Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.652exploits catalogados
34.545CVEs con explotación pública
24.695probados en laboratorio
21.581 exploits
Referência
CVE-2019-6804
An XSS issue was discovered on the Job Edit page in Rundeck Community Edition before 3.0.13, related to assets/javascrip
23RIESGO
abrir
ReferênciaVexDay Proof
JV2 Folder Gallery 3.0 - Remote File Inclusion
CVE-2007-0682webappsphp
PHP remote file inclusion vulnerability in theme/include_mode/template.php in JV2 Folder Gallery 3.0.2 and earlier allow
23RIESGO
abrir
Referência
CVE-2016-5310
The RAR file parser component in the AntiVirus Decomposer engine in Symantec Advanced Threat Protection: Network (ATP);
23RIESGO
abrir
ReferênciaVexDay Proof
wavewoo 0.1.1 - 'loading.php?path_include' Remote File Inclusion
CVE-2007-2273webappsphp
PHP remote file inclusion vulnerability in include/loading.php in Alessandro Lulli wavewoo 0.1.1 allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
TR News 2.1 - 'nb' SQL Injection
CVE-2008-1958webappsphp
Unrestricted file upload vulnerability in the ajout_cat mode in admin/main.php in Tr Script News 2.1 allows remote authe
23RIESGO
abrir
Referência
CVE-2021-27946
SQL Injection vulnerability in MyBB before 1.8.26 via poll vote count. (issue 1 of 3).
23RIESGO
abrir
Referência
CVE-2012-6290
SQL injection vulnerability in ImageCMS before 4.2 allows remote authenticated administrators to execute arbitrary SQL c
23RIESGO
abrir
Referência
CVE-2013-2637
A Cross-Site Scripting (XSS) Vulnerability exists in OTRS ITSM prior to 3.2.4, 3.1.8, and 3.0.7 and FAQ prior to 2.1.4 a
23RIESGO
abrir
Referência
CVE-2017-7221
OpenText Documentum Content Server has an inadequate protection mechanism against SQL injection, which allows remote aut
23RIESGO
abrir
ReferênciaVexDay Proof
groone's Guestbook 2.0 - Remote File Inclusion
CVE-2009-0464webappsphp
PHP remote file inclusion vulnerability in includes/header.php in Groone GBook 2.0 allows remote attackers to execute ar
23RIESGO
abrir
Referência
CVE-2020-12501
Pepperl+Fuchs improper authorization affects multiple Comtrol RocketLinx products
48RIESGO
abrir
Referência
CVE-2019-9592
A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 19.45.1602.0 allows remote attackers to
23RIESGO
abrir
Referência
CVE-2019-9592
A reflected Cross-site scripting (XSS) vulnerability in ShoreTel Connect ONSITE 19.45.1602.0 allows remote attackers to
23RIESGO
abrir
Referência
CVE-2019-16118
Cross site scripting (XSS) in the photo-gallery (10Web Photo Gallery) plugin before 1.5.35 for WordPress exists via admi
23RIESGO
abrir
Referência
CVE-2022-41441
Multiple cross-site scripting (XSS) vulnerabilities in ReQlogic v11.3 allow attackers to execute arbitrary web scripts o
48RIESGO
abrir
Referência
CVE-2010-1090
SQL injection vulnerability in index.php in phpMySite allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir
Referência
CVE-2010-1090
SQL injection vulnerability in index.php in phpMySite allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir
Referência
CVE-2020-2231
Jenkins 2.251 and earlier, LTS 2.235.3 and earlier does not escape the remote address of the host starting a build via '
23RIESGO
abrir
Referência
CVE-2018-6191
The js_strtod function in jsdtoa.c in Artifex MuJS through 1.0.2 has an integer overflow because of incorrect exponent v
23RIESGO
abrir
Referência
CVE-2017-6516
A Local Privilege Escalation Vulnerability in MagniComp's Sysinfo before 10-H64 for Linux and UNIX platforms could allow
38RIESGO
abrir
Referência
CVE-2018-2636
Vulnerability in the Oracle Hospitality Simphony component of Oracle Hospitality Applications (subcomponent: Security).
28RIESGO
abrir
Referência
CVE-2018-15181
JioFi 4G Hotspot M2S devices allow attackers to cause a denial of service (secure configuration outage) via an XSS paylo
23RIESGO
abrir
ReferênciaVexDay Proof
CityWriter 0.9.7 - 'head.php' Remote File Inclusion
CVE-2007-6324webappsphp
PHP remote file inclusion vulnerability in head.php in CityWriter 0.9.7 allows remote attackers to execute arbitrary PHP
23RIESGO
abrir
Referência
CVE-2013-4695
Winamp 5.63: Invalid Pointer Dereference leading to Arbitrary Code Execution
23RIESGO
abrir
Referência
CVE-2021-26085
CVE-2021-26085MEDIUMbajo ataqueransomware
Affected versions of Atlassian Confluence Server allow remote attackers to view restricted resources via a Pre-Authoriza
100RIESGO
abrir
ReferênciaVexDay Proof
RaidenFTPd 2.4 build 3620 - Remote Denial of Service
CVE-2008-6186doswindows
Stack-based buffer overflow in RaidenFTPD 2.4 build 3620 allows remote authenticated users to cause a denial of service
23RIESGO
abrir
Referência
CVE-2025-34082
IGEL OS Secure Terminal and Secure Shadow Remote Code Execution
63RIESGO
abrir
Referência
CVE-2018-20484
Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the self-update layout implementation.
23RIESGO
abrir
Referência
CVE-2021-26086
CVE-2021-26086MEDIUMbajo ataque
Affected versions of Atlassian Jira Server and Data Center allow remote attackers to read particular files via a path tr
100RIESGO
abrir
ReferênciaVexDay Proof
GNUBoard 4.31.03 (08.12.29) - Local File Inclusion
CVE-2009-0290webappsphp
Directory traversal vulnerability in common.php in SIR GNUBoard 4.31.03 allows remote attackers to include and execute a
23RIESGO
abrir
anteriorpágina 225 / 720siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.