Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.056exploits catalogados
35.925CVEs con explotación pública
24.695probados en laboratorio
22.600 exploits
ReferênciaVexDay Proof
Scriptsez Mini Hosting Panel - 'members.php' Local File Inclusion
CVE-2008-6090webappsphp
Directory traversal vulnerability in members.php in ScriptsEz Mini Hosting Panel allows remote attackers to read arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
Ol BookMarks Manager 0.7.5 - Local File Inclusion / Remote File Inclusion / SQL Injection
CVE-2008-6407webappsphp
Directory traversal vulnerability in frame.php in ol'bookmarks manager 0.7.5 allows remote attackers to include and exec
23RIESGO
abrir
ReferênciaVexDay Proof
Ol BookMarks Manager 0.7.5 - Local File Inclusion
CVE-2008-6410webappsphp
Directory traversal vulnerability in show.php in ol'bookmarks manager 0.7.5 and earlier allows remote attackers to inclu
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component live chat - SQL Injection / Open Proxy
CVE-2008-6882webappsphp
Live Chat (com_livechat) component 1.0 for Joomla! allows remote attackers to use the xmlhttp.php script as an open HTTP
23RIESGO
abrir
ReferênciaVexDay Proof
Libra PHP File Manager 1.18 - Insecure Cookie Handling
CVE-2008-7027webappsphp
Libra File Manager 1.18 and earlier allows remote attackers to bypass authentication and gain privileges by setting the
23RIESGO
abrir
ReferênciaVexDay Proof
PAD Site Scripts 3.6 - Arbitrary Database Backup
CVE-2009-1941webappsphp
PAD Site Scripts 3.6 stores sensitive information under the web document root with insufficient access control, which al
23RIESGO
abrir
ReferênciaVexDay Proof
VT-Auth 1.0 - 'zHk8dEes3.txt' File Disclosure
CVE-2009-2024webappsasp
Vlad Titarenko ASP VT Auth 1.0 stores sensitive information under the web root with insufficient access control, which a
23RIESGO
abrir
Referência
CVE-2017-16356
Reflected XSS in Kubik-Rubik SIGE (aka Simple Image Gallery Extended) before 3.3.0 allows attackers to execute JavaScrip
23RIESGO
abrir
Referência
CVE-2018-8738
Airties 5444 1.0.0.18 and 5444TT 1.0.0.18 devices allow XSS.
23RIESGO
abrir
Referência
CVE-2010-1948
Directory traversal vulnerability in scr/soustab.php in openMairie Openfoncier 2.00, when register_globals is enabled, a
23RIESGO
abrir
Referência
CVE-2018-13849
edit_requests.php in yTakkar Instagram-clone through 2018-04-23 has XSS via an onmouseover payload because of an inadequ
23RIESGO
abrir
Referência
CVE-2018-17832
XSS exists in WUZHI CMS 2.0 via the index.php v or f parameter.
23RIESGO
abrir
ReferênciaVexDay Proof
Freelance Auction Script 1.0 - 'browseproject.php' SQL Injection
CVE-2008-2279webappsphp
Freelance Auction Script 1.0 stores user passwords in plaintext in the tbl_users table, which allows attackers to gain p
23RIESGO
abrir
Referência
CVE-2018-19828
Artica Integria IMS 5.0.83 has XSS via the search_string parameter.
23RIESGO
abrir
Referência
CVE-2015-4877
Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.
23RIESGO
abrir
Referência
CVE-2016-6277
CVE-2016-6277HIGHbajo ataque
NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.B
100RIESGO
abrir
Referência
CVE-2009-4671
Login.php in RoomPHPlanning 1.6 allows remote attackers to bypass authentication and obtain administrative access by set
23RIESGO
abrir
Referência
CVE-2009-3966
Arcade Trade Script 1.0 allows remote attackers to bypass authentication and gain administrative access by setting the a
23RIESGO
abrir
Referência
CVE-2016-8812
For the NVIDIA Quadro, NVS, and GeForce products, NVIDIA GeForce Experience R340 before GFE 2.11.4.125 and R375 before G
23RIESGO
abrir
Referência
CVE-2016-6277
CVE-2016-6277HIGHbajo ataque
NETGEAR R6250 before 1.0.4.6.Beta, R6400 before 1.0.1.18.Beta, R6700 before 1.0.1.14.Beta, R6900, R7000 before 1.0.7.6.B
100RIESGO
abrir
Referência
CVE-2014-1459
SQL injection vulnerability in dg-admin/index.php in doorGets CMS 5.2 and earlier allows remote authenticated administra
23RIESGO
abrir
Referência
CVE-2010-1948
Directory traversal vulnerability in scr/soustab.php in openMairie Openfoncier 2.00, when register_globals is enabled, a
23RIESGO
abrir
ReferênciaVexDay Proof
phpBurningPortal 1.0.1 - 'lang_path' Remote File Inclusion
CVE-2006-7102webappsphp
Multiple PHP remote file inclusion vulnerabilities in phpBurningPortal quiz-modul 1.0.1, and possibly earlier, allow rem
23RIESGO
abrir
ReferênciaVexDay Proof
MonGoose 2.4 (Windows) - WebServer Directory Traversal
CVE-2009-1354remotewindows
Directory traversal vulnerability in Mongoose 2.4 allows remote attackers to read arbitrary files via a .. (dot dot) in
23RIESGO
abrir
ReferênciaVexDay Proof
XZero Community Classifieds 4.95.11 - Remote File Inclusion
CVE-2007-6568webappsphp
PHP remote file inclusion vulnerability in config.inc.php in XZero Community Classifieds 4.95.11 and earlier allows remo
23RIESGO
abrir
Referência
CVE-2012-1260
Cross-site scripting (XSS) vulnerability in cgi-bin/userprefs.cgi in Plixer International Scrutinizer NetFlow & sFlow An
23RIESGO
abrir
Referência
CVE-2020-37027
Sickbeard 0.1 - Remote Command Injection
48RIESGO
abrir
Referência
CVE-2015-5075
Cross-site request forgery (CSRF) vulnerability in X2Engine X2CRM before 5.2 allows remote attackers to hijack the authe
23RIESGO
abrir
Referência
CVE-2010-1467
Multiple PHP remote file inclusion vulnerabilities in openUrgence Vaccin 1.03 allow remote attackers to execute arbitrar
23RIESGO
abrir
Referência
CVE-2017-1000370
The offset2lib patch as used in the Linux Kernel contains a vulnerability that allows a PIE binary to be execve()'ed wit
23RIESGO
abrir
anteriorpágina 642 / 754siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.