Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

76.647exploits catalogados
34.986CVEs con explotación pública
24.695probados en laboratorio
21.899 exploits
Referência
Webmin 1.996 - Remote Code Execution (RCE) (Authenticated)
CVE-2022-36446webappslinux
software/apt-lib.pl in Webmin before 1.997 lacks HTML escaping for a UI command.
60RIESGO
abrir
ReferênciaVexDay Proof
Microsoft Visual InterDev 6.0 SP6 - '.sln' Local Buffer Overflow (PoC)
CVE-2008-1709doswindows
Buffer overflow in Microsoft Visual InterDev 6.0 (SP6) allows user-assisted attackers to execute arbitrary code via a St
28RIESGO
abrir
ReferênciaVexDay Proof
Carscripts Classifieds - 'cat' SQL Injection
CVE-2008-2844webappsphp
SQL injection vulnerability in index.php in Carscripts Classifieds allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
ReferênciaVexDay Proof
BoatScripts Classifieds - 'type' SQL Injection
CVE-2008-2846webappsphp
SQL injection vulnerability in index.php in BoatScripts Classifieds allows remote attackers to execute arbitrary SQL com
23RIESGO
abrir
ReferênciaVexDay Proof
AJ Auction Web 2.0 - 'cate_id' SQL Injection
CVE-2008-2860webappsphp
SQL injection vulnerability in category.php in AJSquare AJ Auction Pro web 2.0 allows remote attackers to execute arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
Vinagre < 2.24.2 - 'show_error()' Remote Format String (PoC)
CVE-2008-5660doswindows
Format string vulnerability in the vinagre_utils_show_error function (src/vinagre-utils.c) in Vinagre 0.5.x before 0.5.2
23RIESGO
abrir
ReferênciaVexDay Proof
phpEmployment - 'PHP Upload' Arbitrary File Upload
CVE-2008-6920webappsphp
Unrestricted file upload vulnerability in auth.php in phpEmployment 1.8 allows remote attackers to execute arbitrary cod
23RIESGO
abrir
ReferênciaVexDay Proof
WordPress Plugin Photoracer 1.0 - 'id' SQL Injection
CVE-2009-2122webappsphp
SQL injection vulnerability in viewimg.php in the Paolo Palmonari Photoracer plugin 1.0 for WordPress allows remote atta
23RIESGO
abrir
Referência
CVE-2017-8837
Cleartext password storage exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-
23RIESGO
abrir
Referência
CVE-2025-14534
UTT 进取 512W Endpoint formNatStaticMap strcpy buffer overflow
48RIESGO
abrir
ReferênciaVexDay Proof
Net_DNS 0.3 - '/DNS/RR.php' Remote File Inclusion
CVE-2006-5521webappsphp
PHP remote file inclusion vulnerability in DNS/RR.php in Net_DNS 0.03 and earlier allows remote attackers to execute arb
23RIESGO
abrir
Referência
CVE-2017-9603
SQL injection vulnerability in the WP Jobs plugin before 1.5 for WordPress allows authenticated users to execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
Web Wiz Forums 9.07 - 'sub' Directory Traversal
CVE-2008-0466webappsasp
Web Wiz RTE_file_browser.asp in, as used in Web Wiz Rich Text Editor 4.0, Web Wiz Forums 9.07, and Web Wiz Newspad 1.02,
23RIESGO
abrir
Referência
CVE-2018-19040
The Media File Manager plugin 1.4.2 for WordPress allows directory listing via a ../ directory traversal in the dir para
28RIESGO
abrir
Referência
CVE-2015-3301
Directory traversal vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce
23RIESGO
abrir
ReferênciaVexDay Proof
yourplace 1.0.2 - Multiple Vulnerabilities / Remote Code Execution
CVE-2008-6769webappsphp
Unrestricted file upload vulnerability in upload.php in YourPlace 1.0.2 and earlier allows remote authenticated users to
23RIESGO
abrir
Referência
CVE-2009-3837
Stack-based buffer overflow in Eureka Email 2.2q allows remote POP3 servers to execute arbitrary code via a long error m
50RIESGO
abrir
ReferênciaVexDay Proof
PHP-Nuke 7.9 - 'Encyclopedia' SQL Injection
CVE-2006-5525webappsphp
Incomplete blacklist vulnerability in mainfile.php in PHP-Nuke 7.9 and earlier allows remote attackers to conduct SQL in
23RIESGO
abrir
Referência
CVE-2015-4684
Multiple directory traversal vulnerabilities in Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allow (1) re
23RIESGO
abrir
Referência
CVE-2015-4684
Multiple directory traversal vulnerabilities in Polycom RealPresence Resource Manager (aka RPRM) before 8.4 allow (1) re
23RIESGO
abrir
Referência
CVE-2016-1813
The IOAccelSharedUserClient2::page_off_resource method in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1
23RIESGO
abrir
Referência
CVE-2016-1813
The IOAccelSharedUserClient2::page_off_resource method in Apple iOS before 9.3.2, OS X before 10.11.5, tvOS before 9.2.1
23RIESGO
abrir
Referência
CVE-2009-3307
Multiple PHP remote file inclusion vulnerabilities in FSphp 0.2.1 allow remote attackers to execute arbitrary PHP code v
23RIESGO
abrir
Referência
CVE-2019-6780
The Wise Chat plugin before 2.7 for WordPress mishandles external links because rendering/filters/post/WiseChatLinksPost
23RIESGO
abrir
ReferênciaVexDay Proof
phpProfiles 3.1.2b - Multiple Remote File Inclusions
CVE-2006-6740webappsphp
Multiple PHP remote file inclusion vulnerabilities in phpProfiles 3.1.2b and earlier allow remote attackers to execute a
23RIESGO
abrir
Referência
CVE-2011-0507
FTPService.exe in Blackmoon FTP 3.1 Build 1735 and Build 1736 (3.1.7.1736), and possibly other versions before 3.1.8.173
23RIESGO
abrir
Referência
CVE-2014-1695
Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) 3.1.x before 3.1.20, 3.2.x before 3.2.15,
23RIESGO
abrir
Referência
CVE-2014-1695
Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) 3.1.x before 3.1.20, 3.2.x before 3.2.15,
23RIESGO
abrir
Referência
CVE-2018-5954
phpFreeChat 1.7 and earlier allows remote attackers to cause a denial of service by sending a large number of connect co
23RIESGO
abrir
Referência
CVE-2018-5954
phpFreeChat 1.7 and earlier allows remote attackers to cause a denial of service by sending a large number of connect co
23RIESGO
abrir
anteriorpágina 378 / 730siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.