Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
22.936 exploits
ReferênciaVexDay Proof
AdMan 1.1.20070907 - 'campaignId' SQL Injection
CVE-2008-6156webappsphp
SQL injection vulnerability in editCampaign.php in AdMan 1.1.20070907 allows remote authenticated users to execute arbit
23RIESGO
abrir
ReferênciaVexDay Proof
Amaya 11.1 - W3C Editor/Browser 'defer' Remote Stack Overflow
CVE-2009-1209remotewindows
Stack-based buffer overflow in W3C Amaya Web Browser 11.1 allows remote attackers to execute arbitrary code via a script
28RIESGO
abrir
Referência
CVE-2016-11021
CVE-2016-11021HIGHbajo ataque
setSystemCommand on D-Link DCS-930L devices before 2.12 allows a remote attacker to execute code via an OS command in th
98RIESGO
abrir
Referência
CVE-2009-2929
Multiple SQL injection vulnerabilities in TGS Content Management 0.x allow remote attackers to execute arbitrary SQL com
23RIESGO
abrir
Referência
CVE-2017-11893
ChakraCore and Microsoft Edge in Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execut
35RIESGO
abrir
Referência
CVE-2015-3628
The iControl API in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.0 before 11.5.3 HF2 and 11.6.
50RIESGO
abrir
Referência
CVE-2015-3628
The iControl API in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.0 before 11.5.3 HF2 and 11.6.
50RIESGO
abrir
Referência
CVE-2014-8799
Directory traversal vulnerability in the dp_img_resize function in php/dp-functions.php in the DukaPress plugin before 2
50RIESGO
abrir
ReferênciaVexDay Proof
ProArcadeScript 1.3 - 'random' SQL Injection
CVE-2008-4173webappsphp
SQL injection vulnerability in ProArcadeScript 1.3 allows remote attackers to execute arbitrary SQL commands via the ran
23RIESGO
abrir
Referência
CVE-2019-9213
In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which make
38RIESGO
abrir
ReferênciaVexDay Proof
Pre Real Estate Listings - 'search.php' SQL Injection
CVE-2008-4177webappsphp
SQL injection vulnerability in search.php in Pre Real Estate Listings allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
Referência
CVE-2019-9213
In the Linux kernel before 4.20.14, expand_downwards in mm/mmap.c lacks a check for the mmap minimum address, which make
38RIESGO
abrir
Referência
CVE-2015-7645
CVE-2015-7645HIGHbajo ataqueransomware
Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535
83RIESGO
abrir
Referência
CVE-2015-7645
CVE-2015-7645HIGHbajo ataqueransomware
Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535
83RIESGO
abrir
Referência
Bolt CMS 3.6.4 - Cross-Site Scripting
CVE-2019-9553webappsphp
Bolt 3.6.4 has XSS via the slug, teaser, or title parameter to editcontent/pages, a related issue to CVE-2017-11128 and
23RIESGO
abrir
Referência
CVE-2018-8355
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft brow
35RIESGO
abrir
Referência
CVE-2017-12477
It was discovered that the bpserverd proprietary protocol in Unitrends Backup (UB) before 10.0.0, as invoked through xin
50RIESGO
abrir
Referência
Craft CMS 3.1.12 Pro - Cross-Site Scripting
CVE-2019-9554webappsphp
In the 3.1.12 Pro version of Craft CMS, XSS has been discovered in the header insertion field when adding source code at
23RIESGO
abrir
ReferênciaVexDay Proof
PHPVID 0.9.9 - 'categories_type.php' SQL Injection
CVE-2007-3610webappsphp
SQL injection vulnerability in categories_type.php in phpVID 0.9.9 allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component RWCards 3.0.11 - Local File Inclusion
CVE-2008-6172webappsphp
Directory traversal vulnerability in captcha/captcha_image.php in the RWCards (com_rwcards) 3.0.11 component for Joomla!
43RIESGO
abrir
ReferênciaVexDay Proof
pastelcms 0.8.0 - Local File Inclusion / SQL Injection
CVE-2009-1404webappsphp
SQL injection vulnerability in admin.php in PastelCMS 0.8.0, when magic_quotes_gpc is disabled, allows remote attackers
23RIESGO
abrir
Referência
CVE-2017-6077
CVE-2017-6077CRITICALbajo ataque
ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitra
90RIESGO
abrir
Referência
eBrigade ERP 4.5 - Arbitrary File Download
CVE-2019-9622webappsphp
eBrigade through 4.5 allows Arbitrary File Download via ../ directory traversal in the showfile.php file parameter, as d
23RIESGO
abrir
ReferênciaVexDay Proof
Downline Goldmine newdownlinebuilder - SQL Injection
CVE-2008-4178webappsphp
SQL injection vulnerability in tr.php in DownlineGoldmine Special Category Addon, Downline Builder Pro, New Addon, and D
23RIESGO
abrir
Referência
Core FTP Server FTP / SFTP Server v2 Build 674 - 'MDTM' Directory Traversal
CVE-2019-9649doswindows
An issue was discovered in the SFTP Server component in Core FTP 2.0 Build 674. Using the MDTM FTP command, a remote att
28RIESGO
abrir
Referência
CVE-2009-3023
Buffer overflow in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 6.0 allows remote authen
60RIESGO
abrir
ReferênciaVexDay Proof
Downline Goldmine paidversion - SQL Injection
CVE-2008-4178webappsphp
SQL injection vulnerability in tr.php in DownlineGoldmine Special Category Addon, Downline Builder Pro, New Addon, and D
23RIESGO
abrir
Referência
CVE-2011-0654
Integer underflow in the BowserWriteErrorLogEntry function in the Common Internet File System (CIFS) browser service in
50RIESGO
abrir
Referência
CVE-2017-11809
ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker
35RIESGO
abrir
Referência
CVE-2019-9692
class.showtime2_image.php in CMS Made Simple (CMSMS) before 2.2.10 does not ensure that a watermark file has a standard
50RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.