Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
22.910 exploits
Referência
CVE-2018-14667
CVE-2018-14667CRITICALbajo ataque
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resou
100RIESGO
abrir
Referência
CVE-2012-4867
Directory traversal vulnerability in modules/com_vtiger_workflow/sortfieldsjson.php in vtiger CRM 5.1.0 allows remote at
23RIESGO
abrir
Referência
CVE-2017-5715
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized discl
55RIESGO
abrir
Referência
CVE-2018-15811
CVE-2018-15811HIGHbajo ataque
DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.
100RIESGO
abrir
ReferênciaVexDay Proof
k-links directory - SQL Injection / Cross-Site Scripting
CVE-2008-3580webappsphp
Multiple SQL injection vulnerabilities in Qsoft K-Links allow remote attackers to execute arbitrary SQL commands via (1)
23RIESGO
abrir
Referência
CVE-2015-6522
SQL injection vulnerability in the WP Symposium plugin before 15.8 for WordPress allows remote attackers to execute arbi
60RIESGO
abrir
ReferênciaVexDay Proof
XGuestBook 2.0 - Authentication Bypass
CVE-2009-0810webappsphp
SQL injection vulnerability in login.php in xGuestbook 2.0 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
Referência
CVE-2012-4867
Directory traversal vulnerability in modules/com_vtiger_workflow/sortfieldsjson.php in vtiger CRM 5.1.0 allows remote at
23RIESGO
abrir
Referência
CVE-2009-2598
Multiple SQL injection vulnerabilities in Online Grades & Attendance 3.2.6 and earlier allow (1) remote attackers to exe
23RIESGO
abrir
Referência
CVE-2019-6716
An unauthenticated Insecure Direct Object Reference (IDOR) in Wicket Core in LogonBox Nervepoint Access Manager 2013 thr
23RIESGO
abrir
ReferênciaVexDay Proof
k-links directory - SQL Injection / Cross-Site Scripting
CVE-2008-3581webappsphp
Cross-site scripting (XSS) vulnerability in index.php in Qsoft K-Links allows remote attackers to inject arbitrary web s
23RIESGO
abrir
Referência
CVE-2015-3087
Integer overflow in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and
45RIESGO
abrir
Referência
CVE-2016-9244
A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may
45RIESGO
abrir
Referência
CVE-2017-17405
Ruby before 2.4.3 allows Net::FTP command injection. Net::FTP#get, getbinaryfile, gettextfile, put, putbinaryfile, and p
45RIESGO
abrir
Referência
CVE-2019-6973
Sricam IP CCTV cameras are vulnerable to denial of service via multiple incomplete HTTP requests because the web server
28RIESGO
abrir
ReferênciaVexDay Proof
GreenCart PHP Shopping Cart - 'id' SQL Injection
CVE-2008-3585webappsphp
Multiple SQL injection vulnerabilities in PozScripts GreenCart PHP Shopping Cart allow remote attackers to execute arbit
23RIESGO
abrir
Referência
CVE-2020-8813
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a
60RIESGO
abrir
Referência
CVE-2020-8813
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a
60RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component EZ Store Remote - Blind SQL Injection
CVE-2008-3586webappsphp
SQL injection vulnerability in the EZ Store (com_ezstore) component for Joomla! allows remote attackers to execute arbit
23RIESGO
abrir
Referência
CVE-2020-8813
graph_realtime.php in Cacti 1.2.8 allows remote attackers to execute arbitrary OS commands via shell metacharacters in a
60RIESGO
abrir
Referência
CVE-2012-4869
The callme_startcall function in recordings/misc/callme_page.php in FreePBX 2.9, 2.10, and earlier allows remote attacke
60RIESGO
abrir
Referência
CVE-2013-2010
WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability
60RIESGO
abrir
Referência
CVE-2016-9244
A BIG-IP virtual server configured with a Client SSL profile that has the non-default Session Tickets option enabled may
45RIESGO
abrir
ReferênciaVexDay Proof
phsBlog 0.1.1 - Multiple SQL Injections
CVE-2008-3588webappsphp
Multiple SQL injection vulnerabilities in phsBlog 0.1.1 allow remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir
Referência
CVE-2018-20526
Roxy Fileman 1.4.5 allows unrestricted file upload in upload.php.
60RIESGO
abrir
Referência
CVE-2018-20526
Roxy Fileman 1.4.5 allows unrestricted file upload in upload.php.
60RIESGO
abrir
Referência
CVE-2019-7254
Linear eMerge E3-Series devices allow File Inclusion.
60RIESGO
abrir
ReferênciaVexDay Proof
Symphony 1.7.01 (non-patched) - Remote Code Execution
CVE-2008-3592webappsphp
Unrestricted file upload vulnerability in the File Manager in the admin panel in Twentyone Degrees Symphony 1.7.01 and e
23RIESGO
abrir
Referência
CVE-2015-8249
The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and e
60RIESGO
abrir
Referência
CVE-2015-8249
The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and e
60RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.