Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

78.958exploits catalogados
36.206CVEs con explotación pública
24.695probados en laboratorio
22.832 exploits
Referência
CVE-2019-11358
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) becaus
45RIESGO
abrir
Referência
CVE-2019-11358
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) becaus
45RIESGO
abrir
ReferênciaVexDay Proof
Jokes & Funny Pics Script - 'sb_jokeid' SQL Injection
CVE-2008-2874webappsphp
SQL injection vulnerability in index.php in Softbiz Jokes & Funny Pics Script allows remote attackers to execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
phpAuction 3.2.1 - 'item.php' SQL Injection
CVE-2008-2900webappsphp
SQL injection vulnerability in item.php in PHPAuction 3.2 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
ReferênciaVexDay Proof
Advanced Webhost Billing System (AWBS) 2.7.1 - 'news.php' SQL Injection
CVE-2008-2903webappsphp
SQL injection vulnerability in news.php in Advanced Webhost Billing System (AWBS) 2.3.3 through 2.7.1, when magic_quotes
23RIESGO
abrir
ReferênciaVexDay Proof
Mambo 4.6.4 - 'Output.php' Remote File Inclusion
CVE-2008-2905webappsphp
PHP remote file inclusion vulnerability in includes/Cache/Lite/Output.php in the Cache_Lite package in Mambo 4.6.4 and e
43RIESGO
abrir
Referência
CVE-2008-4447
Cross-site scripting (XSS) vulnerability in actions.php in Positive Software H-Sphere WebShell 4.3.10 allows remote atta
23RIESGO
abrir
ReferênciaVexDay Proof
Natterchat 1.12 - Authentication Bypass
CVE-2008-7049webappsphp
Multiple SQL injection vulnerabilities in login.asp in NatterChat 1.1 and 1.12 allow remote attackers to execute arbitra
23RIESGO
abrir
Referência
CVE-2010-1743
SQL injection vulnerability in projects.php in Scratcher allows remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir
Referência
CVE-2017-16894
In Laravel framework through 5.5.21, remote attackers can obtain sensitive information (such as externally usable passwo
60RIESGO
abrir
Referência
CVE-2018-1002105
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RIESGO
abrir
Referência
CVE-2018-1002105
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upg
70RIESGO
abrir
Referência
CVE-2018-9276
CVE-2018-9276HIGHbajo ataque
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administra
100RIESGO
abrir
Referência
CVE-2018-9276
CVE-2018-9276HIGHbajo ataque
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administra
100RIESGO
abrir
Referência
CVE-2018-9276
CVE-2018-9276HIGHbajo ataque
An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administra
100RIESGO
abrir
Referência
CVE-2009-2310
SQL injection vulnerability in include/get_read.php in Extensible-BioLawCom CMS (X-BLC) 0.2.0 and earlier allows remote
23RIESGO
abrir
ReferênciaVexDay Proof
WebChamado 1.1 - 'tsk_id' SQL Injection
CVE-2008-2906webappsphp
SQL injection vulnerability in lista_anexos.php in WebChamado 1.1 allows remote attackers to execute arbitrary SQL comma
23RIESGO
abrir
ReferênciaVexDay Proof
Pre Job Board - 'JobSearch.php' SQL Injection
CVE-2008-2915webappsphp
Multiple SQL injection vulnerabilities in jobseekers/JobSearch.php (aka the search module) in Pre Job Board allow remote
23RIESGO
abrir
ReferênciaVexDay Proof
Pre ADS Portal 2.0 - SQL Injection
CVE-2008-2916webappsphp
Multiple SQL injection vulnerabilities in Pre ADS Portal 2.0 and earlier, when magic_quotes_gpc is disabled, allow remot
23RIESGO
abrir
Referência
CVE-2020-13151
Aerospike Community Edition 4.9.0.5 allows for unauthenticated submission and execution of user-defined functions (UDFs)
60RIESGO
abrir
Referência
CVE-2020-13151
Aerospike Community Edition 4.9.0.5 allows for unauthenticated submission and execution of user-defined functions (UDFs)
60RIESGO
abrir
ReferênciaVexDay Proof
CJG EXPLORER PRO 3.2 - 'g_pcltar_lib_dir' Remote File Inclusion
CVE-2007-2199webappsphp
PHP remote file inclusion vulnerability in lib/pcltar.lib.php (aka pcltar.php) in the PclTar module 1.3 and 1.3.1 for Vi
35RIESGO
abrir
ReferênciaVexDay Proof
Dana IRC 1.3 - Remote Buffer Overflow (PoC)
CVE-2008-2922doswindows
Stack-based buffer overflow in artegic Dana IRC client 1.3 and earlier allows remote attackers to cause a denial of serv
23RIESGO
abrir
ReferênciaVexDay Proof
mIRC 6.34 - Remote Buffer Overflow
CVE-2008-4449remotewindows
Stack-based buffer overflow in mIRC 6.34 allows remote attackers to execute arbitrary code via a long hostname in a PRIV
50RIESGO
abrir
ReferênciaVexDay Proof
LogMeIn Remote Access Utility - ActiveX Memory Corruption (Denial of Service)
CVE-2008-7053doswindows
LogMeIn Remote Access Utility ActiveX control (RACtrl.dll) allows remote attackers to cause a denial of service (crash)
23RIESGO
abrir
ReferênciaVexDay Proof
PHP-CMS 1 - 'Username' Blind SQL Injection
CVE-2009-0407webappsphp
SQL injection vulnerability in admin/login.php in PHP-CMS Project 1 allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
Referência
CVE-2017-5816
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
60RIESGO
abrir
Referência
CVE-2017-5816
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P04 was found.
60RIESGO
abrir
Referência
CVE-2018-1160
Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking
70RIESGO
abrir
Referência
CVE-2018-1160
Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking
70RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.