Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.900exploits catalogados
35.840CVEs con explotación pública
24.695probados en laboratorio
22.600 exploits
Referência
CVE-2010-3023
Multiple cross-site scripting (XSS) vulnerabilities in DiamondList 0.1.6, and possibly earlier, allow remote attackers t
23RIESGO
abrir
Referência
CVE-2015-3107
Use-after-free vulnerability in Adobe Flash Player before 13.0.0.292 and 14.x through 18.x before 18.0.0.160 on Windows
35RIESGO
abrir
Referência
CVE-2012-5224
PHP remote file inclusion vulnerability in vb/includes/vba_cmps_include_bottom.php in vBadvanced CMPS 3.2.2 and earlier
23RIESGO
abrir
Referência
CVE-2014-10029
SQL injection vulnerability in profile.php in FluxBB before 1.4.13 and 1.5.x before 1.5.7 allows remote attackers to exe
23RIESGO
abrir
Referência
CVE-2016-4226
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.366 and 19.x through 22.x before 22.0.0.209 on Windows
35RIESGO
abrir
Referência
CVE-2017-11830
Device Guard in Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016, and Windows Server, version 1709 allow
23RIESGO
abrir
Referência
CVE-2010-1602
Directory traversal vulnerability in the ZiMB Comment (com_zimbcomment) component 0.8.1 for Joomla! allows remote attack
43RIESGO
abrir
ReferênciaVexDay Proof
IceBB 1.0-rc5 - Remote Code Execution
CVE-2007-1726webappsphp
Unrestricted file upload vulnerability in index.php in IceBB 1.0-rc5 allows remote authenticated users to upload arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
Crux Gallery 1.32 - Insecure Cookie Handling
CVE-2008-4484webappsphp
main.php in Crux Gallery 1.32 and earlier allows remote attackers to gain administrative access by setting the name para
23RIESGO
abrir
ReferênciaVexDay Proof
Enthusiast 3.1.4 - 'show_joined.php' Remote File Inclusion
CVE-2008-5792webappsphp
PHP remote file inclusion vulnerability in show_joined.php in Indiscripts Enthusiast 3.1.4, and possibly earlier, allows
23RIESGO
abrir
ReferênciaVexDay Proof
TurnkeyForms Local Classifieds - Authentication Bypass
CVE-2008-6302webappsphp
TurnkeyForms Local Classifieds allows remote attackers to bypass authentication and gain administrative access via a dir
23RIESGO
abrir
ReferênciaVexDay Proof
AJ Auction - Authentication Bypass
CVE-2008-6965webappsphp
AJ Square AJ Auction OOPD, Pro Platinum Skin #1, Pro Platinum Skin #2, and Web 2.0 send a redirect but do not exit when
23RIESGO
abrir
Referência
CVE-2006-0074
SQL injection vulnerability in profile.php in PHPenpals allows remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir
Referência
CVE-2015-3245
Incomplete blacklist vulnerability in the chfn function in libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in t
38RIESGO
abrir
Referência
CVE-2016-4314
Directory traversal vulnerability in the LogViewer Admin Service in WSO2 Carbon 4.4.5 allows remote authenticated admini
28RIESGO
abrir
Referência
CVE-2026-17541
Bit File Manager < 6.9.1 - Unauthenticated File Activity Log Disclosure
41RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component EXP Shop - 'catid' SQL Injection
CVE-2008-2892webappsphp
SQL injection vulnerability in the EXP Shop (com_expshop) component 1.0 for Joomla! allows remote attackers to execute a
23RIESGO
abrir
Referência
CVE-2010-1657
Directory traversal vulnerability in the SmartSite (com_smartsite) component 1.0.0 for Joomla! allows remote attackers t
43RIESGO
abrir
Referência
CVE-2010-1657
Directory traversal vulnerability in the SmartSite (com_smartsite) component 1.0.0 for Joomla! allows remote attackers t
43RIESGO
abrir
Referência
CVE-2010-1658
Directory traversal vulnerability in the Code-Garage NoticeBoard (com_noticeboard) component 1.3 for Joomla! allows remo
43RIESGO
abrir
Referência
CVE-2026-41940
CVE-2026-41940CRITICALbajo ataqueransomware
WebPros cPanel and WHM Authentication Bypass via Login Flow
100RIESGO
abrir
Referência
CVE-2019-0552
An elevation of privilege exists in Windows COM Desktop Broker, aka "Windows COM Elevation of Privilege Vulnerability."
23RIESGO
abrir
Referência
CVE-2026-14205
WP Events Manager < 2.2.5 - Subscriber+ Payment Bypass via 'qty' Parameter
48RIESGO
abrir
Referência
CVE-2014-9146
Multiple cross-site scripting (XSS) vulnerabilities in Fiyo CMS 2.0.1.8 allow remote attackers to inject arbitrary web s
23RIESGO
abrir
Referência
CVE-2012-5242
Directory traversal vulnerability in functions/suggest.php in Banana Dance B.2.6 and earlier allows remote attackers to
23RIESGO
abrir
Referência
CVE-2009-4467
misc.php in DeluxeBB 1.3 allows remote attackers to register accounts without a valid email address via a valemail actio
23RIESGO
abrir
ReferênciaVexDay Proof
CaLogic Calendars 1.2.2 - 'CLPath' Remote File Inclusion
CVE-2006-2570webappsphp
PHP remote file inclusion vulnerability in CaLogic Calendars 1.2.2 allows remote attackers to execute arbitrary PHP code
23RIESGO
abrir
Referência
CVE-2009-2327
Cross-site scripting (XSS) vulnerability in add_voting.php in KerviNet Forum 1.1 and earlier allows remote authenticated
23RIESGO
abrir
Referência
CVE-2011-1665
PHPBoost 3.0 stores sensitive information under the web root with insufficient access control, which allows remote attac
23RIESGO
abrir
Referência
CVE-2015-3300
Multiple cross-site scripting (XSS) vulnerabilities in the TheCartPress eCommerce Shopping Cart (aka The Professional Wo
23RIESGO
abrir
anteriorpágina 628 / 754siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.