Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.313exploits catalogados
34.834CVEs con explotación pública
24.695probados en laboratorio
21.797 exploits
Referência
CVE-2016-4312
XML external entity (XXE) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 before WSO2-CARBON-PATCH
23RIESGO
abrir
Referência
CVE-2016-4312
XML external entity (XXE) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 before WSO2-CARBON-PATCH
23RIESGO
abrir
Referência
CVE-2022-4395
Membership For WooCommerce < 2.1.7 - Unauthenticated Arbitrary File Upload
53RIESGO
abrir
Referência
CVE-2018-19550
Interspire Email Marketer through 6.1.6 allows arbitrary file upload via a surveys_submit.php "create survey and submit
23RIESGO
abrir
Referência
CVE-2023-2779
Super Socializer < 7.13.52 - Reflected XSS
48RIESGO
abrir
Referência
CVE-2023-2779
Super Socializer < 7.13.52 - Reflected XSS
48RIESGO
abrir
Referência
CVE-2023-2779
Super Socializer < 7.13.52 - Reflected XSS
48RIESGO
abrir
Referência
CVE-2010-4884
PHP remote file inclusion vulnerability in guestbook/gbook.php in Gaestebuch 1.2 allows remote attackers to execute arbi
23RIESGO
abrir
Referência
CVE-2020-16602
Razer Chroma SDK Rest Server through 3.12.17 allows remote attackers to execute arbitrary programs because there is a ra
23RIESGO
abrir
Referência
CVE-2017-3631
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported versio
38RIESGO
abrir
Referência
CVE-2017-3631
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported versio
38RIESGO
abrir
ReferênciaVexDay Proof
TYPSoft FTP Server 1.11 - 'ABORT' Remote Denial of Service
CVE-2009-1668doswindows
TYPSoft FTP Server 1.11 allows remote attackers to cause a denial of service (CPU consumption) by sending an ABOR (abort
23RIESGO
abrir
Referência
CVE-2009-3531
SQL injection vulnerability in vnews.php in Universe CMS 1.0.6 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
CliServ Web Community 0.65 - 'cl_headers' Include
CVE-2006-7068webappsphp
PHP remote file inclusion vulnerability in CliServ Web Community 0.65 and earlier allows remote attackers to execute arb
23RIESGO
abrir
ReferênciaVexDay Proof
TEC-IT TBarCode - OCX ActiveX Arbitrary File Overwrite
CVE-2007-3233remotewindows
The TEC-IT TBarCode OCX ActiveX control (TBarCode7.ocx) 7.0.2.3524 allows remote attackers to overwrite arbitrary files
23RIESGO
abrir
ReferênciaVexDay Proof
Arcadem LE 2.04 - 'loadadminpage' Remote File Inclusion
CVE-2007-6542webappsphp
PHP remote file inclusion vulnerability in admin/frontpage_right.php in Arcadem LE 2.04 and earlier allows remote attack
23RIESGO
abrir
ReferênciaVexDay Proof
Mambo Component SimpleBoard 1.0.1 - Arbitrary File Upload
CVE-2008-6814webappsphp
Unrestricted file upload vulnerability in image_upload.php in the SimpleBoard (com_simpleboard) component 1.0.1 and earl
23RIESGO
abrir
Referência
CVE-2018-6323
The elf_object_p function in elfcode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU B
23RIESGO
abrir
Referência
CVE-2017-5850
httpd in OpenBSD allows remote attackers to cause a denial of service (memory consumption) via a series of requests for
28RIESGO
abrir
Referência
CVE-2010-2045
Directory traversal vulnerability in the Dione Form Wizard (aka FDione or com_dioneformwizard) component 1.0.2 for Jooml
38RIESGO
abrir
Referência
CVE-2019-12189
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do search field.
23RIESGO
abrir
Referência
CVE-2009-2396
PHP remote file inclusion vulnerability in template/album.php in DM Albums 1.9.2, as used standalone or as a WordPress p
23RIESGO
abrir
Referência
CVE-2017-5850
httpd in OpenBSD allows remote attackers to cause a denial of service (memory consumption) via a series of requests for
28RIESGO
abrir
Referência
Nagios Log Server 2024R1.3.1 - Stored XSS
CVE-2025-29471HIGHwebappsmultiple
Cross Site Scripting vulnerability in Nagios Log Server v.2024R1.3.1 allows a remote attacker to execute arbitrary code
41RIESGO
abrir
Referência
CVE-2017-14939
decode_line_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.
23RIESGO
abrir
ReferênciaVexDay Proof
Xilisoft Video Converter Wizard 3 - '.cue' Stack Buffer Overflow (PoC)
CVE-2009-1370doswindows
Stack-based buffer overflow in ape_plugin.plg in Xilisoft Video Converter 3.1.53.0704n and 5.1.23.0402 allows remote att
23RIESGO
abrir
Referência
CVE-2009-2653
The NtUserConsoleControl function in win32k.sys in Microsoft Windows XP SP2 and SP3, and Server 2003 before SP1, allows
23RIESGO
abrir
Referência
CVE-2009-2333
Multiple directory traversal vulnerabilities in CMS Chainuk 1.2 and earlier allow remote attackers to include and execut
23RIESGO
abrir
Referência
CVE-2009-3053
Directory traversal vulnerability in the Agora (com_agora) component 3.0.0b for Joomla! allows remote attackers to inclu
38RIESGO
abrir
Referência
CVE-2014-8386
Multiple stack-based buffer overflows in Advantech AdamView 4.3 and earlier allow remote attackers to execute arbitrary
23RIESGO
abrir
anteriorpágina 303 / 727siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.