Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.008exploits catalogados
34.638CVEs con explotación pública
24.695probados en laboratorio
21.662 exploits
ReferênciaVexDay Proof
Enigma 2 Coppermine Bridge - 'boarddir' Remote File Inclusion
CVE-2006-6864webappsphp
PHP remote file inclusion vulnerability in E2_header.inc.php in Enigma2 Coppermine Bridge 1.0 allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
GNU/Linux mbse-bbs 0.70.0 - Local Buffer Overflow
CVE-2007-0368locallinux
Stack-based buffer overflow in mbse-bbs 0.70 and earlier allows local users to execute arbitrary code via a long string
23RIESGO
abrir
ReferênciaVexDay Proof
XM Easy Personal FTP Server 5.30 - 'ABOR' Format String Denial of Service
CVE-2007-1195doswindows
Multiple buffer overflows in XM Easy Personal FTP Server 5.3.0 allow remote attackers to execute arbitrary code via unsp
23RIESGO
abrir
Referência
CVE-2023-54335
eXtplorer<= 2.1.14 - Authentication Bypass & Remote Code Execution (RCE)
48RIESGO
abrir
Referência
CVE-2021-28242
SQL Injection in the "evoadm.php" component of b2evolution v7.2.2-stable allows remote attackers to obtain sensitive dat
23RIESGO
abrir
Referência
CVE-2017-0300
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2,
23RIESGO
abrir
Referência
CVE-2019-13623
In NSA Ghidra before 9.1, path traversal can occur in RestoreTask.java (from the package ghidra.app.plugin.core.archive)
23RIESGO
abrir
Referência
CVE-2013-4868
Karotz API 12.07.19.00: Session Token Information Disclosure
23RIESGO
abrir
Referência
CVE-2018-10188
phpMyAdmin 4.8.0 before 4.8.0-1 has CSRF, allowing an attacker to execute arbitrary SQL statements, related to js/db_ope
23RIESGO
abrir
Referência
CVE-2017-0100
A DCOM object in Helppane.exe in Microsoft Windows 7 SP1; Windows Server 2008 R2; Windows 8.1; Windows Server 2012 Gold
23RIESGO
abrir
Referência
CVE-2022-4117
IWS - Geo Form Fields <= 1.0 - Unauthenticated SQLi
63RIESGO
abrir
Referência
CVE-2017-4916
VMware Workstation Pro/Player contains a NULL pointer dereference vulnerability that exists in the vstor2 driver. Succes
23RIESGO
abrir
Referência
CVE-2014-9261
The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which
23RIESGO
abrir
Referência
CVE-2014-9261
The sanitize function in Codoforum 2.5.1 does not properly implement filtering for directory traversal sequences, which
23RIESGO
abrir
Referência
CVE-2010-3155
Untrusted search path vulnerability in Adobe ExtendScript Toolkit (ESTK) CS5 3.5.0.52 allows local users, and possibly r
28RIESGO
abrir
Referência
CVE-2017-15014
OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design ga
23RIESGO
abrir
ReferênciaVexDay Proof
WEBO (Web ORGanizer) 1.0 - 'baseDir' Remote File Inclusion
CVE-2007-1391webappsphp
PHP remote file inclusion vulnerability in modules/abook/foldertree.php in Leo West WEBO (aka weborganizer) 1.0 allows r
23RIESGO
abrir
Referência
CVE-2022-37255
TP-Link Tapo C310 1.3.0 devices allow access to the RTSP video feed via credentials of User --- and Password TPL07552646
41RIESGO
abrir
ReferênciaVexDay Proof
Pluck CMS 4.5.3 - 'g_pcltar_lib_dir' Local File Inclusion
CVE-2008-6253webappsphp
Directory traversal vulnerability in data/inc/lib/pcltar.lib.php in Pluck 4.5.3, when register_globals is enabled, allow
23RIESGO
abrir
ReferênciaVexDay Proof
ICQ 6.5 - URL Search Hook (Windows Explorer) Remote Buffer Overflow (PoC)
CVE-2009-1915doswindows
Stack-based buffer overflow in the URL Search Hook (ICQToolBar.dll) in ICQ 6.5 allows remote attackers to cause a denial
23RIESGO
abrir
Referência
CVE-2017-8837
Cleartext password storage exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-
23RIESGO
abrir
Referência
CVE-2025-14534
UTT 进取 512W Endpoint formNatStaticMap strcpy buffer overflow
48RIESGO
abrir
Referência
CVE-2017-15962
iStock Management System 1.0 allows Arbitrary File Upload via user/profile.
23RIESGO
abrir
Referência
CVE-2017-15962
iStock Management System 1.0 allows Arbitrary File Upload via user/profile.
23RIESGO
abrir
Referência
CVE-2017-9603
SQL injection vulnerability in the WP Jobs plugin before 1.5 for WordPress allows authenticated users to execute arbitra
23RIESGO
abrir
Referência
CVE-2017-14955
Check_MK before 1.2.8p26 mishandles certain errors within the failed-login save feature because of a race condition, whi
28RIESGO
abrir
Referência
CVE-2018-19040
The Media File Manager plugin 1.4.2 for WordPress allows directory listing via a ../ directory traversal in the dir para
28RIESGO
abrir
Referência
CVE-2015-3301
Directory traversal vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce
23RIESGO
abrir
Referência
CVE-2015-3301
Directory traversal vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce
23RIESGO
abrir
ReferênciaVexDay Proof
Web Wiz Forums 9.07 - 'sub' Directory Traversal
CVE-2008-0466webappsasp
Web Wiz RTE_file_browser.asp in, as used in Web Wiz Rich Text Editor 4.0, Web Wiz Forums 9.07, and Web Wiz Newspad 1.02,
23RIESGO
abrir
anteriorpágina 258 / 723siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.