Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.008exploits catalogados
34.638CVEs con explotación pública
24.695probados en laboratorio
21.662 exploits
Referência
Local Service Search Engine Management System 1.0 - SQLi Authentication Bypass
CVE-2021-3278webappsmultiple
Local Service Search Engine Management System 1.0 has a vulnerability through authentication bypass using SQL injection
28RIESGO
abrir
Referência
CVE-2021-3291
Zen Cart 1.5.7b allows admins to execute arbitrary OS commands by inspecting an HTML radio input element (within the mod
28RIESGO
abrir
Referência
CASAP Automated Enrollment System 1.0 - 'First Name' Stored XSS
CVE-2021-3294webappsphp
CASAP Automated Enrollment System 1.0 is affected by cross-site scripting (XSS) in users.php. An attacker can steal a co
23RIESGO
abrir
Referência
CVE-2010-1924
SQL injection vulnerability in index.php in Hi Web Wiesbaden Live Shopping Multi Portal System allows remote attackers t
23RIESGO
abrir
Referência
CVE-2018-5754
Cross-site scripting (XSS) vulnerability in the office-web component in Open-Xchange OX App Suite before 7.8.3-rev12 and
23RIESGO
abrir
Referência
CVE-2018-5754
Cross-site scripting (XSS) vulnerability in the office-web component in Open-Xchange OX App Suite before 7.8.3-rev12 and
23RIESGO
abrir
Referência
CVE-2019-6710
Zyxel NBG-418N v2 v1.00(AAXM.4)C0 devices allow login.cgi CSRF.
23RIESGO
abrir
Referência
CVE-2018-12114
Maccms 10 allows CSRF via admin.php/admin/admin/info.html to add user accounts.
23RIESGO
abrir
Referência
CVE-2010-1925
SQL injection vulnerability in makale.php in tekno.Portal 0.1b allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
Referência
CVE-2010-1925
SQL injection vulnerability in makale.php in tekno.Portal 0.1b allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
Referência
CVE-2015-4630
Multiple cross-site request forgery (CSRF) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x
23RIESGO
abrir
Referência
CVE-2017-0282
Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT
23RIESGO
abrir
Referência
CVE-2017-0285
Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT
23RIESGO
abrir
Referência
LightCMS 1.3.4 - 'exclusive' Stored XSS
CVE-2021-3355webappsmultiple
A stored-self XSS exists in LightCMS v1.3.4, allowing an attacker to execute HTML or JavaScript code in a vulnerable Tit
23RIESGO
abrir
Referência
Postbird 0.8.4 - Javascript Injection
CVE-2021-33570webappsmultiple
Postbird 0.8.4 allows stored XSS via the onerror attribute of an IMG element in any PostgreSQL database table. This can
23RIESGO
abrir
ReferênciaVexDay Proof
Millewin 13.39.146.1 - Local Privilege Escalation
CVE-2021-3394localwindows
Millennium Millewin (also known as "Cartella clinica") 13.39.028, 13.39.28.3342, and 13.39.146.1 has insecure folder per
23RIESGO
abrir
Referência
CVE-2017-0284
Uniscribe in Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT
23RIESGO
abrir
Referência
CVE-2021-34369
portlets/contact/ref/refContactDetail.do in Accela Civic Platform through 20.1 allows remote attackers to obtain sensiti
23RIESGO
abrir
Referência
CVE-2010-5007
Cross-site scripting (XSS) vulnerability in pages/match_report.php in UTStats Beta 4 and earlier allows remote attackers
23RIESGO
abrir
Referência
CVE-2022-40946
On D-Link DIR-819 Firmware Version 1.06 Hardware Version A1 devices, it is possible to trigger a Denial of Service via t
41RIESGO
abrir
Referência
CVE-2018-7216
Cross-site request forgery (CSRF) vulnerability in esop/toolkit/profile/regData.do in Bravo Tejari Procurement Portal al
23RIESGO
abrir
Referência
CVE-2018-7216
Cross-site request forgery (CSRF) vulnerability in esop/toolkit/profile/regData.do in Bravo Tejari Procurement Portal al
23RIESGO
abrir
Referência
CVE-2017-16783
In CMS Made Simple 2.1.6, there is Server-Side Template Injection via the cntnt01detailtemplate parameter.
23RIESGO
abrir
Referência
CVE-2010-5007
Cross-site scripting (XSS) vulnerability in pages/match_report.php in UTStats Beta 4 and earlier allows remote attackers
23RIESGO
abrir
Referência
CVE-2019-14280
In some circumstances, Craft 2 before 2.7.10 and 3 before 3.2.6 wasn't stripping EXIF data from user-uploaded images whe
23RIESGO
abrir
ReferênciaVexDay Proof
MODx CMS 0.9.2.1 - 'FCKeditor' Remote File Inclusion
CVE-2006-5730webappsphp
PHP remote file inclusion vulnerability in manager/media/browser/mcpuk/connectors/php/Commands/Thumbnail.php in Modx CMS
23RIESGO
abrir
ReferênciaVexDay Proof
Durian Web Application Server 3.02 - Remote Buffer Overflow
CVE-2006-6853remotewindows
Buffer overflow in Durian Web Application Server 3.02 freeware on Windows allows remote attackers to execute arbitrary c
23RIESGO
abrir
ReferênciaVexDay Proof
Ax Developer CMS 0.1.1 - 'index.php?module' Local File Inclusion
CVE-2007-5820webappsphp
Directory traversal vulnerability in index.php in Ax Developer CMS (AxDCMS) 0.1.1 allows remote attackers to include and
23RIESGO
abrir
ReferênciaVexDay Proof
Lanius CMS 1.2.16 - 'FCKeditor' Arbitrary File Upload
CVE-2007-5156webappsphp
Incomplete blacklist vulnerability in editor/filemanager/upload/php/upload.php in FCKeditor, as used in SiteX CMS 0.7.3.
23RIESGO
abrir
ReferênciaVexDay Proof
SyntaxCMS 1.3 - 'FCKeditor' Arbitrary File Upload
CVE-2007-5156webappsphp
Incomplete blacklist vulnerability in editor/filemanager/upload/php/upload.php in FCKeditor, as used in SiteX CMS 0.7.3.
23RIESGO
abrir
anteriorpágina 276 / 723siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.