Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.305exploits catalogados
36.465CVEs con explotación pública
24.695probados en laboratorio
22.936 exploits
Referência
CVE-2014-3888
Stack-based buffer overflow in BKFSim_vhfd.exe in Yokogawa CENTUM CS 1000, CENTUM CS 3000 R3.09.50 and earlier, CENTUM V
50RIESGO
abrir
Referência
CVE-2017-6622
A vulnerability in the web interface for Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote a
35RIESGO
abrir
Referência
CVE-2023-28503
Authentication bypass in UniRPC's udadmin service
75RIESGO
abrir
Referência
CVE-2018-8384
A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Mi
35RIESGO
abrir
Referência
CVE-2019-6447
The ES File Explorer File Manager application through 4.1.9.7.4 for Android allows remote attackers to read arbitrary fi
50RIESGO
abrir
ReferênciaVexDay Proof
vxFtpSrv 2.0.3 - 'CWD' Remote Buffer Overflow (PoC)
CVE-2008-4452doswindows
Buffer overflow in Cambridge Computer Corporation vxFtpSrv 2.0.3 allows remote attackers to cause a denial of service (c
23RIESGO
abrir
ReferênciaVexDay Proof
MySQL Quick Admin 1.5.5 - 'cookie' Local File Inclusion
CVE-2008-4455webappsphp
Directory traversal vulnerability in index.php in EKINdesigns MySQL Quick Admin 1.5.5 and earlier, when magic_quotes_gpc
23RIESGO
abrir
Referência
CVE-2013-0135
Multiple SQL injection vulnerabilities in PHP Address Book 8.2.5 allow remote attackers to execute arbitrary SQL command
23RIESGO
abrir
Referência
CVE-2015-5477
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RIESGO
abrir
ReferênciaVexDay Proof
CHILKAT ASP String - 'CkString.dll 1.1 SaveToFile()' Insecure Method
CVE-2007-4252remotewindows
Absolute path traversal vulnerability in a certain ActiveX control in CkString.dll 1.1 and earlier in CHILKAT ASP String
23RIESGO
abrir
ReferênciaVexDay Proof
my-colex 1.4.2 - Authentication Bypass / SQL Injection / Cross-Site Scripting
CVE-2009-1809webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in myColex 1.4.2 allow remote attackers to inject arbitrary web scri
23RIESGO
abrir
Referência
CVE-2015-5477
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RIESGO
abrir
Referência
CVE-2017-0059
CVE-2017-0059MEDIUMbajo ataque
Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via
75RIESGO
abrir
Referência
CVE-2017-0059
CVE-2017-0059MEDIUMbajo ataque
Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via
75RIESGO
abrir
Referência
CVE-2017-0059
CVE-2017-0059MEDIUMbajo ataque
Microsoft Internet Explorer 9 through 11 allow remote attackers to obtain sensitive information from process memory via
75RIESGO
abrir
Referência
CVE-2015-2208
The saveObject function in moadmin.php in phpMoAdmin 1.1.2 allows remote attackers to execute arbitrary commands via she
50RIESGO
abrir
Referência
CVE-2015-5477
named in ISC BIND 9.x before 9.9.7-P2 and 9.10.x before 9.10.2-P3 allows remote attackers to cause a denial of service (
60RIESGO
abrir
Referência
CVE-2020-0618
CVE-2020-0618CRITICALbajo ataqueransomware
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page
100RIESGO
abrir
Referência
CVE-2008-4458
SQL injection vulnerability in listings.php in E-Php B2B Trading Marketplace Script allows remote attackers to execute a
23RIESGO
abrir
Referência
CVE-2020-0618
CVE-2020-0618CRITICALbajo ataqueransomware
A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page
100RIESGO
abrir
ReferênciaVexDay Proof
Vastal I-Tech Dating Zone - 'fage' SQL Injection
CVE-2008-4461webappsphp
SQL injection vulnerability in advanced_search_results.php in Vastal I-Tech Dating Zone, possibly 0.9.9, allows remote a
23RIESGO
abrir
ReferênciaVexDay Proof
Banner Exchange Java - Authentication Bypass
CVE-2008-6364webappsasp
SQL injection vulnerability in logon_process.jsp in Ad Server Solutions Banner Exchange Solution Java allows remote atta
23RIESGO
abrir
Referência
CVE-2020-0646
CVE-2020-0646CRITICALbajo ataque
A remote code execution vulnerability exists when the Microsoft .NET Framework fails to validate input properly, aka '.N
100RIESGO
abrir
ReferênciaVexDay Proof
2DayBiz Custom T-shirt Design - SQL Injection / Cross-Site Scripting
CVE-2009-1820webappsphp
Cross-site scripting (XSS) vulnerability in product.php in 2daybiz Custom T-shirt Design Script allows remote attackers
23RIESGO
abrir
Referência
CVE-2009-4660
Stack-based buffer overflow in the AntServer Module (AntServer.exe) in BigAnt IM Server 2.50 allows remote attackers to
50RIESGO
abrir
ReferênciaVexDay Proof
Vastal I-Tech Visa Zone - 'news_id' SQL Injection
CVE-2008-4462webappsphp
SQL injection vulnerability in view_news.php in Vastal I-Tech Visa Zone allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
Referência
CVE-2015-1793
The X509_verify_cert function in crypto/x509/x509_vfy.c in OpenSSL 1.0.1n, 1.0.1o, 1.0.2b, and 1.0.2c does not properly
50RIESGO
abrir
Referência
CVE-2025-34152
Shenzhen Aitemi M300 Wi-Fi Repeater OS Command Injection via Time Parameter
75RIESGO
abrir
Referência
CVE-2016-1209
The Ninja Forms plugin before 2.9.42.1 for WordPress allows remote attackers to conduct PHP object injection attacks via
50RIESGO
abrir
Referência
CVE-2017-8835
SQL injection exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw
50RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.