Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.813exploits catalogados
35.788CVEs con explotación pública
24.695probados en laboratorio
22.523 exploits
Referência
CVE-2010-3456
Directory traversal vulnerability in download.php in EnergyScripts (ES) Simple Download 1.0 allows remote attackers to r
23RIESGO
abrir
Referência
CVE-2025-41244
CVE-2025-41244HIGHbajo ataque
VMSA-2025-0015: VMware Aria Operations and VMware Tools updates address multiple vulnerabilities (CVE-2025-41244,CVE-2025-41245, CVE-2025-41246)
71RIESGO
abrir
Referência
CVE-2021-27519
A cross-site scripting (XSS) issue in FUDForum 3.1.0 allows remote attackers to inject JavaScript via index.php in the "
38RIESGO
abrir
Referência
CVE-2016-6512
epan/dissectors/packet-wap.c in Wireshark 2.x before 2.0.5 omits an overflow check in the tvb_get_guintvar function, whi
23RIESGO
abrir
Referência
CVE-2010-0373
SQL injection vulnerability in the libros (com_libros) component for Joomla! allows remote attackers to execute arbitrar
23RIESGO
abrir
Referência
CVE-2010-4769
Directory traversal vulnerability in the Jimtawl (com_jimtawl) component 1.0.2 Joomla! allows remote attackers to read a
38RIESGO
abrir
ReferênciaVexDay Proof
acronis pxe server 2.0.0.1076 - Directory Traversal / Null Pointer
CVE-2008-1411remotewindows
The PXE Server (pxesrv.exe) in Acronis Snap Deploy 2.0.0.1076 and earlier allows remote attackers to cause a denial of s
23RIESGO
abrir
ReferênciaVexDay Proof
PHP Classifieds Script - Remote Database Disclosure
CVE-2008-7080webappsphp
Team PHP PHP Classifieds Script stores sensitive information under the web root with insufficient access control, which
23RIESGO
abrir
ReferênciaVexDay Proof
BuzzyWall 1.3.1 - 'id' Remote File Disclosure
CVE-2008-4759webappsphp
Directory traversal vulnerability in download.php in BuzzyWall 1.3.1 allows remote attackers to read arbitrary local fil
23RIESGO
abrir
Referência
CVE-2010-4783
Multiple cross-site scripting (XSS) vulnerabilities in index.php in PHP Web Scripts Easy Banner Free 2009.05.18, when ma
23RIESGO
abrir
Referência
CVE-2010-4797
Multiple SQL injection vulnerabilities in the log-in form in Truworth Flex Timesheet allow remote attackers to execute a
23RIESGO
abrir
Referência
CVE-2018-20735
An issue was discovered in BMC PATROL Agent through 11.3.01. It was found that the PatrolCli application can allow for l
38RIESGO
abrir
Referência
CVE-2020-5844
index.php?sec=godmode/extensions&sec2=extensions/files_repo in Pandora FMS v7.0 NG allows authenticated administrators t
35RIESGO
abrir
Referência
CVE-2014-9262
The Duplicator plugin in Wordpress before 0.5.10 allows remote authenticated users to create and download backup files.
23RIESGO
abrir
Referência
CVE-2025-2620
D-Link DAP-1620 Authentication storage mod_graph_auth_uri_handler stack-based overflow
48RIESGO
abrir
Referência
CVE-2017-9936
In LibTIFF 4.0.8, there is a memory leak in tif_jbig.c. A crafted TIFF document can lead to a memory leak resulting in a
23RIESGO
abrir
Referência
CVE-2009-3315
SQL injection vulnerability in admin/index.php in NeLogic Nephp Publisher Enterprise 3.5.9 and 4.5 allows remote attacke
23RIESGO
abrir
Referência
CVE-2010-1951
Multiple directory traversal vulnerabilities in 60cycleCMS allow remote attackers to include and execute arbitrary local
23RIESGO
abrir
ReferênciaVexDay Proof
Telekorn Signkorn Guestbook 1.3 - 'dir_path' Remote File Inclusion
CVE-2006-4788webappsphp
PHP remote file inclusion vulnerability in includes/log.inc.php in Telekorn SignKorn Guestbook (SL) 1.3 and earlier, whe
23RIESGO
abrir
Referência
CVE-2010-2153
Unrestricted file upload vulnerability in admin/code/tce_functions_tcecode_editor.php in TCExam 10.1.006 and 10.1.007 al
23RIESGO
abrir
Referência
CVE-2015-2790
Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1 allow remote attackers to cause a denial of service (memory c
28RIESGO
abrir
Referência
CVE-2008-5753
Stack-based buffer overflow in BulletProof FTP Client 2.63 and 2010 allows user-assisted attackers to execute arbitrary
23RIESGO
abrir
Referência
CVE-2015-2790
Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1 allow remote attackers to cause a denial of service (memory c
28RIESGO
abrir
ReferênciaVexDay Proof
Free Photo Gallery Site Script - 'path' File Disclosure
CVE-2008-1730webappsphp
Directory traversal vulnerability in download.html in ARWScripts Gallery Script Lite (aka gallery-script-lite or Free Ph
23RIESGO
abrir
Referência
CVE-2010-4808
SQL injection vulnerability in index.php in Webmatic allows remote attackers to execute arbitrary SQL commands via the p
23RIESGO
abrir
Referência
CVE-2017-7456
Moxa MXView 2.8 allows remote attackers to cause a Denial of Service by sending overly long junk payload for the MXView
28RIESGO
abrir
Referência
CVE-2018-2380
CVE-2018-2380MEDIUMbajo ataqueransomware
SAP CRM, 7.01, 7.02,7.30, 7.31, 7.33, 7.54, allows an attacker to exploit insufficient validation of path information pr
68RIESGO
abrir
Referência
CVE-2014-4971
Microsoft Windows XP SP3 does not validate addresses in certain IRP handler routines, which allows local users to write
43RIESGO
abrir
Referência
CVE-2014-4971
Microsoft Windows XP SP3 does not validate addresses in certain IRP handler routines, which allows local users to write
43RIESGO
abrir
Referência
CVE-2014-2009
The mPAY24 payment module before 1.6 for PrestaShop allows remote attackers to obtain credentials, the installation path
23RIESGO
abrir
anteriorpágina 552 / 751siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.