Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.724exploits catalogados
35.724CVEs con explotación pública
24.695probados en laboratorio
22.407 exploits
ReferênciaVexDay Proof
Joomla! Component OnlineFlashQuiz 1.0.2 - Remote File Inclusion
CVE-2008-1682webappsphp
PHP remote file inclusion vulnerability in quiz/common/db_config.inc.php in the Online FlashQuiz (com_onlineflashquiz) 1
28RIESGO
abrir
Referência
CVE-2009-4872
Multiple SQL injection vulnerabilities in globepersonnel_login.asp in Logoshows BBS 2.0 allow remote attackers to execut
23RIESGO
abrir
ReferênciaVexDay Proof
VMware - COM API ActiveX Remote Buffer Overflow (PoC)
CVE-2008-3892doswindows
Buffer overflow in a certain ActiveX control in the COM API in VMware Workstation 5.5.x before 5.5.8 build 108000, VMwar
28RIESGO
abrir
Referência
CVE-2018-19126
PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 allows remote attackers to execute arbitrary code via a file u
28RIESGO
abrir
Referência
CVE-2009-4908
Multiple cross-site scripting (XSS) vulnerabilities in oBlog allow remote attackers to inject arbitrary web script or HT
23RIESGO
abrir
Referência
CVE-2009-4925
Multiple SQL injection vulnerabilities in Portale e-commerce Creasito (aka creasito e-commerce content manager) 1.3.16,
23RIESGO
abrir
Referência
CVE-2017-17640
Advanced World Database 2.0.5 has SQL Injection via the city.php country or state parameter, or the state.php country pa
23RIESGO
abrir
Referência
CVE-2016-3987
The HTTP server in Trend Micro Password Manager allows remote web servers to execute arbitrary commands via the url para
28RIESGO
abrir
Referência
CVE-2016-3987
The HTTP server in Trend Micro Password Manager allows remote web servers to execute arbitrary commands via the url para
28RIESGO
abrir
Referência
CVE-2010-1717
Directory traversal vulnerability in the iF surfALERT (com_if_surfalert) component 1.2 for Joomla! allows remote attacke
43RIESGO
abrir
Referência
CVE-2017-3077
Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the PNG image
28RIESGO
abrir
Referência
CVE-2015-8770
Directory traversal vulnerability in the set_skin function in program/include/rcmail_output_html.php in Roundcube before
28RIESGO
abrir
Referência
CVE-2021-3560
CVE-2021-3560HIGHbajo ataque
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
Referência
CVE-2009-4935
SQL injection vulnerability in ogp_show.php in Online Guestbook Pro allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
Referência
CVE-2013-4211
A Code Execution Vulnerability exists in OpenX Ad Server 2.8.10 due to a backdoor in flowplayer-3.1.1.min.js library, wh
60RIESGO
abrir
Referência
CVE-2009-4978
Directory traversal vulnerability in down.php in MyBackup 1.4.0 allows remote attackers to read arbitrary files via a ..
23RIESGO
abrir
Referência
CVE-2009-4982
SQL injection vulnerability in the select function in Irokez CMS 0.7.1, when magic_quotes_gpc is disabled, allows remote
23RIESGO
abrir
Referência
CVE-2026-13527
SourceCodester Class and Exam Timetabling System preview4.php sql injection
33RIESGO
abrir
Referência
CVE-2026-13526
SourceCodester Class and Exam Timetabling System edit_class.php sql injection
33RIESGO
abrir
Referência
CVE-2026-13516
Tenda JD12L WifiGuestSet fromSetWifiGusetBasic stack-based overflow
41RIESGO
abrir
Referência
CVE-2015-3302
The TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1
28RIESGO
abrir
Referência
CVE-2020-24186
A Remote Code Execution vulnerability exists in the gVectors wpDiscuz plugin 7.0 through 7.0.4 for WordPress, which allo
85RIESGO
abrir
Referência
CVE-2009-1330
Stack-based buffer overflow in Easy RM to MP3 Converter allows remote attackers to execute arbitrary code via a long fil
28RIESGO
abrir
Referência
CVE-2009-4437
Multiple SQL injection vulnerabilities in Active Auction House 3.6 allow remote attackers to execute arbitrary SQL comma
23RIESGO
abrir
Referência
CVE-2016-6272
XPath injection vulnerability in Epic MyChart allows remote attackers to access contents of an XML document containing s
28RIESGO
abrir
Referência
CVE-2018-20525
Roxy Fileman 1.4.5 allows Directory Traversal in copydir.php, copyfile.php, and fileslist.php.
28RIESGO
abrir
Referência
CVE-2018-20525
Roxy Fileman 1.4.5 allows Directory Traversal in copydir.php, copyfile.php, and fileslist.php.
28RIESGO
abrir
Referência
CVE-2023-3643
Boss Mini document file inclusion
78RIESGO
abrir
ReferênciaVexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
CVE-2007-6495webappsasp
inc_newuser.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticated users to change the permis
23RIESGO
abrir
Referência
CVE-2013-4341
Multiple cross-site scripting (XSS) vulnerabilities in Moodle through 2.2.11, 2.3.x before 2.3.9, 2.4.x before 2.4.6, an
43RIESGO
abrir
anteriorpágina 529 / 747siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.