Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

71.760exploits catalogados
32.083CVEs con explotación pública
1932probados en laboratorio
19.934 exploits
Referência
CVE-2018-14665
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
43RIESGO
abrir
Referência
CVE-2018-14665
A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options wh
43RIESGO
abrir
Referência
WordPress Core 6.2 - Directory Traversal
WordPress Core < 6.2.1 - Directory Traversal
70RIESGO
abrir
Referência
CVE-2021-25162
A remote execution of arbitrary commands vulnerability was discovered in some Aruba Instant Access Point (IAP) products
28RIESGO
abrir
Referência
Qt QuickTeam - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in Qt quickteam 2 allow remote attackers to execute arbitrary PHP cod
28RIESGO
abrir
Referência
CVE-2019-16405
Centreon Web before 2.8.30, 18.10.x before 18.10.8, 19.04.x before 19.04.5 and 19.10.x before 19.10.2 allows Remote Code
28RIESGO
abrir
Referência
Small Axe 0.3.1 - 'cfile' Remote File Inclusion
PHP remote file inclusion vulnerability in inc/linkbar.php in Small Axe Weblog 0.3.1 allows remote attackers to execute
35RIESGO
abrir
Referência
CVE-2013-2570
A Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 in the General.Time.NTP.Server parameter to t
28RIESGO
abrir
Referência
CVE-2013-6225
LiveZilla 5.0.1.4 has a Remote Code Execution vulnerability
28RIESGO
abrir
Referência
CVE-2020-5515
Gila CMS 1.11.8 allows /admin/sql?query= SQL Injection.
28RIESGO
abrir
Referência
CVE-2020-5515
Gila CMS 1.11.8 allows /admin/sql?query= SQL Injection.
28RIESGO
abrir
Referência
CVE-2010-4598
Directory traversal vulnerability in Ecava IntegraXor 3.6.4000.0 and earlier allows remote attackers to read arbitrary f
28RIESGO
abrir
Referência
CVE-2019-13359
In CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.836, a cwpsrv-xxx cookie allows a normal user to craft and uploa
28RIESGO
abrir
Referência
CVE-2018-4935
Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds write vulnerability. Successful exp
28RIESGO
abrir
Referência
CVE-2018-4937
Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds write vulnerability. Successful exp
28RIESGO
abrir
Referência
CVE-2016-10036
Unrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to
28RIESGO
abrir
Referência
CVE-2016-10036
Unrestricted file upload vulnerability in ui/artifact/upload in JFrog Artifactory before 4.16 allows remote attackers to
28RIESGO
abrir
Referência
CVE-2021-24563
Frontend Uploader <= 1.3.2 - Unauthenticated Stored Cross-Site Scripting
28RIESGO
abrir
Referência
CVE-2017-16642
In PHP before 5.6.32, 7.x before 7.0.25, and 7.1.x before 7.1.11, an error in the date extension's timelib_meridian hand
28RIESGO
abrir
Referência
CVE-2015-2998
SysAid Help Desk before 15.2 uses a hardcoded encryption key, which makes it easier for remote attackers to obtain sensi
43RIESGO
abrir
Referência
CVE-2020-8196
CVE-2020-8196MEDIUMbajo ataque
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14
68RIESGO
abrir
Referência
CVE-2018-0708
Command injection vulnerability in networking of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allo
28RIESGO
abrir
Referência
CVE-2018-0708
Command injection vulnerability in networking of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allo
28RIESGO
abrir
Referência
CVE-2018-5347
Seagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the uploadTelemetry and getLogs
35RIESGO
abrir
Referência
CVE-2008-6132
Eval injection vulnerability in reserve.php in phpScheduleIt 1.2.10 and earlier, when magic_quotes_gpc is disabled, allo
43RIESGO
abrir
Referência
CVE-2008-6132
Eval injection vulnerability in reserve.php in phpScheduleIt 1.2.10 and earlier, when magic_quotes_gpc is disabled, allo
43RIESGO
abrir
Referência
ManageEngine OpManager 12.4x - Unauthenticated Remote Command Execution (Metasploit)
An issue was discovered in Zoho ManageEngine OpManager in builds before 14310. One can bypass the user password requirem
28RIESGO
abrir
Referência
CVE-2015-3073
Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass inten
28RIESGO
abrir
Referência
CVE-2013-2097
ZPanel through 10.1.0 has Remote Command Execution
43RIESGO
abrir
Referência
CVE-2013-2097
ZPanel through 10.1.0 has Remote Command Execution
43RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.