Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.056exploits catalogados
35.925CVEs con explotación pública
24.695probados en laboratorio
22.600 exploits
Referência
CVE-2017-16356
Reflected XSS in Kubik-Rubik SIGE (aka Simple Image Gallery Extended) before 3.3.0 allows attackers to execute JavaScrip
23RIESGO
abrir
Referência
CVE-2018-8738
Airties 5444 1.0.0.18 and 5444TT 1.0.0.18 devices allow XSS.
23RIESGO
abrir
Referência
CVE-2010-1948
Directory traversal vulnerability in scr/soustab.php in openMairie Openfoncier 2.00, when register_globals is enabled, a
23RIESGO
abrir
Referência
CVE-2018-13849
edit_requests.php in yTakkar Instagram-clone through 2018-04-23 has XSS via an onmouseover payload because of an inadequ
23RIESGO
abrir
Referência
CVE-2018-17832
XSS exists in WUZHI CMS 2.0 via the index.php v or f parameter.
23RIESGO
abrir
ReferênciaVexDay Proof
Freelance Auction Script 1.0 - 'browseproject.php' SQL Injection
CVE-2008-2279webappsphp
Freelance Auction Script 1.0 stores user passwords in plaintext in the tbl_users table, which allows attackers to gain p
23RIESGO
abrir
Referência
CVE-2018-19828
Artica Integria IMS 5.0.83 has XSS via the search_string parameter.
23RIESGO
abrir
Referência
CVE-2015-4877
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.
23RIESGO
abrir
Referência
CVE-2016-6277
CVE-2016-6277HIGHbajo ataque
NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.B
100RIESGO
abrir
Referência
CVE-2009-4671
Login.php in RoomPHPlanning 1.6 allows remote attackers to bypass authentication and obtain administrative access by set
23RIESGO
abrir
Referência
CVE-2009-3966
Arcade Trade Script 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the a
23RIESGO
abrir
Referência
CVE-2016-8812
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA GeForce Experience R340 before GFE 2.11.4.125 and R375 before G
23RIESGO
abrir
Referência
CVE-2016-6277
CVE-2016-6277HIGHbajo ataque
NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.B
100RIESGO
abrir
Referência
CVE-2014-1459
SQL injection vulnerability in dg-admin/index.php in doorGets CMS 5.2 and earlier allows remote authenticated administra
23RIESGO
abrir
Referência
CVE-2010-1948
Directory traversal vulnerability in scr/soustab.php in openMairie Openfoncier 2.00, when register_globals is enabled, a
23RIESGO
abrir
ReferênciaVexDay Proof
phpBurningPortal 1.0.1 - 'lang_path' Remote File Inclusion
CVE-2006-7102webappsphp
Multiple PHP remote file inclusion vulnerabilities in phpBurningPortal quiz-modul 1.0.1, and possibly earlier, allow rem
23RIESGO
abrir
ReferênciaVexDay Proof
MonGoose 2.4 (Windows) - WebServer Directory Traversal
CVE-2009-1354remotewindows
Directory traversal vulnerability in Mongoose 2.4 allows remote attackers to read arbitrary files via a .. (dot dot) in
23RIESGO
abrir
ReferênciaVexDay Proof
XZero Community Classifieds 4.95.11 - Remote File Inclusion
CVE-2007-6568webappsphp
PHP remote file inclusion vulnerability in config.inc.php in XZero Community Classifieds 4.95.11 and earlier allows remo
23RIESGO
abrir
Referência
CVE-2012-1260
Cross-site scripting (XSS) vulnerability in cgi-bin/userprefs.cgi in Plixer International Scrutinizer NetFlow & sFlow An
23RIESGO
abrir
Referência
CVE-2020-37027
Sickbeard 0.1 - Remote Command Injection
48RIESGO
abrir
Referência
CVE-2015-5075
Cross-site request forgery (CSRF) vulnerability in X2Engine X2CRM before 5.2 allows remote attackers to hijack the authe
23RIESGO
abrir
Referência
CVE-2010-1467
Multiple PHP remote file inclusion vulnerabilities in openUrgence Vaccin 1.03 allow remote attackers to execute arbitrar
23RIESGO
abrir
Referência
CVE-2017-1000370
The offset2lib patch as used in the Linux Kernel contains a vulnerability that allows a PIE binary to be execve()'ed wit
23RIESGO
abrir
ReferênciaVexDay Proof
FlexPHPNews 0.0.5 - 'newsid' SQL Injection
CVE-2005-1237webappsphp
SQL injection vulnerability in news.php in FlexPHPNews 0.0.3 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
ReferênciaVexDay Proof
XchangeBoard 1.70 - 'boardID' SQL Injection
CVE-2008-3035webappsphp
SQL injection vulnerability in newThread.php in XchangeBoard 1.70 Final and earlier allows remote authenticated users to
23RIESGO
abrir
Referência
CVE-2009-4801
EZ-Blog Beta 1 does not require authentication, which allows remote attackers to create or delete arbitrary posts via re
23RIESGO
abrir
Referência
CVE-2009-4670
admin/delitem.php in RoomPHPlanning 1.6 does not require authentication, which allows remote attackers to (1) delete arb
23RIESGO
abrir
ReferênciaVexDay Proof
Netartmedia Cars Portal 2.0 - SQL Injection
CVE-2008-5310webappsphp
SQL injection vulnerability in image.php in NetArt Media Car Portal 2.0 allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
Referência
CVE-2018-18856
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS.
23RIESGO
abrir
Referência
CVE-2018-18856
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS.
23RIESGO
abrir
anteriorpágina 641 / 754siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.