Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.466Referência 23.051GitHub PoC 15.051VulnCheck XDB 8883Nuclei 4361Metasploit 3493✓ solo verificadosrecientespopularesriesgo
22.910 exploits
Referência
CVE-2019-5420
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RIESGO
abrir ↗Referência✓ VexDay Proof
Maian Guestbook 3.2 - Insecure Cookie Handling
admin/index.php in Maian Guestbook 3.2 and earlier allows remote attackers to bypass authentication and gain administrat
23RIESGO
abrir ↗Referência
CVE-2019-5420
A remote code execution vulnerability in development mode Rails <5.2.2.1, <6.0.0.beta3 can allow an attacker to guess th
60RIESGO
abrir ↗Referência✓ VexDay Proof
Maian Uploader 4.0 - Insecure Cookie Handling
admin/index.php in Maian Uploader 4.0 and earlier allows remote attackers to bypass authentication and gain administrati
23RIESGO
abrir ↗Referência
CVE-2023-5360
Royal Elementor Addons and Templates < 1.3.79 - Unauthenticated Arbitrary File Upload
60RIESGO
abrir ↗Referência✓ VexDay Proof
ShopCartDx 4.30 - 'pid' SQL Injection
SQL injection vulnerability in product_detail.php in ShopCart DX allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir ↗Referência✓ VexDay Proof
Atom Photoblog 1.1.5b1 - 'photoId' SQL Injection
SQL injection vulnerability in atomPhotoBlog.php in Atom PhotoBlog 1.0.9.1 and 1.1.5b1 allows remote attackers to execut
23RIESGO
abrir ↗Referência✓ VexDay Proof
Beacon 0.2.0 - 'splash.lang.php' Remote File Inclusion
PHP remote file inclusion vulnerability in language/1/splash.lang.php in Beacon 0.2.0 allows remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
FAQ Manager 1.2 - 'header.php' Remote File Inclusion
PHP remote file inclusion vulnerability in include/header.php in Werner Hilversum FAQ Manager 1.2, when register_globals
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpList 2.10.8 - Local File Inclusion
Dynamic variable evaluation vulnerability in lists/admin.php in phpList 2.10.8 and earlier, when register_globals is dis
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP Photo Album 0.8b - 'preview' Local File Inclusion
Directory traversal vulnerability in index.php in Php Photo Album (PHPPA) 0.8 BETA allows remote attackers to include an
23RIESGO
abrir ↗Referência
CVE-2016-5734
phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not properly choose delimiters to
60RIESGO
abrir ↗Referência
CVE-2018-5955
An issue was discovered in GitStack through 2.3.10. User controlled input is not sufficiently filtered, allowing an unau
60RIESGO
abrir ↗Referência
CVE-2019-1458
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RIESGO
abrir ↗Referência
CVE-2019-1458
An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in
100RIESGO
abrir ↗Referência✓ VexDay Proof
PHP FirstPost 0.1 - 'block.php?Include' Remote File Inclusion
PHP remote file inclusion vulnerability in block.php in PhpFirstPost 0.1 allows remote attackers to execute arbitrary PH
23RIESGO
abrir ↗Referência
CVE-2022-31704
The vRealize Log Insight contains a broken access control vulnerability. An unauthenticated malicious actor can remotely
85RIESGO
abrir ↗Referência
CVE-2022-31704
The vRealize Log Insight contains a broken access control vulnerability. An unauthenticated malicious actor can remotely
85RIESGO
abrir ↗Referência✓ VexDay Proof
IntelliTamper 2.0.7 - HTML Parser Remote Buffer Overflow
Stack-based buffer overflow in the HTML parser in IntelliTamper 2.0.7 allows remote attackers to execute arbitrary code
23RIESGO
abrir ↗Referência✓ VexDay Proof
IntelliTamper 2.0.7 - HTML Parser Remote Buffer Overflow
Stack-based buffer overflow in the HTML parser in IntelliTamper 2.0.7 allows remote attackers to execute arbitrary code
23RIESGO
abrir ↗Referência
CVE-2014-7862
The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote at
60RIESGO
abrir ↗Referência
CVE-2016-7255
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
93RIESGO
abrir ↗Referência
CVE-2017-10974
Yaws 1.91 allows Unauthenticated Remote File Disclosure via HTTP Directory Traversal with /%5C../ to port 8080. NOTE: th
60RIESGO
abrir ↗Referência✓ VexDay Proof
XOOPS Module GesGaleri - SQL Injection
SQL injection vulnerability in index.php in GesGaleri, a module for XOOPS, allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência
CVE-2019-9621
Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x b
100RIESGO
abrir ↗Referência
CVE-2019-9621
Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x b
100RIESGO
abrir ↗Referência
CVE-2019-9621
Zimbra Collaboration Suite before 8.6 patch 13, 8.7.x before 8.7.11 patch 10, and 8.8.x before 8.8.10 patch 7 or 8.8.x b
100RIESGO
abrir ↗Referência
CVE-2016-7255
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
93RIESGO
abrir ↗Referência✓ VexDay Proof
DMXReady Secure Document Library 1.1 - SQL Injection
SQL injection vulnerability in CategoryManager/upload_image_category.asp in DMXReady Secure Document Library 1.1 and ear
23RIESGO
abrir ↗Referência
CVE-2013-4212
Certain getText methods in the ActionSupport controller in Apache Roller before 5.0.2 allow remote attackers to execute
60RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.