Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.772exploits catalogados
35.760CVEs con explotación pública
24.695probados en laboratorio
22.492 exploits
Referência
CVE-2009-3196
Cross-site scripting (XSS) vulnerability in index.php in JCE-Tech PHP Video Script allows remote attackers to inject arb
23RIESGO
abrir
Referência
CVE-2013-2010
WordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability
60RIESGO
abrir
Referência
CVE-2009-3203
SQL injection vulnerability in store.php in AJ Auction Pro OOPD 2.x allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
Referência
CVE-2009-3205
SQL injection vulnerability in main.php in CBAuthority allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir
Referência
CVE-2015-1487
The management console in Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP1 allows remote authenticat
50RIESGO
abrir
Referência
CVE-2016-3316
Microsoft Word 2013 SP1, 2013 RT SP1, 2016, and 2016 for Mac allow remote attackers to execute arbitrary code via a craf
35RIESGO
abrir
Referência
CVE-2020-11027
Password reset links invalidation issue in WordPress
38RIESGO
abrir
ReferênciaVexDay Proof
jetAudio 7.x - ActiveX 'DownloadFromMusicStore()' Code Execution
CVE-2007-4983remotewindows
Directory traversal vulnerability in the JetAudio.Interface.1 ActiveX control in JetFlExt.dll in jetAudio 7.0.3 Basic an
35RIESGO
abrir
Referência
CVE-2018-7719
Acrolinx Server before 5.2.5 on Windows allows Directory Traversal.
50RIESGO
abrir
Referência
CVE-2019-15276
Cisco Wireless LAN Controller HTTP Parsing Engine Denial of Service Vulnerability
53RIESGO
abrir
Referência
CVE-2023-6875
POST SMTP Mailer – Email log, Delivery Failure Notifications and Best Mail SMTP for WordPress <= 2.8.7 - Authorization Bypass via type connect-app API
85RIESGO
abrir
Referência
CVE-2016-0956
The Servlets Post component 2.3.6 in Apache Sling, as used in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0, allows r
35RIESGO
abrir
Referência
CVE-2016-0956
The Servlets Post component 2.3.6 in Apache Sling, as used in Adobe Experience Manager 5.6.1, 6.0.0, and 6.1.0, allows r
35RIESGO
abrir
Referência
CVE-2013-5036
The Square Squash allows remote attackers to execute arbitrary code via a YAML document in the (1) namespace parameter t
50RIESGO
abrir
Referência
CVE-2017-11903
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Se
35RIESGO
abrir
Referência
CVE-2014-6446
The Infusionsoft Gravity Forms plugin 1.5.3 through 1.5.10 for WordPress does not properly restrict access, which allows
50RIESGO
abrir
Referência
CVE-2023-30145
Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats para
60RIESGO
abrir
ReferênciaVexDay Proof
LightOpenCMS 0.1 - 'id' SQL Injection
CVE-2009-1766webappsphp
SQL injection vulnerability in index.php in LightOpenCMS 0.1 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
Referência
CVE-2010-4749
Multiple cross-site scripting (XSS) vulnerabilities in BLOG:CMS 4.2.1.e, and possibly earlier, allow remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component AlphaUserPoints - SQL Injection
CVE-2009-3342webappsphp
SQL injection vulnerability in frontend/assets/ajax/checkusername.php in the AlphaUserPoints (com_alphauserpoints) compo
23RIESGO
abrir
Referência
CVE-2012-6530
Stack-based buffer overflow in Sysax Multi Server before 5.52, when HTTP is enabled, allows remote authenticated users w
50RIESGO
abrir
Referência
CVE-2018-10201
An issue was discovered in NcMonitorServer.exe in NC Monitor Server in NComputing vSpace Pro 10 and 11. It is possible t
50RIESGO
abrir
ReferênciaVexDay Proof
Ubuntu 6.06 - DHCPd Remote Denial of Service
CVE-2007-5365dosmultiple
Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some othe
45RIESGO
abrir
Referência
CVE-2020-12029
Rockwell Automation FactoryTalk View SE
75RIESGO
abrir
Referência
CVE-2009-3712
Multiple SQL injection vulnerabilities in Ebay Clone 2009 allow remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir
ReferênciaVexDay Proof
my-colex 1.4.2 - Authentication Bypass / SQL Injection / Cross-Site Scripting
CVE-2009-1810webappsphp
Multiple SQL injection vulnerabilities in myColex 1.4.2 allow remote attackers to execute arbitrary SQL commands via (1)
23RIESGO
abrir
Referência
CVE-2009-2777
SQL injection vulnerability in visitor/view.php in GarageSales Script allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
ReferênciaVexDay Proof
phpBB Plus 1.53 - 'phpbb_root_path' Remote File Inclusion
CVE-2007-5009webappsphp
PHP remote file inclusion vulnerability in language/lang_german/lang_main_album.php in phpBB Plus 1.53, and 1.53a before
35RIESGO
abrir
ReferênciaVexDay Proof
TikiWiki 1.9.8 - Remote PHP Injection
CVE-2007-5423webappsphp
tiki-graph_formula.php in TikiWiki 1.9.8 allows remote attackers to execute arbitrary code via PHP sequences in the f ar
60RIESGO
abrir
Referência
CVE-2020-11698
An issue was discovered in Titan SpamTitan 7.07. Improper input sanitization of the parameter community on the page snmp
60RIESGO
abrir
anteriorpágina 524 / 750siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.