Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
77.866exploits catalogados
35.812CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.458Referência 22.573GitHub PoC 14.316VulnCheck XDB 8722Nuclei 4320Metasploit 3477✓ solo verificadosrecientespopularesriesgo
22.549 exploits
Referência
CVE-2010-2045
Directory traversal vulnerability in the Dione Form Wizard (aka FDione or com_dioneformwizard) component 1.0.2 for Jooml
38RIESGO
abrir ↗Referência
CVE-2021-23017
A security issue in nginx resolver was identified, which might allow an attacker who is able to forge UDP packets from t
35RIESGO
abrir ↗Referência
CVE-2009-4367
The Staging Webservice ("sitecore modules/staging/service/api.asmx") in Sitecore Staging Module 5.4.0 rev.080625 and ear
23RIESGO
abrir ↗Referência
CVE-2014-4968
The WebView class and use of the WebView.addJavascriptInterface method in the Boat Browser application 8.0 and 8.0.1 for
23RIESGO
abrir ↗Referência
CVE-2020-15921
Mida eFramework through 2.9.0 has a back door that permits a change of the administrative password and access to restric
28RIESGO
abrir ↗Referência
CVE-2012-2270
Open redirect vulnerability in index.php (aka the Login Page) in ownCloud before 3.0.3 allows remote attackers to redire
23RIESGO
abrir ↗Referência
CVE-2015-3632
Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1.5 allow remote attackers to cause a denial of service (memory
23RIESGO
abrir ↗Referência
CVE-2015-3632
Foxit Reader, Enterprise Reader, and PhantomPDF before 7.1.5 allow remote attackers to cause a denial of service (memory
23RIESGO
abrir ↗Referência✓ VexDay Proof
2DayBiz Business Community Script - Multiple Vulnerabilities
admin/adminaddeditdetails.php in Business Community Script does not properly restrict access, which allows remote attack
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mambo Component zOOm Media Gallery 2.5 Beta 2 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in the com_zoom 2.5 beta 2 and earlier module for Mambo allow remote
23RIESGO
abrir ↗Referência✓ VexDay Proof
Mcms Easy Web Make - 'index.php?template' Local File Inclusion
Directory traversal vulnerability in modules/cms/index.php in Mcms Easy Web Make 1.3, allows remote attackers to include
23RIESGO
abrir ↗Referência
CVE-2017-0160
Microsoft .NET Framework 2.0, 3.5, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allows an attacker with access to the local system t
28RIESGO
abrir ↗Referência
CVE-2015-7570
Multiple server-side request forgery (SSRF) vulnerabilities in Yeager CMS 1.2.1 allow remote attackers to trigger outbou
23RIESGO
abrir ↗Referência
CVE-2015-7570
Multiple server-side request forgery (SSRF) vulnerabilities in Yeager CMS 1.2.1 allow remote attackers to trigger outbou
23RIESGO
abrir ↗Referência
CVE-2017-17874
Vanguard Marketplace Digital Products PHP 1.4 allows arbitrary file upload via an "Add a new product" or "Add a product
23RIESGO
abrir ↗Referência✓ VexDay Proof
VideoLAN VLC Media Player 0.9.8a - Web UI 'input' Remote Denial of Service
requests/status.xml in VLC 0.9.8a allows remote attackers to cause a denial of service (stack consumption and crash) via
23RIESGO
abrir ↗Referência
CVE-2009-4754
Stack-based buffer overflow in Mercury Audio Player 1.21 allows remote attackers to execute arbitrary code via a long st
23RIESGO
abrir ↗Referência
CVE-2009-4754
Stack-based buffer overflow in Mercury Audio Player 1.21 allows remote attackers to execute arbitrary code via a long st
23RIESGO
abrir ↗Referência
CVE-2017-0062
The Graphics Device Interface (GDI) in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; W
28RIESGO
abrir ↗Referência✓ VexDay Proof
Jokes Site Script - 'jokes.php' SQL Injection
SQL injection vulnerability in jokes.php in YourFreeWorld Jokes Site Script allows remote attackers to execute arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
EO Video 1.36 - Local Heap Overflow Denial of Service / (PoC)
Stack-based buffer overflow in EO Video (eo-video) 1.36 allows remote attackers to cause a denial of service (applicatio
23RIESGO
abrir ↗Referência✓ VexDay Proof
RTS Sentry Digital Surveillance - 'CamPanel.dll 2.1.0.2' Remote Buffer Overflow
Stack-based buffer overflow in the PTZCamPanelCtrl ActiveX control (CamPanel.dll) in RTS Sentry 2.1.0.2 allows remote at
23RIESGO
abrir ↗Referência
CVE-2011-1670
Cross-site scripting (XSS) vulnerability in actions/add.php in InTerra Blog Machine 1.84, and possibly earlier versions,
23RIESGO
abrir ↗Referência
CVE-2009-0855
Cross-site scripting (XSS) vulnerability in the administrative console in IBM WebSphere Application Server (WAS) 6.1 bef
23RIESGO
abrir ↗Referência
CVE-2012-2602
Multiple cross-site request forgery (CSRF) vulnerabilities in SolarWinds Orion Network Performance Monitor (NPM) before
23RIESGO
abrir ↗Referência
CVE-2009-3664
Multiple directory traversal vulnerabilities in index.php in Nullam Blog 0.1.2 allow remote attackers to include or exec
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.