Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.589exploits catalogados
34.508CVEs con explotación pública
24.695probados en laboratorio
21.554 exploits
Referência
CVE-2018-15181
JioFi 4G Hotspot M2S devices allow attackers to cause a denial of service (secure configuration outage) via an XSS paylo
23RIESGO
abrir
ReferênciaVexDay Proof
CityWriter 0.9.7 - 'head.php' Remote File Inclusion
CVE-2007-6324webappsphp
PHP remote file inclusion vulnerability in head.php in CityWriter 0.9.7 allows remote attackers to execute arbitrary PHP
23RIESGO
abrir
Referência
CVE-2013-4695
Winamp 5.63: Invalid Pointer Dereference leading to Arbitrary Code Execution
23RIESGO
abrir
Referência
CVE-2021-26085
CVE-2021-26085MEDIUMbajo ataqueransomware
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authoriza
100RIESGO
abrir
ReferênciaVexDay Proof
RaidenFTPd 2.4 build 3620 - Remote Denial of Service
CVE-2008-6186doswindows
Stack-based buffer overflow in RaidenFTPD 2.4 build 3620 allows remote authenticated users to cause a denial of service
23RIESGO
abrir
Referência
CVE-2025-34082
IGEL OS Secure Terminal and Secure Shadow Remote Code Execution
63RIESGO
abrir
Referência
CVE-2018-20484
Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the self-update layout implementation.
23RIESGO
abrir
Referência
CVE-2021-26086
CVE-2021-26086MEDIUMbajo ataque
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path tr
100RIESGO
abrir
ReferênciaVexDay Proof
GNUBoard 4.31.03 (08.12.29) - Local File Inclusion
CVE-2009-0290webappsphp
Directory traversal vulnerability in common.php in SIR GNUBoard 4.31.03 allows remote attackers to include and execute a
23RIESGO
abrir
Referência
CVE-2020-12501
Pepperl+Fuchs improper authorization affects multiple Comtrol RocketLinx products
48RIESGO
abrir
Referência
CVE-2020-12501
Pepperl+Fuchs improper authorization affects multiple Comtrol RocketLinx products
48RIESGO
abrir
Referência
CVE-2017-8852
SAP SAPCAR 721.510 has a Heap Based Buffer Overflow Vulnerability. It could be exploited with a crafted CAR archive file
23RIESGO
abrir
Referência
CVE-2013-2501
Cross-site scripting (XSS) vulnerability in the Terillion Reviews plugin before 1.2 for WordPress allows remote attacker
23RIESGO
abrir
Referência
CVE-2018-16083
An out of bounds read in forward error correction code in WebRTC in Google Chrome prior to 69.0.3497.81 allowed a remote
23RIESGO
abrir
Referência
CVE-2012-1198
base_ag_main.php in Basic Analysis and Security Engine (BASE) 1.4.5 allows remote attackers to execute arbitrary code by
23RIESGO
abrir
Referência
CVE-2017-13797
An issue was discovered in certain Apple products. iOS before 11.1 is affected. Safari before 11.0.1 is affected. iCloud
23RIESGO
abrir
Referência
CVE-2016-1769
QuickTime in Apple OS X before 10.11.4 allows remote attackers to execute arbitrary code or cause a denial of service (m
23RIESGO
abrir
Referência
CVE-2016-1767
QuickTime in Apple OS X before 10.11.4 allows remote attackers to execute arbitrary code or cause a denial of service (m
23RIESGO
abrir
Referência
CVE-2017-14507
Multiple SQL injection vulnerabilities in the Content Timeline plugin 4.4.2 for WordPress allow remote attackers to exec
23RIESGO
abrir
Referência
CVE-2015-4614
Multiple SQL injection vulnerabilities in includes/Function.php in the Easy2Map plugin before 1.2.5 for WordPress allow
23RIESGO
abrir
ReferênciaVexDay Proof
Snircd 1.3.4 - 'send_user_mode' Denial of Service
CVE-2008-1501dosmultiple
The send_user_mode function in s_user.c in (1) Undernet ircu 2.10.12.12 and earlier, (2) snircd 1.3.4 and earlier, and u
23RIESGO
abrir
Referência
CVE-2009-4581
Directory traversal vulnerability in modules/admincp.php in RoseOnlineCMS 3 B1 and earlier, when magic_quotes_gpc is dis
23RIESGO
abrir
Referência
CVE-2009-4581
Directory traversal vulnerability in modules/admincp.php in RoseOnlineCMS 3 B1 and earlier, when magic_quotes_gpc is dis
23RIESGO
abrir
ReferênciaVexDay Proof
WinFTP Server 2.3.0 - 'LIST' (Authenticated) Remote Buffer Overflow
CVE-2009-0351remotewindows
Stack-based buffer overflow in WFTPSRV.exe in WinFTP 2.3.0 allows remote authenticated users to execute arbitrary code v
23RIESGO
abrir
Referência
CVE-2015-1721
The kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista SP2, Windows Server 2008 SP2 and
23RIESGO
abrir
Referência
CVE-2021-26855
CVE-2021-26855CRITICALbajo ataqueransomware
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
Referência
CVE-2012-1663
Double free vulnerability in libgnutls in GnuTLS before 3.0.14 allows remote attackers to cause a denial of service (app
23RIESGO
abrir
Referência
CVE-2021-26855
CVE-2021-26855CRITICALbajo ataqueransomware
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
Referência
CVE-2013-1852
SQL injection vulnerability in leaguemanager.php in the LeagueManager plugin before 3.8.1 for WordPress allows remote at
23RIESGO
abrir
Referência
CVE-2013-1852
SQL injection vulnerability in leaguemanager.php in the LeagueManager plugin before 3.8.1 for WordPress allows remote at
23RIESGO
abrir
anteriorpágina 225 / 719siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.