Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.813exploits catalogados
35.788CVEs con explotación pública
24.695probados en laboratorio
22.523 exploits
Referência
CVE-2014-4710
Cross-site scripting (XSS) vulnerability in zero_user_account.php in ZeroCMS 1.0 allows remote attackers to inject arbit
23RIESGO
abrir
Referência
CVE-2013-7368
Multiple cross-site scripting (XSS) vulnerabilities in Gnew 2013.1 allow remote attackers to inject arbitrary web script
23RIESGO
abrir
Referência
CVE-2013-5312
Multiple cross-site scripting (XSS) vulnerabilities in Vastal I-Tech phpVID 1.2.3 allow remote attackers to inject arbit
23RIESGO
abrir
Referência
CVE-2013-5312
Multiple cross-site scripting (XSS) vulnerabilities in Vastal I-Tech phpVID 1.2.3 allow remote attackers to inject arbit
23RIESGO
abrir
Referência
CVE-2013-4898
Unrestricted file upload vulnerability in the user profile page feature in the Timeline Plugin 4.2.5p9 for SocialEngine
23RIESGO
abrir
ReferênciaVexDay Proof
OpenH323 Opal SIP Protocol - Remote Denial of Service
CVE-2007-4924doswindows
The Open Phone Abstraction Library (opal), as used by (1) Ekiga before 2.0.10 and (2) OpenH323 before 2.2.4, allows remo
28RIESGO
abrir
Referência
CVE-2019-11537
In osTicket before 1.12, XSS exists via /upload/file.php, /upload/scp/users.php?do=import-users, and /upload/scp/ajax.ph
23RIESGO
abrir
ReferênciaVexDay Proof
Cmaps v8.0 - SQL injection
CVE-2023-29809CRITICALwebappsphp
SQL injection vulnerability found in Maximilian Vogt companymaps (cmaps) v.8.0 allows a remote attacker to execute arbit
53RIESGO
abrir
ReferênciaVexDay Proof
Ads Pro - 'dhtml.pl' Remote Command Execution
CVE-2008-6826webappscgi
dhtml.pl in MHF Media Pro allows remote attackers to execute arbitrary commands via shell metacharacters in the page par
23RIESGO
abrir
Referência
CVE-2018-18804
Bakeshop Inventory System 1.0 has SQL injection via the login screen, related to include/publicfunction.vb.
23RIESGO
abrir
Referência
CVE-2018-18804
Bakeshop Inventory System 1.0 has SQL injection via the login screen, related to include/publicfunction.vb.
23RIESGO
abrir
Referência
CVE-2018-13045
SQL injection vulnerability in the "Bazar" page in Yeswiki Cercopitheque 2018-06-19-1 and earlier allows attackers to ex
23RIESGO
abrir
Referência
CVE-2018-13045
SQL injection vulnerability in the "Bazar" page in Yeswiki Cercopitheque 2018-06-19-1 and earlier allows attackers to ex
23RIESGO
abrir
Referência
CVE-2014-9331
Cross-site request forgery (CSRF) vulnerability in ZOHO ManageEngine Desktop Central before 9 build 90130 allows remote
23RIESGO
abrir
Referência
CVE-2017-6552
Livebox 3 Sagemcom SG30_sip-fr-5.15.8.1 devices have an insufficiently large default value for the maximum IPv6 routing
23RIESGO
abrir
Referência
CVE-2014-5189
SQL injection vulnerability in lib/optin/optin_page.php in the Lead Octopus plugin for WordPress allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
Fuju News 1.0 - Authentication Bypass / SQL Injection
CVE-2006-1838webappsphp
edit_kategorie.php in Fuju News 1.0 allows remote attackers to bypass authentication by setting the authorized cookie.
23RIESGO
abrir
ReferênciaVexDay Proof
WFTPD Pro Server 3.23.1.1 - 'APPE' Remote Buffer Overflow (PoC)
CVE-2006-5826doswindows
Buffer overflow in Texas Imperial Software WFTPD Pro Server 3.23.1.1 allows remote authenticated users to execute arbitr
28RIESGO
abrir
ReferênciaVexDay Proof
meBiblio 0.4.5 - 'action' Remote File Inclusion
CVE-2007-6089webappsphp
PHP remote file inclusion vulnerability in index.php in meBiblio 0.4.5 allows remote attackers to execute arbitrary PHP
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component mosDirectory 2.3.2 - 'catid' SQL Injection
CVE-2008-0690webappsphp
SQL injection vulnerability in index.php in the mosDirectory (com_directory) 2.3.2 component for Joomla! allows remote a
23RIESGO
abrir
ReferênciaVexDay Proof
GC Auction Platinum - 'cate_id' SQL Injection
CVE-2008-3413webappsphp
SQL injection vulnerability in category.php in Greatclone GC Auction Platinum allows remote attackers to execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
phpMyRealty 2.0.0 - 'location' SQL Injection
CVE-2008-3445webappsphp
SQL injection vulnerability in index.php in phpMyRealty (PMR) 2.0.0 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
Referência
CVE-2026-12697
wpForo Forum < 3.1.2 - Subscriber+ Cross-User AI Chat Message Deletion via IDOR
33RIESGO
abrir
Referência
CVE-2025-28137
The TOTOLINK A810R V4.1.2cu.5182_B20201026 were found to contain a pre-auth remote command execution vulnerability in th
53RIESGO
abrir
Referência
CVE-2010-1315
Directory traversal vulnerability in weberpcustomer.php in the webERPcustomer (com_weberpcustomer) component 1.2.1 and 1
38RIESGO
abrir
Referência
CVE-2013-6884
The write-blocker in CRU Ditto Forensic FieldStation with firmware before 2013Oct15a has a default "ditto" username and
28RIESGO
abrir
Referência
CVE-2013-6884
The write-blocker in CRU Ditto Forensic FieldStation with firmware before 2013Oct15a has a default "ditto" username and
28RIESGO
abrir
Referência
CVE-2011-4829
SQL injection vulnerability in the com_listing component in Barter Sites component 1.3 for Joomla! allows remote attacke
23RIESGO
abrir
Referência
CVE-2018-17980
NoMachine before 5.3.27 and 6.x before 6.3.6 allows attackers to gain privileges via a Trojan horse wintab32.dll file lo
23RIESGO
abrir
Referência
CVE-2018-17980
NoMachine before 5.3.27 and 6.x before 6.3.6 allows attackers to gain privileges via a Trojan horse wintab32.dll file lo
23RIESGO
abrir
anteriorpágina 585 / 751siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.