Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
22.832 exploits
ReferênciaVexDay Proof
ASPSiteWare Automotive Dealer 1.0/2.0 - SQL Injection
CVE-2008-6874webappsphp
Multiple SQL injection vulnerabilities in ASP SiteWare autoDealer 1 and 2 allow remote attackers to execute arbitrary SQ
23RIESGO
abrir
Referência
CVE-2012-1921
Cross-site request forgery (CSRF) vulnerability in goform/admin/formWlEncrypt in Sitecom WLM-2501 allows remote attacker
23RIESGO
abrir
ReferênciaVexDay Proof
Black Ice Software Inc Barcode SDK - 'BIDIB.ocx' Multiple Vulnerabilities
CVE-2008-2684remotewindows
The BIDIB.BIDIBCtrl.1 ActiveX control in BIDIB.ocx 10.9.3.0 in Black Ice Barcode SDK 5.01 allows remote attackers to exe
23RIESGO
abrir
Referência
CVE-2019-19609
The Strapi framework before 3.0.0-beta.17.8 is vulnerable to Remote Code Execution in the Install and Uninstall Plugin c
35RIESGO
abrir
ReferênciaVexDay Proof
Flux CMS 1.5.0 - 'loadsave.php' Arbitrary File Overwrite
CVE-2008-2686webappsphp
webinc/bxe/scripts/loadsave.php in Flux CMS 1.5.0 and earlier allows remote attackers to execute arbitrary code by overw
23RIESGO
abrir
ReferênciaVexDay Proof
BrowserCRM 5.002.00 - 'clients.php' Remote File Inclusion
CVE-2008-2689webappsphp
PHP remote file inclusion vulnerability in pub/clients.php in BrowserCRM 5.002.00 allows remote attackers to execute arb
35RIESGO
abrir
Referência
CVE-2019-19726
OpenBSD through 6.6 allows local users to escalate to root because a check for LD_LIBRARY_PATH in setuid programs can be
38RIESGO
abrir
ReferênciaVexDay Proof
JiRo's FAQ Manager eXperience 1.0 - 'fID' SQL Injection
CVE-2008-2691webappsasp
SQL injection vulnerability in read.asp in JiRo's FAQ Manager eXperience 1.0 allows remote attackers to execute arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
AJ HYIP ACME - 'comment.php' SQL Injection
CVE-2008-4043webappsphp
Multiple SQL injection vulnerabilities in AJ Square AJ HYIP Acme allow remote attackers to execute arbitrary SQL command
23RIESGO
abrir
ReferênciaVexDay Proof
Zeeways ZeeJobsite 2.0 - Arbitrary File Upload
CVE-2008-6913webappsphp
Unrestricted file upload vulnerability in editresume_next.php in Zeeways ZEEJOBSITE 2.0 allows remote authenticated user
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component Content 1.0.0 - 'itemID' SQL Injection
CVE-2008-6923webappsphp
SQL injection vulnerability in the content component (com_content) 1.0.0 for Joomla! allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component yvComment 1.16 - Blind SQL Injection
CVE-2008-2692webappsphp
SQL injection vulnerability in the yvComment (com_yvcomment) component 1.16.0 and earlier for Joomla! allows remote atta
23RIESGO
abrir
Referência
CVE-2019-19781
CVE-2019-19781CRITICALbajo ataqueransomware
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir
Referência
CVE-2019-19781
CVE-2019-19781CRITICALbajo ataqueransomware
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir
Referência
CVE-2019-19781
CVE-2019-19781CRITICALbajo ataqueransomware
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir
ReferênciaVexDay Proof
Black Ice Software Inc Barcode SDK - 'BITiff.ocx' Remote Buffer Overflow (1)
CVE-2008-2693remotewindows
Stack-based buffer overflow in the BITIFF.BITiffCtrl.1 ActiveX control in BITiff.ocx 10.9.3.0 in Black Ice Barcode SDK 5
28RIESGO
abrir
ReferênciaVexDay Proof
Black Ice Software Inc Barcode SDK - 'BITiff.ocx' Remote Buffer Overflow (2)
CVE-2008-2693remotewindows
Stack-based buffer overflow in the BITIFF.BITiffCtrl.1 ActiveX control in BITiff.ocx 10.9.3.0 in Black Ice Barcode SDK 5
28RIESGO
abrir
Referência
CVE-2019-19781
CVE-2019-19781CRITICALbajo ataqueransomware
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir
Referência
CVE-2019-19781
CVE-2019-19781CRITICALbajo ataqueransomware
An issue was discovered in Citrix Application Delivery Controller (ADC) and Gateway 10.5, 11.1, 12.0, 12.1, and 13.0. Th
100RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component Rapid Recipe 1.6.6/1.6.7 - SQL Injection
CVE-2008-2697webappsphp
SQL injection vulnerability in the Rapid Recipe (com_rapidrecipe) component 1.6.6 and 1.6.7 for Joomla! allows remote at
23RIESGO
abrir
Referência
CVE-2024-13161
CVE-2024-13161CRITICALbajo ataque
Absolute path traversal in Ivanti EPM before the 2024 January-2025 Security Update and 2022 SU6 January-2025 Security Up
100RIESGO
abrir
ReferênciaVexDay Proof
Achievo 1.3.2 - 'FCKeditor' Arbitrary File Upload
CVE-2008-2742webappsphp
Unrestricted file upload in the mcpuk file editor (atk/attributes/fck/editor/filemanager/browser/mcpuk/connectors/php/co
23RIESGO
abrir
Referência
CVE-2020-8193
CVE-2020-8193MEDIUMbajo ataque
Improper access control in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14
100RIESGO
abrir
Referência
CVE-2020-3243
Multiple Vulnerabilities in Cisco UCS Director and Cisco UCS Director Express for Big Data
85RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component mosmedia 1.0.8 - Remote File Inclusion
CVE-2007-2043webappsphp
Multiple PHP remote file inclusion vulnerabilities in the Avant-Garde Solutions MOSMedia (com_mosmedia) 1.08 and earlier
23RIESGO
abrir
ReferênciaVexDay Proof
Nokia e90/n82 (s60v3) - Remote Denial of Service
CVE-2008-4135doshardware
Symbian OS S60 3rd edition on the Nokia E90 Communicator 07.40.1.2 Ra-6 and Nseries N82 allows remote attackers to cause
23RIESGO
abrir
Referência
CVE-2012-2109
SQL injection vulnerability in wp-load.php in the BuddyPress plugin 1.5.x before 1.5.5 of WordPress allows remote attack
23RIESGO
abrir
Referência
CVE-2018-1000115
Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vuln
60RIESGO
abrir
Referência
CVE-2018-1000115
Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vuln
60RIESGO
abrir
Referência
CVE-2022-37042
CVE-2022-37042CRITICALbajo ataqueransomware
Zimbra Collaboration Suite (ZCS) 8.8.15 and 9.0 has mboximport functionality that receives a ZIP archive and extracts fi
100RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.