Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.526exploits catalogados
34.478CVEs con explotación pública
24.695probados en laboratorio
21.497 exploits
Referência
CVE-2021-31673
A Dom-based Cross-site scripting (XSS) vulnerability at registration account in Cyclos 4 PRO.14.7 and before allows remo
23RIESGO
abrir
Referência
CVE-2020-11457
pfSense before 2.4.5 has stored XSS in system_usermanager_addprivs.php in the WebGUI via the descr parameter (aka full n
23RIESGO
abrir
Referência
CVE-2012-6509
Unrestricted file upload vulnerability in NetArt Media Car Portal 3.0 allows remote attackers to execute arbitrary PHP c
23RIESGO
abrir
Referência
CVE-2015-1389
Cross-site scripting (XSS) vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allows remote at
23RIESGO
abrir
Referência
CVE-2015-1389
Cross-site scripting (XSS) vulnerability in Aruba Networks ClearPass Policy Manager (CPPM) before 6.4.5 allows remote at
23RIESGO
abrir
Referência
CVE-2023-2437
UserPro <= 5.1.1 - Authentication Bypass to Administrator
63RIESGO
abrir
Referência
CVE-2018-10653
There is an XML External Entity (XXE) Processing Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 befor
23RIESGO
abrir
Referência
CVE-2009-2557
Directory traversal vulnerability in system/download.php in Admin News Tools 2.5 allows remote attackers to read arbitra
23RIESGO
abrir
Referência
CVE-2017-15639
tasks/feed/readRSS.cfm in Mura CMS before 6.2 allows attackers to bypass intended access restrictions by leveraging the
23RIESGO
abrir
ReferênciaVexDay Proof
FreeWPS 2.11 - 'images.php' Remote Code Execution
CVE-2006-1363webappsphp
images.php in Justin White (aka YTZ) Free Web Publishing System (FreeWPS) 2.11 allows remote attackers to execute arbitr
23RIESGO
abrir
Referência
CVE-2018-8718
Cross-site request forgery (CSRF) vulnerability in the Mailer Plugin 1.20 for Jenkins 2.111 allows remote authenticated
23RIESGO
abrir
ReferênciaVexDay Proof
Xserver 0.1 Alpha - 'POST' Remote Buffer Overflow (PoC)
CVE-2007-3957doslinux
Buffer overflow in Nipun Jain xserver 0.1 alpha allows remote attackers to cause a denial of service via a POST request
23RIESGO
abrir
ReferênciaVexDay Proof
Symphony 1.7.01 (non-patched) - Remote Code Execution
CVE-2008-3592webappsphp
Unrestricted file upload vulnerability in the File Manager in the admin panel in Twentyone Degrees Symphony 1.7.01 and e
23RIESGO
abrir
ReferênciaVexDay Proof
PassWiki 0.9.16 RC3 - 'site_id' Local File Inclusion
CVE-2008-6423webappsphp
Directory traversal vulnerability in passwiki.php in PassWiki 0.9.16 RC3 and earlier allows remote attackers to read arb
23RIESGO
abrir
Referência
pfSense 2.4.4-P3 - 'User Manager' Persistent Cross-Site Scripting
CVE-2020-11457webappsfreebsd
pfSense before 2.4.5 has stored XSS in system_usermanager_addprivs.php in the WebGUI via the descr parameter (aka full n
23RIESGO
abrir
Referência
CVE-2017-2460
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RIESGO
abrir
Referência
CVE-2017-2459
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RIESGO
abrir
Referência
CVE-2026-11413
JingDong JD Cloud Box AX6600 jdcweb_rpc set_macfilter stack-based overflow
41RIESGO
abrir
Referência
CVE-2026-11412
Jinher OA GetFormSn.aspx sql injection
33RIESGO
abrir
ReferênciaVexDay Proof
BinGo News 3.01 - 'bnrep' Remote File Inclusion
CVE-2006-4648webappsphp
PHP remote file inclusion vulnerability in bp_ncom.php in BinGo News (BP News) 3.01 and earlier allows remote attackers
23RIESGO
abrir
Referência
CVE-2018-10286
The Ericsson-LG iPECS NMS A.1Ac web application discloses sensitive information such as the NMS admin credentials and th
23RIESGO
abrir
Referência
CVE-2017-7047
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS
23RIESGO
abrir
Referência
CVE-2017-2524
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS
23RIESGO
abrir
Referência
CVE-2017-7237
The Spiceworks TFTP Server, as distributed with Spiceworks Inventory 7.5, allows remote attackers to access the Spicewor
23RIESGO
abrir
Referência
CVE-2017-10688
In LibTIFF 4.0.8, there is a assertion abort in the TIFFWriteDirectoryTagCheckedLong8Array function in tif_dirwrite.c. A
23RIESGO
abrir
Referência
CVE-2015-4668
Open redirect vulnerability in Xsuite 2.4.4.5 and earlier allows remote attackers to redirect users to arbitrary web sit
38RIESGO
abrir
Referência
CVE-2017-13794
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component mosmedia 1.0.8 - Remote File Inclusion
CVE-2007-2043webappsphp
Multiple PHP remote file inclusion vulnerabilities in the Avant-Garde Solutions MOSMedia (com_mosmedia) 1.08 and earlier
23RIESGO
abrir
ReferênciaVexDay Proof
FreshView 7.15 - '.psp' Local Buffer Overflow
CVE-2007-2283localwindows
Buffer overflow in Fresh View 7.15 allows user-assisted remote attackers to execute arbitrary code via a crafted .PSP fi
23RIESGO
abrir
ReferênciaVexDay Proof
TalkBack 2.2.7 - Multiple Remote File Inclusions
CVE-2007-6105webappsphp
Multiple PHP remote file inclusion vulnerabilities in TalkBack 2.2.7 allow remote attackers to execute arbitrary PHP cod
23RIESGO
abrir
anteriorpágina 186 / 717siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.