Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.900exploits catalogados
35.840CVEs con explotación pública
24.695probados en laboratorio
22.573 exploits
Referência
CVE-2017-6529
An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to session hijacking by guessing the UID pa
23RIESGO
abrir
Referência
CVE-2010-1934
Multiple PHP remote file inclusion vulnerabilities in openMairie openPlanning 1.00, when register_globals is enabled, al
23RIESGO
abrir
Referência
CVE-2010-1934
Multiple PHP remote file inclusion vulnerabilities in openMairie openPlanning 1.00, when register_globals is enabled, al
23RIESGO
abrir
Referência
CVE-2024-13979
St. Joe ERP System SingleRowQueryConverter SQL Injection
63RIESGO
abrir
Referência
CVE-2024-13979
St. Joe ERP System SingleRowQueryConverter SQL Injection
63RIESGO
abrir
Referência
CVE-2018-10118
Monstra CMS 3.0.4 has Stored XSS via the Name field on the Create New Page screen under the admin/index.php?id=pages URI
23RIESGO
abrir
ReferênciaVexDay Proof
Entertainment CMS - Local File Inclusion / Remote Command Execution
CVE-2007-4008webappsphp
Directory traversal vulnerability in custom.php in Entertainment Media Sharing CMS allows remote attackers to include an
23RIESGO
abrir
ReferênciaVexDay Proof
freeSSHd 1.2.1 - (Authenticated) SFTP 'rename' Remote Buffer Overflow (PoC)
CVE-2008-4762doswindows
Stack-based buffer overflow in freeSSHd 1.2.1 allows remote authenticated users to cause a denial of service (service cr
28RIESGO
abrir
ReferênciaVexDay Proof
Social Site Generator 2.0 - 'path' Remote File Inclusion
CVE-2008-6421webappsphp
PHP remote file inclusion vulnerability in social_game_play.php in Social Site Generator (SSG) 2.0 allows remote attacke
23RIESGO
abrir
ReferênciaVexDay Proof
2532/Gigs 1.2.1 - 'activateuser.php' Local File Inclusion
CVE-2007-4585webappsphp
Directory traversal vulnerability in activateuser.php in 2532|Gigs 1.2.1 allows remote attackers to include and execute
23RIESGO
abrir
Referência
CVE-2009-2773
PHP remote file inclusion vulnerability in home.php in PHP Paid 4 Mail Script allows remote attackers to execute arbitra
23RIESGO
abrir
Referência
CVE-2009-4475
SQL injection vulnerability in the Joomlub (com_joomlub) component for Joomla! allows remote attackers to execute arbitr
23RIESGO
abrir
Referência
CVE-2023-31067
An issue was discovered in TSplus Remote Access through 16.0.2.14. There are Full Control permissions for Everyone on so
23RIESGO
abrir
Referência
CVE-2010-1935
Directory traversal vulnerability in scr/soustab.php in openMairie Openpresse 1.01, when register_globals is enabled, al
23RIESGO
abrir
Referência
CVE-2017-2516
An issue was discovered in certain Apple products. macOS before 10.12.5 is affected. The issue involves the "Kernel" com
23RIESGO
abrir
Referência
CVE-2005-3294
Typsoft FTP Server 1.11, with "Sub Directory Include" enabled, allows remote attackers to cause a denial of service (cra
23RIESGO
abrir
Referência
Terratec dmx_6fire USB - Unquoted Service Path
CVE-2024-31804MEDIUMlocalwindows_x86-64
An unquoted service path vulnerability in Terratec DMX_6Fire USB v.1.23.0.02 allows a local attacker to escalate privile
33RIESGO
abrir
Referência
Flowise 1.6.5 - Authentication Bypass
CVE-2024-31621HIGHwebappstypescript
An issue in FlowiseAI Inc Flowise v.1.6.2 and before allows a remote attacker to execute arbitrary code via a crafted sc
68RIESGO
abrir
Referência
CVE-2011-4341
Multiple SQL injection vulnerabilities in symphony/content/content.publish.php in Symphony CMS 2.2.3 and possibly other
23RIESGO
abrir
Referência
CVE-2014-4492
libnetcore in Apple iOS before 8.1.3, Apple OS X before 10.10.2, and Apple TV before 7.0.3 does not verify that certain
28RIESGO
abrir
ReferênciaVexDay Proof
D-Link MPEG4 SHM Audio Control - 'VAPGDecoder.dll 1.7.0.5' Remote Buffer Overflow
CVE-2008-4771remotewindows
Stack-based buffer overflow in VATDecoder.VatCtrl.1 ActiveX control in (1) 4xem VatCtrl Class (VATDecoder.dll 1.0.0.27 a
23RIESGO
abrir
Referência
CVE-2010-4615
Multiple SQL injection vulnerabilities in Oto Galeri Sistemi 1.0 allow remote attackers to execute arbitrary SQL command
23RIESGO
abrir
Referência
CVE-2012-1936
The wp_create_nonce function in wp-includes/pluggable.php in WordPress 3.3.1 and earlier associates a nonce with a user
23RIESGO
abrir
ReferênciaVexDay Proof
vbPortal 3.0.2 < 3.6.0 b1 - 'cookie' Remote Code Execution
CVE-2006-4004webappsphp
Directory traversal vulnerability in index.php in vbPortal 3.0.2 through 3.6.0 Beta 1, when magic_quotes_gpc is disabled
23RIESGO
abrir
Referência
CVE-2019-10893
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.793 (Free/Open Source Version) and 0.9.8.753 (Pro) is vulnerable to
23RIESGO
abrir
Referência
CVE-2019-10893
CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.793 (Free/Open Source Version) and 0.9.8.753 (Pro) is vulnerable to
23RIESGO
abrir
ReferênciaVexDay Proof
Dew-NewPHPLinks 2.0 - Local File Inclusion / Cross-Site Scripting
CVE-2009-1624webappsphp
Directory traversal vulnerability in index.php in Dew-NewPHPLinks 2.0 allows remote attackers to read arbitrary files vi
23RIESGO
abrir
ReferênciaVexDay Proof
Avax Vector 'Avaxswf.dll' 1.0.0.1 - ActiveX Arbitrary Data Write
CVE-2007-3459remotewindows
A certain ActiveX control in Avaxswf.dll 1.0.0.1 in Civitech Avax Vector 1.3 allows remote attackers to create or overwr
23RIESGO
abrir
ReferênciaVexDay Proof
osCommerce Addon Customer Testimonials 3.1 - SQL Injection
CVE-2008-0719webappsphp
SQL injection vulnerability in customer_testimonials.php in the Customer Testimonials 3 and 3.1 Addon for osCommerce Onl
23RIESGO
abrir
Referência
CVE-2018-0745
The Windows kernel in Windows 10 version 1703. Windows 10 version 1709, and Windows Server, version 1709 allows an infor
23RIESGO
abrir
anteriorpágina 583 / 753siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.