Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
75.526exploits catalogados
34.478CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.534GitHub PoC 13.654VulnCheck XDB 8213Nuclei 4218Metasploit 3464✓ solo verificadosrecientespopularesriesgo
21.534 exploits
Referência✓ VexDay Proof
mxCamArchive 2.2 - Bypass Configuration Download
mxCamArchive 2.2 stores sensitive information under the web root with insufficient access control, which allows remote a
23RIESGO
abrir ↗Referência✓ VexDay Proof
CodeAvalanche Articles - Database Disclosure
CodeAvalanche Articles stores sensitive information under the web root with insufficient access control, which allows re
23RIESGO
abrir ↗Referência
CVE-2010-0759
Directory traversal vulnerability in plugins/system/cdscriptegrator/libraries/highslide/js/jsloader.php in the Core Desi
43RIESGO
abrir ↗Referência
CVE-2009-2344
The web-based management interfaces in Sourcefire Defense Center (DC) and 3D Sensor before 4.8.2 allow remote authentica
23RIESGO
abrir ↗Referência
CVE-2019-10963
Moxa EDR 810, all versions 5.1 and prior, allows an unauthenticated attacker to be able to retrieve some log files from
23RIESGO
abrir ↗Referência
CVE-2010-5194
Stack-based buffer overflow in the Image2PDF function in the SCRIBBLE.ScribbleCtrl.1 ActiveX control (ImageViewer2.ocx)
23RIESGO
abrir ↗Referência
CVE-2015-8612
The EnableNetwork method in the Network class in plugins/mechanism/Network.py in Blueman before 2.0.3 allows local users
38RIESGO
abrir ↗Referência
CVE-2015-8612
The EnableNetwork method in the Network class in plugins/mechanism/Network.py in Blueman before 2.0.3 allows local users
38RIESGO
abrir ↗Referência
CVE-2021-45814
Nettmp NNT 5.1 is affected by a SQL injection vulnerability. An attacker can bypass authentication and access the panel
23RIESGO
abrir ↗Referência
CVE-2020-14944
Global RADAR BSA Radar 1.6.7234.24750 and earlier lacks valid authorization controls in multiple functions. This can all
23RIESGO
abrir ↗Referência✓ VexDay Proof
DataTrac Activity Console - Denial of Service
DataTrac Activity Console 1.1 allows remote attackers to cause a denial of service via a long HTTP GET request.
23RIESGO
abrir ↗Referência
CVE-2018-5708
An issue was discovered on D-Link DIR-601 B1 2.02NA devices. Being on the same local network as, but being unauthenticat
23RIESGO
abrir ↗Referência✓ VexDay Proof
Moodle 1.5.2 - 'moodledata' Remote Session Disclosure
Moodle 1.5.2 and earlier stores sensitive information under the web root with insufficient access control, and provides
23RIESGO
abrir ↗Referência✓ VexDay Proof
PcP-Guestbook 3.0 - 'lang' Local File Inclusion
Multiple directory traversal vulnerabilities in PcP-Guestbook (PcP-Book) 3.0 allow remote attackers to include and execu
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Expose RC35 - Arbitrary File Upload
uploadimg.php in the Expose RC35 and earlier (com_expose) component for Joomla! sends an error message but does not exit
23RIESGO
abrir ↗Referência✓ VexDay Proof
PayPal eStore - Admin Password Change
admin/settings.php in PayPal eStores allows remote attackers to bypass intended access restrictions and change the admin
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPUserBase 1.3b - 'unverified.inc.php' Local File Inclusion
Directory traversal vulnerability in include/unverified.inc.php in Linux Web Shop (LWS) php User Base 1.3beta allows rem
23RIESGO
abrir ↗Referência✓ VexDay Proof
Flatnux 2009-01-27 - Remote File Inclusion
PHP remote file inclusion vulnerability in include/flatnux.php in FlatnuX CMS (aka Flatnuke3) 2009-01-27 and 2009-02-04,
23RIESGO
abrir ↗Referência
CVE-2012-2919
Directory traversal vulnerability in Upload/engine.php in Chevereto 1.9.1 allows remote attackers to determine the exist
23RIESGO
abrir ↗Referência
CVE-2010-0759
Directory traversal vulnerability in plugins/system/cdscriptegrator/libraries/highslide/js/jsloader.php in the Core Desi
43RIESGO
abrir ↗Referência
CVE-2019-6192
A potential vulnerability has been reported in Lenovo Power Management Driver versions prior to 1.67.17.48 leading to a
33RIESGO
abrir ↗Referência
CVE-2010-0761
SQL injection vulnerability in index.php in CommodityRentals Books/eBooks Rentals Script allows remote attackers to exec
23RIESGO
abrir ↗Referência
CVE-2018-7705
Directory traversal vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote authenticated users to read e-mai
23RIESGO
abrir ↗Referência✓ VexDay Proof
Envolution 1.1.0 - 'PNSVlang' Remote Code Execution
Directory traversal vulnerability in error.php in Envolution 1.1.0 and earlier allows remote attackers to include and ex
23RIESGO
abrir ↗Referência
CVE-2022-39195
A cross-site scripting (XSS) vulnerability in the LISTSERV 17 web interface allows remote attackers to inject arbitrary
48RIESGO
abrir ↗Referência
CVE-2013-1636
Cross-site scripting (XSS) vulnerability in open-flash-chart.swf in Open Flash Chart (aka Open-Flash Chart), as used in
23RIESGO
abrir ↗Referência
CVE-2013-1636
Cross-site scripting (XSS) vulnerability in open-flash-chart.swf in Open Flash Chart (aka Open-Flash Chart), as used in
23RIESGO
abrir ↗Referência
CVE-2012-4057
Buffer overflow in the Player in Remote-Anything 5.60.15 allows remote attackers to execute arbitrary code via a crafted
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.