Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.056exploits catalogados
35.925CVEs con explotación pública
24.695probados en laboratorio
22.600 exploits
Referência
CVE-2025-13188
D-Link DIR-816L authentication.cgi authenticationcgi_main stack-based overflow
48RIESGO
abrir
Referência
CVE-2015-5285
CRLF injection vulnerability in Kallithea before 0.3 allows remote attackers to inject arbitrary HTTP headers and conduc
23RIESGO
abrir
Referência
CVE-2009-3065
PHP remote file inclusion vulnerability in editor/edit_htmlarea.php in Ve-EDIT 0.1.4 allows remote attackers to execute
23RIESGO
abrir
Referência
CVE-2018-1203
In Dell EMC Isilon OneFS, the compadmin is able to run tcpdump binary with root privileges. In versions between 8.1.0.0
23RIESGO
abrir
Referência
CVE-2006-5209
PHP remote file inclusion vulnerability in admin/admin_topic_action_logging.php in Admin Topic Action Logging Mod 0.95 a
23RIESGO
abrir
Referência
CVE-2010-2005
Multiple PHP remote file inclusion vulnerabilities in DataLife Engine (DLE) 8.3 allow remote attackers to execute arbitr
23RIESGO
abrir
Referência
CVE-2016-7385
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA Windows GPU Display Driver R340 before 342.00 and R375 before 3
23RIESGO
abrir
ReferênciaVexDay Proof
hosting controller 6.1 hot fix 3.3 - Multiple Vulnerabilities
CVE-2007-6504webappsasp
Unspecified vulnerability in IIS/iibind.asp in Hosting Controller 6.1 Hot fix 3.3 and earlier allows remote authenticate
23RIESGO
abrir
Referência
CVE-2022-41912
crewjam/saml go library is vulnerable to signature bypass via multiple Assertion elements
48RIESGO
abrir
Referência
CVE-2018-11512
Stored cross-site scripting (XSS) vulnerability in the "Website's name" field found in the "Settings" page under the "Ge
23RIESGO
abrir
ReferênciaVexDay Proof
Online Rental Property Script 4.5 - 'pid' SQL Injection
CVE-2008-2190webappsphp
SQL injection vulnerability in index.php in Online Rent (aka Online Rental Property Script) 4.5 and earlier allows remot
23RIESGO
abrir
Referência
CVE-2015-5353
Directory traversal vulnerability in Novius OS 5.0.1 (Elche) allows remote attackers to include and execute arbitrary lo
23RIESGO
abrir
Referência
CVE-2016-7612
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchO
23RIESGO
abrir
Referência
CVE-2015-8255
AXIS Communications products allow CSRF, as demonstrated by admin/pwdgrp.cgi, vaconfig.cgi, and admin/local_del.cgi.
23RIESGO
abrir
ReferênciaVexDay Proof
xNews 1.3 - 'xNews.php' SQL Injection
CVE-2007-0569webappsphp
SQL injection vulnerability in xNews.php in xNews 1.3 allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir
Referência
CVE-2022-4693
User Verification < 1.0.94 - Authentication Bypass
48RIESGO
abrir
Referência
CVE-2008-2190
SQL injection vulnerability in index.php in Online Rent (aka Online Rental Property Script) 4.5 and earlier allows remot
23RIESGO
abrir
ReferênciaVexDay Proof
ImperialBB 2.3.5 - Arbitrary File Upload
CVE-2008-3093webappsphp
Unrestricted file upload vulnerability in ImperialBB 2.3.5 and earlier allows remote authenticated users to upload and e
23RIESGO
abrir
ReferênciaVexDay Proof
X-ice News System 1.0 - 'devami.asp?id' SQL Injection
CVE-2007-1438webappsasp
SQL injection vulnerability in devami.asp in X-Ice News System 1.0 allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
Referência
CVE-2010-0681
ZeusCMS 0.2 stores sensitive information under the web root with insufficient access control, which allows remote attack
23RIESGO
abrir
ReferênciaVexDay Proof
XOOPS Module Friendfinder 3.3 - 'view.php?id' SQL Injection
CVE-2007-1838webappsphp
SQL injection vulnerability in view.php in the Friendfinder 3.3 and earlier module for Xoops allows remote attackers to
23RIESGO
abrir
Referência
CVE-2017-14619
Cross-site scripting (XSS) vulnerability in phpMyFAQ through 2.9.8 allows remote attackers to inject arbitrary web scrip
23RIESGO
abrir
Referência
CVE-2017-14619
Cross-site scripting (XSS) vulnerability in phpMyFAQ through 2.9.8 allows remote attackers to inject arbitrary web scrip
23RIESGO
abrir
ReferênciaVexDay Proof
pPIM 1.0 - Arbitrary File Delete / Cross-Site Scripting
CVE-2008-4426webappsphp
Cross-site scripting (XSS) vulnerability in events.php in Phlatline's Personal Information Manager (pPIM) 1.0 allows rem
23RIESGO
abrir
ReferênciaVexDay Proof
Skype Extension for Firefox Beta 2.2.0.95 - Clipboard Writing
CVE-2008-5697remotewindows
The skype_tool.copy_num method in the Skype extension BETA 2.2.0.95 for Firefox allows remote attackers to write arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
Camera Life 2.6.2b4 - SQL Injection / Cross-Site Scripting
CVE-2008-6087webappsphp
Cross-site scripting (XSS) vulnerability in topic.php in Camera Life 2.6.2b4 allows remote attackers to inject arbitrary
23RIESGO
abrir
Referência
CVE-2023-27350
CVE-2023-27350CRITICALbajo ataqueransomware
This vulnerability allows remote attackers to bypass authentication on affected installations of PaperCut NG 22.0.5 (Bui
100RIESGO
abrir
ReferênciaVexDay Proof
PixelPost 1.7 - Blind SQL Injection
CVE-2008-0358webappsphp
SQL injection vulnerability in index.php in Pixelpost 1.7 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
ReferênciaVexDay Proof
living Local 1.1 - Cross-Site Scripting / Arbitrary File Upload
CVE-2008-6529webappsphp
Cross-site scripting (XSS) vulnerability in listtest.php in eZoneScripts Living Local 1.1 allows remote attackers to inj
23RIESGO
abrir
ReferênciaVexDay Proof
XOOPS Module Uploader 1.1 - 'Filename' File Disclosure
CVE-2008-7178webappsphp
Directory traversal vulnerability in Uploader module 1.1 for XOOPS allows remote attackers to read arbitrary files via a
23RIESGO
abrir
anteriorpágina 640 / 754siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.