Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
22.573 exploits
Referência
CVE-2013-3928
Stack-based buffer overflow in the ReadFile function in flt_BMP.dll in Chasys Draw IES before 4.11.02 allows remote atta
50RIESGO
abrir
ReferênciaVexDay Proof
Mambo Component com_Musica - 'id' SQL Injection
CVE-2008-6234webappsphp
SQL injection vulnerability in the com_musica module in Joomla! and Mambo allows remote attackers to execute arbitrary S
23RIESGO
abrir
ReferênciaVexDay Proof
SFS EZ Software - 'id' SQL Injection
CVE-2008-6237webappsphp
SQL injection vulnerability in software-description.php in Scripts For Sites (SFS) Hotscripts-like Site allows remote at
23RIESGO
abrir
Referência
CVE-2019-13101
An issue was discovered on D-Link DIR-600M 3.02, 3.03, 3.04, and 3.06 devices. wan.htm can be accessed directly without
50RIESGO
abrir
ReferênciaVexDay Proof
Flexphpsite 0.0.1 - Authentication Bypass
CVE-2008-6241webappsphp
Multiple SQL injection vulnerabilities in admin/usercheck.php in FlexPHPSite 0.0.1 and 0.0.7, when magic_quotes_gpc is d
23RIESGO
abrir
ReferênciaVexDay Proof
SFS EZ Gaming Cheats - SQL Injection
CVE-2008-6244webappsphp
SQL injection vulnerability in view_reviews.php in Scripts for Sites (SFS) EZ Gaming Cheats allows remote attackers to e
23RIESGO
abrir
Referência
CVE-2010-1870
The OGNL extensive expression evaluation capability in XWork in Struts 2.0.0 through 2.1.8.1, as used in Atlassian Fishe
60RIESGO
abrir
Referência
CVE-2022-1162
A hardcoded password was set for accounts registered using an OmniAuth provider (e.g. OAuth, LDAP, SAML) in GitLab CE/EE
85RIESGO
abrir
Referência
CVE-2013-4988
Stack-based buffer overflow in IcoFX 2.5 and earlier allows remote attackers to execute arbitrary code via a long idCoun
50RIESGO
abrir
Referência
CVE-2013-4988
Stack-based buffer overflow in IcoFX 2.5 and earlier allows remote attackers to execute arbitrary code via a long idCoun
50RIESGO
abrir
ReferênciaVexDay Proof
SFS EZ Top Sites - SQL Injection
CVE-2008-6247webappsphp
SQL injection vulnerability in topsite.php in Scripts For Sites (SFS) EZ Top Sites allows remote attackers to execute ar
23RIESGO
abrir
Referência
CVE-2022-1175
Improper neutralization of user input in GitLab CE/EE versions 14.4 before 14.7.7, all versions starting from 14.8 befor
63RIESGO
abrir
ReferênciaVexDay Proof
Galatolo Web Manager 1.3a - Cross-Site Scripting / SQL Injection
CVE-2008-6249webappsphp
SQL injection vulnerability in plugins/users/index.php in Galatolo WebManager 1.3a and earlier allows remote attackers t
23RIESGO
abrir
Referência
CVE-2010-1870
The OGNL extensive expression evaluation capability in XWork in Struts 2.0.0 through 2.1.8.1, as used in Atlassian Fishe
60RIESGO
abrir
ReferênciaVexDay Proof
AsteriDex 3.0 - 'callboth.php' Remote Code Execution
CVE-2007-3621webappsphp
Multiple CRLF injection vulnerabilities in callboth.php in AsteriDex 3.0 and earlier allow remote attackers to inject ar
23RIESGO
abrir
Referência
CVE-2011-1566
Directory traversal vulnerability in dc.exe 9.00.00.11059 and earlier in 7-Technologies Interactive Graphical SCADA Syst
50RIESGO
abrir
Referência
CVE-2012-6525
SQL injection vulnerability in members.php in PHPBridges allows remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir
Referência
CVE-2015-3081
Race condition in Adobe Flash Player before 13.0.0.289 and 14.x through 17.x before 17.0.0.188 on Windows and OS X and b
28RIESGO
abrir
Referência
CVE-2016-1608
vaconfig/time in Novell Filr before 1.2 Security Update 3 and 2.0 before Security Update 2 allows remote authenticated u
28RIESGO
abrir
Referência
CVE-2009-4797
SQL injection vulnerability in browse.php in JobHut 1.2 and earlier allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
Referência
CVE-2022-24562
In IOBit IOTransfer 4.3.1.1561, an unauthenticated attacker can send GET and POST requests to Airserv and gain arbitrary
35RIESGO
abrir
Referência
CVE-2017-8480
The kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2,
23RIESGO
abrir
Referência
CVE-2008-6264
SQL injection vulnerability in admin/admin.php in E-topbiz Slide Popups 1.0 allows remote attackers to execute arbitrary
23RIESGO
abrir
ReferênciaVexDay Proof
Oracle Internet Directory 10.1.4 - Remote Denial of Service
CVE-2008-2595dosmultiple
Unspecified vulnerability in the Oracle Internet Directory component in Oracle Application Server 9.0.4.3, 10.1.2.3, and
28RIESGO
abrir
Referência
CVE-2017-9430
Stack-based buffer overflow in dnstracer through 1.9 allows attackers to cause a denial of service (application crash) o
28RIESGO
abrir
Referência
CVE-2017-9430
Stack-based buffer overflow in dnstracer through 1.9 allows attackers to cause a denial of service (application crash) o
28RIESGO
abrir
Referência
CVE-2010-2020
sys/nfsclient/nfs_vfsops.c in the NFS client in the kernel in FreeBSD 7.2 through 8.1-PRERELEASE, when vfs.usermount is
23RIESGO
abrir
Referência
CVE-2007-2583
The in_decimal::set function in item_cmpfunc.cc in MySQL before 5.0.40, and 5.1 before 5.1.18-beta, allows context-depen
28RIESGO
abrir
ReferênciaVexDay Proof
WordPress Plugin st_newsletter - SQL Injection
CVE-2008-0683webappsphp
SQL injection vulnerability in shiftthis-preview.php in the ShiftThis Newsletter (st_newsletter) plugin for WordPress al
23RIESGO
abrir
Referência
CVE-2009-2341
SQL injection vulnerability in albumdetail.php in Opial 1.0 allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.