Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
22.936 exploits
Referência
CVE-2017-5972
The TCP stack in the Linux kernel 3.x does not properly implement a SYN cookie protection mechanism for the case of a fa
28RIESGO
abrir
Referência
CVE-2016-4806
Web2py versions 2.14.5 and below was affected by Local File Inclusion vulnerability, which allows a malicious intended u
28RIESGO
abrir
Referência
CVE-2016-4806
Web2py versions 2.14.5 and below was affected by Local File Inclusion vulnerability, which allows a malicious intended u
28RIESGO
abrir
Referência
CVE-2010-2917
Multiple cross-site scripting (XSS) vulnerabilities in index.php in AJ Square AJ Article 3.0 allow remote attackers to i
23RIESGO
abrir
Referência
CVE-2014-10011
Stack-based buffer overflow in UltraCamLib in the UltraCam ActiveX Control (UltraCamX.ocx) for the TRENDnet SecurView ca
28RIESGO
abrir
Referência
CVE-2021-33904
In Accela Civic Platform through 21.1, the security/hostSignon.do parameter servProvCode is vulnerable to XSS. NOTE: The
38RIESGO
abrir
Referência
CVE-2017-17417
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Quest NetVault Backu
23RIESGO
abrir
Referência
CVE-2021-34370
Accela Civic Platform through 20.1 allows ssoAdapter/logoutAction.do successURL XSS. NOTE: the vendor states "there are
38RIESGO
abrir
Referência
Vtiger CRM 7.1.0 - Remote Code Execution
CVE-2019-5009webappsphp
Vtiger CRM 7.1.0 before Hotfix2 allows uploading files with the extension "php3" in the logo upload field, if the upload
23RIESGO
abrir
Referência
CVE-2018-17961
Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving err
23RIESGO
abrir
Referência
CVE-2013-6283
VideoLAN VLC Media Player 2.0.8 and earlier allows remote attackers to cause a denial of service (crash) and possibly ex
23RIESGO
abrir
Referência
CVE-2009-4958
SQL injection vulnerability in video.php in EMO Breeder Manager (aka EMO Breader Manager) allows remote attackers to exe
23RIESGO
abrir
Referência
CVE-2014-5109
SQL injection vulnerability in maint/modules/endpointcfg/endpoint_generic.php in Fonality trixbox allows remote attacker
23RIESGO
abrir
Referência
CVE-2012-3448
Unspecified vulnerability in Ganglia Web before 3.5.1 allows remote attackers to execute arbitrary PHP code via unknown
23RIESGO
abrir
Referência
CVE-2010-1476
Directory traversal vulnerability in the AlphaUserPoints (com_alphauserpoints) component 1.5.5 for Joomla! allows remote
38RIESGO
abrir
Referência
CVE-2010-1476
Directory traversal vulnerability in the AlphaUserPoints (com_alphauserpoints) component 1.5.5 for Joomla! allows remote
38RIESGO
abrir
Referência
CVE-2016-0862
General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authentica
23RIESGO
abrir
Referência
CVE-2016-0862
General Electric (GE) Industrial Solutions UPS SNMP/Web Adapter devices with firmware before 4.8 allow remote authentica
23RIESGO
abrir
Referência
CVE-2018-11523
upload.php on NUUO NVRmini 2 devices allows Arbitrary File Upload, such as upload of .php files.
23RIESGO
abrir
Referência
CVE-2026-6591
ComfyUI LoadImage Node folder_paths.py folder_paths.get_annotated_filepath path traversal
33RIESGO
abrir
Referência
CVE-2009-4973
SQL injection vulnerability in rss.php in TotalCalendar 2.4 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir
Referência
CVE-2019-12461
Web Port 1.19.1 allows XSS via the /log type parameter.
38RIESGO
abrir
ReferênciaVexDay Proof
VidiScript (Avatar) - Arbitrary File Upload
CVE-2008-6518webappsphp
Unrestricted file upload vulnerability in the profile feature in VidiScript allows registered remote authenticated users
23RIESGO
abrir
Referência
CVE-2013-7091
Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zim
60RIESGO
abrir
ReferênciaVexDay Proof
Really Simple PHP and Ajax (RSPA) 2007-03-23 - Remote File Inclusion
CVE-2007-1982webappsphp
Multiple PHP remote file inclusion vulnerabilities in Really Simple PHP and Ajax (RSPA) 2007-03-23 and earlier allow rem
23RIESGO
abrir
Referência
CVE-2015-5161
The Zend_Xml_Security::scan in ZendXml before 1.0.1 and Zend Framework before 1.12.14, 2.x before 2.4.6, and 2.5.x befor
23RIESGO
abrir
Referência
CVE-2015-5161
The Zend_Xml_Security::scan in ZendXml before 1.0.1 and Zend Framework before 1.12.14, 2.x before 2.4.6, and 2.5.x befor
23RIESGO
abrir
Referência
CVE-2018-11479
The VPN component in Windscribe 1.81 uses the OpenVPN client for connections. Also, it creates a WindScribeService.exe s
38RIESGO
abrir
Referência
CVE-2025-34077
WordPress Pie Register Plugin ≤ 3.7.1.4 Authentication Bypass RCE
68RIESGO
abrir
Referência
CVE-2010-3124
Untrusted search path vulnerability in bin/winvlc.c in VLC Media Player 1.1.3 and earlier allows local users, and possib
28RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.