Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.794exploits catalogados
36.057CVEs con explotación pública
24.695probados en laboratorio
22.721 exploits
Referência
CVE-2018-1335
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to
60RIESGO
abrir
Referência
CVE-2016-1524
Multiple unrestricted file upload vulnerabilities in NETGEAR Management System NMS300 1.5.0.11 and earlier allow remote
60RIESGO
abrir
ReferênciaVexDay Proof
Gallery MX 2.0.0 - Blind SQL Injection
CVE-2008-6379webappsasp
SQL injection vulnerability in pics_pre.asp in Gallery MX 2.0.0 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
Referência
CVE-2026-21643
CVE-2026-21643CRITICALbajo ataque
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiC
100RIESGO
abrir
Referência
CVE-2024-48248
CVE-2024-48248HIGHbajo ataque
NAKIVO Backup & Replication before 11.0.0.88174 allows absolute path traversal for reading files via getImageByPath to /
100RIESGO
abrir
ReferênciaVexDay Proof
Woltlab Burning Board 1.0.2/2.3.6 - 'search.php' SQL Injection (2)
CVE-2007-0388webappsphp
SQL injection vulnerability in search.php in Woltlab Burning Board (wBB) 1.0.2 and earlier, and 2.3.6 and earlier in the
23RIESGO
abrir
ReferênciaVexDay Proof
SimpleNews 1.0.0 FINAL - 'print.php?news_id' SQL Injection
CVE-2007-2598webappsphp
SQL injection vulnerability in print.php in SimpleNews 1.0.0 FINAL allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
ReferênciaVexDay Proof
TutorialCMS 1.00 - 'search.php?search' SQL Injection
CVE-2007-2599webappsphp
Multiple SQL injection vulnerabilities in TutorialCMS (aka Photoshop Tutorials) 1.00 and earlier allow remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
TutorialCMS 1.00 - 'search.php?search' SQL Injection
CVE-2007-2600webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in TutorialCMS (aka Photoshop Tutorials) 1.00 and earlier allow remo
23RIESGO
abrir
ReferênciaVexDay Proof
LaVague 0.3 - 'printbar.php?views_path' Remote File Inclusion
CVE-2007-2607webappsphp
PHP remote file inclusion vulnerability in views/print/printbar.php in LaVague 0.3 and earlier allows remote attackers t
45RIESGO
abrir
Referência
CVE-2018-17456
Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x be
60RIESGO
abrir
Referência
CVE-2020-17506
Artica Web Proxy 4.30.00000000 allows remote attacker to bypass privilege detection and gain web backend administrator p
60RIESGO
abrir
Referência
CVE-2015-7857
SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.p
60RIESGO
abrir
Referência
CVE-2015-7857
SQL injection vulnerability in the getListQuery function in administrator/components/com_contenthistory/models/history.p
60RIESGO
abrir
Referência
CVE-2019-16172
LimeSurvey before v3.17.14 allows stored XSS for escalating privileges from a low-privileged account to, for example, Su
23RIESGO
abrir
Referência
CVE-2017-5753
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of
55RIESGO
abrir
Referência
CVE-2008-6392
SQL injection vulnerability in showads.php in Z1Exchange allows remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir
Referência
CVE-2018-14933
CVE-2018-14933CRITICALbajo ataque
upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir par
100RIESGO
abrir
ReferênciaVexDay Proof
Vlbook 1.21 - Cross-Site Scripting / Local File Inclusion
CVE-2008-2072webappsphp
Cross-site scripting (XSS) vulnerability in index.php in Virtual Design Studio vlbook 1.21 allows remote attackers to in
23RIESGO
abrir
ReferênciaVexDay Proof
Vlbook 1.21 - Cross-Site Scripting / Local File Inclusion
CVE-2008-2073webappsphp
Directory traversal vulnerability in include/global.inc.php in Virtual Design Studio vlbook 1.21 allows remote attackers
23RIESGO
abrir
Referência
CVE-2015-5122
CVE-2015-5122HIGHbajo ataque
Use-after-free vulnerability in the DisplayObject class in the ActionScript 3 (AS3) implementation in Adobe Flash Player
100RIESGO
abrir
ReferênciaVexDay Proof
Pivot 1.40.5 - Dreamwind 'load_template()' Credentials Disclosure
CVE-2008-3128webappsphp
Directory traversal vulnerability in search.php in Pivot 1.40.5 allows remote attackers to read arbitrary files via a ..
23RIESGO
abrir
ReferênciaVexDay Proof
Rae Media Contact MS - Authentication Bypass
CVE-2008-6389webappsphp
SQL injection vulnerability in asadmin/default.asp in Rae Media Contact Management Software SOHO, Standard, and Enterpri
23RIESGO
abrir
Referência
CVE-2017-1129
IBM Notes 8.5 and 9.0 is vulnerable to a denial of service. If a user is persuaded to click on a malicious link, it coul
43RIESGO
abrir
Referência
CyberArk Viewfinity 5.5.10.95 - Local Privilege Escalation
CVE-2017-11197HIGHlocalwindows
In CyberArk Viewfinity 5.5.10.95 and 6.x before 6.1.1.220, a low privilege user can escalate to an administrative user v
41RIESGO
abrir
ReferênciaVexDay Proof
Siteman 2.x - Code Execution / Local File Inclusion / Cross-Site Scripting
CVE-2008-2081webappsphp
Directory traversal vulnerability in index.php in Siteman 2.0.x2 allows remote authenticated administrators to include a
23RIESGO
abrir
Referência
CVE-2018-6892
An issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sy
60RIESGO
abrir
ReferênciaVexDay Proof
PHP Forge 3 Beta 2 - 'id' SQL Injection
CVE-2008-2088webappsphp
SQL injection vulnerability in admin/news.php in PHP Forge 3.0 beta 2 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component FlippingBook 1.0.4 - SQL Injection
CVE-2008-2095webappsphp
SQL injection vulnerability in index.php in the FlippingBook (com_flippingbook) 1.0.4 component for Joomla! allows remot
23RIESGO
abrir
ReferênciaVexDay Proof
BackLinkSpider 1.1 - 'cat_id' SQL Injection
CVE-2008-2096webappsphp
SQL injection vulnerability in BackLinkSpider allows remote attackers to execute arbitrary SQL commands via the cat_id p
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.