Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.020exploits catalogados
35.276CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.446Referência 22.166GitHub PoC 14.080VulnCheck XDB 8604Nuclei 4251Metasploit 3473✓ solo verificadosrecientespopularesriesgo
21.899 exploits
Referência
CVE-2014-2044
Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote aut
28RIESGO
abrir ↗Referência
CVE-2014-2044
Incomplete blacklist vulnerability in ajax/upload.php in ownCloud before 5.0, when running on Windows, allows remote aut
28RIESGO
abrir ↗Referência
CVE-2012-3808
Samsung Kies before 2.5.0.12094_27_11 has arbitrary file modification.
23RIESGO
abrir ↗Referência✓ VexDay Proof
NUNE News Script 2.0pre2 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in NUNE News Script 2.0pre2 allow remote attackers to execute arbitra
23RIESGO
abrir ↗Referência✓ VexDay Proof
eFiction 3.1.1 - 'path_to_smf' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in eFiction 3.1.1 and earlier allow remote attackers to execute arbit
23RIESGO
abrir ↗Referência✓ VexDay Proof
Yappa-ng 2.3.3-beta0 - 'album' Local File Inclusion
Directory traversal vulnerability in index.php in Fritz Berger yet another php photo album - next generation (yappa-ng)
23RIESGO
abrir ↗Referência✓ VexDay Proof
minb 0.1.0 - Remote Code Execution
include/modules/top/1-random_quote.php in Minb Is Not a Blog (minb) 0.1.0 allows remote attackers to execute arbitrary P
23RIESGO
abrir ↗Referência
CVE-2009-3421
login.php in Zenas PaoBacheca Guestbook 2.1, when register_globals is enabled, allows remote attackers to bypass authent
23RIESGO
abrir ↗Referência
CVE-2017-7938
Stack-based buffer overflow in DMitry (Deepmagic Information Gathering Tool) version 1.3a (Unix) allows attackers to cau
33RIESGO
abrir ↗Referência
CVE-2017-7938
Stack-based buffer overflow in DMitry (Deepmagic Information Gathering Tool) version 1.3a (Unix) allows attackers to cau
33RIESGO
abrir ↗Referência
CVE-2014-0865
RICOS in IBM Algo Credit Limits (aka ACLM) 4.5.0 through 4.7.0 before 4.7.0.03 FP5 in IBM Algorithmics relies on client-
23RIESGO
abrir ↗Referência
CVE-2019-15742
A local privilege-escalation vulnerability exists in the Poly Plantronics Hub before 3.14 for Windows client application
38RIESGO
abrir ↗Referência
CVE-2018-4206
An issue was discovered in certain Apple products. iOS before 11.3.1 is affected. macOS before 10.13.4 Security Update 2
23RIESGO
abrir ↗Referência
CVE-2018-6410
An issue was discovered in Appnitro MachForm before 4.2.3. There is a download.php SQL injection via the q parameter.
23RIESGO
abrir ↗Referência
CVE-2006-3362
Unrestricted file upload vulnerability in connectors/php/connector.php in FCKeditor mcpuk file manager, as used in (1) G
23RIESGO
abrir ↗Referência
CVE-2023-22629
An issue was discovered in TitanFTP through 1.94.1205. The move-file function has a path traversal vulnerability in the
61RIESGO
abrir ↗Referência
CVE-2016-6174
applications/core/modules/front/system/content.php in Invision Power Services IPS Community Suite (aka Invision Power Bo
28RIESGO
abrir ↗Referência
CVE-2025-34087
Pi-Hole AdminLTE Whitelist (now 'Web Allowlist') Remote Command Execution
63RIESGO
abrir ↗Referência
CVE-2025-34087
Pi-Hole AdminLTE Whitelist (now 'Web Allowlist') Remote Command Execution
63RIESGO
abrir ↗Referência
CVE-2019-6498
GattLib 0.2 has a stack-based buffer over-read in gattlib_connect in dbus/gattlib.c because strncpy is misused.
23RIESGO
abrir ↗Referência✓ VexDay Proof
XChat 2.6.7 (Windows) - Remote Denial of Service
Unspecified vulnerability in Xchat 2.6.7 and earlier allows remote attackers to cause a denial of service (crash) via un
23RIESGO
abrir ↗Referência
CVE-2009-3808
MixSense DJ Studio 1.0.0.1 allows remote attackers to cause a denial of service (application crash) and possibly execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mambo Module MambWeather 1.8.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in Savant2/Savant2_Plugin_options.php in the MambWeather 1.8.1 and earlier compo
23RIESGO
abrir ↗Referência✓ VexDay Proof
Enigma 2 Coppermine Bridge - 'boarddir' Remote File Inclusion
PHP remote file inclusion vulnerability in E2_header.inc.php in Enigma2 Coppermine Bridge 1.0 allows remote attackers to
23RIESGO
abrir ↗Referência✓ VexDay Proof
GNU/Linux mbse-bbs 0.70.0 - Local Buffer Overflow
Stack-based buffer overflow in mbse-bbs 0.70 and earlier allows local users to execute arbitrary code via a long string
23RIESGO
abrir ↗Referência✓ VexDay Proof
XM Easy Personal FTP Server 5.30 - 'ABOR' Format String Denial of Service
Multiple buffer overflows in XM Easy Personal FTP Server 5.3.0 allow remote attackers to execute arbitrary code via unsp
23RIESGO
abrir ↗Referência
CVE-2017-8837
Cleartext password storage exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-
23RIESGO
abrir ↗Referência
CVE-2017-15962
iStock Management System 1.0 allows Arbitrary File Upload via user/profile.
23RIESGO
abrir ↗Referência
CVE-2017-15962
iStock Management System 1.0 allows Arbitrary File Upload via user/profile.
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.