Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
22.832 exploits
ReferênciaVexDay Proof
SysInfo 1.21 - 'sysinfo.cgi' Remote Command Execution
CVE-2006-1832webappscgi
sysinfo.cgi in sysinfo 1.21 allows remote attackers to obtain the installation path via the debugger action.
23RIESGO
abrir
ReferênciaVexDay Proof
Fuju News 1.0 - Authentication Bypass / SQL Injection
CVE-2006-1837webappsphp
SQL injection vulnerability in archiv2.php in Fuju News 1.0 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir
ReferênciaVexDay Proof
Internet PhotoShow 1.3 - 'page' Remote File Inclusion
CVE-2006-1919webappsphp
PHP remote file inclusion vulnerability in index.php in Internet Photoshow 1.3 allows remote attackers to execute arbitr
23RIESGO
abrir
Referência
CVE-2026-9632
UTT HiPER 1250GW Web Management formGroupConfig strcpy stack-based overflow
41RIESGO
abrir
ReferênciaVexDay Proof
Woltlab Burning Board 2.3.5 - 'links.php' SQL Injection
CVE-2006-2569webappsphp
SQL injection vulnerability in links.php in 4R Linklist 1.0 RC2 and earlier, a module for Woltlab Burning Board, allows
23RIESGO
abrir
ReferênciaVexDay Proof
CaLogic Calendars 1.2.2 - 'CLPath' Remote File Inclusion
CVE-2006-2570webappsphp
PHP remote file inclusion vulnerability in CaLogic Calendars 1.2.2 allows remote attackers to execute arbitrary PHP code
23RIESGO
abrir
ReferênciaVexDay Proof
Sugar Suite Open Source 4.2 - 'OptimisticLock' Command Execution
CVE-2006-2460webappsphp
Sugar Suite Open Source (SugarCRM) 4.2 and earlier, when register_globals is enabled, does not protect critical variable
28RIESGO
abrir
Referência
CVE-2006-2465
Buffer overflow in MP3Info 0.8.4 allows attackers to execute arbitrary code via a long command line argument. NOTE: if
23RIESGO
abrir
ReferênciaVexDay Proof
phpMyDirectory 10.4.4 - 'ROOT_PATH' Remote File Inclusion
CVE-2006-2521webappsphp
PHP remote file inclusion vulnerability in cron.php in phpMyDirectory 10.4.4 and earlier allows remote attackers to exec
23RIESGO
abrir
ReferênciaVexDay Proof
phpListPro 2.0.1 - 'Language' Remote Code Execution
CVE-2006-2523webappsphp
PHP remote file inclusion vulnerability in config.php in phpListPro 2.0.1 and earlier, with magic_quotes_gpc disabled, a
23RIESGO
abrir
ReferênciaVexDay Proof
TR Newsportal 0.36tr1 - 'poll.php' Remote File Inclusion
CVE-2006-2557webappsphp
PHP remote file inclusion vulnerability in extras/poll/poll.php in Florian Amrhein NewsPortal before 0.37, and TR Newspo
28RIESGO
abrir
ReferênciaVexDay Proof
open-medium.CMS 0.25 - '404.php' Remote File Inclusion
CVE-2006-2683webappsphp
PHP remote file inclusion vulnerability in 404.php in open-medium.CMS 0.25 allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
Fastpublish CMS 1.6.9 - config[fsBase] Remote File Inclusion
CVE-2006-2726webappsphp
PHP remote file inclusion vulnerability in Fastpublish CMS 1.6.9.d allows remote attackers to include arbitrary files vi
28RIESGO
abrir
ReferênciaVexDay Proof
SmartSite CMS 1.0 - 'root' Remote File Inclusion
CVE-2006-3162webappsphp
PHP remote file inclusion vulnerability in include/inc_foot.php in SmartSiteCMS 1.0 and earlier allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
The Bible Portal Project 2.12 - 'destination' File Inclusion
CVE-2006-3177webappsphp
PHP remote file inclusion vulnerability in Admin/rtf_parser.php in The Bible Portal Project 2.12 and earlier allows remo
23RIESGO
abrir
ReferênciaVexDay Proof
BlueShoes Framework 4.6 - Remote File Inclusion
CVE-2006-2864webappsphp
Multiple PHP remote file inclusion vulnerabilities in BlueShoes Framework 4.6 allow remote attackers to execute arbitrar
28RIESGO
abrir
Referência
CVE-2019-7256
CVE-2019-7256CRITICALbajo ataque
Linear eMerge E3-Series devices allow Command Injections.
100RIESGO
abrir
ReferênciaVexDay Proof
empris r20020923 - 'phormationdir' Remote File Inclusion
CVE-2006-2962webappsphp
PHP remote file inclusion vulnerability in sql_fcnsOLD.php in Emergenices Personnel Information System (Empris) 20020923
23RIESGO
abrir
ReferênciaVexDay Proof
Enterprise Payroll Systems 1.1 - 'footer' Remote File Inclusion
CVE-2006-2982webappsphp
Multiple PHP remote file inclusion vulnerabilities in Enterprise Timesheet and Payroll Systems (EPS) 1.1 and earlier all
23RIESGO
abrir
ReferênciaVexDay Proof
WebprojectDB 0.1.3 - 'INCDIR' Remote File Inclusion
CVE-2006-2995webappsphp
Multiple PHP remote file inclusion vulnerabilities in WebprojectDB 0.1.3 and earlier allow remote attackers to execute a
23RIESGO
abrir
ReferênciaVexDay Proof
aePartner 0.8.3 - 'dir[data]' Remote File Inclusion
CVE-2006-2996webappsphp
PHP remote file inclusion vulnerability in inc/design.inc.php in LoveCompass aePartner 0.8.3 and earlier allows remote a
23RIESGO
abrir
Referência
CVE-2019-7256
CVE-2019-7256CRITICALbajo ataque
Linear eMerge E3-Series devices allow Command Injections.
100RIESGO
abrir
ReferênciaVexDay Proof
free QBoard 1.1 - 'qb_path' Remote File Inclusion
CVE-2006-2998webappsphp
PHP remote file inclusion vulnerability in board/post.php in free QBoard 1.1 and earlier allows remote attackers to exec
23RIESGO
abrir
ReferênciaVexDay Proof
Enthrallweb ePhotos 1.0 - 'subLevel2.asp' SQL Injection
CVE-2006-3027webappsasp
Multiple SQL injection vulnerabilities in Enthrallwebe ePhotos 2.2 and earlier allow remote attackers to execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
Ad Manager Pro 2.6 - 'ipath' Remote File Inclusion
CVE-2006-3192webappsphp
PHP remote file inclusion vulnerability in Ad Manager Pro 2.6 allows remote attackers to execute arbitrary PHP code via
23RIESGO
abrir
Referência
CVE-2026-16486
SourceCodester Class and Exam Timetabling System BSIS.php cross site scripting
33RIESGO
abrir
Referência
CVE-2026-12689
ProfileGrid < 5.9.9.7 - Subscriber+ Cross-User Private Message Thread Deletion and Tampering via Missing Authorization
33RIESGO
abrir
Referência
CVE-2026-16252
Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System Staffshinel Ds.jsp sql injection
33RIESGO
abrir
Referência
CVE-2026-11456
Chanjet CRM HTTP GET Request jxf_dump_systable.php sql injection
33RIESGO
abrir
Referência
CVE-2026-11453
Tiobon Employee Self-Service System Login Endpoint BlogSearch.aspx sql injection
33RIESGO
abrir
anteriorpágina 742 / 762siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.