Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.772exploits catalogados
35.760CVEs con explotación pública
24.695probados en laboratorio
22.523 exploits
Referência
CVE-2008-0843
StatCounteX 3.0 and 3.1 allows remote attackers to obtain sensitive information and edit configuration scripts via a dir
23RIESGO
abrir
Referência
CVE-2016-3652
Multiple cross-site scripting (XSS) vulnerabilities in management scripts in Symantec Endpoint Protection Manager (SEPM)
23RIESGO
abrir
ReferênciaVexDay Proof
PHPAuctionSystem - Insecure Cookie Handling
CVE-2009-0108webappsphp
PHPAuctions (aka PHPAuctionSystem) allows remote attackers to bypass authentication and gain administrative access via m
23RIESGO
abrir
Referência
CVE-2009-4447
Jax Guestbook 3.5.0 allows remote attackers to bypass authentication and modify administrator settings via a direct requ
23RIESGO
abrir
Referência
CVE-2016-1000124
Unauthenticated SQL Injection in Huge-IT Portfolio Gallery Plugin v1.0.6
23RIESGO
abrir
Referência
CVE-2015-6512
SQL injection vulnerability in the get_messages function in server/plugins/chatroom/chatroom.php in FreiChat 9.6 allows
23RIESGO
abrir
ReferênciaVexDay Proof
Online Fantasy Football League (OFFL) 0.2.6 - 'teams.php' SQL Injection
CVE-2008-2890webappsphp
Multiple SQL injection vulnerabilities in Online Fantasy Football League (OFFL) 0.2.6 and earlier allow remote attackers
23RIESGO
abrir
Referência
CVE-2011-4674
SQL injection vulnerability in popup.php in Zabbix 1.8.3 and 1.8.4, and possibly other versions before 1.8.9, allows rem
23RIESGO
abrir
Referência
CVE-2019-16531
LayerBB before 1.1.4 has multiple CSRF issues, as demonstrated by changing the System Settings via admin/general.php.
23RIESGO
abrir
Referência
CVE-2023-34723
An issue was discovered in TechView LA-5570 Wireless Gateway 1.0.19_T53, allows attackers to gain sensitive information
23RIESGO
abrir
Referência
CVE-2010-1653
Directory traversal vulnerability in graphics.php in the Graphics (com_graphics) component 1.0.6 and 1.5.0 for Joomla! a
43RIESGO
abrir
ReferênciaVexDay Proof
Light Weight Calendar 1.x - 'date' Remote Code Execution
CVE-2006-1252webappsphp
Eval injection vulnerability in cal.php in Light Weight Calendar (LWC) 1.0 allows remote attackers to execute arbitrary
23RIESGO
abrir
Referência
CVE-2016-4313
Directory traversal vulnerability in unzip/extract feature in eXtplorer 2.1.9 allows remote attackers to execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
File Store PRO 3.2 - Multiple Blind SQL Injections
CVE-2006-1278webappsphp
SQL injection vulnerability in @1 File Store 2006.03.07 allows remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir
ReferênciaVexDay Proof
Yahoo! Messenger 8.1.0.421 - CYFT Object Arbitrary File Download
CVE-2007-5017remotewindows
Absolute path traversal vulnerability in a certain ActiveX control in the CYFT object in ft60.dll in Yahoo! Messenger 8.
23RIESGO
abrir
ReferênciaVexDay Proof
Calendar Script 1.1 - Insecure Cookie Handling
CVE-2008-5738webappsphp
Nodstrum MySQL Calendar 1.1 and 1.2 allows remote attackers to bypass authentication and gain administrative access by s
23RIESGO
abrir
Referência
CVE-2019-0552
An elevation of privilege exists in Windows COM Desktop Broker, aka "Windows COM Elevation of Privilege Vulnerability."
23RIESGO
abrir
Referência
CVE-2026-14205
WP Events Manager < 2.2.5 - Subscriber+ Payment Bypass via 'qty' Parameter
48RIESGO
abrir
Referência
CVE-2014-9146
Multiple cross-site scripting (XSS) vulnerabilities in Fiyo CMS 2.0.1.8 allow remote attackers to inject arbitrary web s
23RIESGO
abrir
Referência
CVE-2012-5242
Directory traversal vulnerability in functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to
23RIESGO
abrir
Referência
CVE-2009-4467
misc.php in DeluxeBB 1.3 allows remote attackers to register accounts without a valid email address via a valemail actio
23RIESGO
abrir
Referência
CVE-2009-2327
Cross-site scripting (XSS) vulnerability in add_voting.php in KerviNet Forum 1.1 and earlier allows remote authenticated
23RIESGO
abrir
ReferênciaVexDay Proof
Chicomas 2.0.4 - Database Backup / File Disclosure / Cross-Site Scripting
CVE-2008-5853webappsphp
Chilek Content Management System (aka ChiCoMaS) 2.0.4 and earlier stores sensitive information under the web root with i
23RIESGO
abrir
Referência
CVE-2011-1665
PHPBoost 3.0 stores sensitive information under the web root with insufficient access control, which allows remote attac
23RIESGO
abrir
ReferênciaVexDay Proof
CaLogic Calendars 1.2.2 - 'CLPath' Remote File Inclusion
CVE-2006-2570webappsphp
PHP remote file inclusion vulnerability in CaLogic Calendars 1.2.2 allows remote attackers to execute arbitrary PHP code
23RIESGO
abrir
Referência
CVE-2015-3300
Multiple cross-site scripting (XSS) vulnerabilities in the TheCartPress eCommerce Shopping Cart (aka The Professional Wo
23RIESGO
abrir
Referência
CVE-2010-0978
KMSoft Guestbook (aka GBook) 1.0 stores sensitive information under the web root with insufficient access control, which
23RIESGO
abrir
Referência
CVE-2010-0978
KMSoft Guestbook (aka GBook) 1.0 stores sensitive information under the web root with insufficient access control, which
23RIESGO
abrir
Referência
CVE-2026-19196
SourceCodester Photo Share Website ajax.php login sql injection
33RIESGO
abrir
Referência
CVE-2019-11504
Zotonic before version 0.47 has mod_admin XSS.
23RIESGO
abrir
anteriorpágina 566 / 751siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.