Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
22.936 exploits
Referência
CVE-2008-5180
Microsoft Communicator, and Communicator in Microsoft Office 2010 beta, allows remote attackers to cause a denial of ser
45RIESGO
abrir
ReferênciaVexDay Proof
Integramod 1.4.x - Insecure Directory Download Database
CVE-2008-4183webappsphp
IntegraMOD 1.4.x stores sensitive information under the web root with insufficient access control, which allows remote a
23RIESGO
abrir
Referência
CVE-2016-3088
CVE-2016-3088CRITICALbajo ataque
The Fileserver web application in Apache ActiveMQ 5.x before 5.14.0 allows remote attackers to upload and execute arbitr
100RIESGO
abrir
Referência
CVE-2013-7409
Buffer overflow in ALLPlayer 5.6.2 through 5.8.1 allows remote attackers to cause a denial of service (crash) and possib
50RIESGO
abrir
Referência
CVE-2025-2747
CVE-2025-2747CRITICALbajo ataque
Kentico Xperience <= 13.0.178 Staging Sync Server None Password Type Authentication Bypass
100RIESGO
abrir
ReferênciaVexDay Proof
SerWeb 0.9.4 - 'load_lang.php' Remote File Inclusion
CVE-2007-3358webappsphp
PHP remote file inclusion vulnerability in html/load_lang.php in SerWeb 0.9.6 and earlier allows remote attackers to exe
35RIESGO
abrir
ReferênciaVexDay Proof
TotalCalendar 2.4 - 'Include' Local File Inclusion
CVE-2009-1406webappsphp
Directory traversal vulnerability in cms_detect.php in TotalCalendar 2.4 allows remote attackers to include and execute
23RIESGO
abrir
Referência
CVE-2013-7409
Buffer overflow in ALLPlayer 5.6.2 through 5.8.1 allows remote attackers to cause a denial of service (crash) and possib
50RIESGO
abrir
Referência
CVE-2013-7409
Buffer overflow in ALLPlayer 5.6.2 through 5.8.1 allows remote attackers to cause a denial of service (crash) and possib
50RIESGO
abrir
ReferênciaVexDay Proof
DVD X Player 4.1 Professional - '.PLF' File Buffer Overflow
CVE-2007-3068localwindows
Stack-based buffer overflow in DVD X Player 4.1 Professional allows remote attackers to execute arbitrary code via a PLF
50RIESGO
abrir
Referência
CVE-2012-6430
Cross-site scripting (XSS) vulnerability in Open Solution Quick.Cms 5.0 and Quick.Cart 6.0, possibly as downloaded befor
23RIESGO
abrir
Referência
CVE-2025-2747
CVE-2025-2747CRITICALbajo ataque
Kentico Xperience <= 13.0.178 Staging Sync Server None Password Type Authentication Bypass
100RIESGO
abrir
Referência
CVE-2018-0775
Microsoft Edge in Windows 10 1709 allows an attacker to execute arbitrary code in the context of the current user, due t
35RIESGO
abrir
Referência
CVE-2018-0774
Microsoft Edge in Windows 10 1709 allows an attacker to execute arbitrary code in the context of the current user, due t
35RIESGO
abrir
Referência
CVE-2019-18426
CVE-2019-18426HIGHbajo ataque
A vulnerability in WhatsApp Desktop versions prior to 0.3.9309 when paired with WhatsApp for iPhone versions prior to 2.
83RIESGO
abrir
Referência
AirDrop 2.0 - Denial of Service (DoS)
CVE-2019-9832dosandroid
The AirDrop application through 2.0 for Android allows remote attackers to cause a denial of service via a client that m
23RIESGO
abrir
Referência
CVE-2009-3052
SQL injection vulnerability in root/includes/prime_quick_style.php in the Prime Quick Style addon before 1.2.3 for phpBB
23RIESGO
abrir
Referência
CVE-2010-1554
Stack-based buffer overflow in getnnmdata.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows r
50RIESGO
abrir
Referência
CVE-2016-6662
Oracle MySQL through 5.5.52, 5.6.x through 5.6.33, and 5.7.x through 5.7.15; MariaDB before 5.5.51, 10.0.x before 10.0.2
35RIESGO
abrir
Referência
NetData 1.13.0 - HTML Injection
CVE-2019-9834webappsmultiple
The Netdata web application through 1.13.0 allows remote attackers to inject their own malicious HTML code into an impor
23RIESGO
abrir
Referência
CVE-2017-9833
/cgi-bin/wapopen in Boa 0.94.14rc21 allows the injection of "../.." using the FILECAMERA variable (sent by GET) to read
50RIESGO
abrir
Referência
CVE-2018-8353
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
35RIESGO
abrir
Referência
CVE-2009-3056
PHP remote file inclusion vulnerability in include/engine/content/elements/menu.php in KingCMS 0.6.0 allows remote attac
23RIESGO
abrir
Referência
CVE-2019-9879
The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever
50RIESGO
abrir
Referência
CVE-2017-8548
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to obtain
35RIESGO
abrir
Referência
CVE-2013-5014
The management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.7405.1424 and 12.1 before 12.1.40
50RIESGO
abrir
Referência
CVE-2013-5014
The management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.7405.1424 and 12.1 before 12.1.40
50RIESGO
abrir
Referência
CVE-2012-6433
Cross-site request forgery (CSRF) vulnerability in e107_admin/newspost.php in e107 1.0.1 allows remote attackers to hija
23RIESGO
abrir
Referência
CVE-2017-14494
dnsmasq before 2.78, when configured as a relay, allows remote attackers to obtain sensitive memory information via vect
35RIESGO
abrir
Referência
CVE-2018-16858
It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could
68RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.