Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.526exploits catalogados
34.478CVEs con explotación pública
24.695probados en laboratorio
21.534 exploits
ReferênciaVexDay Proof
evilboard 0.1a - SQL Injection / Cross-Site Scripting
CVE-2008-0155webappsphp
Cross-site scripting (XSS) vulnerability in index.php in EvilBoard 0.1a (Alpha) allows remote attackers to inject arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
ContentNow 1.4.1 - Arbitrary File Upload / Cross-Site Scripting
CVE-2008-3181webappsphp
Unrestricted file upload vulnerability in upload.php in ContentNow CMS 1.4.1 allows remote authenticated users to execut
23RIESGO
abrir
Referência
CVE-2017-6367
In Cerberus FTP Server 8.0.10.1, a crafted HTTP request causes the Windows service to crash. The attack methodology invo
23RIESGO
abrir
Referência
CVE-2010-1876
SQL injection vulnerability in index.php in AJ Shopping Cart 1.0 allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
Referência
CVE-2012-2277
The IRM Server in EMC Documentum Information Rights Management 4.x before 4.7.0100 and 5.x before 5.0.1030 allows remote
23RIESGO
abrir
Referência
CVE-2021-30044
Cross Site Scripting (XSS) in Remote Clinic v2.0 via the First Name or Last Name field on staff/register.php.
23RIESGO
abrir
Referência
CVE-2010-1876
SQL injection vulnerability in index.php in AJ Shopping Cart 1.0 allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
Referência
CVE-2017-9602
KBVault Mysql Free Knowledge Base application package 0.16a comes with a FileExplorer/Explorer.aspx?id=/Uploads file-man
23RIESGO
abrir
Referência
CVE-2012-5876
Multiple off-by-one errors in NMMediaServerService.dll in Nero MediaHome 4.5.8.0 and earlier allow remote attackers to c
23RIESGO
abrir
ReferênciaVexDay Proof
Simplog 0.9.2 - 's' Remote Command Execution
CVE-2006-1778webappsphp
Multiple SQL injection vulnerabilities in Jeremy Ashcraft Simplog 0.9.2 and earlier allow remote attackers to execute ar
23RIESGO
abrir
Referência
CVE-2010-2744
The kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP1 and SP2, Windows
23RIESGO
abrir
Referência
CVE-2016-5740
An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev5. JavaScript code can be used as part of ical atta
23RIESGO
abrir
Referência
CVE-2016-5740
An issue was discovered in Open-Xchange OX App Suite before 7.8.2-rev5. JavaScript code can be used as part of ical atta
23RIESGO
abrir
Referência
CVE-2011-4558
Tiki 8.2 and earlier allows remote administrators to execute arbitrary PHP code via crafted input to the regexres and re
23RIESGO
abrir
Referência
CVE-2017-8684
Windows GDI+ on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R
23RIESGO
abrir
Referência
CVE-2017-17110
Techno Portfolio Management Panel 1.0 allows an attacker to inject SQL commands via a single.php?id= request.
23RIESGO
abrir
Referência
CVE-2018-8411
An elevation of privilege vulnerability exists when NTFS improperly checks access, aka "NTFS Elevation of Privilege Vuln
23RIESGO
abrir
Referência
CVE-2009-2890
Cross-site scripting (XSS) vulnerability in results.php in PHP Scripts Now Riddles allows remote attackers to inject arb
23RIESGO
abrir
Referência
CVE-2018-7701
Multiple cross-site request forgery (CSRF) vulnerabilities in SecurEnvoy SecurMail before 9.2.501 allow remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
phpBB Import Tools Mod 0.1.4 - Remote File Inclusion
CVE-2006-7147webappsphp
PHP remote file inclusion vulnerability in includes/functions_mod_user.php in phpBB Import Tools Mod 0.1.4 and earlier a
23RIESGO
abrir
ReferênciaVexDay Proof
Chicken of the VNC 2.0 - 'NULL-pointer' Remote Denial of Service
CVE-2007-0756dososx
Chicken of the VNC (cotv) 2.0 allows remote attackers to cause a denial of service (application crash) via a large compu
23RIESGO
abrir
ReferênciaVexDay Proof
Flat Chat 2.0 - 'include online.txt' Remote Code Execution
CVE-2007-1394webappsphp
Direct static code injection vulnerability in startsession.php in Flat Chat 2.0 allows remote attackers to execute arbit
23RIESGO
abrir
ReferênciaVexDay Proof
STPHPLibrary - 'STPHPLIB_DIR' Remote File Inclusion
CVE-2007-4737webappsphp
Multiple PHP remote file inclusion vulnerabilities in SpeedTech PHP Library (STPHPLibrary) 0.8.0 allow remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
CenterIM 4.22.3 - Remote Command Execution
CVE-2008-1467remotelinux
CenterIM 4.22.3 and earlier allows user-assisted remote attackers to execute arbitrary commands via shell metacharacters
23RIESGO
abrir
ReferênciaVexDay Proof
cPanel 11.x - Cross-Site Scripting / Local File Inclusion
CVE-2008-6927webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in autoinstall4imagesgalleryupgrade.php in the Fantastico De Luxe Mo
23RIESGO
abrir
Referência
CVE-2013-5756
Directory traversal vulnerability in Yealink VoIP Phone SIP-T38G allows remote authenticated users to read arbitrary fil
23RIESGO
abrir
Referência
CVE-2015-7293
Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone bef
23RIESGO
abrir
Referência
CVE-2015-7293
Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone bef
23RIESGO
abrir
Referência
CVE-2017-11330
The DivFixppCore::avi_header_fix function in DivFix++Core.cpp in DivFix++ v0.34 allows remote attackers to cause a denia
23RIESGO
abrir
Referência
CVE-2008-7185
GNOME Rhythmbox 0.11.5 allows remote attackers to cause a denial of service (segmentation fault and crash) via a playlis
23RIESGO
abrir
anteriorpágina 193 / 718siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.