Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.900exploits catalogados
35.840CVEs con explotación pública
24.695probados en laboratorio
22.573 exploits
ReferênciaVexDay Proof
HLStats 1.34 - 'hlstats.php' SQL Injection
CVE-2006-6781webappsphp
HLstats 1.20 through 1.34 allows remote attackers to obtain sensitive information via playinfo mode, with certain values
23RIESGO
abrir
Referência
CVE-2007-3529
videos.php in PHPDirector 0.21 and earlier allows remote attackers to obtain sensitive information via an empty value of
23RIESGO
abrir
ReferênciaVexDay Proof
LokiCMS 0.3.3 - Arbitrary File Delete
CVE-2008-4913webappsphp
Directory traversal vulnerability in admin.php in LokiCMS 0.3.3 and earlier allows remote attackers to delete arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
celerbb 0.0.2 - Multiple Vulnerabilities
CVE-2009-0852webappsphp
showme.php in CelerBB 0.0.2 allows remote attackers to obtain "reserved information" via the user parameter.
23RIESGO
abrir
ReferênciaVexDay Proof
WoW Roster 1.5.1 - 'subdir' Remote File Inclusion
CVE-2006-3998webappsphp
PHP remote file inclusion vulnerability in conf.php in WoWRoster (aka World of Warcraft Roster) 1.5.1 and earlier allows
23RIESGO
abrir
ReferênciaVexDay Proof
Poplar Gedcom Viewer 2.0 - 'common.php' Remote File Inclusion
CVE-2007-0307webappsphp
PHP remote file inclusion vulnerability in include/common.php in Poplar Gedcom Viewer 2.0 and earlier allows remote atta
23RIESGO
abrir
ReferênciaVexDay Proof
Sinapis 2.2 Gastebuch - 'sinagb.php?fuss' Remote File Inclusion
CVE-2007-1130webappsphp
PHP remote file inclusion vulnerability in sinagb.php in Sinapis Gastebuch 2.2 allows remote attackers to execute arbitr
23RIESGO
abrir
Referência
CVE-2012-6045
Cross-site scripting (XSS) vulnerability in gb/user/index.php in Ramui Forum, possibly 1.0 Beta, allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
Pharmacy System 2.0 - 'index.php?ID' SQL Injection
CVE-2007-3434webappsphp
index.php in Pharmacy System 2 and earlier allows remote attackers to obtain sensitive information via a ' (quote) chara
23RIESGO
abrir
Referência
CVE-2010-2438
SQL injection vulnerability in G.CMS generator allows remote attackers to execute arbitrary SQL commands via the lang pa
23RIESGO
abrir
ReferênciaVexDay Proof
Basic-CMS - SQL Injection
CVE-2008-2789webappsphp
SQL injection vulnerability in pages/index.php in BASIC-CMS allows remote attackers to execute arbitrary SQL commands vi
43RIESGO
abrir
ReferênciaVexDay Proof
falcon CMS 1.4.3 - Remote File Inclusion / Cross-Site Scripting
CVE-2007-6488webappsphp
Multiple PHP remote file inclusion vulnerabilities in Falcon Series One CMS 1.4.3 allow remote attackers to execute arbi
23RIESGO
abrir
Referência
CVE-2016-3716
The MSL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to move arbitrary files via
28RIESGO
abrir
Referência
CVE-2015-2843
Multiple SQL injection vulnerabilities in GoAutoDial GoAdmin CE before 3.3-1421902800 allow remote attackers to execute
50RIESGO
abrir
ReferênciaVexDay Proof
cwmExplorer 1.0 - 'show_file' Source Code Disclosure
CVE-2006-6757webappsasp
Directory traversal vulnerability in index.php in cwmExplorer 1.0 allows remote attackers to read arbitrary files and so
23RIESGO
abrir
ReferênciaVexDay Proof
Comparison Engine Power 1.0 - Blind SQL Injection
CVE-2008-2791webappsphp
SQL injection vulnerability in product.detail.php in Kalptaru Infotech Comparison Engine Power Script 1.0 allows remote
23RIESGO
abrir
Referência
CVE-2026-19964
Jij-Inc Jij-MCP-Server jm_check python_repr.py PythonREPL.run code injection
33RIESGO
abrir
ReferênciaVexDay Proof
eroCMS 1.4 - 'site' SQL Injection
CVE-2008-2792webappsphp
SQL injection vulnerability in index.php in eroCMS 1.4 and earlier allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
Referência
CVE-2022-4944
kalcaddle KodExplorer cross-site request forgery
33RIESGO
abrir
ReferênciaVexDay Proof
X7 Chat 2.0.1A1 - 'mini.php' Local File Inclusion
CVE-2008-4718webappsphp
Directory traversal vulnerability in help/mini.php in X7 Chat 2.0.1 A1 and earlier allows remote attackers to include an
23RIESGO
abrir
ReferênciaVexDay Proof
X7 Chat 2.0.1A1 - Local File Inclusion
CVE-2008-4718webappsphp
Directory traversal vulnerability in help/mini.php in X7 Chat 2.0.1 A1 and earlier allows remote attackers to include an
23RIESGO
abrir
ReferênciaVexDay Proof
Pakupaku CMS 0.4 - Arbitrary File Upload / Local File Inclusion
CVE-2007-4641webappsphp
Directory traversal vulnerability in index.php in Pakupaku CMS 0.4 and earlier allows remote attackers to include and ex
23RIESGO
abrir
Referência
CVE-2010-2456
Multiple directory traversal vulnerabilities in index.php in Linker IMG 1.0 and earlier allow remote attackers to read a
23RIESGO
abrir
Referência
CVE-2026-26341
Tattile Smart+ / Vega / Basic <= 1.181.5 Default Credentials
63RIESGO
abrir
Referência
CVE-2024-38887
An issue in Horizon Business Services Inc. Caterease 16.0.1.1663 through 24.0.1.2405 and possibly later versions, allows
48RIESGO
abrir
Referência
CVE-2026-19955
TrailDB TOC Validation tdb.c tdb_open out-of-bounds
33RIESGO
abrir
Referência
CVE-2013-7349
Multiple SQL injection vulnerabilities in Gnew 2013.1 allow remote attackers to execute arbitrary SQL commands via the (
23RIESGO
abrir
Referência
CVE-2013-7349
Multiple SQL injection vulnerabilities in Gnew 2013.1 allow remote attackers to execute arbitrary SQL commands via the (
23RIESGO
abrir
Referência
CVE-2013-7349
Multiple SQL injection vulnerabilities in Gnew 2013.1 allow remote attackers to execute arbitrary SQL commands via the (
23RIESGO
abrir
ReferênciaVexDay Proof
PokerMax Poker League 0.13 - Insecure Cookie Handling
CVE-2008-4600webappsphp
configure.php in PokerMax Poker League Tournament Script 0.13 allows remote attackers to bypass authentication and gain
23RIESGO
abrir
anteriorpágina 623 / 753siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.