Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.813exploits catalogados
35.788CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.455Referência 22.549GitHub PoC 14.290VulnCheck XDB 8722Nuclei 4320Metasploit 3477✓ solo verificadosrecientespopularesriesgo
22.523 exploits
Referência✓ VexDay Proof
HydraIrc 0.3.164 - Remote Denial of Service
HydraIRC 0.3.164 and earlier allows remote attackers to cause a denial of service (NULL pointer dereference and applicat
23RIESGO
abrir ↗Referência
CVE-2010-4913
Cross-site scripting (XSS) vulnerability in the search feature in ColdGen ColdUserGroup 1.06 allows remote attackers to
23RIESGO
abrir ↗Referência
CVE-2014-4688
pfSense before 2.1.4 allows remote authenticated users to execute arbitrary commands via (1) the hostname value to diag_
23RIESGO
abrir ↗Referência
CVE-2011-4810
Multiple directory traversal vulnerabilities in WHMCompleteSolution (WHMCS) 3.x and 4.x allow remote attackers to read a
23RIESGO
abrir ↗Referência✓ VexDay Proof
RhinoSoft Serv-U FTP Server 7.4.0.1 - 'SMNT' (Authenticated) Denial of Service
The FTP server in Serv-U 7.0.0.1 through 7.4.0.1 allows remote authenticated users to cause a denial of service (service
23RIESGO
abrir ↗Referência✓ VexDay Proof
UeberProject 1.0 - '/login/secure.php' Remote File Inclusion
PHP remote file inclusion vulnerability in login/secure.php in UeberProject Management System 1.0 and earlier allows rem
23RIESGO
abrir ↗Referência
CVE-2013-6366
The Groovy script console in VMware Hyperic HQ 4.6.6 allows remote authenticated administrators to execute arbitrary cod
23RIESGO
abrir ↗Referência
CVE-2016-7851
Adobe Connect version 9.5.6 and earlier does not adequately validate input in the events registration module. This vulne
23RIESGO
abrir ↗Referência
CVE-2010-4944
SQL injection vulnerability in the Elite Experts (com_elite_experts) component for Mambo and Joomla! allows remote attac
23RIESGO
abrir ↗Referência
CVE-2017-9147
LibTIFF 4.0.7 has an invalid read in the _TIFFVGetField function in tif_dir.c, which might allow remote attackers to cau
23RIESGO
abrir ↗Referência✓ VexDay Proof
Frequency Clock 0.1b - 'securelib' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Frequency Clock 0.1b (Beta 0.1) allow remote attackers to execute
23RIESGO
abrir ↗Referência✓ VexDay Proof
AuraCMS 2.1 - Remote File Attachment / Local File Inclusion
Unrestricted file upload vulnerability in mod/contak.php in AuraCMS 2.1 allows remote attackers to upload and execute ar
23RIESGO
abrir ↗Referência✓ VexDay Proof
XZero Community Classifieds 4.95.11 - Local File Inclusion / SQL Injection
Directory traversal vulnerability in index.php in XZero Community Classifieds 4.95.11 and earlier allows remote attacker
23RIESGO
abrir ↗Referência✓ VexDay Proof
ChilkatHttp ActiveX 2.3 - Arbitrary Files Overwrite
The ChilkatHttp.ChilkatHttp.1 and ChilkatHttp.ChilkatHttpRequest.1 ActiveX controls in ChilkatHttp.dll 2.4.0.0, 2.3.0.0,
23RIESGO
abrir ↗Referência
CVE-2015-6763
Multiple unspecified vulnerabilities in Google Chrome before 46.0.2490.71 allow attackers to cause a denial of service o
23RIESGO
abrir ↗Referência
CVE-2015-6763
Multiple unspecified vulnerabilities in Google Chrome before 46.0.2490.71 allow attackers to cause a denial of service o
23RIESGO
abrir ↗Referência
CVE-2021-22146
All versions of Elastic Cloud Enterprise has the Elasticsearch “anonymous” user enabled by default in deployed clusters.
28RIESGO
abrir ↗Referência
CVE-2010-0677
SQL injection vulnerability in index.php in Katalog Stron Hurricane 1.3.5, and possibly earlier, allows remote attackers
23RIESGO
abrir ↗Referência
CVE-2015-2518
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Win
23RIESGO
abrir ↗Referência
CVE-2015-2511
The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Win
23RIESGO
abrir ↗Referência✓ VexDay Proof
X10media Mp3 Search Engine 1.6 - Remote File Disclosure
download.php in X10media x10 Automatic Mp3 Search Engine Script 1.5.5 through 1.6 allows remote attackers to read arbitr
23RIESGO
abrir ↗Referência
CVE-2010-4301
epan/dissectors/packet-zbee-zcl.c in the ZigBee ZCL dissector in Wireshark 1.4.0 through 1.4.1 allows remote attackers t
23RIESGO
abrir ↗Referência
CVE-2017-15270
The PSFTPd 10.0.4 Build 729 server does not properly escape data before writing it into a Comma Separated Values (CSV) f
23RIESGO
abrir ↗Referência
CVE-2017-15270
The PSFTPd 10.0.4 Build 729 server does not properly escape data before writing it into a Comma Separated Values (CSV) f
23RIESGO
abrir ↗Referência
CVE-2019-1914
Cisco Small Business 220 Series Smart Switches Command Injection Vulnerability
46RIESGO
abrir ↗Referência
CVE-2015-8358
Directory traversal vulnerability in the bitrix.mpbuilder module before 1.0.12 for Bitrix allows remote administrators t
23RIESGO
abrir ↗Referência
CVE-2015-8358
Directory traversal vulnerability in the bitrix.mpbuilder module before 1.0.12 for Bitrix allows remote administrators t
23RIESGO
abrir ↗Referência
CVE-2017-2363
An issue was discovered in certain Apple products. iOS before 10.2.1 is affected. Safari before 10.0.3 is affected. tvOS
23RIESGO
abrir ↗Referência
CVE-2014-3008
Unitrends Enterprise Backup 7.3.0 allows remote authenticated users to execute arbitrary commands via shell metacharacte
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.