Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.559exploits catalogados
34.978CVEs con explotación pública
24.695probados en laboratorio
21.899 exploits
Referência
CVE-2010-0796
SQL injection vulnerability in the JE Quiz (com_jequizmanagement) component 1.b01 for Joomla! allows remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
GROUP-E 1.6.41 - 'head_auth.php' Remote File Inclusion
CVE-2008-1074webappsphp
PHP remote file inclusion vulnerability in lib/head_auth.php in GROUP-E 1.6.41 allows remote attackers to execute arbitr
35RIESGO
abrir
ReferênciaVexDay Proof
Mambo Component SimpleBoard 1.0.3 - 'catid' SQL Injection
CVE-2008-1077webappsphp
SQL injection vulnerability in index.php in the Simpleboard (com_simpleboard) 1.0.3 Stable component for Mambo and Jooml
23RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Windows - GDI Image Parsing Stack Overflow (MS08-021)
CVE-2008-1083HIGHlocalwindows
Heap-based buffer overflow in the CreateDIBPatternBrushPt function in GDI in Microsoft Windows 2000 SP4, XP SP2, Server
53RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Windows XP SP2 - 'win32k.sys' Local Privilege Escalation (MS08-025)
CVE-2008-1084localwindows
Unspecified vulnerability in the kernel in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, through Vista SP
23RIESGO
abrir
Referência
CVE-2023-22515
CVE-2023-22515CRITICALbajo ataqueransomware
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited
100RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Windows - GDI (EMR_COLORMATCHTOTARGETW) (MS08-021)
CVE-2008-1087remotewindows
Stack-based buffer overflow in GDI in Microsoft Windows 2000 SP4, XP SP2, Server 2003 SP1 and SP2, Vista, and Server 200
35RIESGO
abrir
Referência
CVE-2021-40539
CVE-2021-40539CRITICALbajo ataqueransomware
Zoho ManageEngine ADSelfService Plus version 6113 and prior is vulnerable to REST API authentication bypass with resulta
100RIESGO
abrir
Referência
CVE-2019-3929
CVE-2019-3929CRITICALbajo ataque
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Ba
100RIESGO
abrir
Referência
CVE-2019-3929
CVE-2019-3929CRITICALbajo ataque
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Ba
100RIESGO
abrir
Referência
CVE-2019-3929
CVE-2019-3929CRITICALbajo ataque
The Crestron AM-100 firmware 1.6.0.2, Crestron AM-101 firmware 2.7.0.1, Barco wePresent WiPG-1000P firmware 2.3.0.10, Ba
100RIESGO
abrir
Referência
CVE-2019-25676
Ask Expert Script 3.0.5 Cross Site Scripting SQL Injection
41RIESGO
abrir
Referência
CVE-2017-9791
CVE-2017-9791CRITICALbajo ataque
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passe
100RIESGO
abrir
Referência
CVE-2017-9791
CVE-2017-9791CRITICALbajo ataque
The Struts 1 plugin in Apache Struts 2.1.x and 2.3.x might allow remote code execution via a malicious field value passe
100RIESGO
abrir
Referência
CVE-2016-7612
An issue was discovered in certain Apple products. iOS before 10.2 is affected. macOS before 10.12.2 is affected. watchO
23RIESGO
abrir
ReferênciaVexDay Proof
MailEnable Professional/Enterprise 3.13 - 'Fetch' (Authenticated) Remote Buffer Overflow
CVE-2008-1276remotewindows
Multiple buffer overflows in the IMAP service (MEIMAPS.EXE) in MailEnable Professional Edition and Enterprise Edition 3.
23RIESGO
abrir
ReferênciaVexDay Proof
phpMyNewsletter 0.8b5 - 'msg_id' SQL Injection
CVE-2008-1295webappsphp
SQL injection vulnerability in archives.php in Gregory Kokanosky (aka Greg's Place) phpMyNewsletter 0.8 beta 5 and earli
23RIESGO
abrir
ReferênciaVexDay Proof
Mambo Component eWriting 1.2.1 - 'cat' SQL Injection
CVE-2008-1297webappsphp
SQL injection vulnerability in index.php in the eWriting (com_ewriting) 1.2.1 module for Mambo and Joomla! allows remote
23RIESGO
abrir
Referência
CVE-2026-61524
WebsiteBaker CMS < 2.13.10 File Upload RCE via Module Installation
41RIESGO
abrir
Referência
CVE-2019-11539
CVE-2019-11539HIGHbajo ataqueransomware
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1R
100RIESGO
abrir
Referência
CVE-2019-11539
CVE-2019-11539HIGHbajo ataqueransomware
In Pulse Secure Pulse Connect Secure version 9.0RX before 9.0R3.4, 8.3RX before 8.3R7.1, 8.2RX before 8.2R12.1, and 8.1R
100RIESGO
abrir
ReferênciaVexDay Proof
Knowledge Base Mod 2.0.2 - 'phpBB' Remote File Inclusion
CVE-2006-2134webappsphp
PHP remote file inclusion vulnerability in /includes/kb_constants.php in Knowledge Base Mod for PHPbb 2.0.2 and earlier
23RIESGO
abrir
Referência
CVE-2019-5736
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
Referência
CVE-2019-5736
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
Referência
CVE-2019-5736
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
Referência
CVE-2019-5736
runc through 1.0-rc6, as used in Docker before 18.09.2 and other products, allows attackers to overwrite the host runc b
60RIESGO
abrir
ReferênciaVexDay Proof
Limbo CMS 1.0.4.2 - 'sql.php' Remote File Inclusion
CVE-2006-2142webappsphp
PHP remote file inclusion vulnerability in classes/adodbt/sql.php in Limbo CMS 1.04 and earlier allows remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
EasyGallery 5.0tr - Multiple Vulnerabilities
CVE-2008-1346webappsphp
SQL injection vulnerability in staticpages/easygallery/index.php in MyioSoft EasyGallery 5.0tr and earlier allows remote
23RIESGO
abrir
ReferênciaVexDay Proof
EasyGallery 5.0tr - Multiple Vulnerabilities
CVE-2008-1347webappsphp
Multiple cross-site scripting (XSS) vulnerabilities in staticpages/easygallery/index.php in MyioSoft EasyGallery 5.0tr a
23RIESGO
abrir
ReferênciaVexDay Proof
Fully Modded phpBB - 'kb.php' SQL Injection
CVE-2008-1350webappsphp
SQL injection vulnerability in kb.php in Fully Modded phpBB (phpbbfm) 80220 allows remote attackers to execute arbitrary
23RIESGO
abrir
anteriorpágina 355 / 730siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.