Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.449exploits catalogados
35.552CVEs con explotación pública
24.695probados en laboratorio
22.367 exploits
ReferênciaVexDay Proof
PhFiTo 1.3.0 - 'SRC_PATH' Remote File Inclusion
CVE-2007-5157webappsphp
PHP remote file inclusion vulnerability in phfito-post.php in Alex Kocharin PHP Fidonet Tosser (PhFiTo) 1.3.0 in phpFido
23RIESGO
abrir
ReferênciaVexDay Proof
actSite 1.56 - 'news.php' Local File Inclusion
CVE-2007-5174webappsphp
Directory traversal vulnerability in phpinc/news.php in actSite 1.56 allows remote attackers to include and execute arbi
23RIESGO
abrir
ReferênciaVexDay Proof
Mambo Component Mambads 1.5 - SQL Injection
CVE-2007-5177webappsphp
SQL injection vulnerability in index.php in the MambAds (com_mambads) 1.5 and earlier component for Mambo allows remote
23RIESGO
abrir
ReferênciaVexDay Proof
mxBB Module mx_glance 2.3.3 - Remote File Inclusion
CVE-2007-5178webappsphp
contrib/mx_glance_sdesc.php in the mx_glance 2.3.3 module for mxBB places a critical security check within a comment bec
23RIESGO
abrir
ReferênciaVexDay Proof
smbftpd 0.96 - SMBDirList-function Remote Format String
CVE-2007-5184remotelinux
Format string vulnerability in the SMBDirList function in dirlist.c in SmbFTPD 0.96 allows remote attackers to execute a
28RIESGO
abrir
ReferênciaVexDay Proof
PHP wcms XT 0.0.7 - Multiple Remote File Inclusions
CVE-2007-5185webappsphp
Multiple PHP remote file inclusion vulnerabilities in phpWCMS XT 0.0.7 BETA and earlier allow remote attackers to execut
35RIESGO
abrir
ReferênciaVexDay Proof
Segue CMS 1.8.4 - 'index.php' Remote File Inclusion
CVE-2007-5186webappsphp
PHP remote file inclusion vulnerability in index.php in Segue CMS 1.8.4 and earlier, when register_globals is disabled,
35RIESGO
abrir
ReferênciaVexDay Proof
PHP-Fusion module Expanded Calendar 2.x - SQL Injection
CVE-2007-5187webappsphp
SQL injection vulnerability in infusions/calendar_events_panel/show_single.php in the Expanded Calendar 2.x module for P
23RIESGO
abrir
ReferênciaVexDay Proof
CyberLink PowerDVD - CreateNewFile Remote Rewrite Denial of Service
CVE-2007-5219doswindows
Directory traversal vulnerability in the CLAVSetting.CLSetting.1 ActiveX control in CLAVSetting.DLL 1.00.1829 in the CLA
28RIESGO
abrir
ReferênciaVexDay Proof
MD-Pro 1.0.76 - SQL Injection
CVE-2007-5222webappsphp
SQL injection vulnerability in index.php in MAXdev MDPro (MD-Pro) 1.0.76 allows remote attackers to execute arbitrary SQ
23RIESGO
abrir
Referência
CVE-2007-5225
Integer signedness error in FIFO filesystems (named pipes) on Sun Solaris 8 through 10 allows local users to read the co
23RIESGO
abrir
ReferênciaVexDay Proof
Solaris 8/9/10 - 'fifofs I_PEEK' Local Kernel Memory Leak
CVE-2007-5225localsolaris
Integer signedness error in FIFO filesystems (named pipes) on Sun Solaris 8 through 10 allows local users to read the co
23RIESGO
abrir
ReferênciaVexDay Proof
Zomplog 3.8.1 - Arbitrary File Upload
CVE-2007-5230webappsphp
admin/upload_files.php in Zomplog 3.8.1 and earlier does not check for administrative credentials, which allows remote a
23RIESGO
abrir
ReferênciaVexDay Proof
Zomplog 3.8.1 - Arbitrary File Upload
CVE-2007-5231webappsphp
Unrestricted file upload vulnerability in admin/upload_files.php in Zomplog 3.8.1 and earlier allows remote authenticate
23RIESGO
abrir
ReferênciaVexDay Proof
Web Template Management System 1.3 - SQL Injection
CVE-2007-5233webappsphp
SQL injection vulnerability in index.php in Web Template Management System 1.3 allows remote attackers to execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
Ossigeno CMS 2.2a3 - 'footer.php' Remote File Inclusion
CVE-2007-5234webappsphp
PHP remote file inclusion vulnerability in upload/common/footer.php in Ossigeno CMS 2.2 alpha3 allows remote attackers t
35RIESGO
abrir
Referência
CVE-2017-9413
Multiple cross-site request forgery (CSRF) vulnerabilities in the Podcast feature in Subsonic 6.1.1 allow remote attacke
23RIESGO
abrir
Referência
CVE-2017-9430
Stack-based buffer overflow in dnstracer through 1.9 allows attackers to cause a denial of service (application crash) o
28RIESGO
abrir
Referência
CVE-2017-9730
SQL injection vulnerability in rdr.php in nuevoMailer version 6.0 and earlier allows remote attackers to execute arbitra
23RIESGO
abrir
Referência
CVE-2017-9769
A specially crafted IOCTL can be issued to the rzpnk.sys driver in Razer Synapse 2.20.15.1104 that is forwarded to ZwOpe
60RIESGO
abrir
Referência
CVE-2017-9791
CVE-2017-9791CRITICALbajo ataque
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passe
100RIESGO
abrir
Referência
CVE-2018-0296
CVE-2018-0296HIGHbajo ataque
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remo
100RIESGO
abrir
Referência
CVE-2018-0296
CVE-2018-0296HIGHbajo ataque
A vulnerability in the web interface of the Cisco Adaptive Security Appliance (ASA) could allow an unauthenticated, remo
100RIESGO
abrir
Referência
CVE-2018-0710
Command injection vulnerability in SSH of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authe
28RIESGO
abrir
Referência
CVE-2018-0710
Command injection vulnerability in SSH of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authe
28RIESGO
abrir
Referência
CVE-2018-0748
The Windows kernel in Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and
23RIESGO
abrir
Referência
CVE-2018-0752
The Windows Kernel API in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709
23RIESGO
abrir
Referência
CVE-2018-0823
The Named Pipe File System in Windows 10 version 1709 and Windows Server, version 1709 allows an elevation of privilege
23RIESGO
abrir
Referência
CVE-2018-0838
Microsoft Edge and ChakraCore in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remot
35RIESGO
abrir
Referência
CVE-2023-33580
Phpgurukul Student Study Center Management System V1.0 is vulnerable to Cross Site Scripting (XSS) in the "Admin Name" f
23RIESGO
abrir
anteriorpágina 476 / 746siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.