Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.724exploits catalogados
35.724CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.455Referência 22.492GitHub PoC 14.286VulnCheck XDB 8703Nuclei 4314Metasploit 3474✓ solo verificadosrecientespopularesriesgo
22.407 exploits
Referência
CVE-2008-2565
Multiple SQL injection vulnerabilities in PHP Address Book 3.1.5 and earlier allow remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência
CVE-2022-30076
ENTAB ERP 1.0 allows attackers to discover users' full names via a brute force attack with a series of student usernames
33RIESGO
abrir ↗Referência
CVE-2013-4948
SQL injection vulnerability in view.php in Machform 2 allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir ↗Referência
CVE-2013-4948
SQL injection vulnerability in view.php in Machform 2 allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir ↗Referência
CVE-2018-25114
osCommerce 2.3.4.1 Installer Unauthenticated Configuration File Injection PHP Code Execution
63RIESGO
abrir ↗Referência
CVE-2018-25114
osCommerce 2.3.4.1 Installer Unauthenticated Configuration File Injection PHP Code Execution
63RIESGO
abrir ↗Referência
CVE-2012-3838
Gekko before 1.2.0 allows remote attackers to obtain the installation path via a direct request to (1) admin/templates/b
23RIESGO
abrir ↗Referência✓ VexDay Proof
TemaTres 1.0.3 - Authentication Bypass / SQL Injection / Cross-Site Scripting
Multiple cross-site scripting (XSS) vulnerabilities in TemaTres 1.0.3 and 1.031 allow remote attackers to inject arbitra
23RIESGO
abrir ↗Referência✓ VexDay Proof
TFT Gallery 0.10 - Password Disclosure
TFT Gallery 0.10 stores sensitive information under the web root with insufficient access control, which allows remote a
23RIESGO
abrir ↗Referência
CVE-2008-3371
Directory traversal vulnerability in install/help.php in TalkBack 2.3.5, and other versions before 2.3.6.2, allows remot
23RIESGO
abrir ↗Referência
CVE-2008-3371
Directory traversal vulnerability in install/help.php in TalkBack 2.3.5, and other versions before 2.3.6.2, allows remot
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPMyDesk 1.0 Beta - 'viewticket.php' Local File Inclusion
Directory traversal vulnerability in pmd-config.php in PHPMyDesk 1.0beta allows remote attackers to include arbitrary lo
23RIESGO
abrir ↗Referência
CVE-2020-22841
Stored XSS in b2evolution CMS version 6.11.6 and prior allows an attacker to perform malicious JavaScript code execution
23RIESGO
abrir ↗Referência
CVE-2010-1345
Directory traversal vulnerability in the Cookex Agency CKForms (com_ckforms) component 1.3.3 for Joomla! allows remote a
43RIESGO
abrir ↗Referência✓ VexDay Proof
Social Engine 2.0 - Multiple Local File Inclusions
Multiple directory traversal vulnerabilities in Social Engine 2.0 allow remote attackers to include and execute arbitrar
23RIESGO
abrir ↗Referência✓ VexDay Proof
SezHoo 0.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in SezHooTabsAndActions.php in SezHoo 0.1 allows remote attackers to execute arb
23RIESGO
abrir ↗Referência
CVE-2017-5473
Cross-site request forgery (CSRF) vulnerability in ntopng through 2.4 allows remote attackers to hijack the authenticati
23RIESGO
abrir ↗Referência
CVE-2005-0853
betaparticle blog (bp blog) stores the database under the web root, which allows remote attackers to obtain sensitive in
23RIESGO
abrir ↗Referência
CVE-2014-5308
Multiple SQL injection vulnerabilities in TestLink 1.9.11 allow remote authenticated users to execute arbitrary SQL comm
23RIESGO
abrir ↗Referência
CVE-2014-5308
Multiple SQL injection vulnerabilities in TestLink 1.9.11 allow remote authenticated users to execute arbitrary SQL comm
23RIESGO
abrir ↗Referência
CVE-2026-9436
Totolink A8000RU Web Management cstecgi.cgi setL2tpServerCfg os command injection
48RIESGO
abrir ↗Referência
CVE-2011-1569
download.aspx in Douran Portal 3.9.7.8 allows remote attackers to obtain source code of arbitrary files under the web ro
23RIESGO
abrir ↗Referência
CVE-2019-19726
OpenBSD through 6.6 allows local users to escalate to root because a check for LD_LIBRARY_PATH in setuid programs can be
38RIESGO
abrir ↗Referência
CVE-2019-19726
OpenBSD through 6.6 allows local users to escalate to root because a check for LD_LIBRARY_PATH in setuid programs can be
38RIESGO
abrir ↗Referência
CVE-2014-3080
Multiple cross-site scripting (XSS) vulnerabilities on IBM GCM16 and GCM32 Global Console Manager switches with firmware
23RIESGO
abrir ↗Referência
CVE-2014-0984
The passwordCheck function in SAP Router 721 patch 117, 720 patch 411, 710 patch 029, and earlier terminates validation
23RIESGO
abrir ↗Referência
CVE-2010-0673
SQL injection vulnerability in cplphoto.php in the Copperleaf Photolog plugin 0.16, and possibly earlier, for WordPress
23RIESGO
abrir ↗Referência
CVE-2010-0673
SQL injection vulnerability in cplphoto.php in the Copperleaf Photolog plugin 0.16, and possibly earlier, for WordPress
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.