Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
22.721 exploits
Referência
CVE-2018-3810
Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unau
60RIESGO
abrir
Referência
CVE-2009-3023
Buffer overflow in the FTP Service in Microsoft Internet Information Services (IIS) 5.0 through 6.0 allows remote authen
60RIESGO
abrir
ReferênciaVexDay Proof
IMGallery 2.5 - Multiple SQL Injections
CVE-2008-2337webappsphp
Multiple SQL injection vulnerabilities in IMGallery 2.5, when magic_quotes_gpc is disabled, allow remote attackers to ex
23RIESGO
abrir
Referência
CVE-2015-8556
Local privilege escalation vulnerability in the Gentoo QEMU package before 2.5.0-r1.
23RIESGO
abrir
Referência
CVE-2017-15222
Buffer Overflow vulnerability in Ayukov NFTPD 2.0 and earlier allows remote attackers to execute arbitrary code.
50RIESGO
abrir
ReferênciaVexDay Proof
newsmanager 2.0 - Remote File Inclusion / File Disclosure / SQL Injection
CVE-2008-2340webappsphp
Multiple SQL injection vulnerabilities in News Manager 2.0 allow remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
Referência
CVE-2017-3066
CVE-2017-3066CRITICALbajo ataque
Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier hav
100RIESGO
abrir
ReferênciaVexDay Proof
newsmanager 2.0 - Remote File Inclusion / File Disclosure / SQL Injection
CVE-2008-2342webappsphp
Directory traversal vulnerability in attachments.php in News Manager 2.0 allows remote attackers to read arbitrary files
23RIESGO
abrir
Referência
CVE-2021-42321
CVE-2021-42321HIGHbajo ataqueransomware
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
Referência
CVE-2021-42321
CVE-2021-42321HIGHbajo ataqueransomware
Microsoft Exchange Server Remote Code Execution Vulnerability
100RIESGO
abrir
Referência
CVE-2022-31137
Unauthenticated Remote Code Execution in Roxy-WI
85RIESGO
abrir
Referência
CVE-2022-31137
Unauthenticated Remote Code Execution in Roxy-WI
85RIESGO
abrir
Referência
CVE-2022-31137
Unauthenticated Remote Code Execution in Roxy-WI
85RIESGO
abrir
Referência
CVE-2022-31137
Unauthenticated Remote Code Execution in Roxy-WI
85RIESGO
abrir
Referência
CVE-2019-17220
Rocket.Chat before 2.1.0 allows XSS via a URL on a ![title] line.
23RIESGO
abrir
ReferênciaVexDay Proof
HP Software Update - 'Hpufunction.dll 4.0.0.1' Insecure Method
CVE-2008-2390remotewindows
Hpufunction.dll 4.0.0.1 in HP Software Update exposes the unsafe (1) ExecuteAsync and (2) Execute methods, which allows
23RIESGO
abrir
Referência
CVE-2017-9554
An information exposure vulnerability in forget_passwd.cgi in Synology DiskStation Manager (DSM) before 6.1.3-15152 allo
60RIESGO
abrir
ReferênciaVexDay Proof
TAGWORX.CMS 3.00.02 - Multiple SQL Injections
CVE-2008-2394webappsphp
Multiple SQL injection vulnerabilities in TAGWORX.CMS 3.00.02 allow remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
ReferênciaVexDay Proof
XnView 1.93.6 - '.taac' Local Buffer Overflow
CVE-2008-2427localwindows
Stack-based buffer overflow in NConvert 4.92, GFL SDK 2.82, and XnView 1.93.6 on Windows and 1.70 on Linux and FreeBSD a
28RIESGO
abrir
Referência
CVE-2008-6515
Cross-site scripting (XSS) vulnerability in Fritz Berger yet another php photo album - next generation (yappa-ng) allows
23RIESGO
abrir
ReferênciaVexDay Proof
CaLogic Calendars 1.2.2 - 'langsel' SQL Injection
CVE-2008-2444webappsphp
SQL injection vulnerability in userreg.php in CaLogic Calendars 1.2.2 allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
Referência
CVE-2012-1775
Stack-based buffer overflow in VideoLAN VLC media player before 2.0.1 allows remote attackers to execute arbitrary code
50RIESGO
abrir
ReferênciaVexDay Proof
Web Group Communication Center (WGCC) 1.0.3 - SQL Injection
CVE-2008-2445webappsphp
Cross-site scripting (XSS) vulnerability in profile.php in Web Group Communication Center (WGCC) 1.0.3 PreRelease 1 and
23RIESGO
abrir
ReferênciaVexDay Proof
e-107 Plugin ZoGo-Shop 1.16 Beta 13 - SQL Injection
CVE-2008-2447webappsphp
SQL injection vulnerability in products.php in the Mytipper ZoGo-shop plugin 1.15.5 and 1.16 Beta 13 for e107 allows rem
23RIESGO
abrir
Referência
CVE-2023-40044
CVE-2023-40044CRITICALbajo ataqueransomware
WS_FTP Server Ad Hoc Transfer Module .NET Deserialization Vulnerability
100RIESGO
abrir
Referência
CVE-2020-17463
CVE-2020-17463CRITICALbajo ataque
FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.
100RIESGO
abrir
Referência
CVE-2017-8464
CVE-2017-8464HIGHbajo ataque
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RIESGO
abrir
Referência
CVE-2017-8464
CVE-2017-8464HIGHbajo ataque
Windows Shell in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 201
100RIESGO
abrir
ReferênciaVexDay Proof
ComicShout 2.5 - 'comic_id' SQL Injection
CVE-2008-2456webappsphp
SQL injection vulnerability in index.php in ComicShout 2.5 and earlier allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
ReferênciaVexDay Proof
μTorrent (uTorrent) 1.6 build 474 - 'announce' Key Remote Heap Overflow
CVE-2007-0927remotewindows
Heap-based buffer overflow in uTorrent 1.6 allows remote attackers to execute arbitrary code via a torrent file with a c
35RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.