Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.813exploits catalogados
35.788CVEs con explotación pública
24.695probados en laboratorio
22.549 exploits
ReferênciaVexDay Proof
DFLabs PTK 1.0 - Local Command Execution
CVE-2008-6793webappsphp
The get_file_type function in lib/file_content.php in DFLabs PTK 0.1, 0.2, and 1.0 allows remote attackers to execute ar
23RIESGO
abrir
ReferênciaVexDay Proof
Sun xVM VirtualBox < 1.6.4 - Privilege Escalation (PoC)
CVE-2008-3431HIGHbajo ataquedosmultiple
The VBoxDrvNtDeviceControl function in VBoxDrv.sys in Sun xVM VirtualBox before 1.6.4 uses the METHOD_NEITHER communicat
71RIESGO
abrir
Referência
CVE-2010-4975
SQL injection vulnerability in the Techjoomla SocialAds For JomSocial (com_socialads) component for Joomla! allows remot
23RIESGO
abrir
Referência
CVE-2025-0798
MicroWorld eScan Antivirus Quarantine rtscanner os command injection
48RIESGO
abrir
Referência
CVE-2008-6366
SQL injection vulnerability in logon.jsp in Ad Server Solutions Affiliate Software Java 4.0 allows remote attackers to e
23RIESGO
abrir
Referência
CVE-2025-34117
Netcore / Netis Routers RCE via UDP Port 53413 Backdoor
68RIESGO
abrir
Referência
CVE-2015-7248
ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE allow remote attackers to discover usernames and password ha
23RIESGO
abrir
Referência
CVE-2018-13980
The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated file disclos
38RIESGO
abrir
Referência
CVE-2018-13980
The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated file disclos
38RIESGO
abrir
Referência
CVE-2025-34117
Netcore / Netis Routers RCE via UDP Port 53413 Backdoor
68RIESGO
abrir
Referência
CVE-2025-34117
Netcore / Netis Routers RCE via UDP Port 53413 Backdoor
68RIESGO
abrir
Referência
CVE-2016-1594
Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to read arbitrary attachments via a request
23RIESGO
abrir
Referência
CVE-2016-1594
Micro Focus Novell Service Desk before 7.2 allows remote authenticated users to read arbitrary attachments via a request
23RIESGO
abrir
Referência
CVE-2013-0249
Stack-based buffer overflow in the Curl_sasl_create_digest_md5_message function in lib/curl_sasl.c in curl and libcurl 7
28RIESGO
abrir
Referência
CVE-2016-8017
Special element injection vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows a
23RIESGO
abrir
Referência
CVE-2014-3975
Absolute path traversal vulnerability in filemanager.php in AuraCMS 3.0 allows remote attackers to list a directory via
23RIESGO
abrir
Referência
CVE-2014-3975
Absolute path traversal vulnerability in filemanager.php in AuraCMS 3.0 allows remote attackers to list a directory via
23RIESGO
abrir
Referência
CVE-2014-9436
Absolute path traversal vulnerability in SysAid On-Premise before 14.4.2 allows remote attackers to read arbitrary files
23RIESGO
abrir
Referência
CVE-2014-9436
Absolute path traversal vulnerability in SysAid On-Premise before 14.4.2 allows remote attackers to read arbitrary files
23RIESGO
abrir
Referência
CVE-2008-6280
Cross-site scripting (XSS) vulnerability in apply.cgi on the Linksys WRT160N allows remote attackers to inject arbitrary
23RIESGO
abrir
Referência
CVE-2019-8195
Adobe Acrobat and Reader versions , 2019.012.20040 and earlier, 2017.011.30148 and earlier, 2017.011.30148 and earlier,
28RIESGO
abrir
Referência
CVE-2010-4976
Cross-site scripting (XSS) vulnerability in search/search.php in MetInfo 3.0 allows remote attackers to inject arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
PMB Services 3.0.13 - Multiple Remote File Inclusions
CVE-2007-1415webappsphp
Multiple PHP remote file inclusion vulnerabilities in PMB Services 3.0.13 and earlier allow remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
Site Sift Listings - 'id' SQL Injection
CVE-2008-1869webappsphp
SQL injection vulnerability in Site Sift Listings allows remote attackers to execute arbitrary SQL commands via the id p
23RIESGO
abrir
ReferênciaVexDay Proof
Friendly Technologies - 'fwRemoteCfg.dll' ActiveX Remote Buffer Overflow
CVE-2008-4048remotewindows
Heap-based buffer overflow in a certain ActiveX control in fwRemoteCfg.dll 3.3.3.1 in Friendly Technologies FriendlyPPPo
23RIESGO
abrir
Referência
CVE-2017-0119
Uniscribe in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 allows remote attackers
28RIESGO
abrir
Referência
CVE-2010-0690
SQL injection vulnerability in index.php in CommodityRentals Video Games Rentals allows remote attackers to execute arbi
23RIESGO
abrir
Referência
CVE-2021-31673
A Dom-based Cross-site scripting (XSS) vulnerability at registration account in Cyclos 4 PRO.14.7 and before allows remo
23RIESGO
abrir
Referência
CVE-2020-11457
pfSense before 2.4.5 has stored XSS in system_usermanager_addprivs.php in the WebGUI via the descr parameter (aka full n
23RIESGO
abrir
Referência
CVE-2012-6509
Unrestricted file upload vulnerability in NetArt Media Car Portal 3.0 allows remote attackers to execute arbitrary PHP c
23RIESGO
abrir
anteriorpágina 563 / 752siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.