Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.620exploits catalogados
35.647CVEs con explotación pública
24.695probados en laboratorio
22.429 exploits
Referência
CVE-2016-3074
Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of
35RIESGO
abrir
ReferênciaVexDay Proof
Elkagroup Image Gallery 1.0 - Arbitrary File Upload
CVE-2009-1446webappsphp
Unrestricted file upload vulnerability in upload.php in Elkagroup Image Gallery 1.0 allows remote authenticated users to
23RIESGO
abrir
ReferênciaVexDay Proof
SMA-DB 0.3.13 - Multiple Remote File Inclusions
CVE-2009-1452webappsphp
Multiple PHP remote file inclusion vulnerabilities in theme/format.php in SMA-DB 0.3.13 allow remote attackers to execut
23RIESGO
abrir
Referência
CVE-2012-2576
SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Prof
50RIESGO
abrir
Referência
CVE-2009-3260
Cross-site scripting (XSS) vulnerability in LiveStreet 0.2 allows remote attackers to inject arbitrary web script or HTM
23RIESGO
abrir
Referência
CVE-2025-34030
sar2html OS Command Injection
75RIESGO
abrir
ReferênciaVexDay Proof
Password Protector SD 1.3.1 - Insecure Cookie Handling
CVE-2009-2003webappsphp
Ascad Networks Password Protector SD 1.3.1 allows remote attackers to bypass authentication and gain administrative acce
23RIESGO
abrir
ReferênciaVexDay Proof
Virtue Shopping Mall - 'cid' SQL Injection
CVE-2009-2016webappsphp
SQL injection vulnerability in products.php in Virtue Shopping Mall allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
Referência
CVE-2008-2463
The Microsoft Office Snapshot Viewer ActiveX control in snapview.ocx 10.0.5529.0, as distributed in the standalone Snaps
50RIESGO
abrir
Referência
CVE-2017-17562
CVE-2017-17562HIGHbajo ataque
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. T
100RIESGO
abrir
Referência
CVE-2018-6065
CVE-2018-6065HIGHbajo ataque
Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Ch
83RIESGO
abrir
ReferênciaVexDay Proof
EDraw Office Viewer Component 5.1 - HttpDownloadFile() Insecure Method
CVE-2007-4420remotewindows
Absolute path traversal vulnerability in a certain ActiveX control in officeviewer.ocx 5.1.199.1 in EDraw Office Viewer
23RIESGO
abrir
Referência
CVE-2021-33393
lfs/backup in IPFire 2.25-core155 does not ensure that /var/ipfire/backup/bin/backup.pl is owned by the root account. It
50RIESGO
abrir
ReferênciaVexDay Proof
Virtue Book Store - 'cid' SQL Injection
CVE-2009-2017webappsphp
SQL injection vulnerability in products.php in Virtue Book Store allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
Referência
CVE-2015-1503
Multiple directory traversal vulnerabilities in IceWarp Mail Server before 11.2 allow remote attackers to read arbitrary
50RIESGO
abrir
Referência
CVE-2015-1503
Multiple directory traversal vulnerabilities in IceWarp Mail Server before 11.2 allow remote attackers to read arbitrary
50RIESGO
abrir
ReferênciaVexDay Proof
Virtue Classifieds - 'category' SQL Injection
CVE-2009-2021webappsphp
SQL injection vulnerability in search.php in Virtue Classifieds allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
ReferênciaVexDay Proof
Shop Script Pro 2.12 - SQL Injection
CVE-2009-2023webappsphp
SQL injection vulnerability in index.php in Shop-Script Pro 2.12, when magic_quotes_gpc is disabled, allows remote attac
23RIESGO
abrir
ReferênciaVexDay Proof
yogurt 0.3 - Cross-Site Scripting / SQL Injection
CVE-2009-2034webappsphp
SQL injection vulnerability in writemessage.php in Yogurt 0.3, when register_globals is enabled, allows remote authentic
23RIESGO
abrir
Referência
CVE-2018-12634
CirCarLife Scada before 4.3 allows remote attackers to obtain sensitive information via a direct request for the html/lo
50RIESGO
abrir
Referência
CVE-2019-10475
A reflected cross-site scripting vulnerability in Jenkins build-metrics Plugin allows attackers to inject arbitrary HTML
50RIESGO
abrir
Referência
CVE-2016-6515
The auth_password function in auth-passwd.c in sshd in OpenSSH before 7.3 does not limit password lengths for password a
35RIESGO
abrir
ReferênciaVexDay Proof
elvin bts 1.2.0 - Multiple Vulnerabilities
CVE-2009-2129webappsphp
Cross-site request forgery (CSRF) vulnerability in login.php in Elvin 1.2.0 allows remote attackers to hijack the authen
23RIESGO
abrir
Referência
CVE-2016-3078
Multiple integer overflows in php_zip.c in the zip extension in PHP before 7.0.6 allow remote attackers to cause a denia
35RIESGO
abrir
Referência
CVE-2017-1000170
jqueryFileTree 2.1.5 and older Directory Traversal
50RIESGO
abrir
Referência
CVE-2011-4722
Directory traversal vulnerability in the TFTP Server 1.0.0.24 in Ipswitch WhatsUp Gold allows remote attackers to read a
50RIESGO
abrir
Referência
CVE-2014-2850
The network interface configuration page (netinterface) in Sophos Web Appliance before 3.8.2 allows remote administrator
50RIESGO
abrir
Referência
CVE-2018-14847
CVE-2018-14847CRITICALbajo ataque
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated
100RIESGO
abrir
Referência
CVE-2017-0101
CVE-2017-0101HIGHbajo ataqueransomware
The kernel-mode drivers in Transaction Manager in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2; Windows 7
83RIESGO
abrir
Referência
CVE-2014-5377
ReadUsersFromMasterServlet in ManageEngine DeviceExpert before 5.9 build 5981 allows remote attackers to obtain user acc
50RIESGO
abrir
anteriorpágina 505 / 748siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.