Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.402exploits catalogados
34.906CVEs con explotación pública
24.695probados en laboratorio
21.797 exploits
Referência
CVE-2025-25038
MiniDVBLinux Root Command Injection
48RIESGO
abrir
Referência
CVE-2025-25038
MiniDVBLinux Root Command Injection
48RIESGO
abrir
ReferênciaVexDay Proof
groone's Guestbook 2.0 - Remote File Inclusion
CVE-2009-0464webappsphp
PHP remote file inclusion vulnerability in includes/header.php in Groone GBook 2.0 allows remote attackers to execute ar
23RIESGO
abrir
Referência
CVE-2016-2417
media/libmedia/IOMX.cpp in mediaserver in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, and 6.x befo
23RIESGO
abrir
Referência
CVE-2013-7030
The TFTP service in Cisco Unified Communications Manager (aka CUCM or Unified CM) allows remote attackers to obtain sens
41RIESGO
abrir
Referência
CVE-2022-22832
An issue was discovered in Servisnet Tessa 0.0.2. Authorization data is available via an unauthenticated /data-service/u
28RIESGO
abrir
Referência
CVE-2015-3245
Incomplete blacklist vulnerability in the chfn function in libuser before 0.56.13-8 and 0.60 before 0.60-7, as used in t
38RIESGO
abrir
Referência
CVE-2019-6804
An XSS issue was discovered on the Job Edit page in Rundeck Community Edition before 3.0.13, related to assets/javascrip
23RIESGO
abrir
Referência
CVE-2016-5310
The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP);
23RIESGO
abrir
Referência
CVE-2021-27946
SQL Injection vulnerability in MyBB before 1.8.26 via poll vote count. (issue 1 of 3).
23RIESGO
abrir
Referência
CVE-2012-6290
SQL injection vulnerability in ImageCMS before 4.2 allows remote authenticated administrators to execute arbitrary SQL c
23RIESGO
abrir
Referência
CVE-2013-2637
A Cross-Site Scripting (XSS) Vulnerability exists in OTRS ITSM prior to 3.2.4, 3.1.8, and 3.0.7 and FAQ prior to 2.1.4 a
23RIESGO
abrir
Referência
CVE-2017-7221
OpenText Documentum Content Server has an inadequate protection mechanism against SQL injection, which allows remote aut
23RIESGO
abrir
ReferênciaVexDay Proof
JV2 Folder Gallery 3.0 - Remote File Inclusion
CVE-2007-0682webappsphp
PHP remote file inclusion vulnerability in theme/include_mode/template.php in JV2 Folder Gallery 3.0.2 and earlier allow
23RIESGO
abrir
ReferênciaVexDay Proof
wavewoo 0.1.1 - 'loading.php?path_include' Remote File Inclusion
CVE-2007-2273webappsphp
PHP remote file inclusion vulnerability in include/loading.php in Alessandro Lulli wavewoo 0.1.1 allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
TR News 2.1 - 'nb' SQL Injection
CVE-2008-1958webappsphp
Unrestricted file upload vulnerability in the ajout_cat mode in admin/main.php in Tr Script News 2.1 allows remote authe
23RIESGO
abrir
Referência
CVE-2015-5287
The abrt-hook-ccpp help program in Automatic Bug Reporting Tool (ABRT) before 2.7.1 allows local users with certain perm
38RIESGO
abrir
Referência
CVE-2021-26855
CVE-2021-26855CRITICALbajo ataqueransomware
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
Referência
CVE-2021-26855
CVE-2021-26855CRITICALbajo ataqueransomware
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
Referência
CVE-2018-8550
An elevation of privilege exists in Windows COM Aggregate Marshaler, aka "Windows COM Elevation of Privilege Vulnerabili
23RIESGO
abrir
Referência
CVE-2010-1092
Multiple SQL injection vulnerabilities in login.php in ScriptsFeed Business Directory Software allow remote attackers to
23RIESGO
abrir
Referência
CVE-2017-18001
Trustwave Secure Web Gateway (SWG) through 11.8.0.27 allows remote attackers to append an arbitrary public key to the de
28RIESGO
abrir
Referência
CVE-2024-6928
Opti Marketing <= 2.0.9 - Unauthenticated SQLi
63RIESGO
abrir
Referência
CVE-2024-6924
TrueBooker < 1.0.3 - Multiple Unauthenticated SQLi
63RIESGO
abrir
Referência
CVE-2024-6926
Viral Signup <= 2.1 - Unauthenticated SQLi
63RIESGO
abrir
Referência
CVE-2023-7095
Totolink A7100RU HTTP POST Request main buffer overflow
53RIESGO
abrir
Referência
CVE-2017-7783
If a long user name is used in a username/password combination in a site URL (such as " http://UserName:Password@example
28RIESGO
abrir
Referência
CVE-2017-16353
GraphicsMagick 1.3.26 is vulnerable to a memory information disclosure vulnerability found in the DescribeImage function
28RIESGO
abrir
Referência
CVE-2017-8870
Buffer overflow in AudioCoder 0.8.46 allows remote attackers to execute arbitrary code via a crafted .m3u file.
43RIESGO
abrir
Referência
CVE-2009-3667
SQL injection vulnerability in admin/index.php in AdsDX 3.05 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
anteriorpágina 315 / 727siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.