Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
22.936 exploits
ReferênciaVexDay Proof
Shutter 0.1.1 - Multiple SQL Injections
CVE-2009-1650webappsphp
Multiple SQL injection vulnerabilities in photos.php in Shutter 0.1.1 allow remote attackers to execute arbitrary SQL co
23RIESGO
abrir
Referência
CVE-2024-20353
CVE-2024-20353HIGHbajo ataque
A vulnerability in the management and VPN web servers for Cisco Adaptive Security Appliance (ASA) Software and Cisco Fir
93RIESGO
abrir
Referência
CVE-2015-7768
Buffer overflow in Konica Minolta FTP Utility 1.0 allows remote attackers to execute arbitrary code via a long CWD comma
50RIESGO
abrir
Referência
CVE-2016-0151
CVE-2016-0151HIGHbajo ataqueransomware
The Client-Server Run-time Subsystem (CSRSS) in Microsoft Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1,
83RIESGO
abrir
Referência
CVE-2018-7422
A Local File Inclusion vulnerability in the Site Editor plugin through 1.1.1 for WordPress allows remote attackers to re
50RIESGO
abrir
Referência
CVE-2011-5003
Stack-based buffer overflow in the Phonetic Indexer (AvidPhoneticIndexer.exe) in Avid Media Composer 5.5.3 and earlier a
50RIESGO
abrir
Referência
CVE-2011-5165
Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted rem
50RIESGO
abrir
ReferênciaVexDay Proof
BBlog 0.7.6 - 'mod' SQL Injection
CVE-2008-4436webappsphp
SQL injection vulnerability in bblog_plugins/builtin.help.php in bBlog 0.7.6 allows remote attackers to execute arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Windows XP/2003 - IGMP v3 Denial of Service (MS06-007) (1)
CVE-2006-0021doswindows
Microsoft Windows XP SP1 and SP2, and Server 2003 up to SP1, allows remote attackers to cause a denial of service (hang)
35RIESGO
abrir
ReferênciaVexDay Proof
WordPress Plugin mygallery 1.4b4 - Remote File Inclusion
CVE-2007-2426webappsphp
PHP remote file inclusion vulnerability in myfunctions/mygallerybrowser.php in the myGallery 1.4b4 and earlier plugin fo
35RIESGO
abrir
ReferênciaVexDay Proof
The Recipe Script 5 - Authentication Bypass / Database Backup
CVE-2009-1662webappsphp
Multiple SQL injection vulnerabilities in admin/login.php in Wright Way Services Recipe Script 5 allow remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
XOOPS Module cjay content 3 - Remote File Inclusion
CVE-2007-3220webappsphp
PHP remote file inclusion vulnerability in admin/editor2/spaw_control.class.php in the Cjay Content 3 module for XOOPS a
35RIESGO
abrir
ReferênciaVexDay Proof
PHPNews 0.93 - 'format_menue' Remote File Inclusion
CVE-2007-4232webappsphp
PHP remote file inclusion vulnerability in admin/inc/change_action.php in Andreas Robertz PHPNews 0.93 allows remote att
35RIESGO
abrir
ReferênciaVexDay Proof
mIRC 6.34 - Remote Buffer Overflow (PoC)
CVE-2008-4449doswindows
Stack-based buffer overflow in mIRC 6.34 allows remote attackers to execute arbitrary code via a long hostname in a PRIV
50RIESGO
abrir
Referência
CVE-2015-1171
Stack-based buffer overflow in GSM SIM Utility (aka SIM Card Editor) 6.6 allows remote attackers to execute arbitrary co
50RIESGO
abrir
Referência
CVE-2012-6708
jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks. The jQuery(strInput) function does not differen
23RIESGO
abrir
Referência
CVE-2019-13396
FlightPath 4.x and 5.0-x allows directory traversal and Local File Inclusion through the form_include parameter in an in
50RIESGO
abrir
Referência
CVE-2012-6708
jQuery before 1.9.0 is vulnerable to Cross-site Scripting (XSS) attacks. The jQuery(strInput) function does not differen
23RIESGO
abrir
Referência
CVE-2017-8487
Windows OLE in Windows XP and Windows Server 2003 allows an attacker to execute code when a victim opens a specially cra
35RIESGO
abrir
Referência
CVE-2018-8617
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
35RIESGO
abrir
ReferênciaVexDay Proof
ESET SysInspector 1.1.1.0 - 'esiadrv.sys' (PoC)
CVE-2008-4451doswindows
The SysInspector AntiStealth driver (esiasdrv.sys) 3.0.65535.0 in ESET System Analyzer Tool 1.1.1.0 allows local users t
23RIESGO
abrir
Referência
CVE-2018-6329
It was discovered that the Unitrends Backup (UB) before 10.1.0 libbpext.so authentication could be bypassed with a SQL i
50RIESGO
abrir
Referência
CVE-2018-6329
It was discovered that the Unitrends Backup (UB) before 10.1.0 libbpext.so authentication could be bypassed with a SQL i
50RIESGO
abrir
Referência
CVE-2017-11839
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, version 1709 allows a
35RIESGO
abrir
Referência
CVE-2011-5165
Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted rem
50RIESGO
abrir
Referência
CVE-2011-5165
Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted rem
50RIESGO
abrir
Referência
CVE-2011-5165
Stack-based buffer overflow in Free MP3 CD Ripper 1.1, 2.6 and earlier, when converting a file, allows user-assisted rem
50RIESGO
abrir
ReferênciaVexDay Proof
The Net Guys ASPired2Protect - Database Disclosure
CVE-2008-6355webappsasp
The Net Guys ASPired2Protect stores sensitive information under the web root with insufficient access control, which all
23RIESGO
abrir
Referência
CVE-2009-3209
SQL injection vulnerability in remove.php in PHP eMail Manager 3.3.0 allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir
Referência
CVE-2014-3888
Stack-based buffer overflow in BKFSim_vhfd.exe in Yokogawa CENTUM CS 1000, CENTUM CS 3000 R3.09.50 and earlier, CENTUM V
50RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.