Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.813exploits catalogados
35.788CVEs con explotación pública
24.695probados en laboratorio
22.549 exploits
Referência
CVE-2017-8046
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RIESGO
abrir
Referência
CVE-2017-6326
The Symantec Messaging Gateway can encounter an issue of remote code execution, which describes a situation whereby an i
60RIESGO
abrir
Referência
CVE-2018-7251
An issue was discovered in config/error.php in Anchor 0.12.3. The error log is exposed at an errors.log URI, and contain
60RIESGO
abrir
Referência
CVE-2019-1429
CVE-2019-1429HIGHbajo ataque
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
93RIESGO
abrir
Referência
CVE-2014-3914
Directory traversal vulnerability in the Admin Center for Tivoli Storage Manager (TSM) in Rocket ServerGraph 1.2 allows
60RIESGO
abrir
Referência
CVE-2017-6316
CVE-2017-6316CRITICALbajo ataque
Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as r
100RIESGO
abrir
Referência
CVE-2017-6316
CVE-2017-6316CRITICALbajo ataque
Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as r
100RIESGO
abrir
Referência
CVE-2022-20699
CVE-2022-20699CRITICALbajo ataque
Cisco Small Business RV Series Routers Vulnerabilities
100RIESGO
abrir
Referência
CVE-2017-15889
Command injection vulnerability in smart.cgi in Synology DiskStation Manager (DSM) before 5.2-5967-5 allows remote authe
60RIESGO
abrir
ReferênciaVexDay Proof
Blue Eye CMS 1.0.0 - Remote Cookie SQL Injection
CVE-2009-0883webappsphp
SQL injection vulnerability in Blue Eye CMS 1.0.0 and earlier, when magic_quotes_gpc is disabled, allows remote attacker
23RIESGO
abrir
Referência
CVE-2021-25296
CVE-2021-25296HIGHbajo ataque
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi
100RIESGO
abrir
Referência
CVE-2021-25296
CVE-2021-25296HIGHbajo ataque
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi
100RIESGO
abrir
Referência
CVE-2021-39327
BulletProof Security <= 5.1 Sensitive Information Disclosure
70RIESGO
abrir
Referência
CVE-2016-1560
ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and
60RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component com_bookJoomlas 0.1 - SQL Injection
CVE-2009-1263webappsphp
SQL injection vulnerability in sub_commententry.php in the BookJoomlas (com_bookjoomlas) component 0.1 for Joomla! allow
23RIESGO
abrir
ReferênciaVexDay Proof
phpTrafficA 1.4.2 - 'pageid' SQL Injection
CVE-2007-3426webappsphp
Cross-site scripting (XSS) vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to inject
23RIESGO
abrir
ReferênciaVexDay Proof
WebFileExplorer 3.1 - Authentication Bypass
CVE-2009-1314webappsphp
body.asp in Web File Explorer 3.1 allows remote attackers to create arbitrary files and execute arbitrary code via the s
28RIESGO
abrir
ReferênciaVexDay Proof
Mini-stream Ripper 3.0.1.1 - '.m3u' Universal Stack Overflow
CVE-2009-1325localwindows
Stack-based buffer overflow in Mini-stream Ripper 3.0.1.1 allows remote attackers to execute arbitrary code via a long U
23RIESGO
abrir
ReferênciaVexDay Proof
RM Downloader - '.m3u' Local Stack Overflow (PoC)
CVE-2009-1326doswindows
Stack-based buffer overflow in Mini-stream RM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a
23RIESGO
abrir
ReferênciaVexDay Proof
WM Downloader 3.0.0.9 - '.m3u' Universal Stack Overflow
CVE-2009-1327localwindows
Stack-based buffer overflow in Mini-stream WM Downloader 3.0.0.9 allows remote attackers to execute arbitrary code via a
23RIESGO
abrir
Referência
CVE-2014-4880
Buffer overflow in Hikvision DVR DS-7204 Firmware 2.2.10 build 131009, and other models and versions, allows remote atta
60RIESGO
abrir
Referência
CVE-2025-34299
Monsta FTP <= 2.11 Unauthenticated Arbitrary File Upload
85RIESGO
abrir
ReferênciaVexDay Proof
Mini-stream RM-MP3 Converter 3.0.0.7 - '.m3u' Local Stack Overflow (PoC)
CVE-2009-1328doswindows
Stack-based buffer overflow in Mini-stream RM-MP3 Converter 3.0.0.7 allows remote attackers to execute arbitrary code vi
23RIESGO
abrir
ReferênciaVexDay Proof
Mini-stream RM-MP3 Converter 3.0.0.7 - '.m3u' Local Stack Overflow
CVE-2009-1328localwindows
Stack-based buffer overflow in Mini-stream RM-MP3 Converter 3.0.0.7 allows remote attackers to execute arbitrary code vi
23RIESGO
abrir
Referência
CVE-2017-16709
Crestron Airmedia AM-100 devices with firmware before 1.6.0 and AM-101 devices with firmware before 2.7.0 allows remote
60RIESGO
abrir
Referência
CVE-2017-8540
CVE-2017-8540HIGHbajo ataque
The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Serve
93RIESGO
abrir
Referência
CVE-2013-3623
Multiple stack-based buffer overflows in cgi/close_window.cgi in the web interface in the Intelligent Platform Managemen
60RIESGO
abrir
Referência
CVE-2010-2263
nginx 0.8 before 0.8.40 and 0.7 before 0.7.66, when running on Windows, allows remote attackers to obtain source code or
60RIESGO
abrir
Referência
CVE-2019-0568
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
35RIESGO
abrir
Referência
CVE-2012-0209
Horde 3.3.12, Horde Groupware 1.2.10, and Horde Groupware Webmail Edition 1.2.10, as distributed by FTP between November
60RIESGO
abrir
anteriorpágina 559 / 752siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.