Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.589exploits catalogados
34.508CVEs con explotación pública
24.695probados en laboratorio
21.554 exploits
Referência
CVE-2022-0492
CVE-2022-0492HIGHbajo ataque
A vulnerability was found in the Linux kernel’s cgroup_release_agent_write in the kernel/cgroup/cgroup-v1.c function. Th
86RIESGO
abrir
Referência
CVE-2021-24299
ReDi Restaurant Reservations < 21.0426 - Unauthenticated Stored Cross-Site Scripting (XSS)
23RIESGO
abrir
ReferênciaVexDay Proof
Mambo Module HTMLArea3 1.5 - Remote File Inclusion
CVE-2006-3751webappsphp
PHP remote file inclusion vulnerability in popups/ImageManager/config.inc.php in the HTMLArea3 Addon Component (com_html
23RIESGO
abrir
ReferênciaVexDay Proof
Hospital Management System 4.0 - Persistent Cross-Site Scripting
CVE-2020-5191webappsphp
PHPGurukul Hospital Management System in PHP v4.0 suffers from multiple Persistent XSS vulnerabilities.
38RIESGO
abrir
Referência
CVE-2023-30198
Prestashop winbizpayment <= 1.0.2 is vulnerable to Incorrect Access Control via modules/winbizpayment/downloads/download
41RIESGO
abrir
Referência
CVE-2023-30198
Prestashop winbizpayment <= 1.0.2 is vulnerable to Incorrect Access Control via modules/winbizpayment/downloads/download
41RIESGO
abrir
ReferênciaVexDay Proof
DM Guestbook 0.4.1 - Multiple Local File Inclusions
CVE-2007-5821webappsphp
Multiple directory traversal vulnerabilities in DM Guestbook 0.4.1 and earlier allow remote attackers to include and exe
23RIESGO
abrir
ReferênciaVexDay Proof
U-Mail Webmail 4.91 - 'edit.php' Arbitrary File Write
CVE-2008-4932webappsphp
webmail/modules/filesystem/edit.php in U-Mail Webmail server 4.91 allows remote attackers to overwrite arbitrary files v
23RIESGO
abrir
Referência
CVE-2014-4014
The capabilities implementation in the Linux kernel before 3.14.8 does not properly consider that namespaces are inappli
23RIESGO
abrir
Referência
CVE-2007-5253
c32web.exe in McMurtrey/Whitaker Cart32 before 6.4 allows remote attackers to read arbitrary files via the ImageName par
23RIESGO
abrir
Referência
CVE-2017-11663
The _WM_SetupMidiEvent function in internal_midi.c:2315 in WildMIDI 0.4.2 can cause a denial of service (invalid memory
23RIESGO
abrir
Referência
Online Doctor Appointment System 1.0 - 'Multiple' Stored XSS
CVE-2021-25791webappsphp
Multiple stored cross site scripting (XSS) vulnerabilities in the "Update Profile" module of Online Doctor Appointment S
23RIESGO
abrir
Referência
CVE-2017-14083
A vulnerability in Trend Micro OfficeScan 11.0 and XG allows remote unauthenticated users who can access the system to d
23RIESGO
abrir
Referência
CVE-2017-14083
A vulnerability in Trend Micro OfficeScan 11.0 and XG allows remote unauthenticated users who can access the system to d
23RIESGO
abrir
Referência
CVE-2022-31062
Unauthenticated Local File Inclusion
33RIESGO
abrir
Referência
CVE-2019-6218
A memory corruption issue was addressed with improved input validation. This issue is fixed in iOS 12.1.3, macOS Mojave
23RIESGO
abrir
Referência
CVE-2009-4168
Cross-site scripting (XSS) vulnerability in Roy Tanck tagcloud.swf, as used in the WP-Cumulus plugin before 1.23 for Wor
23RIESGO
abrir
Referência
CVE-2016-1848
QuickTime in Apple OS X before 10.11.5 allows remote attackers to execute arbitrary code or cause a denial of service (m
23RIESGO
abrir
Referência
CVE-2010-1062
Directory traversal vulnerability in codelib/sys/common.inc.php in Phpkobo Free Real Estate Contact Form 1.09, when magi
23RIESGO
abrir
Referência
CVE-2017-16542
Zoho ManageEngine Applications Manager 13 before build 13500 allows Post-authentication SQL injection via the name param
23RIESGO
abrir
Referência
CVE-2010-1066
AR Web Content Manager (AWCM) 2.1 stores sensitive information under the web root with insufficient access control, whic
23RIESGO
abrir
Referência
CVE-2019-25706
Across DR-810 ROM-0 Unauthenticated File Disclosure
41RIESGO
abrir
Referência
CVE-2014-0866
RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics sends cleartext c
23RIESGO
abrir
Referência
CVE-2017-18016
Parity Browser 1.6.10 and earlier allows remote attackers to bypass the Same Origin Policy and obtain sensitive informat
23RIESGO
abrir
ReferênciaVexDay Proof
SQuery 4.5 - 'libpath' Remote File Inclusion
CVE-2006-1610webappsphp
PHP remote file inclusion vulnerability in lib/armygame.php in SQuery 4.5 and earlier, as used in products such as Auton
23RIESGO
abrir
Referência
CVE-2015-8285
The webssx.sys driver in QuickHeal 16.00 allows remote attackers to cause a denial of service.
23RIESGO
abrir
Referência
CVE-2014-8391
The Web interface in Sendio before 7.2.4 does not properly handle sessions, which allows remote authenticated users to o
23RIESGO
abrir
Referência
CVE-2014-8391
The Web interface in Sendio before 7.2.4 does not properly handle sessions, which allows remote authenticated users to o
23RIESGO
abrir
Referência
CVE-2010-5280
Directory traversal vulnerability in the Community Builder Enhanced (CBE) (com_cbe) component 1.4.8, 1.4.9, and 1.4.10 f
23RIESGO
abrir
Referência
CVE-2010-5280
Directory traversal vulnerability in the Community Builder Enhanced (CBE) (com_cbe) component 1.4.8, 1.4.9, and 1.4.10 f
23RIESGO
abrir
anteriorpágina 220 / 719siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.