Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.056exploits catalogados
35.925CVEs con explotación pública
24.695probados en laboratorio
22.600 exploits
Referência
CVE-2010-2028
Buffer overflow in k23productions TFTPUtil GUI (aka TFTPGUI) 1.4.5 allows remote attackers to cause a denial of service
28RIESGO
abrir
Referência
CVE-2012-10059
Dolibarr ERP/CRM Post-Auth OS Command Injection
63RIESGO
abrir
Referência
CVE-2012-10059
Dolibarr ERP/CRM Post-Auth OS Command Injection
63RIESGO
abrir
Referência
CVE-2012-10059
Dolibarr ERP/CRM Post-Auth OS Command Injection
63RIESGO
abrir
Referência
CVE-2018-0880
The Desktop Bridge in Windows 10 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an el
23RIESGO
abrir
Referência
CVE-2025-35028
HexStrike AI MCP Server Command Injection
48RIESGO
abrir
Referência
CVE-2012-3524
libdbus 1.5.x and earlier, when used in setuid or other privileged programs in X.org and possibly other products, allows
23RIESGO
abrir
Referência
CVE-2019-19032
XMLBlueprint through 16.191112 is affected by XML External Entity Injection. The impact is: Arbitrary File Read when an
23RIESGO
abrir
Referência
CVE-2018-13457
qh_echo in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to
23RIESGO
abrir
Referência
CVE-2014-1906
Multiple cross-site scripting (XSS) vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5
23RIESGO
abrir
ReferênciaVexDay Proof
fresh email script 1.0 - Multiple Vulnerabilities
CVE-2008-7043webappsphp
Cross-site scripting (XSS) vulnerability in register.php in FreshScripts Fresh Email Script 1.0 through 1.11 allows remo
23RIESGO
abrir
Referência
CVE-2020-7680
docsify prior to 4.11.4 is susceptible to Cross-site Scripting (XSS). Docsify.js uses fragment identifiers (parameters a
23RIESGO
abrir
Referência
CVE-2020-7680
docsify prior to 4.11.4 is susceptible to Cross-site Scripting (XSS). Docsify.js uses fragment identifiers (parameters a
23RIESGO
abrir
Referência
CVE-2011-5033
Stack-based buffer overflow in CFS.c in ConfigServer Security & Firewall (CSF) before 5.43, when running on a DirectAdmi
23RIESGO
abrir
ReferênciaVexDay Proof
TorrentTrader Classic 1.09 - Multiple Vulnerabilities
CVE-2009-2158webappsphp
account-recover.php in TorrentTrader Classic 1.09 chooses random passwords from an insufficiently large set, which makes
23RIESGO
abrir
ReferênciaVexDay Proof
PPC Search Engine 1.61 - 'INC' Multiple Remote File Inclusions
CVE-2007-0167webappsphp
Multiple PHP file inclusion vulnerabilities in WGS-PPC (aka PPC Search Engine), as distributed with other aliases, allow
28RIESGO
abrir
Referência
CVE-2009-4092
Cross-site request forgery (CSRF) vulnerability in user.php in Simplog 0.9.3.2, and possibly earlier, allows remote atta
23RIESGO
abrir
Referência
CVE-2011-5039
Multiple SQL injection vulnerabilities in Infoproject Biznis Heroj allow remote attackers to execute arbitrary SQL comma
23RIESGO
abrir
Referência
CVE-2018-20782
The GloBee plugin before 1.1.2 for WooCommerce mishandles IPN messages.
23RIESGO
abrir
Referência
CVE-2021-28379
web/upload/UploadHandler.php in Vesta Control Panel (aka VestaCP) through 0.9.8-27 and myVesta through 0.9.8-26-39 allow
23RIESGO
abrir
Referência
CVE-2013-2474
Directory traversal vulnerability in AWS XMS 2.5 allows remote attackers to view arbitrary files via the 'what' paramete
28RIESGO
abrir
ReferênciaVexDay Proof
Hewlett Packard 1.0.0.309 - 'hpqvwocx.dll' ActiveX Magview Overflow (PoC)
CVE-2007-2656doswindows
Stack-based buffer overflow in the Hewlett-Packard (HP) Magview ActiveX control in hpqvwocx.dll 1.0.0.309 allows remote
23RIESGO
abrir
Referência
CVE-2013-0238
The try_parse_v4_netmask function in hostmask.c in IRCD-Hybrid before 8.0.6 does not properly validate masks, which allo
23RIESGO
abrir
Referência
CVE-2015-2291
CVE-2015-2291HIGHbajo ataqueransomware
(1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows all
71RIESGO
abrir
ReferênciaVexDay Proof
Ipswitch WS_FTP Home/Professional FTP Client - Remote Format String (PoC)
CVE-2008-3734doswindows
Format string vulnerability in Ipswitch WS_FTP Home 2007.0.0.2 and WS_FTP Professional 2007.1.0.0 allows remote FTP serv
28RIESGO
abrir
Referência
CVE-2018-7538
A SQL injection vulnerability in the tracker functionality of Enalean Tuleap software engineering platform before 9.18 a
23RIESGO
abrir
Referência
CVE-2016-9351
An issue was discovered in Advantech SUISAccess Server Version 3.0 and prior. The directory traversal/file upload error
23RIESGO
abrir
Referência
CVE-2009-4097
Stack-based buffer overflow in the MplayInputFile function in Serenity Audio Player 3.2.3 and earlier allows remote atta
23RIESGO
abrir
Referência
CVE-2014-3120
CVE-2014-3120HIGHbajo ataque
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execut
100RIESGO
abrir
ReferênciaVexDay Proof
NVR SP2 2.0 'nvUnifiedControl.dll 1.1.45.0' - 'SetText()' Command Execution
CVE-2007-4582remotewindows
Buffer overflow in the nvUnifiedControl.AUnifiedControl.1 ActiveX control in nvUnifiedControl.dll 1.1.45.0 in ACTi Netwo
23RIESGO
abrir
anteriorpágina 617 / 754siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.