Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.951exploits catalogados
34.636CVEs con explotación pública
24.695probados en laboratorio
21.624 exploits
Referência
CVE-2018-7477
SQL Injection exists in PHP Scripts Mall School Management Script 3.0.4 via the Username and Password fields to parents/
23RIESGO
abrir
Referência
CVE-2023-3844
mooSocial mooDating URL friends cross site scripting
43RIESGO
abrir
Referência
CVE-2018-8449
A security feature bypass exists when Device Guard incorrectly validates an untrusted file, aka "Device Guard Security F
23RIESGO
abrir
Referência
CVE-2018-8734
SQL injection vulnerability in the core config manager in Nagios XI 5.2.x through 5.4.x before 5.4.13 allows an attacker
50RIESGO
abrir
Referência
CVE-2023-3846
mooSocial mooDating URL pages cross site scripting
43RIESGO
abrir
Referência
CVE-2023-3849
mooSocial mooDating URL find-a-match cross site scripting
43RIESGO
abrir
Referência
CVE-2018-9237
iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site Description" field.
23RIESGO
abrir
Referência
CVE-2018-9445
In readMetadata of Utils.cpp, there is a possible path traversal bug due to a confused deputy. This could lead to local
23RIESGO
abrir
Referência
CVE-2018-9488
In the SELinux permissions of crash_dump.te, there is a permissions bypass due to a missing restriction. This could lead
23RIESGO
abrir
Referência
CVE-2018-9515
In sdcardfs_create and sdcardfs_mkdir of inode.c, there is a possible memory corruption due to improper locking. This co
23RIESGO
abrir
Referência
CVE-2018-9948
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader
50RIESGO
abrir
Referência
CVE-2023-39115
install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG docum
23RIESGO
abrir
Referência
Campcodes Online Matrimonial Website System v3.3 - Code Execution via malicious SVG file upload
CVE-2023-39115webappsphp
install/aiz-uploader/upload in Campcodes Online Matrimonial Website System Script 3.3 allows XSS via a crafted SVG docum
23RIESGO
abrir
Referência
CVE-2019-0731
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), ak
23RIESGO
abrir
Referência
CVE-2019-0796
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), ak
23RIESGO
abrir
Referência
CVE-2019-0808
CVE-2019-0808HIGHbajo ataque
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
98RIESGO
abrir
Referência
Titan FTP Server Version 2019 Build 3505 - Directory Traversal / Local File Inclusion
CVE-2019-10009webappswindows
A Directory Traversal issue was discovered in the Web GUI in Titan FTP Server 2019 Build 3505. When an authenticated use
28RIESGO
abrir
Referência
TeemIp IPAM < 2.4.0 - 'new_config' Command Injection (Metasploit)
CVE-2019-10863remotephp
A command injection vulnerability exists in TeemIp versions before 2.4.0. The new_config parameter of exec.php allows on
28RIESGO
abrir
Referência
CVE-2019-10893
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.793 (Free/Open Source Version) and 0.9.8.753 (Pro) is vulnerable to
23RIESGO
abrir
Referência
CVE-2019-11354
The client in Electronic Arts (EA) Origin 10.5.36 on Windows allows template injection in the title parameter of the Ori
28RIESGO
abrir
Referência
CVE-2019-11354
The client in Electronic Arts (EA) Origin 10.5.36 on Windows allows template injection in the title parameter of the Ori
28RIESGO
abrir
Referência
ManageEngine Applications Manager 11.0 < 14.0 - SQL Injection / Remote Code Execution (Metasploit)
CVE-2019-11448remotewindows
An issue was discovered in Zoho ManageEngine Applications Manager 11.0 through 14.0. An unauthenticated user can gain th
28RIESGO
abrir
Referência
CVE-2023-4113
PHP Jabbers Service Booking Script index.php cross site scripting
48RIESGO
abrir
Referência
CVE-2023-4115
PHP Jabbers Cleaning Business index.php cross site scripting
48RIESGO
abrir
Referência
CVE-2023-4116
PHP Jabbers Taxi Booking index.php cross site scripting
48RIESGO
abrir
Referência
CVE-2023-4119
Academy LMS courses cross site scripting
33RIESGO
abrir
Referência
WonderCMS 3.4.2 - Remote Code Execution (RCE)
CVE-2023-41425MEDIUMremotephp
Cross Site Scripting vulnerability in Wonder CMS v.3.2.0 thru v.3.4.2 allows a remote attacker to execute arbitrary code
60RIESGO
abrir
Referência
CVE-2023-4174
mooSocial mooStore cross site scripting
43RIESGO
abrir
Referência
CVE-2024-11954
Pimcore Search Document cross site scripting
33RIESGO
abrir
Referência
CVE-2024-11956
Pimcore customer-data-framework list sql injection
33RIESGO
abrir
anteriorpágina 251 / 721siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.