Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

72.018exploits catalogados
32.219CVEs con explotación pública
1932probados en laboratorio
20.023 exploits
Referência
Printix Client 1.3.1106.0 - Privilege Escalation
Printix Secure Cloud Print Management through 1.3.1106.0 creates a temporary temp.ini file in a directory with insecure
28RIESGO
abrir
Referência
UltimateHG/CVE-2025-52689-PoC
Weak Session ID Check in the OmniAccess Stellar Web Management Interface
53RIESGO
abrir
Referência
CVE-2022-38580
Zalando Skipper v0.13.236 is vulnerable to Server-Side Request Forgery (SSRF).
53RIESGO
abrir
Referência
CVE-2015-6023
ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers with firmware before 3G10WVE-L101-S306ETS-C01_R05 allows remot
28RIESGO
abrir
Referência
CVE-2015-6023
ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers with firmware before 3G10WVE-L101-S306ETS-C01_R05 allows remot
28RIESGO
abrir
Referência
CVE-2013-1670
The Chrome Object Wrapper (COW) implementation in Mozilla Firefox before 21.0, Firefox ESR 17.x before 17.0.6, Thunderbi
28RIESGO
abrir
Referência
TopList 1.3.8 - 'phpBB Hack' Remote File Inclusion (1)
PHP remote file inclusion vulnerability in toplist.php in phpBB TopList 1.3.8 and earlier, when register_globals is enab
28RIESGO
abrir
Referência
TopList 1.3.8 - 'phpBB Hack' Remote File Inclusion (2)
PHP remote file inclusion vulnerability in toplist.php in phpBB TopList 1.3.8 and earlier, when register_globals is enab
28RIESGO
abrir
Referência
CVE-2018-5407
Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks
23RIESGO
abrir
Referência
CVE-2011-5212
SQL injection vulnerability in admin/index.php in Subrion CMS 2.0.4 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
Referência
CVE-2014-7221
TeamSpeak Client 3.0.14 and earlier allows remote authenticated users to cause a denial of service (buffer overflow and
28RIESGO
abrir
Referência
CVE-2014-7222
Buffer overflow in TeamSpeak Client 3.0.14 and earlier allows remote authenticated users to cause a denial of service (a
28RIESGO
abrir
Referência
CVE-2020-13144
Studio in Open edX Ironwood 2.5, when CodeJail is not used, allows a user to go to the "Create New course>New section>Ne
28RIESGO
abrir
Referência
CVE-2020-11060
Remote Code Execution in GLPI
46RIESGO
abrir
Referência
CVE-2010-3145
Untrusted search path vulnerability in the BitLocker Drive Encryption API, as used in sdclt.exe in Backup Manager in Mic
28RIESGO
abrir
Referência
CVE-2021-38648
CVE-2021-38648HIGHbajo ataque
Open Management Infrastructure Elevation of Privilege Vulnerability
91RIESGO
abrir
Referência
CVE-2009-3250
The saveForwardAttachments procedure in the Compose Mail functionality in vtiger CRM 5.0.4 allows remote authenticated u
28RIESGO
abrir
Referência
Sony CONNECT Player 4.x - '.m3u' Local Stack Overflow
Stack-based buffer overflow in Sony SonicStage CONNECT Player (CP) 4.3 allows remote attackers to execute arbitrary code
28RIESGO
abrir
Referência
Drupal 4.7 - 'Attachment mod_mime' Remote Command Execution
Drupal 4.6.x before 4.6.7 and 4.7.0, when running on Apache with mod_mime, does not properly handle files with multiple
28RIESGO
abrir
Referência
CVE-2009-2254
Zen Cart 1.3.8a, 1.3.8, and earlier does not require administrative authentication for admin/sqlpatch.php, which allows
28RIESGO
abrir
Referência
gxine 0.5.6 - HTTP Plugin Remote Buffer Overflow (PoC)
Buffer overflow in the HTTP Plugin (xineplug_inp_http.so) for xine-lib 1.1.1 allows remote attackers to cause a denial o
28RIESGO
abrir
Referência
CVE-2018-10123
p910nd on Inteno IOPSYS 2.0 through 4.2.0 allows remote attackers to read, or append data to, arbitrary files via reques
28RIESGO
abrir
Referência
CVE-2015-5452
SQL injection vulnerability in Watchguard XCS 9.2 and 10.0 before build 150522 allows remote attackers to execute arbitr
23RIESGO
abrir
Referência
Claroline 1.7.6 - 'includePath' Remote Code Execution
Multiple PHP remote file inclusion vulnerabilities in Claroline 1.7.6 allow remote attackers to execute arbitrary PHP co
28RIESGO
abrir
Referência
CVE-2014-8656
The Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOSH have a d
28RIESGO
abrir
Referência
CVE-2014-8656
The Compal Broadband Networks (CBN) CH6640E and CG6640E Wireless Gateway 1.0 with firmware CH6640-3.5.11.7-NOSH have a d
28RIESGO
abrir
Referência
CVE-2010-4259
Stack-based buffer overflow in FontForge 20100501 allows remote attackers to cause a denial of service (application cras
28RIESGO
abrir
Referência
CVE-2018-9302
SSRF (Server Side Request Forgery) in /assets/lib/fuc.js.php in Cockpit 0.4.4 through 0.5.5 allows remote attackers to r
23RIESGO
abrir
Referência
CVE-2014-1907
Multiple directory traversal vulnerabilities in the VideoWhisper Live Streaming Integration plugin before 4.29.5 for Wor
28RIESGO
abrir
Referência
CVE-2015-6567
Wolf CMS before 0.8.3.1 allows unrestricted file upload and PHP Code Execution because admin/plugin/file_manager/browse/
28RIESGO
abrir
anteriorpágina 148 / 668siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.