Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.445exploits catalogados
34.432CVEs con explotación pública
24.695probados en laboratorio
21.497 exploits
ReferênciaVexDay Proof
AFGB Guestbook 2.2 - 'Htmls' Remote File Inclusion
CVE-2006-5307webappsphp
Multiple PHP remote file inclusion vulnerabilities in AFGB GUESTBOOK 2.2 allow remote attackers to execute arbitrary PHP
23RIESGO
abrir
Referência
CVE-2015-4073
Multiple SQL injection vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to exe
23RIESGO
abrir
ReferênciaVexDay Proof
IP3 NetAccess < 4.1.9.6 - Arbitrary File Disclosure
CVE-2007-0883remotehardware
Directory traversal vulnerability in portalgroups/portalgroups/getfile.cgi in IP3 NetAccess before firmware 4.1.9.6 allo
23RIESGO
abrir
ReferênciaVexDay Proof
muvee autoProducer 6.1 - 'TextOut.dll' ActiveX Remote Buffer Overflow
CVE-2008-2910remotewindows
Buffer overflow in the DXTTextOutEffect ActiveX control (aka the Text-Effect DXT Filter), as distributed in TextOut.dll
23RIESGO
abrir
ReferênciaVexDay Proof
Social Groupie - 'create_album.php' Arbitrary File Upload
CVE-2008-6367webappsphp
Unrestricted file upload vulnerability in Photos/create_album.php in Social Groupie allows remote authenticated users to
23RIESGO
abrir
ReferênciaVexDay Proof
Youngzsoft CMailServer 5.4.6 - 'CMailCOM.dll' Remote Overwrite (SEH)
CVE-2008-6922remotewindows
Multiple stack-based buffer overflows in CMailCOM.dll in CMailServer 5.4.6 allow remote attackers to execute arbitrary c
23RIESGO
abrir
ReferênciaVexDay Proof
e107 Plugin BLOG Engine 2.1.4 - SQL Injection
CVE-2008-6438webappsphp
SQL injection vulnerability in macgurublog_menu/macgurublog.php in the MacGuru BLOG Engine plugin 2.2 for e107 allows re
23RIESGO
abrir
ReferênciaVexDay Proof
Page Manager CMS 2006-02-04 - Arbitrary File Upload
CVE-2008-7167webappsphp
Unrestricted file upload vulnerability in upload.php in Page Manager 2006-02-04 allows remote attackers to execute arbit
23RIESGO
abrir
ReferênciaVexDay Proof
Winamp GEN_MSN Plugin - Heap Buffer Overflow (PoC)
CVE-2009-0833doswindows
Heap-based buffer overflow in gen_msn.dll in the gen_msn plugin 0.31 for Winamp 5.541 allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
ablespace 1.0 - Cross-Site Scripting / Blind SQL Injection
CVE-2009-1315webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in AbleSpace 1.0 allow remote attackers to inject arbitrary web scri
23RIESGO
abrir
Referência
CVE-2009-3271
Apple Safari on iPhone OS 3.0.1 allows remote attackers to cause a denial of service (application crash) via a long tel:
23RIESGO
abrir
Referência
CVE-2018-0833
The Microsoft Server Message Block 2.0 and 3.0 (SMBv2/SMBv3) client in Windows 8.1 and RT 8.1 and Windows Server 2012 R2
35RIESGO
abrir
Referência
Webmin 1.900 - Remote Command Execution (Metasploit)
CVE-2019-9624remotecgi
Webmin 1.900 allows remote attackers to execute arbitrary code by leveraging the "Java file manager" and "Upload and Dow
43RIESGO
abrir
Referência
CVE-2016-0121
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
35RIESGO
abrir
Referência
CVE-2011-1524
Cross-site scripting (XSS) vulnerability in the management login GUI page in Symantec LiveUpdate Administrator (LUA) bef
23RIESGO
abrir
Referência
CVE-2009-4989
Cross-site scripting (XSS) vulnerability in index.php in AJ Auction Pro OOPD 3.0 allows remote attackers to inject arbit
23RIESGO
abrir
Referência
CVE-2021-29995
A Cross Site Request Forgery (CSRF) issue in Server Console in CloverDX through 5.9.0 allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
Adobe Acrobat Reader 8.1.2 - '.PDF' Remote Denial of Service (PoC)
CVE-2008-2549doswindows
Adobe Acrobat Reader 8.1.2 and earlier, and before 7.1.1, allows remote attackers to cause a denial of service (applicat
35RIESGO
abrir
Referência
CVE-2021-41382
Plastic SCM before 10.0.16.5622 mishandles the WebAdmin server management interface.
23RIESGO
abrir
ReferênciaVexDay Proof
F-Prot AntiVirus 4.6.6 - 'ACE' Denial of Service
CVE-2006-6352doslinux
FRISK Software F-Prot Antivirus before 4.6.7 allows user-assisted remote attackers to cause a denial of service (infinit
23RIESGO
abrir
Referência
CVE-2019-2107
In ihevcd_parse_pps of ihevcd_parse_headers.c, there is a possible out of bounds write due to a missing bounds check. Th
23RIESGO
abrir
Referência
CVE-2018-1038
The Windows kernel in Windows 7 SP1 and Windows Server 2008 R2 SP1 allows an elevation of privilege vulnerability due to
23RIESGO
abrir
ReferênciaVexDay Proof
EZWebAlbum - Remote File Disclosure
CVE-2008-3293webappsphp
Directory traversal vulnerability in download.php in EZWebAlbum allows remote attackers to read arbitrary files via the
23RIESGO
abrir
Referência
CVE-2019-11269
Open Redirector in spring-security-oauth2
33RIESGO
abrir
Referência
CVE-2016-8377
An issue was discovered in Fatek Automation PLC WinProladder Version 3.11 Build 14701. A stack-based buffer overflow vul
23RIESGO
abrir
ReferênciaVexDay Proof
Mozilla Firefox 3.0.3 - User Interface Null Pointer Dereference Crash
CVE-2008-4324doswindows
The user interface event dispatcher in Mozilla Firefox 3.0.3 on Windows XP SP2 allows remote attackers to cause a denial
23RIESGO
abrir
Referência
CVE-2015-0097
Microsoft Excel 2007 SP3, PowerPoint 2007 SP3, Word 2007 SP3, Excel 2010 SP2, PowerPoint 2010 SP2, and Word 2010 SP2 all
35RIESGO
abrir
Referência
CVE-2021-25297
CVE-2021-25297HIGHbajo ataque
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi
98RIESGO
abrir
Referência
CVE-2026-32746
telnetd in GNU inetutils through 2.7 allows an out-of-bounds write in the LINEMODE SLC (Set Local Characters) suboption
53RIESGO
abrir
Referência
CVE-2012-4750
A Code Execution vulnerability exists in the memcpy function when processing AMF requests in Ezhometech EzServer 7.0, wh
23RIESGO
abrir
anteriorpágina 160 / 717siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.