Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
76.313exploits catalogados
34.834CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.797GitHub PoC 13.885VulnCheck XDB 8484Nuclei 4237Metasploit 3467✓ solo verificadosrecientespopularesriesgo
21.797 exploits
Referência
CVE-2020-8644
PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.
100RIESGO
abrir ↗Referência
CVE-2010-1179
Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash)
23RIESGO
abrir ↗Referência
CVE-2014-9000
Mule Enterprise Management Console (MMC) does not properly restrict access to handler/securityService.rpc, which allows
23RIESGO
abrir ↗Referência
CVE-2018-7653
In YzmCMS 3.6, index.php has XSS via the a, c, or m parameter.
38RIESGO
abrir ↗Referência
CVE-2018-7653
In YzmCMS 3.6, index.php has XSS via the a, c, or m parameter.
38RIESGO
abrir ↗Referência
CVE-2009-4991
Cross-site scripting (XSS) vulnerability in users/resume_register.php in Omnistar Recruiting allows remote attackers to
23RIESGO
abrir ↗Referência
CVE-2015-7894
The DCMProvider service in Samsung LibQjpeg on a Samsung SM-G925V device running build number LRX22G.G925VVRU1AOE2 allow
23RIESGO
abrir ↗Referência
CVE-2009-2533
rmserver in RealNetworks Helix Server and Helix Mobile Server before 13.0.0 allows remote attackers to cause a denial of
23RIESGO
abrir ↗Referência✓ VexDay Proof
AAA EasyGrid ActiveX 3.51 - Remote File Overwrite
Insecure method vulnerability in the EasyGrid.SGCtrl.32 ActiveX control in EasyGrid.ocx 1.0.0.1 in AAA EasyGrid ActiveX
23RIESGO
abrir ↗Referência
CVE-2017-17058
The WooCommerce plugin through 3.x for WordPress has a Directory Traversal Vulnerability via a /wp-content/plugins/wooco
46RIESGO
abrir ↗Referência
CVE-2017-17058
The WooCommerce plugin through 3.x for WordPress has a Directory Traversal Vulnerability via a /wp-content/plugins/wooco
46RIESGO
abrir ↗Referência
CVE-2013-1599
A Command Injection vulnerability exists in the /var/www/cgi-bin/rtpd.cgi script in D-Link IP Cameras DCS-3411/3430 firm
35RIESGO
abrir ↗Referência
CVE-2017-4914
VMware vSphere Data Protection (VDP) 6.1.x, 6.0.x, 5.8.x, and 5.5.x contains a deserialization issue. Exploitation of th
23RIESGO
abrir ↗Referência
CVE-2013-1599
A Command Injection vulnerability exists in the /var/www/cgi-bin/rtpd.cgi script in D-Link IP Cameras DCS-3411/3430 firm
35RIESGO
abrir ↗Referência
CVE-2020-8615
A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 for WordPress can result in an attacker approving themselves a
38RIESGO
abrir ↗Referência
CVE-2024-51978
Authentication bypass via default password generation affecting multiple models from Brother Industries, Ltd, Toshiba Tec, and Konica Minolta, Inc.
68RIESGO
abrir ↗Referência
CVE-2024-51978
Authentication bypass via default password generation affecting multiple models from Brother Industries, Ltd, Toshiba Tec, and Konica Minolta, Inc.
68RIESGO
abrir ↗Referência
CVE-2024-51978
Authentication bypass via default password generation affecting multiple models from Brother Industries, Ltd, Toshiba Tec, and Konica Minolta, Inc.
68RIESGO
abrir ↗Referência
CVE-2016-4656
The kernel in Apple iOS before 9.3.5 allows attackers to execute arbitrary code in a privileged context or cause a denia
91RIESGO
abrir ↗Referência✓ VexDay Proof
GeoVision LiveAudio - ActiveX Remote Freed-Memory Access
Use-after-free vulnerability in the LIVEAUDIO.LiveAudioCtrl.1 ActiveX control in LIVEAU~1.OCX 7.0 for GeoVision DVR syst
23RIESGO
abrir ↗Referência
CVE-2009-2534
RealNetworks Helix Server and Helix Mobile Server before 13.0.0 allow remote attackers to cause a denial of service (dae
23RIESGO
abrir ↗Referência
CVE-2006-3144
PHP remote file inclusion vulnerability in micro_cms_files/microcms-include.php in Implied By Design (IBD) Micro CMS 3.5
23RIESGO
abrir ↗Referência
CVE-2018-7737
In Z-BlogPHP 1.5.1.1740, there is Web Site physical path leakage, as demonstrated by admin_footer.php or admin_footer.ph
23RIESGO
abrir ↗Referência
CVE-2009-4992
SQL injection vulnerability in paidbanner.php in LM Starmail Paidmail 2.0 allows remote attackers to execute arbitrary S
23RIESGO
abrir ↗Referência
CVE-2018-7737
In Z-BlogPHP 1.5.1.1740, there is Web Site physical path leakage, as demonstrated by admin_footer.php or admin_footer.ph
23RIESGO
abrir ↗Referência
CVE-2012-3579
Symantec Messaging Gateway (SMG) before 10.0 has a default password for an unspecified account, which makes it easier fo
50RIESGO
abrir ↗Referência
CVE-2014-3225
Absolute path traversal vulnerability in the web interface in Cobbler 2.4.x through 2.6.x allows remote authenticated us
23RIESGO
abrir ↗Referência
CVE-2017-17111
Posty Readymade Classifieds Script 1.0 allows an attacker to inject SQL commands via a listings.php?catid= or ads-detail
23RIESGO
abrir ↗Referência
CVE-2017-17111
Posty Readymade Classifieds Script 1.0 allows an attacker to inject SQL commands via a listings.php?catid= or ads-detail
23RIESGO
abrir ↗Referência
CVE-2010-0718
Buffer overflow in Microsoft Windows Media Player 9 and 11.0.5721.5145 allows remote attackers to cause a denial of serv
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.