Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
22.936 exploits
ReferênciaVexDay Proof
e107 Plugin ZoGo-Shop 1.15.4 - 'product' SQL Injection
CVE-2008-6114webappsphp
SQL injection vulnerability in product_details.php in the Mytipper Zogo-shop 1.15.4 plugin for e107 allows remote attack
23RIESGO
abrir
Referência
CVE-2017-11873
ChakraCore and Microsoft Edge in Windows 10 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709
35RIESGO
abrir
Referência
CVE-2014-0257
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly determine whether it
50RIESGO
abrir
Referência
CVE-2014-0257
Microsoft .NET Framework 1.0 SP3, 1.1 SP1, 2.0 SP2, 3.5, 3.5.1, 4, 4.5, and 4.5.1 does not properly determine whether it
50RIESGO
abrir
Referência
CVE-2011-3176
Stack-based buffer overflow in the Preboot Service in Novell ZENworks Configuration Management (ZCM) 11.1 and 11.1a allo
60RIESGO
abrir
Referência
CVE-2025-48827
vBulletin 5.0.0 through 5.7.5 and 6.0.0 through 6.0.3 allows unauthenticated users to invoke protected API controllers'
85RIESGO
abrir
Referência
CVE-2011-1567
Multiple stack-based buffer overflows in IGSSdataServer.exe 9.00.00.11063 and earlier in 7-Technologies Interactive Grap
50RIESGO
abrir
ReferênciaVexDay Proof
Full PHP Emlak Script - 'arsaprint.php' SQL Injection
CVE-2008-6133webappsphp
SQL injection vulnerability in arsaprint.php in Full PHP Emlak Script allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
Referência
CVE-2012-5900
Multiple SQL injection vulnerabilities in SAMEDIA LandShop 0.9.2 allow remote attackers to execute arbitrary SQL command
23RIESGO
abrir
Referência
Visual Tools DVR VX16 4.2.28.0 - OS Command Injection (Unauthenticated)
CVE-2021-42071webappsmultiple
In Visual Tools DVR VX16 4.2.28.0, an unauthenticated attacker can achieve remote command execution via shell metacharac
50RIESGO
abrir
ReferênciaVexDay Proof
phpMyAdmin - '/scripts/setup.php' PHP Code Injection
CVE-2009-1151CRITICALbajo ataquewebappsphp
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remo
100RIESGO
abrir
ReferênciaVexDay Proof
Particle Gallery 1.0.1 - SQL Injection
CVE-2007-3065webappsphp
SQL injection vulnerability in viewimage.php in Particle Soft Particle Gallery 1.0.1 and earlier allows remote attackers
23RIESGO
abrir
Referência
CVE-2012-5896
The Annotation Objects Extension ActiveX control in AnnotateX.dll in Quest InTrust 10.4.0.853 and earlier does not prope
50RIESGO
abrir
Referência
CVE-2012-5896
The Annotation Objects Extension ActiveX control in AnnotateX.dll in Quest InTrust 10.4.0.853 and earlier does not prope
50RIESGO
abrir
ReferênciaVexDay Proof
Acoustica Beatcraft 1.02 Build 19 - '.bcproj' Local Buffer Overflow
CVE-2008-4087localwindows
Stack-based buffer overflow in Acoustica Beatcraft 1.02 Build 19 allows user-assisted attackers to cause a denial of ser
23RIESGO
abrir
Referência
CVE-2019-9193
In PostgreSQL 9.3 through 11.2, the "COPY TO/FROM PROGRAM" function allows superusers and users in the 'pg_execute_serve
60RIESGO
abrir
Referência
CVE-2019-10867
An issue was discovered in Pimcore before 5.7.1. An attacker with classes permission can send a POST request to /admin/c
50RIESGO
abrir
Referência
CVE-2019-10867
An issue was discovered in Pimcore before 5.7.1. An attacker with classes permission can send a POST request to /admin/c
50RIESGO
abrir
Referência
CVE-2017-8646
Microsoft Edge in Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in t
35RIESGO
abrir
Referência
CVE-2017-8640
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary cod
35RIESGO
abrir
Referência
CVE-2017-8645
Microsoft Edge in Windows 10 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in t
35RIESGO
abrir
Referência
CVE-2018-8631
A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory, aka "Internet
35RIESGO
abrir
Referência
CVE-2017-11802
ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker
35RIESGO
abrir
ReferênciaVexDay Proof
Yourownbux 3.1/3.2 Beta - SQL Injection
CVE-2008-4093webappsphp
SQL injection vulnerability in memberstats.php in YourOwnBux 3.1 and 3.2 beta, when magic_quotes_gpc is disabled, allows
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Windows - 'WRITE_ANDX' SMB Command Handling Kernel Denial of Service (Metasploit)
CVE-2008-4114doswindows
srv.sys in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1
50RIESGO
abrir
Referência
CVE-2022-22960
CVE-2022-22960HIGHbajo ataque
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due t
98RIESGO
abrir
Referência
CVE-2022-22960
CVE-2022-22960HIGHbajo ataque
VMware Workspace ONE Access, Identity Manager and vRealize Automation contain a privilege escalation vulnerability due t
98RIESGO
abrir
ReferênciaVexDay Proof
The Personal FTP Server 6.0f - RETR Denial of Service
CVE-2008-4136doswindows
Michael Roth Software Personal FTP Server (PFT) 6.0f allows remote attackers to cause a denial of service (service crash
23RIESGO
abrir
ReferênciaVexDay Proof
OwenPoll 1.0 - Insecure Cookie Handling
CVE-2008-6143webappsphp
OwenPoll 1.0 allows remote attackers to bypass authentication and obtain administrative access via a modified account na
23RIESGO
abrir
ReferênciaVexDay Proof
E-PHP CMS - 'article.php' SQL Injection
CVE-2008-4142webappsphp
SQL injection vulnerability in article.php in E-Php CMS allows remote attackers to execute arbitrary SQL commands via th
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.