Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.772exploits catalogados
35.760CVEs con explotación pública
24.695probados en laboratorio
22.492 exploits
ReferênciaVexDay Proof
moziloCMS 1.11 - Local File Inclusion / Full Path Disclosure / Cross-Site Scripting
CVE-2009-1369webappsphp
moziloCMS 1.11 allows remote attackers to obtain sensitive information via the (1) gal[] parameter to gallery.php, (2) p
23RIESGO
abrir
Referência
CVE-2016-11021
CVE-2016-11021HIGHbajo ataque
setSystemCommand on D-Link DCS-930L devices before 2.12 allows a remote attacker to execute code via an OS command in th
98RIESGO
abrir
Referência
CVE-2009-2929
Multiple SQL injection vulnerabilities in TGS Content Management 0.x allow remote attackers to execute arbitrary SQL com
23RIESGO
abrir
Referência
CVE-2017-11893
ChakraCore and Microsoft Edge in Windows 10 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execut
35RIESGO
abrir
Referência
CVE-2015-3628
The iControl API in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.0 before 11.5.3 HF2 and 11.6.
50RIESGO
abrir
Referência
CVE-2015-3628
The iControl API in F5 BIG-IP LTM, AFM, Analytics, APM, ASM, Link Controller, and PEM 11.3.0 before 11.5.3 HF2 and 11.6.
50RIESGO
abrir
Referência
CVE-2014-8799
Directory traversal vulnerability in the dp_img_resize function in php/dp-functions.php in the DukaPress plugin before 2
50RIESGO
abrir
Referência
CVE-2015-7645
CVE-2015-7645HIGHbajo ataqueransomware
Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535
83RIESGO
abrir
Referência
CVE-2015-7645
CVE-2015-7645HIGHbajo ataqueransomware
Adobe Flash Player 18.x through 18.0.0.252 and 19.x through 19.0.0.207 on Windows and OS X and 11.x through 11.2.202.535
83RIESGO
abrir
ReferênciaVexDay Proof
pastelcms 0.8.0 - Local File Inclusion / SQL Injection
CVE-2009-1404webappsphp
SQL injection vulnerability in admin.php in PastelCMS 0.8.0, when magic_quotes_gpc is disabled, allows remote attackers
23RIESGO
abrir
Referência
CVE-2018-8355
A remote code execution vulnerability exists in the way the scripting engine handles objects in memory in Microsoft brow
35RIESGO
abrir
Referência
CVE-2017-12477
It was discovered that the bpserverd proprietary protocol in Unitrends Backup (UB) before 10.0.0, as invoked through xin
50RIESGO
abrir
ReferênciaVexDay Proof
PHPVID 0.9.9 - 'categories_type.php' SQL Injection
CVE-2007-3610webappsphp
SQL injection vulnerability in categories_type.php in phpVID 0.9.9 allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
Referência
CVE-2017-9833
/cgi-bin/wapopen in Boa 0.94.14rc21 allows the injection of "../.." using the FILECAMERA variable (sent by GET) to read
50RIESGO
abrir
Referência
CVE-2018-8353
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
35RIESGO
abrir
Referência
CVE-2009-3056
PHP remote file inclusion vulnerability in include/engine/content/elements/menu.php in KingCMS 0.6.0 allows remote attac
23RIESGO
abrir
Referência
CVE-2017-8548
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to obtain
35RIESGO
abrir
Referência
CVE-2013-5014
The management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.7405.1424 and 12.1 before 12.1.40
50RIESGO
abrir
Referência
CVE-2013-5014
The management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.7405.1424 and 12.1 before 12.1.40
50RIESGO
abrir
Referência
CVE-2012-6433
Cross-site request forgery (CSRF) vulnerability in e107_admin/newspost.php in e107 1.0.1 allows remote attackers to hija
23RIESGO
abrir
Referência
CVE-2017-14494
dnsmasq before 2.78, when configured as a relay, allows remote attackers to obtain sensitive memory information via vect
35RIESGO
abrir
Referência
CVE-2018-16858
It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could
68RIESGO
abrir
Referência
CVE-2018-16858
It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could
68RIESGO
abrir
Referência
CVE-2018-12613
An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute
60RIESGO
abrir
Referência
CVE-2009-3058
Stack-based buffer overflow in akPlayer 1.9.0 allows remote attackers to execute arbitrary code via a long string in a .
23RIESGO
abrir
Referência
CVE-2015-0802
Mozilla Firefox before 37.0 relies on docshell type information instead of page principal information for Window.webidl
50RIESGO
abrir
Referência
CVE-2013-3628
Zabbix 2.0.9 has an Arbitrary Command Execution Vulnerability
50RIESGO
abrir
Referência
CVE-2008-4687
manage_proj_page.php in Mantis before 1.1.4 allows remote authenticated users to execute arbitrary code via a sort param
50RIESGO
abrir
Referência
Flowise 1.6.5 - Authentication Bypass
CVE-2024-31621HIGHwebappstypescript
An issue in FlowiseAI Inc Flowise v.1.6.2 and before allows a remote attacker to execute arbitrary code via a crafted sc
68RIESGO
abrir
ReferênciaVexDay Proof
Sitellite CMS 4.2.12 - '559668.php' Remote File Inclusion
CVE-2007-3228webappsphp
PHP remote file inclusion vulnerability in saf/lib/PEAR/PhpDocumentor/Documentation/tests/bug-559668.php in Sitellite CM
35RIESGO
abrir
anteriorpágina 525 / 750siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.