Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.957exploits catalogados
32.195CVEs con explotación pública
1932probados en laboratorio
20.003 exploits
Referência
CVE-2011-4153
PHP 5.3.8 does not always check the return value of the zend_strndup function, which might allow remote attackers to cau
28RIESGO
abrir
Referência
CVE-2014-100015
Directory traversal vulnerability in pdmwService.exe in SolidWorks Workgroup PDM 2014 allows remote attackers to write t
50RIESGO
abrir
Referência
CVE-2014-100015
Directory traversal vulnerability in pdmwService.exe in SolidWorks Workgroup PDM 2014 allows remote attackers to write t
50RIESGO
abrir
Referência
CVE-2017-9024
Secure Bytes Cisco Configuration Manager, as bundled in Secure Bytes Secure Cisco Auditor (SCA) 3.0, has a Directory Tra
28RIESGO
abrir
Referência
XOOPS Module wiwimod 0.4 - Remote File Inclusion
PHP remote file inclusion vulnerability in spaw/spaw_control.class.php in the WiwiMod 0.4 module for XOOPS allows remote
28RIESGO
abrir
Referência
CVE-2013-4863
The HomeAutomationGateway service in MiCasaVerde VeraLite with firmware 1.5.408 allows (1) remote attackers to execute a
28RIESGO
abrir
Referência
CVE-2013-4863
The HomeAutomationGateway service in MiCasaVerde VeraLite with firmware 1.5.408 allows (1) remote attackers to execute a
28RIESGO
abrir
Referência
CVE-2013-1300
win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, W
43RIESGO
abrir
Referência
CVE-2018-6397
Directory Traversal exists in the Picture Calendar 3.1.4 component for Joomla! via the list.php folder parameter.
28RIESGO
abrir
Referência
MailEnable Professional/Enterprise 2.37 - 'APPEND' Remote Buffer Overflow
Stack-based buffer overflow in the IMAP service in MailEnable Enterprise and Professional Editions 2.37 and earlier allo
28RIESGO
abrir
Referência
CVE-2019-7385
An authenticated shell command injection issue has been discovered in Raisecom ISCOM HT803G-U, HT803G-W, HT803G-1GE, and
28RIESGO
abrir
Referência
CVE-2024-8956
CVE-2024-8956CRITICALbajo ataque
PTZOptics NDI and SDI Cameras /cgi-bin/param.cgi Insufficient Authentication
90RIESGO
abrir
Referência
CVE-2016-1741
The NVIDIA driver in the Graphics Drivers subsystem in Apple OS X before 10.11.4 allows attackers to execute arbitrary c
28RIESGO
abrir
Referência
CVE-2017-5358
Stack-based buffer overflows in php_Easycom5_3_0.dll in EasyCom for PHP 4.0.0.29 allows remote attackers to execute arbi
28RIESGO
abrir
Referência
CVE-2017-5358
Stack-based buffer overflows in php_Easycom5_3_0.dll in EasyCom for PHP 4.0.0.29 allows remote attackers to execute arbi
28RIESGO
abrir
Referência
CVE-2018-5702
Transmission through 2.92 relies on X-Transmission-Session-Id (which is not a forbidden header for Fetch) for access con
28RIESGO
abrir
Referência
WordPress Plugin User Photo Component - Arbitrary File Upload
In WordPress Plugin User Photo 0.9.4, when a photo is uploaded, it is only partially validated and it is possible to upl
28RIESGO
abrir
Referência
CVE-2022-28213
When a user access SOAP Web services in SAP BusinessObjects Business Intelligence Platform - version 420, 430, it does n
28RIESGO
abrir
Referência
CVE-2012-5306
Stack-based buffer overflow in the SelectDirectory method in DcsCliCtrl.dll in Camera Stream Client ActiveX Control, as
28RIESGO
abrir
Referência
LoveCMS 1.6.2 Final - Update Settings
LoveCMS 1.6.2 does not require administrative authentication for (1) addblock.php, (2) blocks.php, and (3) themes.php in
23RIESGO
abrir
Referência
CVE-2021-36356
KRAMER VIAware through August 2021 allows remote attackers to execute arbitrary code because ajaxPages/writeBrowseFilePa
50RIESGO
abrir
Referência
CVE-2025-15471
TRENDnet TEW-713RE formFSrvX os command injection
53RIESGO
abrir
Referência
CVE-2013-10048
D-Link Devices command.php Unauthenticated RCE
68RIESGO
abrir
Referência
CVE-2013-10048
D-Link Devices command.php Unauthenticated RCE
68RIESGO
abrir
Referência
CVE-2013-10048
D-Link Devices command.php Unauthenticated RCE
68RIESGO
abrir
Referência
CVE-2013-10048
D-Link Devices command.php Unauthenticated RCE
68RIESGO
abrir
Referência
CVE-2017-9675
On D-Link DIR-605L devices, firmware before 2.08UIBetaB01.bin allows an unauthenticated GET request to trigger a reboot.
28RIESGO
abrir
Referência
CVE-2012-4399
The Xml class in CakePHP 2.1.x before 2.1.5 and 2.2.x before 2.2.1 allows remote attackers to read arbitrary files via X
28RIESGO
abrir
Referência
CVE-2009-2479
Mozilla Firefox 3.0.x, 3.5, and 3.5.1 on Windows allows remote attackers to cause a denial of service (uncaught exceptio
28RIESGO
abrir
Referência
CVE-2010-4557
Buffer overflow in the lm_tcp service in Invensys Wonderware InBatch 8.1 and 9.0, as used in Invensys Foxboro I/A Series
28RIESGO
abrir
anteriorpágina 139 / 667siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.