Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.866exploits catalogados
35.812CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.458Referência 22.573GitHub PoC 14.316VulnCheck XDB 8722Nuclei 4320Metasploit 3477✓ solo verificadosrecientespopularesriesgo
22.549 exploits
Referência
CVE-2009-3717
Heap-based buffer overflow in LucVil PatPlayer 3.9 allows remote attackers to cause a denial of service (crash) or execu
23RIESGO
abrir ↗Referência
CVE-2013-1464
Cross-site scripting (XSS) vulnerability in assets/player.swf in the Audio Player plugin before 2.0.4.6 for Wordpress al
23RIESGO
abrir ↗Referência✓ VexDay Proof
Google Chrome 0.2.149.27 - Automatic File Download
Google Chrome BETA (0.2.149.27) does not prompt the user before saving an executable file, which makes it easier for rem
23RIESGO
abrir ↗Referência
CVE-2018-15536
/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 does not properly validate file paths in arc
23RIESGO
abrir ↗Referência
CVE-2018-10371
An issue was discovered in the wunderfarm WF Cookie Consent plugin 1.1.3 for WordPress. A persistent cross-site scriptin
23RIESGO
abrir ↗Referência
CVE-2009-3493
Multiple cross-site scripting (XSS) vulnerabilities in Zenas PaoBacheca Guestbook 2.1 allow remote attackers to inject a
23RIESGO
abrir ↗Referência
CVE-2020-6364
SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an att
48RIESGO
abrir ↗Referência
CVE-2015-1494
The FancyBox for WordPress plugin before 3.0.3 for WordPress does not properly restrict access, which allows remote atta
23RIESGO
abrir ↗Referência✓ VexDay Proof
BigAnt Server 2.2 - Remote Overflow (SEH)
Stack-based buffer overflow in the AntServer module (AntServer.exe) in BigAnt IM Server in BigAnt Messenger 2.2 allows r
60RIESGO
abrir ↗Referência
CVE-2010-5019
SQL injection vulnerability in view_photo.php in 2daybiz Online Classified Script allows remote attackers to execute arb
23RIESGO
abrir ↗Referência
CVE-2010-5021
SQL injection vulnerability in view_group.asp in Digital Interchange Document Library 5.8.5 allows remote attackers to e
23RIESGO
abrir ↗Referência
CVE-2010-0759
Directory traversal vulnerability in plugins/system/cdscriptegrator/libraries/highslide/js/jsloader.php in the Core Desi
43RIESGO
abrir ↗Referência
CVE-2009-2344
The web-based management interfaces in Sourcefire Defense Center (DC) and 3D Sensor before 4.8.2 allow remote authentica
23RIESGO
abrir ↗Referência
CVE-2019-10963
Moxa EDR 810, all versions 5.1 and prior, allows an unauthenticated attacker to be able to retrieve some log files from
23RIESGO
abrir ↗Referência
CVE-2015-8612
The EnableNetwork method in the Network class in plugins/mechanism/Network.py in Blueman before 2.0.3 allows local users
38RIESGO
abrir ↗Referência
CVE-2015-8612
The EnableNetwork method in the Network class in plugins/mechanism/Network.py in Blueman before 2.0.3 allows local users
38RIESGO
abrir ↗Referência
CVE-2021-45814
Nettmp NNT 5.1 is affected by a SQL injection vulnerability. An attacker can bypass authentication and access the panel
23RIESGO
abrir ↗Referência✓ VexDay Proof
PHPUserBase 1.3b - 'unverified.inc.php' Local File Inclusion
Directory traversal vulnerability in include/unverified.inc.php in Linux Web Shop (LWS) php User Base 1.3beta allows rem
23RIESGO
abrir ↗Referência
CVE-2018-5708
An issue was discovered on D-Link DIR-601 B1 2.02NA devices. Being on the same local network as, but being unauthenticat
23RIESGO
abrir ↗Referência
CVE-2009-3506
Multiple cross-site scripting (XSS) vulnerabilities in CMSphp 0.21 allow remote attackers to inject arbitrary web script
23RIESGO
abrir ↗Referência✓ VexDay Proof
Moodle 1.5.2 - 'moodledata' Remote Session Disclosure
Moodle 1.5.2 and earlier stores sensitive information under the web root with insufficient access control, and provides
23RIESGO
abrir ↗Referência✓ VexDay Proof
Flatnux 2009-01-27 - Remote File Inclusion
PHP remote file inclusion vulnerability in include/flatnux.php in FlatnuX CMS (aka Flatnuke3) 2009-01-27 and 2009-02-04,
23RIESGO
abrir ↗Referência✓ VexDay Proof
Joomla! Component Expose RC35 - Arbitrary File Upload
uploadimg.php in the Expose RC35 and earlier (com_expose) component for Joomla! sends an error message but does not exit
23RIESGO
abrir ↗Referência
CVE-2010-5026
SQL injection vulnerability in winners.php in Science Fair In A Box (SFIAB) 2.0.6 and 2.2.0 allows remote attackers to e
23RIESGO
abrir ↗Referência
CVE-2010-5026
SQL injection vulnerability in winners.php in Science Fair In A Box (SFIAB) 2.0.6 and 2.2.0 allows remote attackers to e
23RIESGO
abrir ↗Referência
CVE-2017-0165
An elevation of privilege vulnerability exists when Microsoft Windows running on Windows 10, Windows 10 1511, Windows 8.
23RIESGO
abrir ↗Referência
CVE-2018-14057
Pimcore before 5.3.0 allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging validati
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.