Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.902exploits catalogados
34.597CVEs con explotación pública
24.695probados en laboratorio
21.624 exploits
Referência
CVE-2014-9558
Multiple SQL injection vulnerabilities in SmartCMS v.2.
23RIESGO
abrir
Referência
CVE-2015-7346
SQL injection vulnerability in ZCMS 1.1.
23RIESGO
abrir
Referência
CVE-2015-7346
SQL injection vulnerability in ZCMS 1.1.
23RIESGO
abrir
Referência
CVE-2014-9179
Cross-site scripting (XSS) vulnerability in the SupportEzzy Ticket System plugin 1.2.5 for WordPress allows remote authe
23RIESGO
abrir
Referência
CVE-2008-7010
Skalfa Software SkaLinks Exchange Script 1.5 allows remote attackers to add new administrators and gain privileges via a
23RIESGO
abrir
Referência
CVE-2023-7304
Ruijie RG-UAC nmc_sync.php Command Injection
48RIESGO
abrir
ReferênciaVexDay Proof
2WIRE Modems/Routers - 'CRLF' Denial of Service
CVE-2006-4523doshardware
The web-based management interface in 2Wire, Inc. HomePortal and OfficePortal Series modems and routers allows remote at
23RIESGO
abrir
ReferênciaVexDay Proof
TCExam 4.0.011 - 'SessionUserLang' Shell Injection
CVE-2007-2430webappsphp
shared/code/tce_tmx.php in TCExam 4.0.011 and earlier allows remote attackers to create arbitrary PHP files in cache/ by
23RIESGO
abrir
ReferênciaVexDay Proof
eIQnetworks ESA SEARCHREPORT - Remote Overflow (Metasploit)
CVE-2007-5699remotewindows
Stack-based buffer overflow in eIQNetworks Enterprise Security Analyzer (ESA) 2.5 allows remote attackers to execute arb
23RIESGO
abrir
ReferênciaVexDay Proof
PolDoc CMS 0.96 - 'download_file.php' File Disclosure
CVE-2007-6400webappsphp
Directory traversal vulnerability in download_file.php in PolDoc CMS (aka PDDMS) 0.96 allows remote attackers to read ar
23RIESGO
abrir
ReferênciaVexDay Proof
Unreal Tournament 3 1.3 - Directory Traversal
CVE-2008-4243remotewindows
Directory traversal vulnerability in ImageServer (aka UTImageServer) in WebAdmin before 1.7 for Epic Games Unreal Tourna
23RIESGO
abrir
ReferênciaVexDay Proof
SkaLinks 1.5 - 'register.php' Arbitrary Add Editor
CVE-2008-7010webappsphp
Skalfa Software SkaLinks Exchange Script 1.5 allows remote attackers to add new administrators and gain privileges via a
23RIESGO
abrir
Referência
CVE-2018-14888
inc/plugins/thankyoulike.php in the Eldenroot Thank You/Like plugin before 3.1.0 for MyBB allows XSS via a post or threa
23RIESGO
abrir
Referência
CVE-2018-14888
inc/plugins/thankyoulike.php in the Eldenroot Thank You/Like plugin before 3.1.0 for MyBB allows XSS via a post or threa
23RIESGO
abrir
Referência
CVE-2013-1604
Directory traversal vulnerability in MayGion IP Cameras with firmware before 2013.04.22 (05.53) allows remote attackers
23RIESGO
abrir
Referência
CVE-2013-3739
Directory traversal vulnerability in editor.php in Network Weathermap 0.97c and earlier allows remote attackers to read
23RIESGO
abrir
Referência
CVE-2018-5405
The Quest Kace K1000 Appliance is vulnerable to JavaScript injection.
23RIESGO
abrir
Referência
CVE-2023-3848
mooSocial mooDating URL view cross site scripting
43RIESGO
abrir
Referência
CVE-2017-8708
The Windows kernel component on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server
23RIESGO
abrir
Referência
CVE-2019-16173
LimeSurvey before v3.17.14 allows reflected XSS for escalating privileges from a low-privileged account to, for example,
23RIESGO
abrir
Referência
CVE-2022-2841
CrowdStrike Falcon Uninstallation authorization
28RIESGO
abrir
Referência
CVE-2014-2340
Cross-site request forgery (CSRF) vulnerability in the XCloner plugin before 3.1.1 for WordPress allows remote attackers
23RIESGO
abrir
Referência
CVE-2015-7567
SQL injection vulnerability in Yeager CMS 1.2.1 allows remote attackers to execute arbitrary SQL commands via the "passw
23RIESGO
abrir
Referência
CVE-2015-7567
SQL injection vulnerability in Yeager CMS 1.2.1 allows remote attackers to execute arbitrary SQL commands via the "passw
23RIESGO
abrir
Referência
CVE-2021-21465
The BW Database Interface allows an attacker with low privileges to execute any crafted database queries, exposing the b
48RIESGO
abrir
ReferênciaVexDay Proof
@lex Guestbook 4.0.2 - Remote Command Execution
CVE-2007-0202webappsphp
SQL injection vulnerability in index.php in @lex Guestbook 4.0.2 and earlier, when magic_quotes_gpc is disabled, allows
23RIESGO
abrir
ReferênciaVexDay Proof
JBlog 1.0 - Create / Delete Admin Authentication Bypass
CVE-2007-3974webappsphp
admin/ajoutaut.php in JBlog 1.0 does not require authentication, which allows remote attackers to create arbitrary accou
23RIESGO
abrir
Referência
CVE-2018-14840
uploads/.htaccess in Subrion CMS 4.2.1 allows XSS because it does not block .html file uploads (but does block, for exam
23RIESGO
abrir
ReferênciaVexDay Proof
EDraw Flowchart ActiveX Control 2.0 - Insecure Method
CVE-2007-5826remotewindows
Absolute path traversal vulnerability in the EDraw Flowchart ActiveX control in EDImage.ocx 2.0.2005.1104 allows remote
23RIESGO
abrir
ReferênciaVexDay Proof
bloofox 0.3 - SQL Injection / File Disclosure
CVE-2008-0427webappsphp
Directory traversal vulnerability in file.php in bloofoxCMS 0.3 allows remote attackers to read arbitrary files via a ..
23RIESGO
abrir
anteriorpágina 243 / 721siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.