Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.496exploits catalogados
34.964CVEs con explotación pública
24.695probados en laboratorio
21.797 exploits
Referência
CVE-2018-17375
SQL Injection exists in the Music Collection 3.0.3 component for Joomla! via the id parameter.
23RIESGO
abrir
Referência
CVE-2018-11535
An issue was discovered in SITEMAKIN SLAC (Site Login and Access Control) v1.0. The parameter "my_item_search" in users.
23RIESGO
abrir
ReferênciaVexDay Proof
NewsLetter 3.5 - 'NL_PATH' Remote File Inclusion
CVE-2006-3986webappsphp
PHP remote file inclusion vulnerability in index.php in Knusperleicht Newsletter 3.5 and earlier allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component Webring 1.0 - Remote File Inclusion
CVE-2006-4129webappsphp
PHP remote file inclusion vulnerability in admin.webring.docs.php in the Webring Component (com_webring) 1.0 and earlier
23RIESGO
abrir
ReferênciaVexDay Proof
Magic Photo Storage Website - '_config[site_path]' File Inclusion
CVE-2007-0181webappsphp
PHP remote file inclusion vulnerability in include/common_function.php in magic photo storage website allows remote atta
23RIESGO
abrir
ReferênciaVexDay Proof
Jshop Server 1.3 - 'fieldValidation.php' Remote File Inclusion
CVE-2007-0232webappsphp
PHP remote file inclusion vulnerability in routines/fieldValidation.php in Jshop Server 1.3 allows remote attackers to e
23RIESGO
abrir
Referência
CVE-2017-3064
Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability when parsing a sh
28RIESGO
abrir
ReferênciaVexDay Proof
Tropicalm Crowell Resource 4.5.2 - 'RESPATH' Remote File Inclusion
CVE-2007-2530webappsphp
Multiple PHP remote file inclusion vulnerabilities in Tropicalm Crowell Resource 4.5.2 allow remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
Media Gallery for Geeklog 1.4.8a - Remote File Inclusion
CVE-2007-2706webappsphp
PHP remote file inclusion vulnerability in maint/ftpmedia.php in Media Gallery 1.4.8a and earlier for Geeklog allows rem
23RIESGO
abrir
ReferênciaVexDay Proof
Venalsur on-line Booking Centre - Cross-Site Scripting / SQL Injection
CVE-2008-6215webappsphp
Cross-site scripting (XSS) vulnerability in cadena_ofertas_ext.php in Venalsur Booking Centre Booking System for Hotels
23RIESGO
abrir
Referência
CVE-2015-2791
The "menu sync" function in the WPML plugin before 3.1.9 for WordPress allows remote attackers to delete arbitrary posts
28RIESGO
abrir
Referência
CVE-2018-11525
The plugin "Advanced Order Export For WooCommerce" for WordPress (v1.5.4 and before) is vulnerable to CSV Injection.
23RIESGO
abrir
Referência
CVE-2009-3704
ZoIPer 2.22, and possibly other versions before 2.24 Library 5324, allows remote attackers to cause a denial of service
23RIESGO
abrir
Referência
CVE-2018-11526
The plugin "WordPress Comments Import & Export" for WordPress (v2.0.4 and before) is vulnerable to CSV Injection.
23RIESGO
abrir
Referência
CVE-2019-0863
CVE-2019-0863HIGHbajo ataque
An elevation of privilege vulnerability exists in the way Windows Error Reporting (WER) handles files, aka 'Windows Erro
71RIESGO
abrir
Referência
CVE-2024-11237
TP-Link VN020 F3v(T) DHCP DISCOVER Packet Parser TP-Thumper stack-based overflow
41RIESGO
abrir
ReferênciaVexDay Proof
PowerPoint Viewer OCX 3.2 - ActiveX Control Denial of Service
CVE-2007-2494doswindows
Multiple stack-based buffer overflows in the PowerPointOCX ActiveX control in PowerPointViewer.ocx 3.1.0.3 allow remote
23RIESGO
abrir
Referência
CVE-2012-1790
Absolute path traversal vulnerability in Webgrind 1.0 and 1.0.2 allows remote attackers to read arbitrary files via a fu
23RIESGO
abrir
Referência
CVE-2012-1790
Absolute path traversal vulnerability in Webgrind 1.0 and 1.0.2 allows remote attackers to read arbitrary files via a fu
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! 1.5 Beta1/Beta2/RC1 - SQL Injection
CVE-2007-4781webappsphp
administrator/index.php in the installer component (com_installer) in Joomla! 1.5 Beta1, Beta2, and RC1 allows remote au
23RIESGO
abrir
Referência
CVE-2019-16383
MOVEit.DMZ.WebApi.dll in Progress MOVEit Transfer 2018 SP2 before 10.2.4, 2019 before 11.0.2, and 2019.1 before 11.1.1 a
23RIESGO
abrir
Referência
CVE-2014-7280
Cross-site scripting (XSS) vulnerability in the Web UI before 2.3.4 Build #85 for Tenable Nessus 5.x allows remote web s
23RIESGO
abrir
Referência
CVE-2014-1944
Cross-site scripting (XSS) vulnerability in Ilch CMS 2.0 and earlier allows remote attackers to inject arbitrary web scr
23RIESGO
abrir
ReferênciaVexDay Proof
PHPizabi 0.848b C1 HFP1 - Arbitrary File Upload
CVE-2008-0805webappsphp
Unrestricted file upload vulnerability in image.php in PHPizabi 0.848b C1 HFP1 allows remote attackers to execute arbitr
23RIESGO
abrir
Referência
CVE-2017-11120
On Broadcom BCM4355C0 Wi-Fi chips 9.44.78.27.0.1.56 and other chips, an attacker can craft a malformed RRM neighbor repo
23RIESGO
abrir
ReferênciaVexDay Proof
SugarCRM Community Edition 4.5.1/5.0.0 - File Disclosure
CVE-2008-2045webappsphp
Absolute path traversal vulnerability in SugarCRM Sugar Community Edition 4.5.1 and 5.0.0 allows remote attackers to rea
23RIESGO
abrir
Referência
CVE-2016-1755
The kernel in Apple iOS before 9.3, OS X before 10.11.4, tvOS before 9.2, and watchOS before 2.2 allows attackers to exe
23RIESGO
abrir
Referência
CVE-2015-4591
eClinicalWorks Population Health (CCMR) suffers from a cross site scripting vulnerability in login.jsp which allows remo
23RIESGO
abrir
Referência
CVE-2015-4591
eClinicalWorks Population Health (CCMR) suffers from a cross site scripting vulnerability in login.jsp which allows remo
23RIESGO
abrir
Referência
CVE-2009-2766
httpd.c in httpd in the management GUI in DD-WRT 24 sp1 does not require administrative authentication for programs unde
23RIESGO
abrir
anteriorpágina 319 / 727siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.