Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.231exploits catalogados
35.420CVEs con explotación pública
24.695probados en laboratorio
22.233 exploits
Referência
CVE-2026-66750
Let's Chat 0.3.0 - 0.4.8 Broken Access Control File Disclosure via GET /files route
33RIESGO
abrir
Referência
CVE-2012-10045
XODA 0.4.5 Arbitrary PHP File Upload
63RIESGO
abrir
Referência
CVE-2012-10045
XODA 0.4.5 Arbitrary PHP File Upload
63RIESGO
abrir
Referência
CVE-2012-10045
XODA 0.4.5 Arbitrary PHP File Upload
63RIESGO
abrir
Referência
CVE-2012-10049
WebPageTest Arbitrary PHP File Upload RCE
63RIESGO
abrir
Referência
CVE-2012-10049
WebPageTest Arbitrary PHP File Upload RCE
63RIESGO
abrir
Referência
CVE-2012-10049
WebPageTest Arbitrary PHP File Upload RCE
63RIESGO
abrir
ReferênciaVexDay Proof
DigiAffiliate 1.4 - 'id' SQL Injection
CVE-2007-0306webappsasp
SQL injection vulnerability in visu_user.asp in Digiappz DigiAffiliate 1.4 and earlier allows remote attackers to execut
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component Car Manager 1.1 - SQL Injection
CVE-2007-1704webappsphp
SQL injection vulnerability in index.php in the Car Manager (com_resman) 1.1 and earlier component for Joomla! allows re
23RIESGO
abrir
ReferênciaVexDay Proof
XOOPS Module myAlbum-P 2.0 - 'cid' SQL Injection
CVE-2007-1807webappsphp
SQL injection vulnerability in modules/myalbum/viewcat.php in the myAlbum-P 2.0 and earlier module for Xoops allows remo
23RIESGO
abrir
ReferênciaVexDay Proof
Tutti Nova 1.6 - 'TNLIB_DIR' Remote File Inclusion
CVE-2006-4276webappsphp
PHP remote file inclusion vulnerability in Tutti Nova 1.6 and earlier allows remote attackers to execute arbitrary PHP c
23RIESGO
abrir
ReferênciaVexDay Proof
PHP League 0.82 - 'classement.php' SQL Injection
CVE-2006-5676webappsasp
SQL injection vulnerability in consult/classement.php in Uni-Vert PhpLeague 0.82 and earlier allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
Dokeos 1.8.0 - 'my_progress.php?course' SQL Injection
CVE-2007-2902webappsphp
SQL injection vulnerability in main/auth/my_progress.php in Dokeos 1.8.0 and earlier allows remote authenticated users t
23RIESGO
abrir
Referência
CVE-2009-3215
SQL injection vulnerability in IXXO Cart Standalone before 3.9.6.1, and the IXXO Cart component for Joomla! 1.0.x, allow
23RIESGO
abrir
ReferênciaVexDay Proof
Elkagroup Image Gallery 1.0 - SQL Injection
CVE-2007-3461webappsphp
SQL injection vulnerability in property.php in elkagroup Image Gallery 1.0 allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
ArcadeBuilder Game Portal Manager 1.7 - SQL Injection
CVE-2007-3521webappsphp
SQL injection vulnerability in ArcadeBuilder Game Portal Manager 1.7 allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir
ReferênciaVexDay Proof
PHP123 Top Sites - 'category.php?cat' SQL Injection
CVE-2007-4054webappsphp
SQL injection vulnerability in category.php in PHP123 Top Sites allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
ReferênciaVexDay Proof
SimpleBlog 3.0 - 'comments_get.asp?id' SQL Injection
CVE-2007-4055webappsasp
SQL injection vulnerability in comments_get.asp in SimpleBlog 3.0 allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir
ReferênciaVexDay Proof
ABC estore 3.0 - 'cat_id' Blind SQL Injection
CVE-2007-4627webappsphp
SQL injection vulnerability in index.php in ABC eStore 3.0 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
ReferênciaVexDay Proof
Blog:CMS 4.2.1b - SQL Injection / Cross-Site Scripting
CVE-2008-0360webappsphp
Multiple SQL injection vulnerabilities in BLOG:CMS 4.2.1b allow remote attackers to execute arbitrary SQL commands via (
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component com_doc - SQL Injection
CVE-2008-0772webappsphp
SQL injection vulnerability in index.php in the com_doc component for Joomla! and Mambo allows remote attackers to execu
23RIESGO
abrir
ReferênciaVexDay Proof
PHP-Nuke Module EasyContent - 'page_id' SQL Injection
CVE-2008-0880webappsphp
SQL injection vulnerability in modules.php in the EasyContent module for PHP-Nuke allows remote attackers to execute arb
23RIESGO
abrir
ReferênciaVexDay Proof
vShare YouTube Clone 2.6 - 'tid' SQL Injection
CVE-2008-2223webappsphp
SQL injection vulnerability in group_posts.php in vShare YouTube Clone 2.6 allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
easyTrade 2.x - 'id' SQL Injection
CVE-2008-2790webappsphp
SQL injection vulnerability in detail.php in MountainGrafix easyTrade 2.x allows remote attackers to execute arbitrary S
23RIESGO
abrir
ReferênciaVexDay Proof
FlashGet 1.9 - 'FTP PWD Response' Remote Buffer Overflow (PoC)
CVE-2008-4321doswindows
Buffer overflow in FlashGet (formerly JetCar) FTP 1.9 allows remote FTP servers to execute arbitrary code via a long res
23RIESGO
abrir
ReferênciaVexDay Proof
FlashGet 1.9.0.1012 - 'FTP PWD Response' Remote Buffer Overflow (SafeSEH)
CVE-2008-4321remotewindows
Buffer overflow in FlashGet (formerly JetCar) FTP 1.9 allows remote FTP servers to execute arbitrary code via a long res
23RIESGO
abrir
ReferênciaVexDay Proof
celerbb 0.0.2 - Multiple Vulnerabilities
CVE-2009-0851webappsphp
Multiple SQL injection vulnerabilities in CelerBB 0.0.2, when magic_quotes_gpc is disabled, allow remote attackers to ex
23RIESGO
abrir
Referência
CVE-2022-45707
IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the rules parameter in the formAddDnsHijac
48RIESGO
abrir
Referência
CVE-2022-45708
IP-COM M50 V15.11.0.33(10768) was discovered to contain a buffer overflow via the sPortMapIndex parameter in the formDel
48RIESGO
abrir
Referência
CVE-2022-45710
IP-COM M50 V15.11.0.33(10768) was discovered to contain multiple buffer overflows via the pEnable, pLevel, and pModule p
48RIESGO
abrir
anteriorpágina 424 / 742siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.