Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.772exploits catalogados
35.760CVEs con explotación pública
24.695probados en laboratorio
22.523 exploits
Referência
CVE-2012-4886
Stack-based buffer overflow in wpsio.dll in Kingsoft WPS Office 2012 possibly 8.1.0.3238 allows remote attackers to exec
28RIESGO
abrir
ReferênciaVexDay Proof
nweb2fax 0.2.7 - Multiple Vulnerabilities
CVE-2008-6668webappsphp
Multiple directory traversal vulnerabilities in nweb2fax 0.2.7 and earlier allow remote attackers to read arbitrary file
43RIESGO
abrir
Referência
CVE-2020-35749
Directory traversal vulnerability in class-simple_job_board_resume_download_handler.php in the Simple Board Job plugin 2
50RIESGO
abrir
Referência
CVE-2018-0744
The Windows kernel in Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Wi
28RIESGO
abrir
Referência
CVE-2021-40378
An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. /cgi-bin/support/killp
28RIESGO
abrir
Referência
CVE-2012-4409
Stack-based buffer overflow in the check_file_head function in extra.c in mcrypt 2.6.8 and earlier allows user-assisted
28RIESGO
abrir
Referência
CVE-2009-4669
Multiple SQL injection vulnerabilities in RoomPHPlanning 1.6 allow remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir
ReferênciaVexDay Proof
BS.Player 2.34 - '.bsl' Universal Overwrite (SEH)
CVE-2009-1068localwindows
Stack-based buffer overflow in BS.Player (bsplayer) 2.32 Build 975 Free and 2.34 Build 980 PRO and earlier allows remote
28RIESGO
abrir
Referência
CVE-2018-18557
LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3
28RIESGO
abrir
Referência
CVE-2017-17672
In vBulletin through 5.3.x, there is an unauthenticated deserialization vulnerability that leads to arbitrary file delet
28RIESGO
abrir
Referência
CVE-2015-7258
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated users to obtain
28RIESGO
abrir
Referência
CVE-2015-7258
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated users to obtain
28RIESGO
abrir
ReferênciaVexDay Proof
KingSoft - 'UpdateOcx2.dll SetUninstallName()' Heap Overflow (PoC)
CVE-2008-1307doswindows
Heap-based buffer overflow in the KUpdateObj2 Class ActiveX control in UpdateOcx2.dll in Beijing KingSoft Antivirus Onli
28RIESGO
abrir
Referência
CVE-2017-13861
An issue was discovered in certain Apple products. iOS before 11.2 is affected. tvOS before 11.2 is affected. watchOS be
43RIESGO
abrir
Referência
CVE-2013-6987
Multiple directory traversal vulnerabilities in the FileBrowser components in Synology DiskStation Manager (DSM) before
28RIESGO
abrir
ReferênciaVexDay Proof
Pluck CMS 4.6.2 - 'langpref' Local File Inclusion
CVE-2009-1765webappsphp
Multiple directory traversal vulnerabilities in pluck 4.6.2, when register_globals is enabled, allow remote attackers to
28RIESGO
abrir
Referência
CVE-2009-4680
SQL injection vulnerability in search.php in phpDirectorySource 1.x allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
Referência
CVE-2022-24715
Arbitrary code execution for authenticated users in Icinga Web 2
46RIESGO
abrir
ReferênciaVexDay Proof
BitchX 1.1 Final - MODE Remote Heap Overflow
CVE-2007-4584remotelinux
Stack-based buffer overflow in BitchX 1.1 Final allows remote IRC servers to execute arbitrary code via a long string in
28RIESGO
abrir
Referência
CVE-2014-7186
The redirection implementation in parse.y in GNU Bash through 4.3 bash43-026 allows remote attackers to cause a denial o
35RIESGO
abrir
Referência
CVE-2013-5220
goform/login on the HOT HOTBOX router with software 2.1.11 allows remote attackers to cause a denial of service (device
23RIESGO
abrir
Referência
CVE-2009-3663
Format string vulnerability in the h_readrequest function in http.c in httpdx Web Server 1.4 allows remote attackers to
28RIESGO
abrir
Referência
CVE-2010-5300
Stack-based buffer overflow in Jzip 1.3 through 2.0.0.132900 allows remote attackers to cause a denial of service (crash
28RIESGO
abrir
Referência
CVE-2020-24223
Mara CMS 7.5 allows cross-site scripting (XSS) in contact.php via the theme or pagetheme parameters.
43RIESGO
abrir
Referência
CVE-2013-5318
SQL injection vulnerability in Ginkgo CMS 5.0 allows remote attackers to execute arbitrary SQL commands via the rang par
23RIESGO
abrir
Referência
CVE-2010-1306
Directory traversal vulnerability in the Picasa (com_joomlapicasa2) component 2.0 and 2.0.5 for Joomla! allows remote at
43RIESGO
abrir
Referência
CVE-2010-1306
Directory traversal vulnerability in the Picasa (com_joomlapicasa2) component 2.0 and 2.0.5 for Joomla! allows remote at
43RIESGO
abrir
ReferênciaVexDay Proof
aflog 1.01 - Cross-Site Scripting / SQL Injection
CVE-2008-0397webappsphp
Multiple SQL injection vulnerabilities in aflog 1.01, and possibly earlier versions, allow remote attackers to execute a
23RIESGO
abrir
Referência
Centos WebPanel 7 - 'term' SQL Injection
CVE-2020-10230webappslinux
CentOS-WebPanel.com (aka CWP) CentOS Web Panel (for CentOS 6 and 7) allows SQL Injection via the /cwp_{SESSION_HASH}/adm
28RIESGO
abrir
Referência
CVE-2025-14705
Shiguangwu sgwbox N3 SHARESERVER Feature command injection
53RIESGO
abrir
anteriorpágina 540 / 751siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.