Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.900exploits catalogados
35.840CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.458Referência 22.600GitHub PoC 14.323VulnCheck XDB 8722Nuclei 4320Metasploit 3477✓ solo verificadosrecientespopularesriesgo
22.600 exploits
Referência
CVE-2015-1476
Multiple SQL injection vulnerabilities in xlinkerz ecommerceMajor allow remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗Referência✓ VexDay Proof
Google Chrome 1.0.154.43 - Clickjacking
Google Chrome 1.0.154.43 allows remote attackers to trick a user into visiting an arbitrary URL via an onclick action th
23RIESGO
abrir ↗Referência✓ VexDay Proof
snetworks PHP Classifieds 5.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in config.inc.php in SNETWORKS PHP CLASSIFIEDS 5.0 allows remote attackers to ex
23RIESGO
abrir ↗Referência
CVE-2013-1347
Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbit
100RIESGO
abrir ↗Referência
CVE-2012-5350
SQL injection vulnerability in the Pay With Tweet plugin before 1.2 for WordPress allows remote authenticated users with
23RIESGO
abrir ↗Referência✓ VexDay Proof
Contenido 4.8.4 - Remote File Inclusion / Cross-Site Scripting
Multiple PHP remote file inclusion vulnerabilities in Contenido CMS 4.8.4 allow remote attackers to execute arbitrary PH
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP Multiple Newsletters 2.7 - Local File Inclusion / Cross-Site Scripting
Directory traversal vulnerability in index.php in PHP Multiple Newsletters 2.7, when magic_quotes_gpc is disabled, allow
23RIESGO
abrir ↗Referência
CVE-2010-4851
Multiple SQL injection vulnerabilities in Eclime 1.1.2b allow remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir ↗Referência
CVE-2010-4851
Multiple SQL injection vulnerabilities in Eclime 1.1.2b allow remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir ↗Referência
CVE-2010-1497
Cross-site scripting (XSS) vulnerability in download_proc.php in dl_stats before 2.0 allows remote attackers to inject a
23RIESGO
abrir ↗Referência
CVE-2010-1497
Cross-site scripting (XSS) vulnerability in download_proc.php in dl_stats before 2.0 allows remote attackers to inject a
23RIESGO
abrir ↗Referência
CVE-2019-10261
CentOS Web Panel (CWP) 0.9.8.789 is vulnerable to Stored/Persistent XSS for the "Name Server 1" and "Name Server 2" fiel
23RIESGO
abrir ↗Referência
CVE-2015-4065
Cross-site scripting (XSS) vulnerability in shared/shortcodes/inbound-shortcodes.php in the Landing Pages plugin before
23RIESGO
abrir ↗Referência✓ VexDay Proof
My Simple Forum 3.0 - Local File Inclusion
Directory traversal vulnerability in index.php in My Simple Forum 3.0 and 4.1, when magic_quotes_gpc is disabled, allows
23RIESGO
abrir ↗Referência
CVE-2015-4065
Cross-site scripting (XSS) vulnerability in shared/shortcodes/inbound-shortcodes.php in the Landing Pages plugin before
23RIESGO
abrir ↗Referência
CVE-2010-1858
Directory traversal vulnerability in the SMEStorage (com_smestorage) component before 1.1 for Joomla! allows remote atta
43RIESGO
abrir ↗Referência
CVE-2013-1409
Cross-site scripting (XSS) vulnerability in the CommentLuv plugin before 2.92.4 for WordPress allows remote attackers to
23RIESGO
abrir ↗Referência
CVE-2013-1412
DataLife Engine (DLE) 9.7 allows remote attackers to execute arbitrary PHP code via the catlist[] parameter to engine/pr
50RIESGO
abrir ↗Referência
CVE-2016-20088
Comodo Chromodo Browser 52.15.25.664 Unquoted Service Path Privilege Escalation
41RIESGO
abrir ↗Referência✓ VexDay Proof
Sphider 1.3 - 'configset.php' Remote File Inclusion
PHP remote file inclusion vulnerability in admin/configset.php in Sphider 1.3 and earlier, when register_globals is disa
23RIESGO
abrir ↗Referência
CVE-2013-1412
DataLife Engine (DLE) 9.7 allows remote attackers to execute arbitrary PHP code via the catlist[] parameter to engine/pr
50RIESGO
abrir ↗Referência
CVE-2008-5072
vsfilter.dll in K-Lite Mega Codec Pack 3.5.7.0 allows remote attackers to cause a denial of service (application crash)
23RIESGO
abrir ↗Referência
CVE-2018-7465
An XSS issue was discovered in VirtueMart before 3.2.14. All the textareas in the backend of the plugin can be closed by
23RIESGO
abrir ↗Referência
CVE-2009-4465
DeluxeBB 1.3 stores sensitive information under the web root with insufficient access control, which allows remote attac
23RIESGO
abrir ↗Referência
CVE-2015-4077
The (1) mdare64_48.sys, (2) mdare32_48.sys, (3) mdare32_52.sys, and (4) mdare64_52.sys drivers in Fortinet FortiClient b
23RIESGO
abrir ↗Referência
CVE-2017-9650
An Unrestricted Upload of File with Dangerous Type issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL
23RIESGO
abrir ↗Referência
CVE-2013-5640
Multiple SQL injection vulnerabilities in Gnew 2013.1 allow remote attackers to execute arbitrary SQL commands via the (
23RIESGO
abrir ↗Referência
CVE-2013-5640
Multiple SQL injection vulnerabilities in Gnew 2013.1 allow remote attackers to execute arbitrary SQL commands via the (
23RIESGO
abrir ↗Referência
CVE-2010-3480
Directory traversal vulnerability in index.php in ApPHP PHP MicroCMS 1.0.1, when magic_quotes_gpc is disabled, allows re
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.