Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.008exploits catalogados
34.638CVEs con explotación pública
24.695probados en laboratorio
21.662 exploits
Referência
CVE-2018-16302
MediaComm Zip-n-Go before 4.95 has a Buffer Overflow via a crafted file.
23RIESGO
abrir
Referência
CVE-2016-5348
The GPS component in Android 4.x before 4.4.4, 5.0.x before 5.0.2, 5.1.x before 5.1.1, 6.x before 2016-10-01, and 7.0 be
23RIESGO
abrir
Referência
CVE-2012-6644
Multiple cross-site scripting (XSS) vulnerabilities in ClipBucket 2.6 allow remote attackers to inject arbitrary web scr
23RIESGO
abrir
ReferênciaVexDay Proof
pandaBB - 'displayCategory' Remote File Inclusion
CVE-2006-5494webappsphp
Multiple PHP remote file inclusion vulnerabilities in modules/My_eGallery/public/displayCategory.php in the pandaBB modu
23RIESGO
abrir
ReferênciaVexDay Proof
IrfanView 4.00 - '.iff' Local Buffer Overflow
CVE-2007-2363localwindows
Buffer overflow in IrfanView 4.00 and earlier allows user-assisted remote attackers to execute arbitrary code via a craf
23RIESGO
abrir
ReferênciaVexDay Proof
GlobalLink 2.7.0.8 - 'glItemCom.dll SetInfo()' Heap Overflow
CVE-2007-4802remotewindows
Multiple heap-based buffer overflows in GlobalLink 2.7.0.8 allow remote attackers to execute arbitrary code via (1) a lo
23RIESGO
abrir
ReferênciaVexDay Proof
GlobalLink 2.7.0.8 - 'glitemflat.dll SetClientInfo()' Heap Overflow
CVE-2007-4802remotewindows
Multiple heap-based buffer overflows in GlobalLink 2.7.0.8 allow remote attackers to execute arbitrary code via (1) a lo
23RIESGO
abrir
ReferênciaVexDay Proof
Mini File Host 1.x - Arbitrary '.PHP' File Upload
CVE-2008-6785webappsphp
Unrestricted file upload vulnerability in Mini File Host 1.5 allows remote attackers to execute arbitrary code by upload
23RIESGO
abrir
ReferênciaVexDay Proof
Exodus 0.10 - URI Handler Arbitrary Parameter Injection (2)
CVE-2008-6936remotewindows
Argument injection vulnerability in Exodus 0.10 allows remote attackers to inject arbitrary command line arguments, over
23RIESGO
abrir
Referência
CVE-2012-6644
Multiple cross-site scripting (XSS) vulnerabilities in ClipBucket 2.6 allow remote attackers to inject arbitrary web scr
23RIESGO
abrir
Referência
CVE-2018-0715
Cross-site scripting vulnerability in QNAP Photo Station versions 5.7.0 and earlier could allow remote attackers to inje
23RIESGO
abrir
Referência
CVE-2019-3474
Path traversal vulnerability in Filr web application
33RIESGO
abrir
ReferênciaVexDay Proof
TorrentTrader Classic 1.09 - Multiple Vulnerabilities
CVE-2009-2157webappsphp
Multiple SQL injection vulnerabilities in TorrentTrader Classic 1.09 allow remote authenticated users to execute arbitra
23RIESGO
abrir
Referência
CVE-2016-4004
Directory traversal vulnerability in Dell OpenManage Server Administrator (OMSA) 8.2 allows remote authenticated adminis
23RIESGO
abrir
Referência
CVE-2026-5813
PHPGurukul Online Course Registration check_availability.php sql injection
33RIESGO
abrir
Referência
CVE-2010-1743
SQL injection vulnerability in projects.php in Scratcher allows remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir
Referência
CVE-2021-41382
Plastic SCM before 10.0.16.5622 mishandles the WebAdmin server management interface.
23RIESGO
abrir
Referência
CVE-2023-38357
Session tokens in RWS WorldServer 11.7.3 and earlier have a low entropy and can be enumerated, leading to unauthorized a
23RIESGO
abrir
Referência
CVE-2023-4490
WP Job Portal < 2.0.6 - Unauthenticated SQLi
63RIESGO
abrir
ReferênciaVexDay Proof
PHP121 Instant Messenger 2.2 - Local File Inclusion
CVE-2007-1908webappsphp
PHP file inclusion vulnerability in php121db.php in PHP121 Instant Messenger 2.2 allows remote attackers to execute arbi
23RIESGO
abrir
Referência
CVE-2026-49491
Pixa Bank 2.0 SQL Injection via agence-ajax.php API
41RIESGO
abrir
Referência
CVE-2018-18955
In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalat
38RIESGO
abrir
Referência
CVE-2026-5812
SourceCodester Pharmacy Product Management System POST Parameter add-sales.php logic error
33RIESGO
abrir
ReferênciaVexDay Proof
Attachmax Dolphin 2.1.0 - Multiple Vulnerabilities
CVE-2008-4207webappsphp
Attachmax Dolphin 2.1.0 and earlier does not properly protect info.php in the main folder, which allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
webid 0.5.4 - Multiple Vulnerabilities
CVE-2008-7117webappsphp
eledicss.php in WeBid auction script 0.5.4 allows remote attackers to modify arbitrary cascading style sheets (CSS) file
23RIESGO
abrir
Referência
CVE-2013-1408
Multiple SQL injection vulnerabilities in the Wysija Newsletters plugin before 2.2.1 for WordPress allow remote authenti
23RIESGO
abrir
Referência
CVE-2019-2861
Vulnerability in the Oracle Hyperion Planning component of Oracle Hyperion (subcomponent: Security). The supported versi
23RIESGO
abrir
Referência
CVE-2017-2480
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. iCloud b
23RIESGO
abrir
Referência
CVE-2016-6663
Race condition in Oracle MySQL before 5.5.52, 5.6.x before 5.6.33, 5.7.x before 5.7.15, and 8.x before 8.0.1; MariaDB be
23RIESGO
abrir
Referência
CVE-2023-31702
SQL injection in the View User Profile in MicroWorld eScan Management Console 14.0.1400.2281 allows remote attacker to d
41RIESGO
abrir
anteriorpágina 266 / 723siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.