Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
76.008exploits catalogados
34.638CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.662GitHub PoC 13.743VulnCheck XDB 8460Nuclei 4233Metasploit 3467✓ solo verificadosrecientespopularesriesgo
21.662 exploits
Referência
CVE-2012-6046
Static code injection vulnerability in admin/banners.php in PHP Enter allows remote attackers to inject arbitrary PHP co
23RIESGO
abrir ↗Referência
CVE-2007-6218
Multiple PHP remote file inclusion vulnerabilities in Ossigeno CMS 2.2 pre1 allow remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência
CVE-2010-2016
SQL injection vulnerability in details.php in Iceberg CMS allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗Referência
CVE-2010-2016
SQL injection vulnerability in details.php in Iceberg CMS allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir ↗Referência✓ VexDay Proof
Crafty Syntax Image Gallery 3.1g - Remote Code Execution
newimage.php in Eric Gerdes Crafty Syntax Image Gallery (CSIG) (aka PHP thumbnail Photo Gallery) 3.1g and earlier allows
23RIESGO
abrir ↗Referência
CVE-2019-14418
An issue was discovered in Veritas Resiliency Platform (VRP) before 3.4 HF1. When uploading an application bundle, a dir
48RIESGO
abrir ↗Referência
CVE-2017-7064
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RIESGO
abrir ↗Referência
CVE-2016-5304
Open redirect vulnerability in a report-routing component in Symantec Endpoint Protection Manager (SEPM) 12.1 before RU6
23RIESGO
abrir ↗Referência
CVE-2012-4260
Multiple SQL injection vulnerabilities in myCare2x allow remote attackers to execute arbitrary SQL commands via the (1)
23RIESGO
abrir ↗Referência✓ VexDay Proof
CentiPaid 1.4.2 - 'centipaid_class.php' Remote File Inclusion
PHP remote file inclusion vulnerability in centipaid_class.php in CentiPaid 1.4.2 and earlier allows remote attackers to
23RIESGO
abrir ↗Referência
CVE-2012-1208
Multiple cross-site scripting (XSS) vulnerabilities in backend/core/engine/base.php in Fork CMS 3.2.4 and possibly other
23RIESGO
abrir ↗Referência✓ VexDay Proof
Weblogicnet - 'files_dir' Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Weblogicnet allow remote attackers to execute arbitrary PHP code v
23RIESGO
abrir ↗Referência✓ VexDay Proof
NULL FTP Server 1.1.0.7 - 'Site' Command Injection
Incomplete blacklist vulnerability in NULL FTP Server Free and Pro 1.1.0.7 allows remote authenticated users to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
Kwalbum 2.0.2 - Arbitrary File Upload
Unrestricted file upload vulnerability in Kwalbum 2.0.4, 2.0.2, and earlier, when PICS_PATH is located in the web root,
23RIESGO
abrir ↗Referência
CVE-2018-6219
An Insecure Update via HTTP vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to eavesdr
23RIESGO
abrir ↗Referência
CVE-2019-10716
An Information Disclosure issue in Verodin Director 3.5.3.1 and earlier reveals usernames and passwords of integrated se
23RIESGO
abrir ↗Referência
CVE-2015-6102
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
23RIESGO
abrir ↗Referência
CVE-2015-6102
The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Wi
23RIESGO
abrir ↗Referência
CVE-2016-1914
Multiple SQL injection vulnerabilities in the com.rim.mdm.ui.server.ImageServlet servlet in BlackBerry Enterprise Server
23RIESGO
abrir ↗Referência
CVE-2010-2018
Directory traversal vulnerability in downlot.php in Lokomedia CMS 1.4.1 and 2.0 allows remote attackers to read arbitrar
38RIESGO
abrir ↗Referência
CVE-2010-1466
Directory traversal vulnerability in scr/soustab.php in openUrgence Vaccin 1.03 allows remote attackers to read arbitrar
23RIESGO
abrir ↗Referência
CVE-2010-2020
sys/nfsclient/nfs_vfsops.c in the NFS client in the kernel in FreeBSD 7.2 through 8.1-PRERELEASE, when vfs.usermount is
23RIESGO
abrir ↗Referência
CVE-2010-2020
sys/nfsclient/nfs_vfsops.c in the NFS client in the kernel in FreeBSD 7.2 through 8.1-PRERELEASE, when vfs.usermount is
23RIESGO
abrir ↗Referência✓ VexDay Proof
TopList 1.3.8 - 'phpBB Hack' Remote File Inclusion (2)
PHP remote file inclusion vulnerability in toplist.php in phpBB TopList 1.3.8 and earlier, when register_globals is enab
28RIESGO
abrir ↗Referência
CVE-2018-2892
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Availability Suite Service).
23RIESGO
abrir ↗Referência✓ VexDay Proof
X7 Chat 2.0 - 'help_file' Remote Command Execution
Directory traversal vulnerability in help/index.php in X7 Chat 2.0 and earlier allows remote attackers to include arbitr
23RIESGO
abrir ↗Referência✓ VexDay Proof
Ipswitch WS_FTP LE 5.08 - PASV Response Remote Buffer Overflow
Buffer overflow in Ipswitch WS_FTP Limited Edition (LE) 5.08 allows remote FTP servers to execute arbitrary code via a l
23RIESGO
abrir ↗Referência✓ VexDay Proof
Linksys WRT54G Firmware 1.00.9 - Security Bypass (2)
Linksys WRT54g firmware 1.00.9 does not require credentials when making configuration changes, which allows remote attac
23RIESGO
abrir ↗Referência✓ VexDay Proof
DFF PHP Framework API - 'Data Feed File' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in DataFeedFile (DFF) PHP Framework API allow remote attackers to exe
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP-Fusion Mod Classifieds - 'lid' SQL Injection
SQL injection vulnerability in classifieds.php in PHP-Fusion allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.