Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.107exploits catalogados
34.679CVEs con explotación pública
24.695probados en laboratorio
21.692 exploits
Referência
CVE-2014-8722
GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) data/users/<user
28RIESGO
abrir
Referência
CVE-2019-7193
CVE-2019-7193CRITICALbajo ataqueransomware
This improper input validation vulnerability allows remote attackers to inject arbitrary code to the system. To fix the
83RIESGO
abrir
Referência
CVE-2011-2443
Multiple buffer overflows in Adobe Photoshop Elements 8.0 and earlier allow remote attackers to cause a denial of servic
28RIESGO
abrir
Referência
CVE-2016-0165
CVE-2016-0165HIGHbajo ataque
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, W
76RIESGO
abrir
Referência
Core FTP Server FTP / SFTP Server v2 Build 674 - 'SIZE' Directory Traversal
CVE-2019-9648doswindows
An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. A directory traversal vulnerability exis
28RIESGO
abrir
Referência
CVE-2017-2547
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. The
28RIESGO
abrir
Referência
CVE-2017-16944
The receive_msg function in receive.c in the SMTP daemon in Exim 4.88 and 4.89 allows remote attackers to cause a denial
35RIESGO
abrir
Referência
CVE-2024-11972
Hunk Companion < 1.9.0 - Unauthenticated Plugin Installation
75RIESGO
abrir
Referência
CVE-2018-11742
NEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI.
28RIESGO
abrir
Referência
CVE-2018-11742
NEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI.
28RIESGO
abrir
Referência
CVE-2010-1081
Directory traversal vulnerability in the Community Polls (com_communitypolls) component 1.5.2, and possibly earlier, for
43RIESGO
abrir
Referência
CVE-2019-9648
An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. A directory traversal vulnerability exis
28RIESGO
abrir
Referência
CVE-2021-45901
The password-reset form in ServiceNow Orlando provides different responses to invalid authentication attempts depending
28RIESGO
abrir
Referência
CVE-2019-15637
Numerous Tableau products are vulnerable to XXE via a malicious workbook, extension, or data source, leading to informat
46RIESGO
abrir
ReferênciaVexDay Proof
Apple CFNetwork - HTTP Response Denial of Service
CVE-2007-0464dososx
The _CFNetConnectionWillEnqueueRequests function in CFNetwork 129.19 on Apple Mac OS X 10.4 through 10.4.10 allows remot
28RIESGO
abrir
Referência
CVE-2026-14753
mjperpinosa stumasy Note Handler/Assignment notes authorization
33RIESGO
abrir
Referência
CVE-2026-14752
mjperpinosa stumasy add_into_dictionary.php add_definition cross site scripting
33RIESGO
abrir
Referência
CVE-2026-14751
mjperpinosa stumasy search_scratch_data.php search_scratch_data sql injection
33RIESGO
abrir
Referência
CVE-2026-14750
mjperpinosa stumasy accessing_dictionary_authorization.php accessing_dictionary_authorization sql injection
33RIESGO
abrir
Referência
CVE-2018-9958
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1
50RIESGO
abrir
Referência
CVE-2018-9958
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1
50RIESGO
abrir
Referência
CVE-2018-9958
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1
50RIESGO
abrir
Referência
CVE-2011-0917
Buffer overflow in nLDAP.exe in IBM Lotus Domino allows remote attackers to execute arbitrary code via a long string in
28RIESGO
abrir
Referência
CVE-2014-4158
Stack-based buffer overflow in Kolibri 2.0 allows remote attackers to execute arbitrary code via a long URI in a GET req
28RIESGO
abrir
Referência
CVE-2014-4158
Stack-based buffer overflow in Kolibri 2.0 allows remote attackers to execute arbitrary code via a long URI in a GET req
28RIESGO
abrir
Referência
CVE-2014-4158
Stack-based buffer overflow in Kolibri 2.0 allows remote attackers to execute arbitrary code via a long URI in a GET req
28RIESGO
abrir
Referência
CVE-2020-5377
Dell EMC OpenManage Server Administrator (OMSA) versions 9.4 and prior contain multiple path traversal vulnerabilities.
60RIESGO
abrir
Referência
CVE-2015-7246
D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 has a default password of root for the root accou
28RIESGO
abrir
Referência
CVE-2015-7246
D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 has a default password of root for the root accou
28RIESGO
abrir
Referência
CVE-2010-3132
Untrusted search path vulnerability in Adobe Dreamweaver CS5 11.0 build 4916, build 4909, and probably other versions, a
28RIESGO
abrir
anteriorpágina 280 / 724siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.