Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.900exploits catalogados
35.840CVEs con explotación pública
24.695probados en laboratorio
22.600 exploits
ReferênciaVexDay Proof
Prozilla Reviews Script 1.0 - Arbitrary Delete User
CVE-2008-1783webappsphp
Prozilla Reviews 1.0 allows remote attackers to delete arbitrary users via a modified UserID parameter in a direct reque
23RIESGO
abrir
ReferênciaVexDay Proof
ScriptMagix Jokes 2.0 - 'index.php?catid' SQL Injection
CVE-2007-1615webappsphp
SQL injection vulnerability in index.php in ScriptMagix Jokes 2.0 and earlier allows remote attackers to execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
Meto Forum 1.1 - Multiple SQL Injections
CVE-2008-2448webappsasp
Multiple SQL injection vulnerabilities in Meto Forum 1.1 allow remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir
ReferênciaVexDay Proof
Sisplet CMS 2008-01-24 - 'id' SQL Injection
CVE-2008-3026webappsphp
SQL injection vulnerability in index.php in OneClick CMS (aka Sisplet CMS) 2008-01-24 allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
CMS MAXSITE Component Guestbook - Remote Command Execution
CVE-2008-6446webappsphp
Static code injection vulnerability in the Guestbook component in CMS MAXSITE allows remote attackers to inject arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
MauryCMS 0.53.2 - Arbitrary File Upload
CVE-2008-6952webappsphp
SQL injection vulnerability in Rss.php in MauryCMS 0.53.2 and earlier allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
Referência
CVE-2024-36840
SQL Injection vulnerability in Boelter Blue System Management v.1.3 allows a remote attacker to execute arbitrary code a
48RIESGO
abrir
Referência
CVE-2024-36840
SQL Injection vulnerability in Boelter Blue System Management v.1.3 allows a remote attacker to execute arbitrary code a
48RIESGO
abrir
Referência
CVE-2009-2780
Multiple cross-site scripting (XSS) vulnerabilities in 68 Classifieds 4.1 allow remote attackers to inject arbitrary web
23RIESGO
abrir
Referência
CVE-2009-4433
Multiple cross-site scripting (XSS) vulnerabilities in IDevSpot iSupport 1.8 and earlier allow remote attackers to injec
23RIESGO
abrir
Referência
CVE-2014-3934
SQL injection vulnerability in the Submit_News module for PHP-Nuke 8.3 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
Referência
CVE-2026-14821
Quiz And Survey Master < 11.1.5 - Contributor+ Arbitrary Template Deletion
28RIESGO
abrir
Referência
CVE-2023-42628
Stored cross-site scripting (XSS) vulnerability in the Wiki widget in Liferay Portal 7.1.0 through 7.4.3.87, and Liferay
48RIESGO
abrir
Referência
CVE-2023-42629
Stored cross-site scripting (XSS) vulnerability in the manage vocabulary page in Liferay Portal 7.4.2 through 7.4.3.87,
48RIESGO
abrir
Referência
CVE-2015-7889
The SecEmailComposer/EmailComposer application in the Samsung S6 Edge before the October 2015 MR uses weak permissions f
23RIESGO
abrir
Referência
CVE-2015-7889
The SecEmailComposer/EmailComposer application in the Samsung S6 Edge before the October 2015 MR uses weak permissions f
23RIESGO
abrir
Referência
CVE-2017-16567
Persistent Cross-Site Scripting (XSS) vulnerability in Logitech Media Server 7.9.0, affecting the "Favorites" feature. T
23RIESGO
abrir
Referência
CVE-2015-5591
SQL injection vulnerability in Zenphoto before 1.4.9 allow remote administrators to execute arbitrary SQL commands.
23RIESGO
abrir
Referência
CVE-2018-10313
WUZHI CMS 4.1.0 allows persistent XSS via the form%5Bqq_10%5D parameter to the /index.php?m=member&f=index&v=profile&set
23RIESGO
abrir
Referência
CVE-2011-5222
SQL injection vulnerability in rub2_w.php in PHP Flirt-Projekt 4.8 and possibly earlier allows remote attackers to execu
23RIESGO
abrir
Referência
CVE-2024-25414
An arbitrary file upload vulnerability in /admin/upgrade of CSZ CMS v1.3.0 allows attackers to execute arbitrary code vi
48RIESGO
abrir
Referência
CVE-2013-3536
SQL injection vulnerability in the gp_LoadUserFromHash function in functions_hash.php in the Group Pay module 1.5 and ea
23RIESGO
abrir
Referência
CVE-2013-3536
SQL injection vulnerability in the gp_LoadUserFromHash function in functions_hash.php in the Group Pay module 1.5 and ea
23RIESGO
abrir
Referência
CVE-2026-66730
facil.io 0.6.0 - 0.7.6 Infinite Loop DoS via Multipart MIME Body Parser
41RIESGO
abrir
Referência
CVE-2024-53537
An issue in OpenPanel v0.3.4 to v0.2.1 allows attackers to execute a directory traversal in File Actions of File Manager
48RIESGO
abrir
Referência
CVE-2007-6135
Cross-site scripting (XSS) vulnerability in phpslideshow.php in PHPSlideShow 0.9.9.2, and possibly earlier, allows remot
23RIESGO
abrir
Referência
CVE-2014-8995
SQL injection vulnerability in Maarch LetterBox 2.8 allows remote attackers to execute arbitrary SQL commands via the Us
23RIESGO
abrir
Referência
CVE-2017-12970
Cross-site request forgery (CSRF) vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack the authenticati
23RIESGO
abrir
Referência
CVE-2017-12970
Cross-site request forgery (CSRF) vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack the authenticati
23RIESGO
abrir
Referência
CVE-2009-4961
Lanai Core 0.6 allows remote attackers to obtain configuration information via a direct request to info.php, which calls
23RIESGO
abrir
anteriorpágina 630 / 754siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.