Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.900exploits catalogados
35.840CVEs con explotación pública
24.695probados en laboratorio
22.600 exploits
ReferênciaVexDay Proof
2DayBiz Custom T-shirt Design - SQL Injection / Cross-Site Scripting
CVE-2009-1820webappsphp
Cross-site scripting (XSS) vulnerability in product.php in 2daybiz Custom T-shirt Design Script allows remote attackers
23RIESGO
abrir
Referência
CVE-2018-16836
Rubedo through 3.4.0 contains a Directory Traversal vulnerability in the theme component, allowing unauthenticated attac
50RIESGO
abrir
ReferênciaVexDay Proof
LimeSurvey (phpsurveyor) 1.49rc2 - Remote File Inclusion
CVE-2007-3632webappsphp
Multiple PHP remote file inclusion vulnerabilities in LimeSurvey (aka PHPSurveyor) 1.49RC2 allow remote attackers to exe
35RIESGO
abrir
Referência
CVE-2015-4133
Unrestricted file upload vulnerability in admin/scripts/FileUploader/php.php in the ReFlex Gallery plugin before 3.1.4 f
50RIESGO
abrir
Referência
CVE-2015-4133
Unrestricted file upload vulnerability in admin/scripts/FileUploader/php.php in the ReFlex Gallery plugin before 3.1.4 f
50RIESGO
abrir
ReferênciaVexDay Proof
HotScripts Clone - 'cid' SQL Injection
CVE-2008-6405webappsphp
SQL injection vulnerability in showcategory.php in Hotscripts Clone allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
Referência
CVE-2017-1000119
October CMS build 412 is vulnerable to PHP code execution in the file upload functionality resulting in site compromise
50RIESGO
abrir
Referência
CVE-2015-8399
Atlassian Confluence before 5.8.17 allows remote authenticated users to read configuration files via the decoratorName p
43RIESGO
abrir
Referência
CVE-2023-28502
Stack buffer overflow in UniRPC's udadmin_server service
75RIESGO
abrir
ReferênciaVexDay Proof
Microsoft DXMedia SDK 6 - 'SourceUrl' ActiveX Remote Code Execution
CVE-2007-4336remotewindows
Buffer overflow in the Live Picture Corporation DXSurface.LivePicture.FlashPix.1 (DirectTransform FlashPix) ActiveX cont
35RIESGO
abrir
Referência
CVE-2019-17662
ThinVNC 1.0b1 is vulnerable to arbitrary file read, which leads to a compromise of the VNC server. The vulnerability exi
60RIESGO
abrir
Referência
CVE-2020-3250
Multiple Vulnerabilities in Cisco UCS Director and Cisco UCS Director Express for Big Data
75RIESGO
abrir
Referência
CVE-2011-0257
Integer signedness error in Apple QuickTime before 7.7 allows remote attackers to execute arbitrary code or cause a deni
50RIESGO
abrir
Referência
CVE-2014-10021
Unrestricted file upload vulnerability in UploadHandler.php in the WP Symposium plugin 14.11 for WordPress allows remote
50RIESGO
abrir
Referência
CVE-2019-5485
NPM package gitlabhook version 0.0.17 is vulnerable to a Command Injection vulnerability. Arbitrary commands can be inje
35RIESGO
abrir
Referência
CVE-2017-11841
ChakraCore and Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, Windows Server 2016 and Windows Server, versio
35RIESGO
abrir
Referência
CVE-2017-11870
ChakraCore and Microsoft Edge in Windows 10 1703, 1709, and Windows Server, version 1709 allows an attacker to gain the
35RIESGO
abrir
Referência
Servisnet Tessa - Add sysAdmin User (Unauthenticated) (Metasploit)
CVE-2022-22831webappsmultiple
An issue was discovered in Servisnet Tessa 0.0.2. An attacker can add a new sysadmin user via a manipulation of the Auth
28RIESGO
abrir
Referência
CVE-2016-3074
Integer signedness error in GD Graphics Library 2.1.1 (aka libgd or libgd2) allows remote attackers to cause a denial of
35RIESGO
abrir
Referência
CVE-2022-22832
An issue was discovered in Servisnet Tessa 0.0.2. Authorization data is available via an unauthenticated /data-service/u
28RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component prayercenter 1.4.9 - 'id' SQL Injection
CVE-2008-6429webappsphp
SQL injection vulnerability in the PrayerCenter (com_prayercenter) component 1.4.9 and earlier for Joomla! allows remote
23RIESGO
abrir
ReferênciaVexDay Proof
Elkagroup Image Gallery 1.0 - Arbitrary File Upload
CVE-2009-1446webappsphp
Unrestricted file upload vulnerability in upload.php in Elkagroup Image Gallery 1.0 allows remote authenticated users to
23RIESGO
abrir
Referência
CVE-2012-2576
SQL injection vulnerability in the LoginServlet page in SolarWinds Storage Manager before 5.1.2, SolarWinds Storage Prof
50RIESGO
abrir
Referência
CVE-2009-3260
Cross-site scripting (XSS) vulnerability in LiveStreet 0.2 allows remote attackers to inject arbitrary web script or HTM
23RIESGO
abrir
Referência
CVE-2025-34030
sar2html OS Command Injection
75RIESGO
abrir
Referência
CVE-2008-2463
The Microsoft Office Snapshot Viewer ActiveX control in snapview.ocx 10.0.5529.0, as distributed in the standalone Snaps
50RIESGO
abrir
Referência
CVE-2017-17562
CVE-2017-17562HIGHbajo ataque
Embedthis GoAhead before 3.6.5 allows remote code execution if CGI is enabled and a CGI program is dynamically linked. T
100RIESGO
abrir
Referência
CVE-2018-6065
CVE-2018-6065HIGHbajo ataque
Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Ch
83RIESGO
abrir
ReferênciaVexDay Proof
e107 Plugin BLOG Engine 2.2 - 'uid' SQL Injection
CVE-2008-6438webappsphp
SQL injection vulnerability in macgurublog_menu/macgurublog.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows re
23RIESGO
abrir
Referência
CVE-2021-33393
lfs/backup in IPFire 2.25-core155 does not ensure that /var/ipfire/backup/bin/backup.pl is owned by the root account. It
50RIESGO
abrir
anteriorpágina 595 / 754siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.