Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.043exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
22.832 exploits
ReferênciaVexDay Proof
PHPBandManager 0.8 - 'index.php?pg' Remote File Inclusion
CVE-2007-2341webappsphp
PHP remote file inclusion vulnerability in suite/index.php in phpBandManager 0.8 allows remote attackers to execute arbi
23RIESGO
abrir
Referência
CVE-2014-0322
CVE-2014-0322HIGHbajo ataque
Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code v
100RIESGO
abrir
Referência
CVE-2015-6132
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2
60RIESGO
abrir
Referência
CVE-2017-2741
A potential security vulnerability has been identified with HP PageWide Printers, HP OfficeJet Pro Printers, with firmwa
60RIESGO
abrir
Referência
CVE-2009-2335
WordPress and WordPress MU before 2.8.1 exhibit different behavior for a failed login attempt depending on whether the u
60RIESGO
abrir
Referência
CVE-2013-3906
CVE-2013-3906HIGHbajo ataque
GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2; Office 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compati
100RIESGO
abrir
Referência
CVE-2014-0322
CVE-2014-0322HIGHbajo ataque
Use-after-free vulnerability in Microsoft Internet Explorer 9 and 10 allows remote attackers to execute arbitrary code v
100RIESGO
abrir
Referência
CVE-2019-20499
D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Restore Config
60RIESGO
abrir
Referência
CVE-2020-28949
CVE-2020-28949HIGHbajo ataque
Archive_Tar through 1.4.10 has :// filename sanitization only to address phar attacks, and thus any other stream-wrapper
100RIESGO
abrir
ReferênciaVexDay Proof
PHPortal 1.2 - Multiple Remote File Inclusions
CVE-2008-3022webappsphp
Multiple PHP remote file inclusion vulnerabilities in sablonlar/gunaysoft/gunaysoft.php in PHPortal 1.2 Beta allow remot
23RIESGO
abrir
ReferênciaVexDay Proof
Efestech Shop 2.0 - 'cat_id' SQL Injection
CVE-2008-3030webappsphp
SQL injection vulnerability in default.asp in EfesTECH Shop 2.0 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
Referência
CVE-2026-7097
Tenda F456 httpd webExcptypemanFilter fromwebExcptypemanFilter buffer overflow
41RIESGO
abrir
Referência
CVE-2026-7096
Tenda HG3 formgponConf os command injection
41RIESGO
abrir
Referência
CVE-2015-7858
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via un
60RIESGO
abrir
Referência
CVE-2018-1000006
GitHub Electron versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier, 1.6.15 and earlier has a vulnerability in the pro
60RIESGO
abrir
Referência
CVE-2026-7095
code-projects Employee Management System edit.php cross site scripting
33RIESGO
abrir
Referência
CVE-2026-7094
ShadowCloneLabs GlutamateMCPServers puppeteer_navigate index.ts server-side request forgery
33RIESGO
abrir
Referência
CVE-2026-7098
Tenda F456 httpd DhcpListClient fromDhcpListClient buffer overflow
41RIESGO
abrir
ReferênciaVexDay Proof
Absolute Poll Manager XE 4.1 - 'xlacomments.asp' SQL Injection
CVE-2008-4569webappsasp
SQL injection vulnerability in xlacomments.asp in XIGLA Software Absolute Poll Manager XE 4.1 allows remote attackers to
23RIESGO
abrir
Referência
CVE-2009-2389
Multiple SQL injection vulnerabilities in newsscript.php in USOLVED NEWSolved 1.1.6, when magic_quotes_gpc is disabled,
23RIESGO
abrir
Referência
CVE-2018-1000006
GitHub Electron versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier, 1.6.15 and earlier has a vulnerability in the pro
60RIESGO
abrir
ReferênciaVexDay Proof
Microsoft HTML Workshop 4.74 - Universal Buffer Overflow
CVE-2009-0133localwindows
Buffer overflow in Microsoft HTML Help Workshop 4.74 and earlier allows context-dependent attackers to execute arbitrary
50RIESGO
abrir
Referência
CVE-2015-7858
SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via un
60RIESGO
abrir
ReferênciaVexDay Proof
Acoustica MP3 CD Burner 4.51 Build 147 - '.asx' Local Buffer Overflow
CVE-2007-3006localwindows
Buffer overflow in Acoustica MP3 CD Burner 4.32 allows user-assisted remote attackers to execute arbitrary code via a .a
23RIESGO
abrir
Referência
D-Link DWL-2600AP - Multiple OS Command Injection
CVE-2019-20499webappshardware
D-Link DWL-2600AP 4.2.0.15 Rev A devices have an authenticated OS command injection vulnerability via the Restore Config
60RIESGO
abrir
Referência
CVE-2017-8759
CVE-2017-8759HIGHbajo ataque
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely vi
93RIESGO
abrir
Referência
CVE-2012-2741
Cross-site scripting (XSS) vulnerability in public_html/lists/admin/ in phpList before 2.10.18 allows remote attackers t
23RIESGO
abrir
Referência
CVE-2014-6037
Directory traversal vulnerability in the agentUpload servlet in ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8
60RIESGO
abrir
Referência
CVE-2017-0213
CVE-2017-0213HIGHbajo ataqueransomware
Windows COM Aggregate Marshaler in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Ser
93RIESGO
abrir
Referência
CVE-2018-17431
Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication
60RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.