Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.813exploits catalogados
35.788CVEs con explotación pública
24.695probados en laboratorio
22.523 exploits
Referência
CVE-2022-4395
Membership For WooCommerce < 2.1.7 - Unauthenticated Arbitrary File Upload
53RIESGO
abrir
Referência
CVE-2018-19550
Interspire Email Marketer through 6.1.6 allows arbitrary file upload via a surveys_submit.php "create survey and submit
23RIESGO
abrir
Referência
CVE-2023-2779
Super Socializer < 7.13.52 - Reflected XSS
48RIESGO
abrir
Referência
CVE-2023-2779
Super Socializer < 7.13.52 - Reflected XSS
48RIESGO
abrir
Referência
CVE-2023-2779
Super Socializer < 7.13.52 - Reflected XSS
48RIESGO
abrir
Referência
CVE-2010-4884
PHP remote file inclusion vulnerability in guestbook/gbook.php in Gaestebuch 1.2 allows remote attackers to execute arbi
23RIESGO
abrir
ReferênciaVexDay Proof
TYPSoft FTP Server 1.11 - 'ABORT' Remote Denial of Service
CVE-2009-1668doswindows
TYPSoft FTP Server 1.11 allows remote attackers to cause a denial of service (CPU consumption) by sending an ABOR (abort
23RIESGO
abrir
Referência
CVE-2020-16602
Razer Chroma SDK Rest Server through 3.12.17 allows remote attackers to execute arbitrary programs because there is a ra
23RIESGO
abrir
ReferênciaVexDay Proof
CliServ Web Community 0.65 - 'cl_headers' Include
CVE-2006-7068webappsphp
PHP remote file inclusion vulnerability in CliServ Web Community 0.65 and earlier allows remote attackers to execute arb
23RIESGO
abrir
Referência
CVE-2017-3631
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported versio
38RIESGO
abrir
Referência
CVE-2017-3631
Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel). The supported versio
38RIESGO
abrir
ReferênciaVexDay Proof
TEC-IT TBarCode - OCX ActiveX Arbitrary File Overwrite
CVE-2007-3233remotewindows
The TEC-IT TBarCode OCX ActiveX control (TBarCode7.ocx) 7.0.2.3524 allows remote attackers to overwrite arbitrary files
23RIESGO
abrir
Referência
CVE-2009-3531
SQL injection vulnerability in vnews.php in Universe CMS 1.0.6 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
Arcadem LE 2.04 - 'loadadminpage' Remote File Inclusion
CVE-2007-6542webappsphp
PHP remote file inclusion vulnerability in admin/frontpage_right.php in Arcadem LE 2.04 and earlier allows remote attack
23RIESGO
abrir
ReferênciaVexDay Proof
Siteman 2.x - Code Execution / Local File Inclusion / Cross-Site Scripting
CVE-2008-2082webappsphp
Cross-site scripting (XSS) vulnerability in index.php in Siteman 2.0.x2 allows remote attackers to inject arbitrary web
23RIESGO
abrir
Referência
CVE-2018-6323
The elf_object_p function in elfcode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU B
23RIESGO
abrir
Referência
CVE-2017-5850
httpd in OpenBSD allows remote attackers to cause a denial of service (memory consumption) via a series of requests for
28RIESGO
abrir
Referência
CVE-2010-2045
Directory traversal vulnerability in the Dione Form Wizard (aka FDione or com_dioneformwizard) component 1.0.2 for Jooml
38RIESGO
abrir
Referência
CVE-2019-12189
An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3. There is XSS via the SearchN.do search field.
23RIESGO
abrir
Referência
CVE-2009-2396
PHP remote file inclusion vulnerability in template/album.php in DM Albums 1.9.2, as used standalone or as a WordPress p
23RIESGO
abrir
Referência
CVE-2017-5850
httpd in OpenBSD allows remote attackers to cause a denial of service (memory consumption) via a series of requests for
28RIESGO
abrir
Referência
CVE-2017-14939
decode_line_info in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.
23RIESGO
abrir
Referência
CVE-2009-2653
The NtUserConsoleControl function in win32k.sys in Microsoft Windows XP SP2 and SP3, and Server 2003 before SP1, allows
23RIESGO
abrir
Referência
Nagios Log Server 2024R1.3.1 - Stored XSS
CVE-2025-29471HIGHwebappsmultiple
Cross Site Scripting vulnerability in Nagios Log Server v.2024R1.3.1 allows a remote attacker to execute arbitrary code
41RIESGO
abrir
Referência
CVE-2009-2333
Multiple directory traversal vulnerabilities in CMS Chainuk 1.2 and earlier allow remote attackers to include and execut
23RIESGO
abrir
Referência
CVE-2009-3053
Directory traversal vulnerability in the Agora (com_agora) component 3.0.0b for Joomla! allows remote attackers to inclu
38RIESGO
abrir
ReferênciaVexDay Proof
mailwatch 1.0.4 - 'doc' Local File Inclusion
CVE-2008-5991webappsphp
Directory traversal vulnerability in docs.php in MailWatch for MailScanner 1.0.4 and earlier allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
PHPCollab 2.x / NetOffice 2.x - 'sendpassword.php' SQL Injection
CVE-2006-1495webappsphp
SQL injection vulnerability in general/sendpassword.php in (1) PHPCollab 2.4 and 2.5.rc3, and (2) NetOffice 2.5.3-pl1 an
23RIESGO
abrir
ReferênciaVexDay Proof
PHP 4.4.6/5.2.1 - ext/gd Already Freed Resources Usage
CVE-2007-1582locallinux
The resource system in PHP 4.0.0 through 4.4.6 and 5.0.0 through 5.2.1 allows context-dependent attackers to execute arb
23RIESGO
abrir
ReferênciaVexDay Proof
Xilisoft Video Converter Wizard 3 - '.cue' Stack Buffer Overflow (PoC)
CVE-2009-1370doswindows
Stack-based buffer overflow in ape_plugin.plg in Xilisoft Video Converter 3.1.53.0704n and 5.1.23.0402 allows remote att
23RIESGO
abrir
anteriorpágina 553 / 751siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.