Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.107exploits catalogados
34.679CVEs con explotación pública
24.695probados en laboratorio
21.692 exploits
ReferênciaVexDay Proof
@lex Guestbook 4.0.2 - Remote Command Execution
CVE-2007-0205webappsphp
Directory traversal vulnerability in admin/skins.php for @lex Guestbook 4.0.2 and earlier allows remote attackers to cre
23RIESGO
abrir
ReferênciaVexDay Proof
uniForum 4 - 'wbsearch.aspx' SQL Injection
CVE-2007-0226webappsphp
SQL injection vulnerability in wbsearch.aspx in uniForum 4 and earlier allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
WordPress Core 2.0.6 - 'wp-trackback.php' SQL Injection
CVE-2007-0233webappsphp
wp-trackback.php in WordPress 2.0.6 and earlier does not properly unset variables when the input data includes a numeric
28RIESGO
abrir
ReferênciaVexDay Proof
Apple Mac OSX 10.4.8 - AppleTalk 'ATPsndrsp()' Heap Buffer Overflow (PoC)
CVE-2007-0236dososx
Double free vulnerability in the _ATPsndrsp function in Apple Mac OS X 10.4.8, and possibly other versions, allows remot
28RIESGO
abrir
ReferênciaVexDay Proof
sNews 1.5.30 - Remote Reset Admin Pass / Command Execution
CVE-2007-0261webappsphp
snews.php in sNews 1.5.30 and earlier does not properly exit when authentication fails, which allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
Mint Haber Sistemi 2.7 - 'duyuru.asp?id' SQL Injection
CVE-2007-0304webappsphp
SQL injection vulnerability in duyuru.asp in MiNT Haber Sistemi 2.7 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
ReferênciaVexDay Proof
Article System 0.1 - 'INCLUDE_DIR' Remote File Inclusion
CVE-2007-0314webappsphp
Multiple PHP remote file inclusion vulnerabilities in Article System 1.0 allow remote attackers to execute arbitrary PHP
23RIESGO
abrir
ReferênciaVexDay Proof
BolinTech DreamFTP Server - 'USER' Remote Buffer Overflow (PoC)
CVE-2007-0338doswindows
Heap-based buffer overflow in Dream FTP Server allows remote attackers to execute arbitrary code via a USER command with
23RIESGO
abrir
Referência
CVE-2022-41040
CVE-2022-41040HIGHbajo ataqueransomware
Microsoft Exchange Server Elevation of Privilege Vulnerability
100RIESGO
abrir
Referência
CVE-2021-3129
CVE-2021-3129CRITICALbajo ataqueransomware
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
Referência
CVE-2021-3129
CVE-2021-3129CRITICALbajo ataqueransomware
Ignition before 2.5.2, as used in Laravel and other products, allows unauthenticated remote attackers to execute arbitra
100RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Help Workshop 4.03.0002 - '.cnt' Local Buffer Overflow
CVE-2007-0352localwindows
Stack-based buffer overflow in Microsoft Help Workshop 4.03.0002 allows user-assisted remote attackers to execute arbitr
35RIESGO
abrir
Referência
CVE-2009-4781
TUKEVA Password Reminder before 1.0.0.4 uses a hard-coded password for rem.accdb, which allows local users to discover c
23RIESGO
abrir
ReferênciaVexDay Proof
Apple Mac OSX 10.4.8 - SLP Daemon Service Registration Buffer Overflow (PoC)
CVE-2007-0355dososx
Buffer overflow in the Apple Minimal SLP v2 Service Agent (slpd) in Mac OS X 10.4.11 and earlier, including 10.4.8, allo
23RIESGO
abrir
ReferênciaVexDay Proof
CCRP Folder Treeview Control (ccrpftv6.ocx) - IE Denial of Service
CVE-2007-0356doswindows
The Common Controls Replacement Project (CCRP) FolderTreeview (FTV) ActiveX control (ccrpftv6.ocx) allows remote attacke
28RIESGO
abrir
Referência
CVE-2009-4783
Multiple SQL injection vulnerabilities in Theeta CMS, possibly 0.01, allow remote attackers to execute arbitrary SQL com
23RIESGO
abrir
ReferênciaVexDay Proof
Oreon 1.2.3 RC4 - '/lang/index.php' Remote File Inclusion
CVE-2007-0360webappsphp
PHP remote file inclusion vulnerability in lang/index.php in Oreon 1.2.3 RC4 and earlier allows remote attackers to exec
23RIESGO
abrir
ReferênciaVexDay Proof
phpBP RC3 (2.204) - SQL Injection / Remote Code Execution
CVE-2007-0369webappsphp
SQL injection vulnerability in phpBP RC3 (2.204) and earlier allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
Referência
CVE-2009-4784
SQL injection vulnerability in the Joaktree (com_joaktree) component 1.0 for Joomla! allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
BrowseDialog Class 'ccrpbds6.dll' Internet Explorer 7 - Denial of Service
CVE-2007-0371doswindows
A certain ActiveX control in the Common Controls Replacement Project (CCRP) CCRP BrowseDialog Server (ccrpbds6.dll) allo
23RIESGO
abrir
Referência
CVE-2020-10189
CVE-2020-10189CRITICALbajo ataque
Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted d
100RIESGO
abrir
ReferênciaVexDay Proof
Woltlab Burning Board 1.0.2/2.3.6 - 'search.php' SQL Injection (2)
CVE-2007-0388webappsphp
SQL injection vulnerability in search.php in Woltlab Burning Board (wBB) 1.0.2 and earlier, and 2.3.6 and earlier in the
23RIESGO
abrir
Referência
CVE-2026-7292
o2oa NodeAgent NodeAgent.java syncFile improper authorization
33RIESGO
abrir
Referência
CVE-2026-7290
JeecgBoot loadDict Endpoint SqlInjectionUtil.java SqlInjectionUtil sql injection
33RIESGO
abrir
Referência
CVE-2026-7289
D-Link DIR-825M formWanConfigSetup sub_414BA8 buffer overflow
41RIESGO
abrir
Referência
CVE-2022-35405
CVE-2022-35405CRITICALbajo ataque
Zoho ManageEngine Password Manager Pro before 12101 and PAM360 before 5510 are vulnerable to unauthenticated remote code
100RIESGO
abrir
ReferênciaVexDay Proof
DivX Player 6.4.1 - DivXBrowserPlugin 'npdivx32.dll' IE Denial of Service
CVE-2007-0429doswindows
DivXBrowserPlugin (aka DivX Web Player) npdivx32.dll, as distributed with DivX Player 6.4.1, allows remote attackers to
23RIESGO
abrir
Referência
CVE-2009-4785
SQL injection vulnerability in the Quick News (com_quicknews) component for Joomla! allows remote attackers to execute a
23RIESGO
abrir
Referência
CVE-2026-7288
D-Link DIR-825M formVpnConfigSetup sub_4151FC buffer overflow
41RIESGO
abrir
Referência
CVE-2026-7283
SourceCodester Pharmacy Sales and Inventory System ajax.php save_expired sql injection
33RIESGO
abrir
anteriorpágina 291 / 724siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.