Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

72.018exploits catalogados
32.219CVEs con explotación pública
1932probados en laboratorio
20.023 exploits
Referência
CVE-2013-7375
SQL injection vulnerability in includes/classes/Authenticate.class.php in PHP-Fusion 7.02.01 through 7.02.05 allows remo
23RIESGO
abrir
Referência
CVE-2013-7375
SQL injection vulnerability in includes/classes/Authenticate.class.php in PHP-Fusion 7.02.01 through 7.02.05 allows remo
23RIESGO
abrir
Referência
Battle Blog 1.25 - 'uploadform.asp' Arbitrary File Upload
Unrestricted file upload vulnerability in admin/uploadform.asp in Battle Blog 1.25 allows remote attackers to execute ar
23RIESGO
abrir
Referência
phpMyWebmin 1.0 - 'window.php' Remote File Inclusion
Directory traversal vulnerability in window.php, possibly used by home.php, in Joshua Muheim phpMyWebmin 1.0 allows remo
23RIESGO
abrir
Referência
CVE-2014-3210
SQL injection vulnerability in dopbs-backend-forms.php in the Booking System (Booking Calendar) plugin before 1.3 for Wo
23RIESGO
abrir
Referência
CVE-2015-2528
Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 do not proper
23RIESGO
abrir
Referência
CVE-2015-2528
Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10 do not proper
23RIESGO
abrir
Referência
CVE-2017-14266
tcprewrite in Tcpreplay 3.4.4 has a Heap-Based Buffer Overflow vulnerability triggered by a crafted PCAP file, a related
23RIESGO
abrir
Referência
WordPress Plugin fMoblog 2.1 - 'id' SQL Injection
SQL injection vulnerability in fmoblog.php in the fMoblog plugin 2.1 for WordPress allows remote attackers to execute ar
23RIESGO
abrir
Referência
phpEventMan 1.0.2 - 'level' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in phpEventMan 1.0.2 allow remote attackers to execute arbitrary PHP
23RIESGO
abrir
Referência
CVE-2014-9581
Directory traversal vulnerability in components/filemanager/download.php in Codiad 2.4.3 allows remote attackers to read
23RIESGO
abrir
Referência
CVE-2014-6070
Multiple cross-site scripting (XSS) vulnerabilities in Adiscon LogAnalyzer before 3.6.6 allow remote attackers to inject
23RIESGO
abrir
Referência
CVE-2014-6070
Multiple cross-site scripting (XSS) vulnerabilities in Adiscon LogAnalyzer before 3.6.6 allow remote attackers to inject
23RIESGO
abrir
Referência
IBM Director < 5.10 - 'Redirect.bat' Directory Traversal
Directory traversal vulnerability in Redirect.bat in IBM Director before 5.10 allows remote attackers to read arbitrary
23RIESGO
abrir
Referência
CVE-2018-17997
LayerBB 1.1.1 allows XSS via the titles of conversations (PMs).
23RIESGO
abrir
Referência
CVE-2018-17997
LayerBB 1.1.1 allows XSS via the titles of conversations (PMs).
23RIESGO
abrir
Referência
CVE-2018-0973
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RIESGO
abrir
Referência
CVE-2018-0969
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RIESGO
abrir
Referência
CVE-2018-0974
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RIESGO
abrir
Referência
CVE-2018-0970
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RIESGO
abrir
Referência
CVE-2008-7008
HyperStop Web Host Directory 1.2 allows remote attackers to bypass authentication and download a database backup via a d
23RIESGO
abrir
Referência
CVE-2012-3435
SQL injection vulnerability in frontends/php/popup_bitem.php in Zabbix 1.8.15rc1 and earlier, and 2.x before 2.0.2rc1, a
23RIESGO
abrir
Referência
CVE-2018-0971
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RIESGO
abrir
Referência
CVE-2018-0972
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RIESGO
abrir
Referência
TinyWebGallery 1.5 - 'image' Remote File Inclusion
PHP remote file inclusion vulnerability in TinyWebGallery 1.5 and earlier allows remote attackers to execute arbitrary P
23RIESGO
abrir
Referência
PhpHostBot 1.06 - 'svr_rootscript' Remote File Inclusion
PHP remote file inclusion vulnerability in order/login.php in IDevSpot PhpHostBot 1.06 and earlier allows remote attacke
23RIESGO
abrir
Referência
CVE-2014-2995
Multiple cross-site scripting (XSS) vulnerabilities in twitget.php in the Twitget plugin before 3.3.3 for WordPress allo
23RIESGO
abrir
Referência
A-Link WL54AP3 / WL54AP2 - Cross-Site Request Forgery / Cross-Site Scripting
The management interface on the A-LINK WL54AP3 and WL54AP2 access points has a blank default password for the admin acco
23RIESGO
abrir
Referência
CVE-2009-3716
Unrestricted file upload vulnerability in admin.php in MCshoutbox 1.1 allows remote authenticated users to execute arbit
23RIESGO
abrir
Referência
CVE-2017-8840
Debug information disclosure exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before f
23RIESGO
abrir
anteriorpágina 156 / 668siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.