exploits
Referência
CVE-2012-6042
GPSMapEdit 1.1.73.2 allows user-assisted remote attackers to cause a denial of service (crash) via a long string in a ls
23RIESGO
abrir
Referência
CVE-2009-5094
SQL injection vulnerability in info.php in CMS Faethon 2.2.0 Ultimate allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
Referência
CVE-2010-5019
SQL injection vulnerability in view_photo.php in 2daybiz Online Classified Script allows remote attackers to execute arb
23RIESGO
abrir
Referência
CVE-2010-2618
PHP remote file inclusion vulnerability in inc/smarty/libs/init.php in AdaptCMS 2.0.0 Beta, when register_globals is ena
23RIESGO
abrir
Referência
CVE-2010-2618
PHP remote file inclusion vulnerability in inc/smarty/libs/init.php in AdaptCMS 2.0.0 Beta, when register_globals is ena
23RIESGO
abrir
Referência
CVE-2016-8809
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 3
23RIESGO
abrir
ReferênciaVexDay Proof
HRS Multi - 'key' Blind SQL Injection
CVE-2008-3266webappsasp
SQL injection vulnerability in picture_pic_bv.asp in SoftAcid Hotel Reservation System (HRS) Multi allows remote attacke
23RIESGO
abrir
Referência
CVE-2016-8811
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 3
23RIESGO
abrir
Referência
CVE-2026-9604
JeecgBoot AiragModelController access control
33RIESGO
abrir
Referência
CVE-2022-0316
Multiple themes - Unauthenticated Arbitrary File Upload
48RIESGO
abrir
Referência
CVE-2013-6364
Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book
23RIESGO
abrir
Referência
CVE-2026-9603
SourceCodester eDoc Doctor Appointment System delete-session.php authorization
33RIESGO
abrir
Referência
CVE-2014-125115
Pandora FMS ≤ 5.0 SP2 Default Credential SQL Injection RCE
63RIESGO
abrir
Referência
CVE-2014-125115
Pandora FMS ≤ 5.0 SP2 Default Credential SQL Injection RCE
63RIESGO
abrir
ReferênciaVexDay Proof
Voodoo chat 1.0RC1b - 'users.dat' Password Disclosure
CVE-2006-6890webappsphp
Voodoo chat 1.0RC1b stores sensitive information under the web root with insufficient access control, which allows remot
23RIESGO
abrir
ReferênciaVexDay Proof
Prozilla Cheat Script 2.0 - 'id' SQL Injection
CVE-2008-1863webappsphp
SQL injection vulnerability in view_reviews.php in Prozilla Cheat Script (aka Cheats) 2.0 allows remote attackers to exe
23RIESGO
abrir
Referência
CVE-2014-3935
SQL injection vulnerability in glossaire-aff.php in the Glossaire module 1.0 for XOOPS allows remote attackers to execut
23RIESGO
abrir
Referência
CVE-2025-5630
D-Link DIR-816 form2lansetup.cgi stack-based overflow
48RIESGO
abrir
Referência
CVE-2009-3665
Multiple SQL injection vulnerabilities in index.php in Nullam Blog 0.1.2 allow remote attackers to execute arbitrary SQL
23RIESGO
abrir
Referência
CVE-2016-9079
CVE-2016-9079HIGHbajo ataque
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been dis
100RIESGO
abrir
Referência
CVE-2018-20472
An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. The logs web interface is vulnerable to stored XSS.
23RIESGO
abrir
Referência
CVE-2014-2081
Multiple SQL injection vulnerabilities in the login in web_reports/cgi-bin/InfoStation.cgi in Innovative vtls-Virtua bef
23RIESGO
abrir
Referência
CVE-2016-9079
CVE-2016-9079HIGHbajo ataque
A use-after-free vulnerability in SVG Animation has been discovered. An exploit built on this vulnerability has been dis
100RIESGO
abrir
ReferênciaVexDay Proof
Ultrastats 0.2.142 - 'players-detail.php' Blind SQL Injection
CVE-2008-3241webappsphp
SQL injection vulnerability in players-detail.php in UltraStats 0.2.136, 0.2.140, and 0.2.142 allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
OpenSSL 0.9.8c-1 < 0.9.8g-9 (Debian and Derivatives) - Predictable PRNG Brute Force SSH
CVE-2008-3280remotelinux
It was found that various OpenID Providers (OPs) had TLS Server Certificates that used weak keys, as a result of the Deb
23RIESGO
abrir
ReferênciaVexDay Proof
ASP Portal - Multiple SQL Injections
CVE-2008-5605webappsasp
Multiple SQL injection vulnerabilities in ASP Portal allow remote attackers to execute arbitrary SQL commands via the (1
23RIESGO
abrir
ReferênciaVexDay Proof
Pligg 9.9.5b - Arbitrary File Upload / SQL Injection
CVE-2008-5739webappsphp
SQL injection vulnerability in evb/check_url.php in Pligg CMS 9.9.5 Beta allows remote attackers to execute arbitrary SQ
23RIESGO
abrir
ReferênciaVexDay Proof
k-rate - SQL Injection / Cross-Site Scripting
CVE-2008-7097webappsphp
Multiple SQL injection vulnerabilities in Qsoft K-Rate Premium allow remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
2DayBiz Template Monster Clone - 'edituser.php' Change Pass
CVE-2009-1767webappsphp
admin/edituser.php in 2daybiz Template Monster Clone does not require administrative authentication, which allows remote
23RIESGO
abrir
Referência
CVE-2011-5109
Multiple SQL injection vulnerabilities in Freelancer calendar 1.01 and earlier allow remote attackers to inject arbitrar
23RIESGO
abrir
anteriorpágina 410 / 742siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.