Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.466Referência 23.051GitHub PoC 15.051VulnCheck XDB 8883Nuclei 4361Metasploit 3493✓ solo verificadosrecientespopularesriesgo
22.910 exploits
Referência
CVE-2019-3978
RouterOS versions 6.45.6 Stable, 6.44.5 Long-term, and below allow remote unauthenticated attackers to trigger DNS queri
28RIESGO
abrir ↗Referência✓ VexDay Proof
Aprox CMS Engine 5.1.0.4 - 'index.php' SQL Injection
SQL injection vulnerability in index.php in AproxEngine (aka Aprox CMS Engine) 5.1.0.4 allows remote attackers to execut
23RIESGO
abrir ↗Referência✓ VexDay Proof
EZWebAlbum - Insecure Cookie Handling
constants.inc in EZWebAlbum 1.0 allows remote attackers to bypass authentication and gain administrator privileges by se
23RIESGO
abrir ↗Referência✓ VexDay Proof
Persism CMS 0.9.2 - system[path] Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Persism CMS 0.9.2 and earlier allow remote attackers to execute ar
35RIESGO
abrir ↗Referência
CVE-2019-4716
IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated use
100RIESGO
abrir ↗Referência
CVE-2010-1297
Adobe Flash Player before 9.0.277.0 and 10.x before 10.1.53.64; Adobe AIR before 2.0.2.12610; and Adobe Reader and Acrob
100RIESGO
abrir ↗Referência
CVE-2011-0276
HP OpenView Performance Insight Server 5.2, 5.3, 5.31, 5.4, and 5.41 contains a "hidden account" in the com.trinagy.secu
60RIESGO
abrir ↗Referência
CVE-2018-6789
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted mes
100RIESGO
abrir ↗Referência
CVE-2024-8957
PTZOptics NDI and SDI Cameras Command Injection via NTP Address Configuration
93RIESGO
abrir ↗Referência✓ VexDay Proof
DeluxeBB 1.07 - Remote Create Admin
SQL injection vulnerability in cp.php in DeluxeBB 1.07 and earlier allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir ↗Referência
CVE-2017-0038
gdi32.dll in Graphics Device Interface (GDI) in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows
45RIESGO
abrir ↗Referência✓ VexDay Proof
bilboblog 2.1 - Multiple Vulnerabilities
SQL injection vulnerability in admin/delete.php in BilboBlog 0.2.1, when magic_quotes_gpc is disabled, allows remote aut
23RIESGO
abrir ↗Referência
CVE-2017-8779
rpcbind through 0.2.4, LIBTIRPC through 1.0.1 and 1.0.2-rc through 1.0.2-rc3, and NTIRPC through 1.4.3 do not consider t
60RIESGO
abrir ↗Referência
CVE-2018-10660
An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection.
60RIESGO
abrir ↗Referência
CVE-2019-5392
A disclosure of information vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than ve
23RIESGO
abrir ↗Referência
CVE-2020-35578
An issue was discovered in the Manage Plugins page in Nagios XI before 5.8.0. Because the line-ending conversion feature
60RIESGO
abrir ↗Referência
CVE-2020-35578
An issue was discovered in the Manage Plugins page in Nagios XI before 5.8.0. Because the line-ending conversion feature
60RIESGO
abrir ↗Referência
CVE-2023-22232
Adobe Connect Improper Access Control Security feature bypass
70RIESGO
abrir ↗Referência
CVE-2014-8440
Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on Windows and OS X and before 11.2.202.418 on
60RIESGO
abrir ↗Referência
CVE-2015-0336
Adobe Flash Player before 13.0.0.277 and 14.x through 17.x before 17.0.0.134 on Windows and OS X and before 11.2.202.451
60RIESGO
abrir ↗Referência
CVE-2015-6922
Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.33, 8.x before 8.0.0.23, 9.0 before 9.0.0.19, and 9.1 before
60RIESGO
abrir ↗Referência
CVE-2015-6922
Kaseya Virtual System Administrator (VSA) 7.x before 7.0.0.33, 8.x before 8.0.0.23, 9.0 before 9.0.0.19, and 9.1 before
60RIESGO
abrir ↗Referência✓ VexDay Proof
bilboblog 2.1 - Multiple Vulnerabilities
BilboBlog 0.2.1 allows remote attackers to obtain sensitive information via (1) an enable_cache=false query string to fo
23RIESGO
abrir ↗Referência
CVE-2019-5418
There is a File Content Disclosure vulnerability in Action View <5.2.2.1, <5.1.6.2, <5.0.7.2, <4.2.11.1 and v3 where spe
100RIESGO
abrir ↗Referência✓ VexDay Proof
Pre Survey Poll - 'catid' SQL Injection
SQL injection vulnerability in default.asp in Pre Survey Poll allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência✓ VexDay Proof
feedDemon 2.7 - OPML Outline Tag Buffer Overflow
Stack-based buffer overflow in NewsGator FeedDemon 2.7 and earlier allows user-assisted remote attackers to execute arbi
50RIESGO
abrir ↗Referência
CVE-2009-2428
Multiple SQL injection vulnerabilities in Tausch Ticket Script 3 allow remote attackers to execute arbitrary SQL command
23RIESGO
abrir ↗Referência
CVE-2017-17641
Resume Clone Script 2.0.5 has SQL Injection via the preview.php id parameter.
23RIESGO
abrir ↗Referência
CVE-2024-9464
Expedition: Authenticated OS Command Injection Vulnerability Leads to Firewall Admin Credential Disclosure
70RIESGO
abrir ↗Referência✓ VexDay Proof
Maian Search 1.1 - Insecure Cookie Handling
admin/index.php in Maian Search 1.1 and earlier allows remote attackers to bypass authentication and gain administrative
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.