Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.542exploits catalogados
34.971CVEs con explotación pública
24.695probados en laboratorio
21.899 exploits
Referência
CVE-2026-7248
D-Link DI-8100 CGI Endpoint tgfile.htm tgfile_htm buffer overflow
48RIESGO
abrir
Referência
CVE-2026-7247
D-Link DI-8100 File Extension file_exten.asp file_exten_asp buffer overflow
41RIESGO
abrir
Referência
CVE-2026-7244
Totolink A8000RU CGI cstecgi.cgi setWiFiEasyGuestCfg os command injection
48RIESGO
abrir
Referência
CVE-2026-7243
Totolink A8000RU CGI cstecgi.cgi setRadvdCfg os command injection
48RIESGO
abrir
Referência
CVE-2025-10539
Improper TLS Certificate Validation RCE via Malicious Update in DeskTime Time Tracking App
33RIESGO
abrir
Referência
CVE-2026-7241
Totolink A8000RU CGI cstecgi.cgi setWiFiBasicCfg os command injection
48RIESGO
abrir
Referência
CVE-2026-7240
Totolink A8000RU CGI cstecgi.cgi setVpnAccountCfg os command injection
48RIESGO
abrir
Referência
CVE-2026-5306
Check & Log Email < 2.0.13 - Unauthenticated Stored XSS
33RIESGO
abrir
Referência
CVE-2026-7227
SourceCodester Pizzafy Ecommerce System ajax.php login sql injection
33RIESGO
abrir
ReferênciaVexDay Proof
Connectix Boards 0.7 - 'p_skin' Multiple Vulnerabilities
CVE-2007-1254webappsphp
SQL injection vulnerability in part.userprofile.php in Connectix Boards 0.7 and earlier allows remote authenticated user
23RIESGO
abrir
Referência
CVE-2009-4856
Cross-site scripting (XSS) vulnerability in subitems.php in PHP Easy Shopping Cart 3.1R allows remote attackers to injec
23RIESGO
abrir
ReferênciaVexDay Proof
Connectix Boards 0.7 - 'p_skin' Multiple Vulnerabilities
CVE-2007-1255webappsphp
Unrestricted file upload vulnerability in admin.bbcode.php in Connectix Boards 0.7 and earlier allows remote authenticat
23RIESGO
abrir
ReferênciaVexDay Proof
WebMod 0.48 - Content-Length Remote Buffer Overflow
CVE-2007-1260remotewindows
Stack-based buffer overflow in the connectHandle function in server.cpp in WebMod 0.48 allows remote attackers to execut
23RIESGO
abrir
ReferênciaVexDay Proof
Mani Stats Reader 1.2 - 'ipath' Remote File Inclusion
CVE-2007-1299webappsphp
PHP remote file inclusion vulnerability in index.php in Mani Stats Reader 1.2 and earlier allows remote attackers to exe
23RIESGO
abrir
ReferênciaVexDay Proof
MailEnable Professional/Enterprise 2.37 - 'APPEND' Remote Buffer Overflow
CVE-2007-1301remotewindows
Stack-based buffer overflow in the IMAP service in MailEnable Enterprise and Professional Editions 2.37 and earlier allo
28RIESGO
abrir
ReferênciaVexDay Proof
News-Letterman 1.1 - 'eintrag.php?sqllog' Remote File Inclusion
CVE-2007-1340webappsphp
PHP remote file inclusion vulnerability in eintrag.php in Weltennetz News-Letterman 1.1 allows remote attackers to execu
23RIESGO
abrir
ReferênciaVexDay Proof
PHP 5.2.1 - 'substr_compare()' Information Leak
CVE-2007-1375localmultiple
Integer overflow in the substr_compare function in PHP 5.2.1 and earlier allows context-dependent attackers to read sens
23RIESGO
abrir
ReferênciaVexDay Proof
PHP 4.4.6 - 'crack_opendict()' Local Buffer Overflow
CVE-2007-1401localwindows
Buffer overflow in the crack extension (CrackLib), as bundled with PHP 4.4.6 and other versions before 5.0.0, might allo
23RIESGO
abrir
ReferênciaVexDay Proof
Macromedia 10.1.4.20 - 'SwDir.dll' Internet Explorer Stack Overflow Denial of Service
CVE-2007-1403doswindows
Multiple stack-based buffer overflows in an ActiveX control in SwDir.dll 10.1.4.20 in Macromedia Shockwave allow remote
28RIESGO
abrir
Referência
CVE-2021-33044
CVE-2021-33044CRITICALbajo ataque
The identity authentication bypass vulnerability found in some Dahua products during the login process. Attackers can by
100RIESGO
abrir
ReferênciaVexDay Proof
wbblog - Cross-Site Scripting / SQL Injection
CVE-2007-1481webappsphp
SQL injection vulnerability in index.php in WBBlog allows remote attackers to execute arbitrary SQL commands via the e_i
23RIESGO
abrir
Referência
CVE-2009-4862
Multiple SQL injection vulnerabilities in Alwasel 1.5 allow remote attackers to execute arbitrary SQL commands via the i
23RIESGO
abrir
ReferênciaVexDay Proof
wbblog - Cross-Site Scripting / SQL Injection
CVE-2007-1482webappsphp
Cross-site scripting (XSS) vulnerability in index.php in WBBlog allows remote attackers to inject arbitrary web script o
23RIESGO
abrir
ReferênciaVexDay Proof
WebLog - 'index.php' Remote File Disclosure
CVE-2007-1487webappsphp
Directory traversal vulnerability in index.php in Sascha Schroeder (aka CyberTeddy or Cyber-inside) WebLog allows remote
23RIESGO
abrir
ReferênciaVexDay Proof
NetVIOS Portal - 'page.asp' SQL Injection
CVE-2007-1566webappsasp
SQL injection vulnerability in News/page.asp in NetVIOS Portal allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
ReferênciaVexDay Proof
News Bin Pro 4.32 - Article Grabbing Remote Unicode Buffer Overflow
CVE-2007-1569doswindows
Stack-based buffer overflow in NewsBin Pro 4.32 allows remote attackers to cause a denial of service or execute arbitrar
23RIESGO
abrir
ReferênciaVexDay Proof
Mercur IMAPD 5.00.14 (Windows x86) - Remote Denial of Service
CVE-2007-1578doswindows_x86
Multiple integer signedness errors in the NTLM implementation in Atrium MERCUR IMAPD (mcrimap4.exe) 5.00.14, with SP4, a
28RIESGO
abrir
ReferênciaVexDay Proof
Mercur Messaging 2005 (Windows 2000 SP4) - IMAP 'Subscribe' Remote Overflow
CVE-2007-1579remotewindows
Stack-based buffer overflow in Atrium MERCUR IMAPD allows remote attackers to have an unknown impact via a certain SUBSC
35RIESGO
abrir
Referência
CVE-2009-4870
Multiple SQL injection vulnerabilities in login.php in PHPCityPortal allow remote attackers to execute arbitrary SQL com
23RIESGO
abrir
ReferênciaVexDay Proof
PHP 5.2.0 (OSX) - 'header()' Space Trimming Buffer Underflow
CVE-2007-1584localosx
Buffer underflow in the header function in PHP 5.2.0 allows context-dependent attackers to execute arbitrary code by pas
23RIESGO
abrir
anteriorpágina 341 / 730siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.