Explotación pública
Catálogo de exploits
Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.
75.902exploits catalogados
34.597CVEs con explotación pública
24.695probados en laboratorio
TodosExploit-DB 24.443Referência 21.624GitHub PoC 13.727VulnCheck XDB 8410Nuclei 4231Metasploit 3467✓ solo verificadosrecientespopularesriesgo
21.624 exploits
Referência
CVE-2014-6070
Multiple cross-site scripting (XSS) vulnerabilities in Adiscon LogAnalyzer before 3.6.6 allow remote attackers to inject
23RIESGO
abrir ↗Referência✓ VexDay Proof
IBM Director < 5.10 - 'Redirect.bat' Directory Traversal
Directory traversal vulnerability in Redirect.bat in IBM Director before 5.10 allows remote attackers to read arbitrary
23RIESGO
abrir ↗Referência✓ VexDay Proof
phpEventMan 1.0.2 - 'level' Remote File Inclusion
Multiple PHP remote file inclusion vulnerabilities in phpEventMan 1.0.2 allow remote attackers to execute arbitrary PHP
23RIESGO
abrir ↗Referência
CVE-2018-17997
LayerBB 1.1.1 allows XSS via the titles of conversations (PMs).
23RIESGO
abrir ↗Referência
CVE-2018-17997
LayerBB 1.1.1 allows XSS via the titles of conversations (PMs).
23RIESGO
abrir ↗Referência
CVE-2018-0969
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RIESGO
abrir ↗Referência
CVE-2018-0970
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RIESGO
abrir ↗Referência
CVE-2008-7008
HyperStop Web Host Directory 1.2 allows remote attackers to bypass authentication and download a database backup via a d
23RIESGO
abrir ↗Referência
CVE-2012-3435
SQL injection vulnerability in frontends/php/popup_bitem.php in Zabbix 1.8.15rc1 and earlier, and 2.x before 2.0.2rc1, a
23RIESGO
abrir ↗Referência
CVE-2018-0971
An information disclosure vulnerability exists in the Windows kernel that could allow an attacker to retrieve informatio
23RIESGO
abrir ↗Referência
CVE-2014-2995
Multiple cross-site scripting (XSS) vulnerabilities in twitget.php in the Twitget plugin before 3.3.3 for WordPress allo
23RIESGO
abrir ↗Referência
CVE-2009-3716
Unrestricted file upload vulnerability in admin.php in MCshoutbox 1.1 allows remote authenticated users to execute arbit
23RIESGO
abrir ↗Referência
CVE-2017-8840
Debug information disclosure exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before f
23RIESGO
abrir ↗Referência
CVE-2012-0699
Multiple cross-site request forgery (CSRF) vulnerabilities in Family Connections CMS (aka FCMS) 2.9 and earlier allow re
23RIESGO
abrir ↗Referência
CVE-2023-37759
Incorrect access control in the User Registration page of Crypto Currency Tracker (CCT) before v9.5 allows unauthenticat
23RIESGO
abrir ↗Referência
CVE-2021-33570
Postbird 0.8.4 allows stored XSS via the onerror attribute of an IMG element in any PostgreSQL database table. This can
23RIESGO
abrir ↗Referência
CVE-2021-33570
Postbird 0.8.4 allows stored XSS via the onerror attribute of an IMG element in any PostgreSQL database table. This can
23RIESGO
abrir ↗Referência✓ VexDay Proof
PhpHostBot 1.06 - 'svr_rootscript' Remote File Inclusion
PHP remote file inclusion vulnerability in order/login.php in IDevSpot PhpHostBot 1.06 and earlier allows remote attacke
23RIESGO
abrir ↗Referência✓ VexDay Proof
e107 module 123 flash chat 6.8.0 - Remote File Inclusion
PHP remote file inclusion vulnerability in 123flashchat.php in the 123 Flash Chat 6.8.0 module for e107, when register_g
23RIESGO
abrir ↗Referência✓ VexDay Proof
A-Link WL54AP3 / WL54AP2 - Cross-Site Request Forgery / Cross-Site Scripting
The management interface on the A-LINK WL54AP3 and WL54AP2 access points has a blank default password for the admin acco
23RIESGO
abrir ↗Referência
CVE-2018-18548
ajenticp (aka Ajenti Docker control panel) for Ajenti through v1.2.23.13 has XSS via a filename that is mishandled in Fi
23RIESGO
abrir ↗Referência
CVE-2018-18548
ajenticp (aka Ajenti Docker control panel) for Ajenti through v1.2.23.13 has XSS via a filename that is mishandled in Fi
23RIESGO
abrir ↗Referência
CVE-2010-2254
SQL injection vulnerability in the Shape5 Bridge of Hope template for Joomla! allows remote attackers to execute arbitra
23RIESGO
abrir ↗Referência
CVE-2010-2254
SQL injection vulnerability in the Shape5 Bridge of Hope template for Joomla! allows remote attackers to execute arbitra
23RIESGO
abrir ↗Referência
CVE-2012-4267
Cross-site scripting (XSS) vulnerability in user/register in Sockso 1.5 and earlier allows remote attackers to inject ar
23RIESGO
abrir ↗Referência
CVE-2006-0944
Archangel Weblog 0.90.02 allows remote attackers to bypass authentication by setting the ba_admin cookie to 1.
23RIESGO
abrir ↗Referência
CVE-2013-2760
Buffer overflow in Groovy Media Player 3.2.0 allows remote attackers to execute arbitrary code via a long string in a .m
23RIESGO
abrir ↗Referência
CVE-2014-4944
Multiple SQL injection vulnerabilities in inc/bsk-pdf-dashboard.php in the BSK PDF Manager plugin 1.3.2 for WordPress al
23RIESGO
abrir ↗Referência
CVE-2015-2554
The kernel in Microsoft Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT Gold and 8.1, and Windows 10
23RIESGO
abrir ↗Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.