Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.620exploits catalogados
35.647CVEs con explotación pública
24.695probados en laboratorio
22.407 exploits
Referência
glibc 2.38 - Buffer Overflow
CVE-2023-4911HIGHbajo ataquelocallinux
Glibc: buffer overflow in ld.so leading to privilege escalation
100RIESGO
abrir
ReferênciaVexDay Proof
Cobalt 0.1 - Multiple SQL Injections
CVE-2008-6202webappsasp
SQL injection vulnerability in CoBaLT 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter
23RIESGO
abrir
Referência
CVE-2024-11954
Pimcore Search Document cross site scripting
33RIESGO
abrir
Referência
CVE-2024-12344
TP-Link VN020 F3v(T) FTP USER Command memory corruption
33RIESGO
abrir
Referência
CVE-2008-6209
SQL injection vulnerability in view_product.php in Vastal I-Tech Software Zone allows remote attackers to execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
Vastal I-Tech Software Zone - 'cat_id' SQL Injection
CVE-2008-6209webappsphp
SQL injection vulnerability in view_product.php in Vastal I-Tech Software Zone allows remote attackers to execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
Dream4 Koobi 4.4/5.4 - gallery SQL Injection
CVE-2008-6210webappsphp
SQL injection vulnerability in index.php in dream4 Koobi 4.4 and 5.4 allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir
Referência
CVE-2019-10068
CVE-2019-10068CRITICALbajo ataque
An issue was discovered in Kentico 12.0.x before 12.0.15, 11.0.x before 11.0.48, 10.0.x before 10.0.52, and 9.x versions
100RIESGO
abrir
Referência
CVE-2026-7228
SourceCodester Pizzafy Ecommerce System ajax.php get_cart_count sql injection
33RIESGO
abrir
ReferênciaVexDay Proof
Venalsur on-line Booking Centre - Cross-Site Scripting / SQL Injection
CVE-2008-6215webappsphp
Cross-site scripting (XSS) vulnerability in cadena_ofertas_ext.php in Venalsur Booking Centre Booking System for Hotels
23RIESGO
abrir
Referência
CVE-2012-1125
Unrestricted file upload vulnerability in uploadify/scripts/uploadify.php in the Kish Guest Posting plugin before 1.2 fo
28RIESGO
abrir
ReferênciaVexDay Proof
Simple Document Management System 1.1.4 - Authentication Bypass
CVE-2008-6220webappsphp
SQL injection vulnerability in login.php in Simple Document Management System (SDMS) 1.1.5 and 1.1.4, and possibly earli
23RIESGO
abrir
Referência
CVE-2020-17530
CVE-2020-17530CRITICALbajo ataque
Forced OGNL evaluation, when evaluated on raw user input in tag attributes, may lead to remote code execution. Affected
100RIESGO
abrir
Referência
CVE-2020-5847
CVE-2020-5847CRITICALbajo ataque
Unraid through 6.8.0 allows Remote Code Execution.
100RIESGO
abrir
ReferênciaVexDay Proof
PHP Auto Listings - 'pg' SQL Injection
CVE-2008-6226webappsphp
SQL injection vulnerability in moreinfo.php in Pre Projects PHP Auto Listings Script, when magic_quotes_gpc is disabled,
23RIESGO
abrir
Referência
CVE-2009-2235
SQL injection vulnerability in page.php in Your Articles Directory allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
Referência
CVE-2011-4862
Buffer overflow in libtelnet/encrypt.c in telnetd in FreeBSD 7.3 through 9.0, MIT Kerberos Version 5 Applications (aka k
60RIESGO
abrir
ReferênciaVexDay Proof
Jadu Galaxies - 'categoryId' Blind SQL Injection
CVE-2008-6254webappsphp
SQL injection vulnerability in scripts/documents.php in Jadu Galaxies allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
ReferênciaVexDay Proof
OpenASP 3.0 - Blind SQL Injection
CVE-2008-6257webappsasp
SQL injection vulnerability in default.asp in Openasp 3.0 and earlier allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
Referência
CVE-2014-6332
CVE-2014-6332HIGHbajo ataque
OleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
100RIESGO
abrir
Referência
CVE-2023-25440
Stored Cross Site Scripting (XSS) vulnerability in the add contact function CiviCRM 5.59.alpha1, allows attackers to exe
33RIESGO
abrir
ReferênciaVexDay Proof
Q-Shop 3.0 - Cross-Site Scripting / SQL Injection
CVE-2008-6258webappsasp
SQL injection vulnerability in users.asp in QuadComm Q-Shop 3.0, and possibly earlier, allows remote attackers to execut
23RIESGO
abrir
ReferênciaVexDay Proof
Q-Shop 3.0 - Cross-Site Scripting / SQL Injection
CVE-2008-6259webappsasp
Cross-site scripting (XSS) vulnerability in search.asp in QuadComm Q-Shop 3.0, and possibly earlier, allows remote attac
23RIESGO
abrir
ReferênciaVexDay Proof
TurnkeyForms Local Classifieds - Cross-Site Scripting / SQL Injection
CVE-2008-6350webappsphp
SQL injection vulnerability in listtest.php in TurnkeyForms Local Classifieds allows remote attackers to execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
TurnkeyForms Local Classifieds - Cross-Site Scripting / SQL Injection
CVE-2008-6351webappsphp
Cross-site scripting (XSS) vulnerability in listtest.php in TurnkeyForms Local Classifieds allows remote attackers to in
23RIESGO
abrir
ReferênciaVexDay Proof
Xpoze 4.10 - 'menu' Blind SQL Injection
CVE-2008-6352webappsphp
SQL injection vulnerability in home.html in Xpoze Pro 4.10 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
ReferênciaVexDay Proof
ASP-CMS 1.0 - 'cha' SQL Injection
CVE-2008-6353webappsasp
SQL injection vulnerability in index.asp in ASP-CMS 1.0 allows remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir
ReferênciaVexDay Proof
The Net Guys ASPired2Protect - Database Disclosure
CVE-2008-6355webappsasp
The Net Guys ASPired2Protect stores sensitive information under the web root with insufficient access control, which all
23RIESGO
abrir
ReferênciaVexDay Proof
evCal Events Calendar - Database Disclosure
CVE-2008-6356webappsasp
evCal Events Calendar stores sensitive information under the web root with insufficient access control, which allows rem
23RIESGO
abrir
ReferênciaVexDay Proof
MyCal Personal Events Calendar - Database Disclosure
CVE-2008-6357webappsasp
MyCal Personal Events Calendar stores sensitive information under the web root with insufficient access control, which a
23RIESGO
abrir
anteriorpágina 520 / 747siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.