Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.813exploits catalogados
35.788CVEs con explotación pública
24.695probados en laboratorio
22.523 exploits
ReferênciaVexDay Proof
Eserv 3.x - FTP Server (ABOR) Remote Stack Overflow (PoC)
CVE-2008-4588doswindows
Stack-based buffer overflow in the FTP server in Etype Eserv 3.x, possibly 3.26, allows remote attackers to cause a deni
23RIESGO
abrir
ReferênciaVexDay Proof
Stash 1.0.3 - SQL Injection User Credentials Disclosure
CVE-2008-4590webappsphp
Multiple SQL injection vulnerabilities in Stash 1.0.3 allow remote attackers to execute arbitrary SQL commands via (1) t
23RIESGO
abrir
Referência
CVE-2009-4082
PHP remote file inclusion vulnerability in forums/Forum_Include/index.php in Outreach Project Tool (OPT) 1.2.7 and earli
23RIESGO
abrir
Referência
CVE-2009-4082
PHP remote file inclusion vulnerability in forums/Forum_Include/index.php in Outreach Project Tool (OPT) 1.2.7 and earli
23RIESGO
abrir
ReferênciaVexDay Proof
WebSVN 2.0 - Cross-Site Scripting / File Handling / Code Execution
CVE-2008-5920webappsphp
The create_anchors function in utils.inc in WebSVN 1.x allows remote attackers to execute arbitrary PHP code via a craft
23RIESGO
abrir
Referência
CVE-2010-1114
Multiple PHP remote file inclusion vulnerabilities in Web Server Creator - Web Portal 0.1 allow remote attackers to exec
23RIESGO
abrir
Referência
CVE-2019-16197
In htdocs/societe/card.php in Dolibarr 10.0.1, the value of the User-Agent HTTP header is copied into the HTML document
23RIESGO
abrir
Referência
CVE-2010-0975
PHP remote file inclusion vulnerability in external.php in PHPCityPortal allows remote attackers to execute arbitrary PH
23RIESGO
abrir
Referência
CVE-2010-0975
PHP remote file inclusion vulnerability in external.php in PHPCityPortal allows remote attackers to execute arbitrary PH
23RIESGO
abrir
Referência
CVE-2010-1703
Multiple cross-site scripting (XSS) vulnerabilities in index_search.php in 2daybiz Polls (aka Advanced Poll) Script allo
23RIESGO
abrir
Referência
CVE-2010-1703
Multiple cross-site scripting (XSS) vulnerabilities in index_search.php in 2daybiz Polls (aka Advanced Poll) Script allo
23RIESGO
abrir
Referência
CVE-2014-3961
SQL injection vulnerability in the Export CSV page in the Participants Database plugin before 1.5.4.9 for WordPress allo
23RIESGO
abrir
Referência
CVE-2014-3974
Cross-site scripting (XSS) vulnerability in filemanager.php in AuraCMS 3.0 and earlier allows remote attackers to inject
23RIESGO
abrir
Referência
CVE-2021-4462
Employee Records System v1.0 Arbitrary File Upload RCE
63RIESGO
abrir
Referência
CVE-2010-1921
Multiple PHP remote file inclusion vulnerabilities in OpenMairie openAnnuaire 2.00, when register_globals is enabled, al
23RIESGO
abrir
ReferênciaVexDay Proof
Crysis 1.1.1.5879 - Remote Format String Denial of Service (PoC)
CVE-2008-1127doswindows
Format string vulnerability in the cryactio function in Crysis 1.1.1.5879 allows remote authenticated users to execute a
23RIESGO
abrir
ReferênciaVexDay Proof
KISGB (tmp_theme) 5.1.1 - Local File Inclusion
CVE-2008-1635webappsphp
Directory traversal vulnerability in view_private.php in Keep It Simple Guest Book (KISGB) 5.0.0 and earlier allows remo
23RIESGO
abrir
ReferênciaVexDay Proof
Sports Clubs Web Panel 0.0.1 - 'p' Local File Inclusion
CVE-2008-4592webappsphp
Directory traversal vulnerability in index.php in Sports Clubs Web Panel 0.0.1 allows remote attackers to include and ex
23RIESGO
abrir
Referência
CVE-2012-0911
TikiWiki CMS/Groupware before 6.7 LTS and before 8.4 allows remote attackers to execute arbitrary PHP code via a crafted
50RIESGO
abrir
Referência
CVE-2021-31642
A denial of service condition exists after an integer overflow in several IoT devices from CHIYU Technology, including B
35RIESGO
abrir
Referência
CVE-2012-1008
OfficeSIP Server 3.1 allows remote attackers to cause a denial of service (daemon crash) via a crafted To header in a SI
28RIESGO
abrir
Referência
CVE-2014-3978
SQL injection vulnerability in TomatoCart 1.1.8.6.1 allows remote authenticated users to execute arbitrary SQL commands
23RIESGO
abrir
Referência
CVE-2012-1024
Directory traversal vulnerability in file in Enigma2 Webinterface 1.5rc1 and 1.5beta4 allows remote attackers to read ar
23RIESGO
abrir
Referência
CVE-2012-1026
Multiple SQL injection vulnerabilities in login2.php in XRay CMS 1.1.1 allow remote attackers to execute arbitrary SQL c
23RIESGO
abrir
Referência
CVE-2018-5754
Cross-site scripting (XSS) vulnerability in the office-web component in Open-Xchange OX App Suite before 7.8.3-rev12 and
23RIESGO
abrir
Referência
CVE-2018-5754
Cross-site scripting (XSS) vulnerability in the office-web component in Open-Xchange OX App Suite before 7.8.3-rev12 and
23RIESGO
abrir
Referência
CVE-2019-6710
Zyxel NBG-418N v2 v1.00(AAXM.4)C0 devices allow login.cgi CSRF.
23RIESGO
abrir
Referência
CVE-2026-11866
LatePoint < 5.6.3 - Multiple Privileged Actions via CSRF
33RIESGO
abrir
Referência
CVE-2026-11371
BetterDocs < 4.5.5 - Unauthenticated Stored XSS via AI Doc Summarizer Prompt Injection
33RIESGO
abrir
Referência
CVE-2017-0282
Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT
23RIESGO
abrir
anteriorpágina 583 / 751siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.