Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.008exploits catalogados
35.919CVEs con explotación pública
24.695probados en laboratorio
22.600 exploits
Referência
CVE-2017-9418
SQL injection vulnerability in the WP-Testimonials plugin 3.4.1 for WordPress allows an authenticated user to execute ar
23RIESGO
abrir
Referência
CVE-2010-2908
SQL injection vulnerability in the Joomdle (com_joomdle) component 0.24 and earlier for Joomla! allows remote attackers
23RIESGO
abrir
Referência
CVE-2010-2908
SQL injection vulnerability in the Joomdle (com_joomdle) component 0.24 and earlier for Joomla! allows remote attackers
23RIESGO
abrir
Referência
CVE-2012-3836
Multiple cross-site scripting (XSS) vulnerabilities in Baby Gekko before 1.2.0 allow remote attackers to inject arbitrar
23RIESGO
abrir
Referência
CVE-2013-1359
An Authentication Bypass Vulnerability exists in DELL SonicWALL Analyzer 7.0, Global Management System (GMS) 4.1, 5.0, 5
60RIESGO
abrir
Referência
CVE-2012-5899
Cross-site scripting (XSS) vulnerability in admin/action/objects.php in SAMEDIA LandShop 0.9.2 allows remote attackers t
23RIESGO
abrir
ReferênciaVexDay Proof
PHPortal 1.0 - Insecure Cookie Handling
CVE-2009-2117webappsphp
uye_paneli.php in phPortal 1.0 allows remote attackers to bypass authentication and obtain administrative access by sett
23RIESGO
abrir
ReferênciaVexDay Proof
WebText 0.4.5.2 - Remote Code Execution
CVE-2006-6856webappsphp
Direct static code injection vulnerability in WebText CMS 0.4.5.2 and earlier allows remote attackers to inject arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
FTP Explorer 1.0.1 Build 047 - Remote CPU Consumption (Denial of Service)
CVE-2007-1082doswindows
FTP Explorer 1.0.1 Build 047, and other versions before 1.0.1.52, allows remote servers to cause a denial of service (CP
23RIESGO
abrir
Referência
CVE-2013-1360
An Authentication Bypass vulnerability exists in DELL SonicWALL Global Management System (GMS) 4.1, 5.0, 5.1, 6.0, and 7
28RIESGO
abrir
ReferênciaVexDay Proof
XCMS 1.1 - 'Galerie.php' Local File Inclusion
CVE-2007-3523webappsphp
Multiple directory traversal vulnerabilities in Module/Galerie.php in XCMS 1.1 allow remote attackers to include and exe
23RIESGO
abrir
Referência
CVE-2008-5072
vsfilter.dll in K-Lite Mega Codec Pack 3.5.7.0 allows remote attackers to cause a denial of service (application crash)
23RIESGO
abrir
Referência
CVE-2018-7465
An XSS issue was discovered in VirtueMart before 3.2.14. All the textareas in the backend of the plugin can be closed by
23RIESGO
abrir
Referência
CVE-2026-12202
Intelliants Subrion CMS Blocks Endpoint cross site scripting
33RIESGO
abrir
Referência
CVE-2009-4465
DeluxeBB 1.3 stores sensitive information under the web root with insufficient access control, which allows remote attac
23RIESGO
abrir
Referência
CVE-2015-4077
The (1) mdare64_48.sys, (2) mdare32_48.sys, (3) mdare32_52.sys, and (4) mdare64_52.sys drivers in Fortinet FortiClient b
23RIESGO
abrir
Referência
CVE-2017-9650
An Unrestricted Upload of File with Dangerous Type issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL
23RIESGO
abrir
Referência
CVE-2013-5640
Multiple SQL injection vulnerabilities in Gnew 2013.1 allow remote attackers to execute arbitrary SQL commands via the (
23RIESGO
abrir
Referência
CVE-2013-5640
Multiple SQL injection vulnerabilities in Gnew 2013.1 allow remote attackers to execute arbitrary SQL commands via the (
23RIESGO
abrir
Referência
CVE-2010-3480
Directory traversal vulnerability in index.php in ApPHP PHP MicroCMS 1.0.1, when magic_quotes_gpc is disabled, allows re
23RIESGO
abrir
Referência
CVE-2015-4077
The (1) mdare64_48.sys, (2) mdare32_48.sys, (3) mdare32_52.sys, and (4) mdare64_52.sys drivers in Fortinet FortiClient b
23RIESGO
abrir
Referência
CVE-2026-15383
Blog Floating Button <= 1.4.20 - Unauthenticated Stored XSS via User-Agent Header
33RIESGO
abrir
ReferênciaVexDay Proof
GNU/Gallery 1.1.1.0 - 'admin.php' Local File Inclusion
CVE-2008-2353webappsphp
Directory traversal vulnerability in admin.php in GNU/Gallery 1.1.1.0 and earlier allows remote attackers to include and
23RIESGO
abrir
Referência
CVE-2012-6557
Multiple cross-site scripting (XSS) vulnerabilities in the AboutMe plugin 1.1.1 for Vanilla Forums allow remote attacker
23RIESGO
abrir
Referência
CVE-2011-5041
Multiple cross-site scripting (XSS) vulnerabilities in Pulse Pro CMS 1.7.2 allow remote attackers to inject arbitrary we
23RIESGO
abrir
Referência
CVE-2012-10038
Auxilium RateMyPet Arbitrary File Upload RCE
63RIESGO
abrir
ReferênciaVexDay Proof
MyBlog: PHP and MySQL Blog/CMS software - SQL Injection / Cross-Site Scripting
CVE-2008-2963webappsphp
Multiple SQL injection vulnerabilities in MyBlog allow remote attackers to execute arbitrary SQL commands via the (1) vi
23RIESGO
abrir
ReferênciaVexDay Proof
K-Lite Mega Codec Pack 3.5.7.0 - Local Windows Explorer Denial of Service (PoC)
CVE-2008-5072doswindows
vsfilter.dll in K-Lite Mega Codec Pack 3.5.7.0 allows remote attackers to cause a denial of service (application crash)
23RIESGO
abrir
ReferênciaVexDay Proof
Mafia Scum Tools 2.0.0 - 'index.php?gen' Remote File Inclusion
CVE-2007-0501webappsphp
PHP remote file inclusion vulnerability in index.php in Mafia Scum Tools 2.0.0 in Matthew Wardrop Advanced Random Genera
23RIESGO
abrir
ReferênciaVexDay Proof
PHP 4.4.6 - 'ibase_connect()' Local Buffer Overflow
CVE-2007-1475localwindows
Multiple buffer overflows in the (1) ibase_connect and (2) ibase_pconnect functions in the interbase extension in PHP 4.
23RIESGO
abrir
anteriorpágina 634 / 754siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.