Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
22.573 exploits
Referência
CVE-2018-7750
transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x
28RIESGO
abrir
Referência
CVE-2022-41413
perfSONAR v4.x <= v4.4.5 was discovered to contain a Cross-Site Request Forgery (CSRF) which is triggered when an attack
33RIESGO
abrir
Referência
Sahi pro 8.x - Directory Traversal
CVE-2019-13063webappsmultiple
Within Sahi Pro 8.0.0, an attacker can send a specially crafted URL to include any victim files on the system via the sc
28RIESGO
abrir
ReferênciaVexDay Proof
Toko Instan 7.6 - Multiple SQL Injections
CVE-2007-6004webappsphp
Multiple SQL injection vulnerabilities in index.php in Toko Instan 7.6 allow remote attackers to execute arbitrary SQL c
23RIESGO
abrir
Referência
CVE-2015-2166
Directory traversal vulnerability in the Instance Monitor in Ericsson Drutt Mobile Service Delivery Platform (MSDP) 4, 5
43RIESGO
abrir
Referência
CVE-2019-19576
class.upload.php in verot.net class.upload before 1.0.3 and 2.x before 2.0.4, as used in the K2 extension for Joomla! an
28RIESGO
abrir
Referência
CVE-2018-17057
An issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the phar://
28RIESGO
abrir
Referência
CVE-2018-17057
An issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the phar://
28RIESGO
abrir
Referência
CVE-2015-6024
ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers with firmware before 3G10WVE-L101-S306ETS-C01_R05 allows remot
28RIESGO
abrir
Referência
CVE-2015-6024
ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers with firmware before 3G10WVE-L101-S306ETS-C01_R05 allows remot
28RIESGO
abrir
Referência
CVE-2010-3749
The browser-plugin implementation in RealNetworks RealPlayer 11.0 through 11.1 and RealPlayer SP 1.0 through 1.1 allows
28RIESGO
abrir
Referência
CVE-2020-28976
The Canto plugin 1.3.0 for WordPress contains a blind SSRF vulnerability. It allows an unauthenticated attacker can make
43RIESGO
abrir
Referência
CVE-2017-3548
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Integratio
35RIESGO
abrir
ReferênciaVexDay Proof
Vigile CMS 1.4 - Multiple Vulnerabilities
CVE-2007-6086webappsphp
Directory traversal vulnerability in index.php in VigileCMS 1.4 allows remote attackers to include and execute arbitrary
23RIESGO
abrir
Referência
CVE-2009-4753
Multiple buffer overflows in the FTP server on the Addonics NAS Adapter NASU2FW41 with loader 1.17 allow remote attacker
23RIESGO
abrir
ReferênciaVexDay Proof
Vigile CMS 1.4 - Multiple Vulnerabilities
CVE-2007-6087webappsphp
Cross-site request forgery (CSRF) vulnerability in index.php in VigileCMS 1.4 allows remote attackers to change the admi
23RIESGO
abrir
ReferênciaVexDay Proof
PowerNews 2.5.4 - 'newsid' SQL Injection
CVE-2009-0705webappsphp
SQL injection vulnerability in news.php in PowerScripts PowerNews 2.5.4, when magic_quotes_gpc is disabled, allows remot
23RIESGO
abrir
Referência
CVE-2016-3216
GDI32.dll in the Graphics component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, W
28RIESGO
abrir
Referência
CVE-2022-31854
Codoforum v5.1 was discovered to contain an arbitrary file upload vulnerability via the logo change option in the admin
50RIESGO
abrir
ReferênciaVexDay Proof
Kipper 2.01 - Cross-Site Scripting / Local File Inclusion / File Disclosure
CVE-2009-0765webappsphp
Directory traversal vulnerability in index.php in Kipper 2.01 allows remote attackers to include and execute arbitrary l
23RIESGO
abrir
Referência
CVE-2018-19864
NUUO NVRmini2 Network Video Recorder firmware through 3.9.1 allows remote attackers to execute arbitrary code or cause a
28RIESGO
abrir
Referência
CVE-2022-3038
CVE-2022-3038HIGHbajo ataque
Use after free in Network Service in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially explo
76RIESGO
abrir
Referência
CVE-2017-3061
Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability in the SWF parser
28RIESGO
abrir
Referência
CVE-2017-3076
Adobe Flash Player versions 25.0.0.171 and earlier have an exploitable memory corruption vulnerability in the MPEG-4 AVC
28RIESGO
abrir
ReferênciaVexDay Proof
YapBB 1.2 - 'forumID' Blind SQL Injection
CVE-2009-0768webappsphp
SQL injection vulnerability in forumhop.php in YapBB 1.2 and earlier allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir
ReferênciaVexDay Proof
Web-MeetMe 3.0.3 - 'play.php' Remote File Disclosure
CVE-2007-6215webappsphp
Multiple directory traversal vulnerabilities in play.php in Web-MeetMe 3.0.3 allow remote attackers to read arbitrary fi
23RIESGO
abrir
ReferênciaVexDay Proof
Hex Workshop 6.0 - '.hex' Local Code Execution
CVE-2009-0812localwindows
Stack-based buffer overflow in BreakPoint Software Hex Workshop 4.23, 6.0.1.4603, and other 6.x and earlier versions all
23RIESGO
abrir
Referência
CVE-2018-4934
Adobe Flash Player versions 29.0.0.113 and earlier have an exploitable out-of-bounds read vulnerability. Successful expl
28RIESGO
abrir
Referência
CVE-2009-2307
SQL injection vulnerability in the CWGuestBook module 2.1 and earlier for MAXdev MDPro (aka MD-Pro) allows remote attack
23RIESGO
abrir
ReferênciaVexDay Proof
PHP-Fusion Mod Members CV (job) 1.0 - SQL Injection
CVE-2009-0831webappsphp
SQL injection vulnerability in members.php in the Members CV (job) module 1.0 for PHP-Fusion, when magic_quotes_gpc is d
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.