Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
75.589exploits catalogados
34.508CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.554GitHub PoC 13.689VulnCheck XDB 8216Nuclei 4223Metasploit 3464✓ solo verificadosrecientespopularesriesgo
21.554 exploits
Referência
CVE-2016-3717
The LABEL coder in ImageMagick before 6.9.3-10 and 7.x before 7.0.1-1 allows remote attackers to read arbitrary files vi
28RIESGO
abrir ↗Referência
CVE-2009-3272
Stack consumption vulnerability in WebKit.dll in WebKit in Apple Safari 3.2.3, and possibly other versions before 4.1.2,
23RIESGO
abrir ↗Referência
CVE-2018-6221
An unvalidated software update vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a man-in-the-middle
23RIESGO
abrir ↗Referência
CVE-2018-12589
Polaris Office 2017 8.1 allows attackers to execute arbitrary code via a Trojan horse puiframeworkproresenu.dll file in
28RIESGO
abrir ↗Referência
CVE-2018-12589
Polaris Office 2017 8.1 allows attackers to execute arbitrary code via a Trojan horse puiframeworkproresenu.dll file in
28RIESGO
abrir ↗Referência✓ VexDay Proof
Boonex Dolphin 6.1.2 - Multiple Remote File Inclusions
Multiple PHP remote file inclusion vulnerabilities in BoonEx Dolphin 6.1.2, when register_globals is enabled, allow remo
23RIESGO
abrir ↗Referência✓ VexDay Proof
Opencart 1.1.8 - 'route' Local File Inclusion
Directory traversal vulnerability in index.php in OpenCart 1.1.8 allows remote attackers to read arbitrary files via a .
23RIESGO
abrir ↗Referência
CVE-2009-4987
admin/header.php in Scripteen Free Image Hosting Script 2.3 allows remote attackers to bypass authentication and gain ad
23RIESGO
abrir ↗Referência
CVE-2010-1217
Directory traversal vulnerability in the JE Form Creator (com_jeformcr) component for Joomla!, when magic_quotes_gpc is
38RIESGO
abrir ↗Referência
CVE-2010-1217
Directory traversal vulnerability in the JE Form Creator (com_jeformcr) component for Joomla!, when magic_quotes_gpc is
38RIESGO
abrir ↗Referência
CVE-2015-3300
Multiple cross-site scripting (XSS) vulnerabilities in the TheCartPress eCommerce Shopping Cart (aka The Professional Wo
23RIESGO
abrir ↗Referência
CVE-2009-2694
The msn_slplink_process_msg function in libpurple/protocols/msn/slplink.c in libpurple, as used in Pidgin (formerly Gaim
28RIESGO
abrir ↗Referência
CVE-2009-3717
Heap-based buffer overflow in LucVil PatPlayer 3.9 allows remote attackers to cause a denial of service (crash) or execu
23RIESGO
abrir ↗Referência
CVE-2013-1464
Cross-site scripting (XSS) vulnerability in assets/player.swf in the Audio Player plugin before 2.0.4.6 for Wordpress al
23RIESGO
abrir ↗Referência
CVE-2018-15536
/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 does not properly validate file paths in arc
23RIESGO
abrir ↗Referência
CVE-2018-10371
An issue was discovered in the wunderfarm WF Cookie Consent plugin 1.1.3 for WordPress. A persistent cross-site scriptin
23RIESGO
abrir ↗Referência
CVE-2020-6364
SAP Solution Manager and SAP Focused Run (update provided in WILY_INTRO_ENTERPRISE 9.7, 10.1, 10.5, 10.7), allows an att
48RIESGO
abrir ↗Referência
CVE-2015-1494
The FancyBox for WordPress plugin before 3.0.3 for WordPress does not properly restrict access, which allows remote atta
23RIESGO
abrir ↗Referência✓ VexDay Proof
Advanced Poll 2.0.5-dev - Remote Admin Session Generator
admin/index.php in Advanced Poll 2.0.0 through 2.0.5-dev allows remote attackers to bypass authentication and gain admin
23RIESGO
abrir ↗Referência✓ VexDay Proof
LokiCMS 0.3.4 - 'index.php' Arbitrary Check File
Directory traversal vulnerability in index.php in LokiCMS 0.3.4 and earlier, when magic_quotes_gpc is disabled, allows r
23RIESGO
abrir ↗Referência✓ VexDay Proof
Google Chrome 0.2.149.27 - Automatic File Download
Google Chrome BETA (0.2.149.27) does not prompt the user before saving an executable file, which makes it easier for rem
23RIESGO
abrir ↗Referência
CVE-2010-0753
SQL injection vulnerability in the SQL Reports (com_sqlreport) component 1.1 for Joomla! allows remote attackers to exec
23RIESGO
abrir ↗Referência
CVE-2010-0753
SQL injection vulnerability in the SQL Reports (com_sqlreport) component 1.1 for Joomla! allows remote attackers to exec
23RIESGO
abrir ↗Referência
CVE-2018-5688
ILIAS before 5.2.4 has XSS via the cmd parameter to the displayHeader function in setup/classes/class.ilSetupGUI.php in
23RIESGO
abrir ↗Referência
CVE-2019-8391
qdPM 9.1 suffers from Cross-site Scripting (XSS) via configuration?type=[XSS] parameter.
23RIESGO
abrir ↗Referência
CVE-2008-5281
Heap-based buffer overflow in Titan FTP Server 6.05 build 550 allows remote attackers to execute arbitrary code via a lo
38RIESGO
abrir ↗Referência
CVE-2014-0997
WiFiMonitor in Android 4.4.4 as used in the Nexus 5 and 4, Android 4.2.2 as used in the LG D806, Android 4.2.2 as used i
23RIESGO
abrir ↗Referência
CVE-2017-13156
An elevation of privilege vulnerability in the Android system (art). Product: Android. Versions: 5.1.1, 6.0, 6.0.1, 7.0,
43RIESGO
abrir ↗Referência
CVE-2001-0198
Buffer overflow in QuickTime Player plugin 4.1.2 (Japanese) allows remote attackers to execute arbitrary commands via a
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.