Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.837exploits catalogados
35.811CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.455Referência 22.572GitHub PoC 14.291VulnCheck XDB 8722Nuclei 4320Metasploit 3477✓ solo verificadosrecientespopularesriesgo
22.549 exploits
Referência
CVE-2015-4040
Directory traversal vulnerability in the configuration utility in F5 BIG-IP before 12.0.0 and Enterprise Manager 3.0.0 t
23RIESGO
abrir ↗Referência
CVE-2012-4334
The ConnectDDNS method in the (1) STWConfigNVR 1.1.13.15 and (2) STWConfig 1.1.14.13 ActiveX controls in Samsung NET-i v
23RIESGO
abrir ↗Referência
CVE-2014-6308
Directory traversal vulnerability in OSClass before 3.4.2 allows remote attackers to read arbitrary files via a .. (dot
43RIESGO
abrir ↗Referência✓ VexDay Proof
GOM Player 2.1.16.6134 - Subtitle Local Buffer Overflow (PoC)
Stack-based buffer overflow in srt2smi.exe in Gretech Online Movie Player (GOM Player) 2.1.16.4635 allows remote attacke
23RIESGO
abrir ↗Referência✓ VexDay Proof
WebED 0.0.9 - 'index.php' Remote File Disclosure
Multiple directory traversal vulnerabilities in mod/chat/index.php in WebED 0.0.9 allow remote attackers to read arbitra
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHP Photo Gallery 1.0 - 'photo_id' SQL Injection
SQL injection vulnerability in index.php in Terong PHP Photo Gallery (aka Advanced Web Photo Gallery) 1.0 allows remote
23RIESGO
abrir ↗Referência
CVE-2017-2459
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RIESGO
abrir ↗Referência
CVE-2026-11413
JingDong JD Cloud Box AX6600 jdcweb_rpc set_macfilter stack-based overflow
41RIESGO
abrir ↗Referência
CVE-2018-10286
The Ericsson-LG iPECS NMS A.1Ac web application discloses sensitive information such as the NMS admin credentials and th
23RIESGO
abrir ↗Referência
CVE-2017-7047
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. macOS before 10.12.6 is affected. tvOS
23RIESGO
abrir ↗Referência✓ VexDay Proof
FreshView 7.15 - '.psp' Local Buffer Overflow
Buffer overflow in Fresh View 7.15 allows user-assisted remote attackers to execute arbitrary code via a crafted .PSP fi
23RIESGO
abrir ↗Referência✓ VexDay Proof
LoveCMS 1.6.2 Final (Download Manager 1.0) - Arbitrary File Upload
Unrestricted file upload vulnerability in admin/index.php in Download Manager module 1.0 for LoveCMS 1.6.2 Final allows
23RIESGO
abrir ↗Referência
CVE-2017-10688
In LibTIFF 4.0.8, there is a assertion abort in the TIFFWriteDirectoryTagCheckedLong8Array function in tif_dirwrite.c. A
23RIESGO
abrir ↗Referência
CVE-2015-4668
Open redirect vulnerability in Xsuite 2.4.4.5 and earlier allows remote attackers to redirect users to arbitrary web sit
38RIESGO
abrir ↗Referência
pfSense 2.4.4-P3 - 'User Manager' Persistent Cross-Site Scripting
pfSense before 2.4.5 has stored XSS in system_usermanager_addprivs.php in the WebGUI via the descr parameter (aka full n
23RIESGO
abrir ↗Referência
CVE-2010-4988
PHP remote file inclusion vulnerability in mod_chatting/themes/default/header.php in Family Connections Who is Chatting
23RIESGO
abrir ↗Referência✓ VexDay Proof
TalkBack 2.2.7 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in TalkBack 2.2.7 allow remote attackers to execute arbitrary PHP cod
23RIESGO
abrir ↗Referência
CVE-2010-4990
SQL injection vulnerability in the Front-edit Address Book (com_addressbook) component for Joomla! allows remote attacke
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joovili 3.0.6 - 'joovili.images.php' Remote File Disclosure
Directory traversal vulnerability in include/images.inc.php in Joovili 2.x allows remote attackers to read arbitrary fil
23RIESGO
abrir ↗Referência✓ VexDay Proof
visualpic 0.3.1 - Remote File Inclusion
PHP remote file inclusion vulnerability in index.php in VisualPic 0.3.1 allows remote attackers to execute arbitrary PHP
28RIESGO
abrir ↗Referência✓ VexDay Proof
Autodesk DWF Viewer Control / LiveUpdate Module - Remote Code Execution
Directory traversal vulnerability in the CExpressViewerControl class in the DWF Viewer ActiveX control (AdView.dll 9.0.0
23RIESGO
abrir ↗Referência✓ VexDay Proof
mini-pub 0.3 - File Disclosure / Code Execution
mini-pub.php/front-end/cat.php in mini-pub 0.3 allows remote attackers to execute arbitrary commands via shell metachara
23RIESGO
abrir ↗Referência
CVE-2010-0691
SQL injection vulnerability in druckansicht.php in JTL-Shop 2 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir ↗Referência
CVE-2015-7257
ZTE ADSL ZXV10 W300 modems W300V2.1.0f_ER7_PE_O57 and W300V2.1.0h_ER7_PE_O57 allow remote authenticated non-administrato
23RIESGO
abrir ↗Referência
CVE-2013-6234
Unrestricted file upload vulnerability in the Worksheet designer in SpagoBI before 4.1 allows remote authenticated users
23RIESGO
abrir ↗Referência
CVE-2021-4436
3DPrint Lite < 1.9.1.5 - Unauthenticated Arbitrary File Upload
63RIESGO
abrir ↗Referência
CVE-2017-7005
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. Safari before 10.1.1 is affected. tvOS
23RIESGO
abrir ↗Referência
CVE-2015-1560
SQL injection vulnerability in the isUserAdmin function in include/common/common-Func.php in Centreon (formerly Merethis
23RIESGO
abrir ↗Referência
CVE-2009-2258
Directory traversal vulnerability in cgi-bin/webcm in the administrative web interface on the Netgear DG632 with firmwar
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! / Mambo Component Taskhopper 1.1 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in the Taskhopper 1.1 component for Mambo and Joomla! allow remote at
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.