Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
22.936 exploits
ReferênciaVexDay Proof
VideoLAN VLC Media Player < 0.9.6 - '.rt' Local Stack Buffer Overflow
CVE-2008-5036localwindows
Stack-based buffer overflow in VideoLAN VLC media player 0.9.x before 0.9.6 might allow user-assisted attackers to execu
50RIESGO
abrir
Referência
CVE-2020-8425
Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account deletion via userdelete.php.
23RIESGO
abrir
ReferênciaVexDay Proof
Artmedic CMS 3.4 - 'index.php' Local File Inclusion
CVE-2007-5489webappsphp
Directory traversal vulnerability in index.php in Artmedic CMS 3.4 and earlier allows remote attackers to include and ex
23RIESGO
abrir
ReferênciaVexDay Proof
zKup CMS 2.0 < 2.3 - Arbitrary File Upload
CVE-2008-7124webappsphp
zKup CMS 2.0 through 2.3 does not require administrative authentication for admin/configuration/modifier.php, which allo
23RIESGO
abrir
ReferênciaVexDay Proof
Soulseek 157 NS - Remote Buffer Overflow (SEH)
CVE-2009-1830remotewindows
Stack-based buffer overflow in Soulseek 156 and 157 NS allows remote attackers to execute arbitrary code via a long sear
23RIESGO
abrir
Referência
CVE-2016-0122
Microsoft Excel 2007 SP3, Excel 2010 SP2, Excel 2013 SP1, Excel 2013 RT SP1, Excel 2016, Word 2016 for Mac, Office Compa
35RIESGO
abrir
Referência
CVE-2008-1609
Multiple PHP remote file inclusion vulnerabilities in just another flat file (JAF) CMS 4.0 RC2 allow remote attackers to
35RIESGO
abrir
ReferênciaVexDay Proof
ClanLite 2.x - SQL Injection / Cross-Site Scripting
CVE-2008-5215webappsphp
SQL injection vulnerability in service/profil.php in ClanLite 2.2006.05.20 allows remote attackers to execute arbitrary
23RIESGO
abrir
Referência
CVE-2017-17411
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authe
60RIESGO
abrir
Referência
CVE-2015-2065
SQL injection vulnerability in videogalleryrss.php in the Apptha WordPress Video Gallery (contus-video-gallery) plugin b
50RIESGO
abrir
Referência
CVE-2015-2065
SQL injection vulnerability in videogalleryrss.php in the Apptha WordPress Video Gallery (contus-video-gallery) plugin b
50RIESGO
abrir
ReferênciaVexDay Proof
FREEze Greetings 1.0 - Remote Password Retrieve
CVE-2008-5218webappsphp
ScriptsEz FREEze Greetings 1.0 stores pwd.txt under the web root with insufficient access control, which allows remote a
23RIESGO
abrir
ReferênciaVexDay Proof
AJ Article 1.0 - 'featured_article.php' SQL Injection
CVE-2008-5213webappsphp
SQL injection vulnerability in featured_article.php in AJ Article 1.0 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
Referência
CVE-2019-12593
IceWarp Mail Server through 10.4.4 is prone to a local file inclusion vulnerability via webmail/calendar/minimizer/index
50RIESGO
abrir
ReferênciaVexDay Proof
wPortfolio 0.3 - Arbitrary File Upload
CVE-2008-5220webappsphp
Unrestricted file upload vulnerability in admin/upload_form.php in wPortfolio 0.3 and earlier allows remote attackers to
28RIESGO
abrir
Referência
CVE-2023-34124
The authentication mechanism in SonicWall GMS and Analytics Web Services had insufficient checks, allowing authenticatio
75RIESGO
abrir
Referência
CVE-2007-6258
Multiple stack-based buffer overflows in the legacy mod_jk2 2.0.3-DEV and earlier Apache module allow remote attackers t
35RIESGO
abrir
ReferênciaVexDay Proof
Winamp 5.551 - MAKI Parsing Integer Overflow (PoC)
CVE-2009-1831doswindows
The Nullsoft Modern Skins Support module (gen_ff.dll) in Nullsoft Winamp before 5.552 allows remote attackers to execute
50RIESGO
abrir
Referência
CVE-2014-8676
Directory traversal vulnerability in the file_get_contents function in SOPlanning 1.32 and earlier allows remote attacke
50RIESGO
abrir
Referência
CVE-2014-8676
Directory traversal vulnerability in the file_get_contents function in SOPlanning 1.32 and earlier allows remote attacke
50RIESGO
abrir
Referência
CVE-2017-7442
Nitro Pro 11.0.3.173 allows remote attackers to execute arbitrary code via saveAs and launchURL calls with directory tra
50RIESGO
abrir
Referência
CVE-2018-7583
Proxy.exe in DualDesk 20 allows Remote Denial Of Service (daemon crash) via a long string to TCP port 5500.
35RIESGO
abrir
Referência
CVE-2021-25297
CVE-2021-25297HIGHbajo ataque
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi
98RIESGO
abrir
Referência
CVE-2023-1730
SupportCandy < 3.1.5 - Unauthenticated SQLi
75RIESGO
abrir
Referência
CVE-2018-1000094
CMS Made Simple version 2.2.5 contains a Remote Code Execution vulnerability in File Manager that can result in Allows a
50RIESGO
abrir
Referência
CVE-2022-36446
software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.
60RIESGO
abrir
Referência
CVE-2012-5223
The proc_deutf function in includes/functions_vbseocp_abstract.php in vBSEO 3.5.0, 3.5.1, 3.5.2, 3.6.0, and earlier allo
50RIESGO
abrir
Referência
CVE-2021-25156
A remote arbitrary directory create vulnerability was discovered in some Aruba Instant Access Point (IAP) products in ve
35RIESGO
abrir
Referência
CVE-2022-29548
A reflected XSS issue exists in the Management Console of several WSO2 products. This affects API Manager 2.2.0, 2.5.0,
60RIESGO
abrir
Referência
CVE-2012-4924
Buffer overflow in the CxDbgPrint function in the ipswcom.dll ActiveX component 1.0.0.1 for ASUS Net4Switch 1.0.0020 all
50RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.