Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.772exploits catalogados
35.760CVEs con explotación pública
24.695probados en laboratorio
22.523 exploits
Referência
CVE-2020-0986
CVE-2020-0986HIGHbajo ataque
An elevation of privilege vulnerability exists when the Windows kernel fails to properly handle objects in memory, aka '
76RIESGO
abrir
Referência
CVE-2018-11311
A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attack
28RIESGO
abrir
ReferênciaVexDay Proof
DigitalHive 2.0 RC2 - 'user_id' SQL Injection
CVE-2008-0290webappsphp
Multiple SQL injection vulnerabilities in Digital Hive 2.0 RC2 and earlier allow (1) remote attackers to execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
RichStrong CMS - 'cat' SQL Injection
CVE-2008-0291webappsasp
SQL injection vulnerability in showproduct.asp in RichStrong CMS allows remote attackers to execute arbitrary SQL comman
23RIESGO
abrir
Referência
CVE-2018-8139
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft
35RIESGO
abrir
Referência
CVE-2017-12965
Session fixation vulnerability in Apache2Triad 1.5.4 allows remote attackers to hijack web sessions via the PHPSESSID pa
28RIESGO
abrir
Referência
CVE-2015-8352
Directory traversal vulnerability in Zen Cart 1.5.4 allows remote attackers to include and execute arbitrary local files
28RIESGO
abrir
Referência
CVE-2019-3778
Open Redirect in spring-security-oauth2
28RIESGO
abrir
Referência
CVE-2013-7051
D-Link DIR-100 4.03B07: cli.cgi security bypass due to failure to check authentication parameters
28RIESGO
abrir
Referência
CVE-2018-0491
A use-after-free issue was discovered in Tor 0.3.2.x before 0.3.2.10. It allows remote attackers to cause a denial of se
28RIESGO
abrir
Referência
CVE-2020-25790
Typesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archi
28RIESGO
abrir
Referência
CVE-2020-25790
Typesetter CMS 5.x through 5.1 allows admins to upload and execute arbitrary PHP code via a .php file inside a ZIP archi
28RIESGO
abrir
Referência
CVE-2016-0793
Incomplete blacklist vulnerability in the servlet filter restriction mechanism in WildFly (formerly JBoss Application Se
28RIESGO
abrir
ReferênciaVexDay Proof
FaScript FaName 1.0 - SQL Injection
CVE-2008-0328webappsphp
SQL injection vulnerability in page.php in FaScript FaName 1.0 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
Referência
CVE-2025-44823
Nagios Log Server before 2024R1.3.2 allows authenticated users to retrieve cleartext administrative API keys via a /nagi
53RIESGO
abrir
Referência
CVE-2015-2049
Unrestricted file upload vulnerability in D-Link DCS-931L with firmware 1.04 and earlier allows remote authenticated use
50RIESGO
abrir
Referência
CVE-2017-6554
pmmasterd in Quest Privilege Manager before 6.0.0.061, when configured as a policy server, allows remote attackers to wr
28RIESGO
abrir
Referência
CVE-2017-1084
In FreeBSD before 11.2-RELEASE, multiple issues with the implementation of the stack guard-page reduce the protections a
28RIESGO
abrir
Referência
CVE-2017-1084
In FreeBSD before 11.2-RELEASE, multiple issues with the implementation of the stack guard-page reduce the protections a
28RIESGO
abrir
Referência
CVE-2007-0213
Microsoft Exchange Server 2000 SP3, 2003 SP1 and SP2, and 2007 does not properly decode certain MIME encoded e-mails, wh
35RIESGO
abrir
Referência
CVE-2017-6360
QNAP QTS before 4.2.4 Build 20170313 allows attackers to gain administrator privileges and obtain sensitive information
35RIESGO
abrir
Referência
CVE-2019-13605
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.838 to 0.9.8.846, remote attackers can bypass authentication in
28RIESGO
abrir
Referência
CVE-2015-3456
The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a
28RIESGO
abrir
Referência
CVE-2018-9248
FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass via a "Cookie: Name=0admin" header.
28RIESGO
abrir
Referência
CVE-2020-28977
The Canto plugin 1.3.0 for WordPress contains blind SSRF vulnerability. It allows an unauthenticated attacker can make a
28RIESGO
abrir
Referência
CVE-2010-4977
SQL injection vulnerability in menu.php in the Canteen (com_canteen) component 1.0 for Joomla! allows remote attackers t
43RIESGO
abrir
Referência
CVE-2009-2618
SQL injection vulnerability in the Surveys (aka NS-Polls) module in MDPro (MD-Pro) 1.083.x allows remote attackers to ex
23RIESGO
abrir
ReferênciaVexDay Proof
sPHPell 1.01 - Multiple Remote File Inclusions
CVE-2007-3522webappsphp
Multiple PHP remote file inclusion vulnerabilities in sPHPell 1.01 allow remote attackers to execute arbitrary PHP code
35RIESGO
abrir
ReferênciaVexDay Proof
EDraw Office Viewer Component 5.3 - 'FtpDownloadFile()' Remote Buffer Overflow
CVE-2007-5257doswindows
Stack-based buffer overflow in the EDraw.OfficeViewer ActiveX control in officeviewer.ocx in EDraw Office Viewer Compone
28RIESGO
abrir
Referência
CVE-2020-8512
In IceWarp Webmail Server through 11.4.4.1, there is XSS in the /webmail/ color parameter.
43RIESGO
abrir
anteriorpágina 538 / 751siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.