Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

75.655exploits catalogados
34.547CVEs con explotación pública
24.695probados en laboratorio
21.581 exploits
Referência
CVE-2013-1763
Array index error in the __sock_diag_rcv_msg function in net/core/sock_diag.c in the Linux kernel before 3.7.10 allows l
23RIESGO
abrir
Referência
CVE-2013-3535
Multiple cross-site scripting (XSS) vulnerabilities in CMSLogik 1.2.0 and 1.2.1 allow remote attackers to inject arbitra
23RIESGO
abrir
Referência
CVE-2013-3535
Multiple cross-site scripting (XSS) vulnerabilities in CMSLogik 1.2.0 and 1.2.1 allow remote attackers to inject arbitra
23RIESGO
abrir
Referência
CVE-2014-4312
Multiple cross-site scripting (XSS) vulnerabilities in Epicor Enterprise 7.4 before FS74SP6_HotfixTL054181 allow remote
23RIESGO
abrir
Referência
CVE-2014-4312
Multiple cross-site scripting (XSS) vulnerabilities in Epicor Enterprise 7.4 before FS74SP6_HotfixTL054181 allow remote
23RIESGO
abrir
ReferênciaVexDay Proof
Aardvark Topsites PHP 4.2.2 - 'lostpw.php' Remote File Inclusion
CVE-2006-2149webappsphp
PHP remote file inclusion vulnerability in sources/lostpw.php in Aardvark Topsites PHP 4.2.2 and earlier, when register_
23RIESGO
abrir
Referência
CVE-2015-8284
SeaWell Networks Spectrum SDC 02.05.00 allows remote viewer users to perform administrative functions.
23RIESGO
abrir
Referência
CVE-2015-8284
SeaWell Networks Spectrum SDC 02.05.00 allows remote viewer users to perform administrative functions.
23RIESGO
abrir
Referência
CVE-2018-9245
The Ericsson-LG iPECS NMS A.1Ac login portal has a SQL injection vulnerability in the User ID and password fields that a
23RIESGO
abrir
ReferênciaVexDay Proof
Phpjobscheduler 3.0 - 'installed_config_file' File Inclusion
CVE-2006-5928webappsphp
Multiple PHP remote file inclusion vulnerabilities in Phpjobscheduler 3.0 allow remote attackers to execute arbitrary PH
23RIESGO
abrir
ReferênciaVexDay Proof
RsGallery2 < 1.11.2 - 'rsgallery.html.php' File Inclusion
CVE-2006-6962webappsphp
PHP remote file inclusion vulnerability in rsgallery2.html.php in the RS Gallery2 component (com_rsgallery2) 1.11.2 for
23RIESGO
abrir
Referência
CVE-2014-6242
Multiple SQL injection vulnerabilities in the All In One WP Security & Firewall plugin before 3.8.3 for WordPress allow
23RIESGO
abrir
Referência
CVE-2014-6242
Multiple SQL injection vulnerabilities in the All In One WP Security & Firewall plugin before 3.8.3 for WordPress allow
23RIESGO
abrir
Referência
CVE-2022-0847
CVE-2022-0847HIGHbajo ataque
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
Referência
CVE-2015-4066
Multiple SQL injection vulnerabilities in admin/handlers.php in the GigPress plugin before 2.3.9 for WordPress allow rem
23RIESGO
abrir
Referência
CVE-2015-4066
Multiple SQL injection vulnerabilities in admin/handlers.php in the GigPress plugin before 2.3.9 for WordPress allow rem
23RIESGO
abrir
Referência
CVE-2022-0847
CVE-2022-0847HIGHbajo ataque
A flaw was found in the way the "flags" member of the new pipe buffer structure was lacking proper initialization in cop
100RIESGO
abrir
Referência
CVE-2016-6707
An elevation of privilege vulnerability in System Server in Android 6.x before 2016-11-01 and 7.0 before 2016-11-01 coul
23RIESGO
abrir
ReferênciaVexDay Proof
VS-News-System 1.2.1 - 'newsordner' Remote File Inclusion
CVE-2007-1017webappsphp
PHP remote file inclusion vulnerability in show_news_inc.php in VirtualSystem VS-News-System 1.2.1 and earlier allows re
23RIESGO
abrir
Referência
CVE-2014-2023
Multiple SQL injection vulnerabilities in the Tapatalk plugin 4.9.0 and earlier and 5.x through 5.2.1 for vBulletin allo
23RIESGO
abrir
ReferênciaVexDay Proof
PrecisionID Barcode ActiveX 1.3 - Denial of Service
CVE-2007-2657doswindows
Unspecified vulnerability in the PrecisionID Barcode 1.3 ActiveX control in PrecisionID_DataMatrix.DLL allows remote att
23RIESGO
abrir
Referência
CVE-2016-7216
The kernel API in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, and Windows 7 SP1 mishandles permissi
23RIESGO
abrir
Referência
CVE-2019-0836
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), ak
23RIESGO
abrir
Referência
CVE-2019-0836
An elevation of privilege vulnerability exists when Windows improperly handles calls to the LUAFV driver (luafv.sys), ak
23RIESGO
abrir
Referência
CVE-2017-11567
Cross-site request forgery (CSRF) vulnerability in Mongoose Web Server before 6.9 allows remote attackers to hijack the
23RIESGO
abrir
ReferênciaVexDay Proof
LE.CMS 1.4 - Arbitrary File Upload
CVE-2008-2833webappsphp
admin/upload.php in le.cms 1.4 and earlier allows remote attackers to bypass administrative authentication, and upload a
23RIESGO
abrir
ReferênciaVexDay Proof
Studio Lounge Address Book 2.5 - 'profile' Arbitrary File Upload
CVE-2009-1483webappsphp
Unrestricted file upload vulnerability in upload-file.php in Adam Patterson Studio Lounge Address Book 2.5, as reachable
23RIESGO
abrir
Referência
CVE-2017-2443
An issue was discovered in certain Apple products. macOS before 10.12.4 is affected. The issue involves the "Intel Graph
23RIESGO
abrir
Referência
CVE-2018-11242
An issue was discovered in the MakeMyTrip application 7.2.4 for Android. The databases (locally stored) are not encrypte
23RIESGO
abrir
Referência
CVE-2024-0725
ProSSHD denial of service
33RIESGO
abrir
anteriorpágina 235 / 720siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.