Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.526exploits catalogados
34.478CVEs con explotación pública
24.695probados en laboratorio
21.534 exploits
Referência
CVE-2010-0802
SQL injection vulnerability in index.php in (nv2) Awards 1.1.0, a modification for Invision Power Board, allows remote a
23RIESGO
abrir
Referência
CVE-2012-2593
Cross-site scripting (XSS) vulnerability in the administrative interface in Atmail Webmail Server 6.4 allows remote atta
23RIESGO
abrir
Referência
CVE-2010-0802
SQL injection vulnerability in index.php in (nv2) Awards 1.1.0, a modification for Invision Power Board, allows remote a
23RIESGO
abrir
Referência
CVE-2016-2208
The kernel component in Symantec Anti-Virus Engine (AVE) 20151.1 before 20151.1.1.4 allows remote attackers to execute a
28RIESGO
abrir
ReferênciaVexDay Proof
PHP Project Management 0.8.10 - Multiple Local/Remote File Inclusions
CVE-2007-5642webappsphp
Multiple directory traversal vulnerabilities in PHP Project Management 0.8.10 and earlier allow remote attackers to incl
23RIESGO
abrir
Referência
CVE-2017-7049
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RIESGO
abrir
Referência
CVE-2009-3838
Stack-based buffer overflow in Pegasus Mail (PMail) 4.41 and possibly 4.51 allows remote POP3 servers to cause a denial
23RIESGO
abrir
ReferênciaVexDay Proof
Moodle < 1.6.9/1.7.7/1.8.9/1.9.5 - File Disclosure
CVE-2009-1171webappsphp
The TeX filter in Moodle 1.6 before 1.6.9+, 1.7 before 1.7.7+, 1.8 before 1.8.9, and 1.9 before 1.9.5 allows user-assist
23RIESGO
abrir
Referência
CVE-2014-2579
Multiple cross-site request forgery (CSRF) vulnerabilities in XCloner Standalone 3.5 and earlier allow remote attackers
23RIESGO
abrir
Referência
CVE-2015-1723
Use-after-free vulnerability in the kernel-mode drivers in Microsoft Windows Server 2003 SP2 and R2 SP2, Windows Vista S
23RIESGO
abrir
Referência
CVE-2026-6143
farion1231 cc-switch ProxyServer server.rs cross-domain policy
33RIESGO
abrir
Referência
CVE-2012-1025
Absolute path traversal vulnerability in file in Enigma2 Webinterface 1.6.0 through 1.6.8, 1.6rc3, and 1.7.0 allows remo
23RIESGO
abrir
Referência
CVE-2009-2382
admin.php in phpMyBlockchecker 1.0.0055 allows remote attackers to bypass authentication and gain administrative access
23RIESGO
abrir
Referência
CVE-2023-38501
copyparty vulnerable to reflected cross-site scripting via k304 parameter
48RIESGO
abrir
Referência
CVE-2025-11418
Tenda CH22 HTTP Request AdvSetWrlsafeset formWrlsafeset stack-based overflow
48RIESGO
abrir
Referência
CVE-2018-18762
SaltOS 3.1 r8126 contains a database download vulnerability.
23RIESGO
abrir
Referência
CVE-2018-18762
SaltOS 3.1 r8126 contains a database download vulnerability.
23RIESGO
abrir
Referência
CVE-2010-0982
Directory traversal vulnerability in the CARTwebERP (com_cartweberp) component 1.56.75 for Joomla! allows remote attacke
38RIESGO
abrir
Referência
CVE-2009-2568
Stack-based buffer overflow in Sorinara Streaming Audio Player (SAP) 0.9 allows remote attackers to execute arbitrary co
23RIESGO
abrir
Referência
CVE-2009-2568
Stack-based buffer overflow in Sorinara Streaming Audio Player (SAP) 0.9 allows remote attackers to execute arbitrary co
23RIESGO
abrir
ReferênciaVexDay Proof
PortalApp 4.0 - SQL Injection / Cross-Site Scripting / Authentication Bypass
CVE-2008-4614webappsasp
PortalApp 4.0 does not require authentication for (1) forums.asp and (2) content.asp, which allows remote attackers to c
23RIESGO
abrir
ReferênciaVexDay Proof
CodeAvalanche FreeForum - Database Disclosure
CVE-2008-5932webappsasp
CodeAvalanche FreeForum stores sensitive information under the web root with insufficient access control, which allows r
23RIESGO
abrir
ReferênciaVexDay Proof
OraMon 2.0.1 - Remote Configuration File Disclosure
CVE-2008-6869webappsphp
Oramon Oracle Database Monitoring Tool 2.0.1 stores sensitive information under the web root with insufficient access co
23RIESGO
abrir
ReferênciaVexDay Proof
Triologic Media Player 7 - '.m3u' Local Heap Buffer Overflow (PoC)
CVE-2009-0262doswindows
Stack-based buffer overflow in Triologic Media Player 7 and 8.0.0.0 allows user-assisted remote attackers to execute arb
23RIESGO
abrir
ReferênciaVexDay Proof
Pinnacle Studio 12 - '.hfz' Directory Traversal
CVE-2009-1743localwindows
Directory traversal vulnerability in InstallHFZ.exe 6.5.201.0 in Pinnacle Hollywood Effects 6, a module in Pinnacle Syst
23RIESGO
abrir
ReferênciaVexDay Proof
pc4 Uploader 10.0 - Remote File Disclosure
CVE-2009-2180webappsphp
Multiple directory traversal vulnerabilities in upfiles/index.php in Pc4 Uploader 10.0 and earlier allow remote attacker
23RIESGO
abrir
Referência
CVE-2010-3147
Untrusted search path vulnerability in wab.exe 6.00.2900.5512 in Windows Address Book in Microsoft Windows XP SP2 and SP
28RIESGO
abrir
ReferênciaVexDay Proof
Mambo Component pc_cookbook 0.3 - Remote File Inclusion
CVE-2006-3530webappsphp
PHP remote file inclusion vulnerability in com_pccookbook/pccookbook.php in the PccookBook Component for Mambo and Jooml
23RIESGO
abrir
Referência
CVE-2018-5751
The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev4
23RIESGO
abrir
Referência
CVE-2015-1481
Ansible Tower (aka Ansible UI) before 2.0.5 allows remote organization administrators to gain privileges by creating a s
23RIESGO
abrir
anteriorpágina 173 / 718siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.