Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
71.957exploits catalogados
32.195CVEs con explotación pública
1932probados en laboratorio
TodosExploit-DB 22.786Referência 20.003GitHub PoC 13.307VulnCheck XDB 8182Nuclei 4217Metasploit 3462✓ solo verificadosrecientespopularesriesgo
20.003 exploits
Referência
Joomla! Component RWCards 3.0.11 - Local File Inclusion
Directory traversal vulnerability in captcha/captcha_image.php in the RWCards (com_rwcards) 3.0.11 component for Joomla!
43RIESGO
abrir ↗Referência
CVE-2007-3655
Stack-based buffer overflow in javaws.exe in Sun Java Web Start in JRE 5.0 Update 11 and earlier, and 6.0 Update 1 and e
28RIESGO
abrir ↗Referência
CVE-2014-100015
Directory traversal vulnerability in pdmwService.exe in SolidWorks Workgroup PDM 2014 allows remote attackers to write t
50RIESGO
abrir ↗Referência
CVE-2017-7185
Use-after-free vulnerability in the mg_http_multipart_wait_for_boundary function in mongoose.c in Cesanta Mongoose Embed
28RIESGO
abrir ↗Referência
CVE-2015-1375
pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not properly restrict access to the upload
28RIESGO
abrir ↗Referência
CVE-2015-1375
pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not properly restrict access to the upload
28RIESGO
abrir ↗Referência
CVE-2019-17554
The XML content type entity deserializer in Apache Olingo versions 4.0.0 to 4.6.0 is not configured to deny the resoluti
28RIESGO
abrir ↗Referência
CVE-2021-36711
WebInterface in OctoBot before 0.4.4 allows remote code execution because Tentacles upload is mishandled.
28RIESGO
abrir ↗Referência
CVE-2011-4878
Directory traversal vulnerability in miniweb.exe in the HMI web server in Siemens WinCC flexible 2004, 2005, 2007, and 2
28RIESGO
abrir ↗Referência
Online Fantasy Football League (OFFL) 0.2.6 - Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in Online Fantasy Football League (OFFL) 0.2.6 allow remote attackers
35RIESGO
abrir ↗Referência
vsftpd 2.0.5 - 'CWD' (Authenticated) Remote Memory Consumption
Memory leak in a certain Red Hat patch, applied to vsftpd 2.0.5 on Red Hat Enterprise Linux (RHEL) 5 and Fedora 6 throug
28RIESGO
abrir ↗Referência
CVE-2008-4128
Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the
68RIESGO
abrir ↗Referência
MySpace Uploader - 'MySpaceUploader.ocx 1.0.0.4' Remote Buffer Overflow
Stack-based buffer overflow in Aurigma Image Uploader ActiveX control (ImageUploader4.ocx) 4.5.70 and earlier, as used i
35RIESGO
abrir ↗Referência
CVE-2018-10956
IPConfigure Orchid Core VMS 2.0.5 allows Directory Traversal.
50RIESGO
abrir ↗Referência
CVE-2018-10956
IPConfigure Orchid Core VMS 2.0.5 allows Directory Traversal.
50RIESGO
abrir ↗Referência
Cisco Router - HTTP Administration Cross-Site Request Forgery / Command Execution (1)
Multiple cross-site request forgery (CSRF) vulnerabilities in the HTTP Administration component in Cisco IOS 12.4 on the
68RIESGO
abrir ↗Referência
CVE-2016-9722
IBM QRadar 7.2 and 7.3 specifies permissions for a security-critical resource in a way that allows that resource to be r
43RIESGO
abrir ↗Referência
xeCMS 1.0.0 RC2 - Insecure Cookie Handling
admin.php in xeCMS 1.0.0 RC2 and earlier allows remote attackers to bypass authentication and access the admin panel by
28RIESGO
abrir ↗Referência
LoveCMS 1.6.2 Final - Remote Code Execution
LoveCMS 1.6.2 does not require administrative authentication for (1) addblock.php, (2) blocks.php, and (3) themes.php in
23RIESGO
abrir ↗Referência
CVE-2014-9241
Multiple cross-site scripting (XSS) vulnerabilities in MyBB (aka MyBulletinBoard) 1.8.x before 1.8.2 allow remote attack
23RIESGO
abrir ↗Referência
CVE-2019-9053
An issue was discovered in CMS Made Simple 2.2.8. It is possible with the News module, through a crafted URL, to achieve
35RIESGO
abrir ↗Referência
CVE-2014-5289
Buffer overflow in Senkas Kolibri 2.0 allows remote attackers to execute arbitrary code via a long URI in a POST request
28RIESGO
abrir ↗Referência
CVE-2010-3894
Stack-based buffer overflow in the Java_com_ibm_es_oss_CryptionNative_ESEncrypt function in /opt/IBM/es/lib/libffq.crypt
28RIESGO
abrir ↗Referência
WordPress MU < 1.3.2 - 'active_plugins' Code Execution
wp-admin/options.php in WordPress MU before 1.3.2, and WordPress 2.3.2 and earlier, does not properly validate requests
28RIESGO
abrir ↗Referência
Solaris 9 PortBind - XDR-DECODE 'taddr2uaddr()' Remote Denial of Service
The RPC subsystem in Sun Solaris 9 allows remote attackers to cause a denial of service (daemon crash) via a crafted req
28RIESGO
abrir ↗Referência
CVE-2016-5677
NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.
28RIESGO
abrir ↗Referência
Hannon Hill Cascade Server - (Authenticated) Command Execution
Hannon Hill Cascade Server 5.7 and other versions allows remote authenticated users to execute arbitrary programs or Jav
28RIESGO
abrir ↗Referência
Citadel SMTP 7.10 - Remote Overflow
Buffer overflow in Citadel SMTP server 7.10 and earlier allows remote attackers to execute arbitrary code via a long RCP
28RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.