Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
22.573 exploits
Referência
CVE-2019-7440
JioFi 4G M2S 1.0.2 devices have CSRF via the SSID name and Security Key field under Edit Wi-Fi Settings (aka a SetWiFi_S
23RIESGO
abrir
ReferênciaVexDay Proof
WebMaster Marketplace - SQL Injection
CVE-2008-5574webappsphp
SQL injection vulnerability in member.php in Webmaster Marketplace allows remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
ReferênciaVexDay Proof
sCssBoard (Multiple Versions) - 'pwnpack' Remote s
CVE-2008-5578webappsphp
Multiple SQL injection vulnerabilities in index.php in sCssBoard 1.0, 1.1, 1.11, and 1.12 allow remote attackers to exec
23RIESGO
abrir
Referência
CVE-2017-0070
A remote code execution vulnerability exists in the way affected Microsoft scripting engines render when handling object
45RIESGO
abrir
Referência
CVE-2014-5301
Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 t
60RIESGO
abrir
Referência
CVE-2021-1732
CVE-2021-1732HIGHbajo ataqueransomware
Windows Win32k Elevation of Privilege Vulnerability
100RIESGO
abrir
Referência
CVE-2021-1732
CVE-2021-1732HIGHbajo ataqueransomware
Windows Win32k Elevation of Privilege Vulnerability
100RIESGO
abrir
Referência
snapd < 2.37 (Ubuntu) - 'dirty_sock' Local Privilege Escalation (2)
CVE-2019-7304HIGHlocallinux
Local privilege escalation via snapd socket
53RIESGO
abrir
Referência34
CVE-2024-23108: Fortinet FortiSIEM Unauthenticated 2nd Order Command Injection
An improper neutralization of special elements used in an os command ('os command injection') vulnerability in Fortinet
85RIESGO
abrir
ReferênciaVexDay Proof
Nukedit 4.9.x - Remote Create Admin
CVE-2008-5582webappsphp
SQL injection vulnerability in utilities/login.asp in Nukedit 4.9.x, and possibly earlier, allows remote attackers to ex
23RIESGO
abrir
Referência
CVE-2012-3873
Multiple SQL injection vulnerabilities in Open Constructor 3.12.0 allow remote authenticated users to execute arbitrary
23RIESGO
abrir
Referência
CVE-2008-5585
Multiple PHP remote file inclusion vulnerabilities in lcxBBportal 0.1 Alpha 2 allow remote attackers to execute arbitrar
23RIESGO
abrir
Referência
CVE-2017-12478
It was discovered that the api/storage web interface in Unitrends Backup (UB) before 10.0.0 has an issue in which one of
60RIESGO
abrir
Referência
CVE-2017-12478
It was discovered that the api/storage web interface in Unitrends Backup (UB) before 10.0.0 has an issue in which one of
60RIESGO
abrir
ReferênciaVexDay Proof
Vistered Little 1.6a - 'skin' Remote File Disclosure
CVE-2007-2934webappsphp
Directory traversal vulnerability in skins/common.css.php in Vistered Little 1.6a allows remote attackers to read arbitr
23RIESGO
abrir
ReferênciaVexDay Proof
Rankem - Authentication Bypass
CVE-2008-5589webappsasp
SQL injection vulnerability in processlogin.asp in Katy Whitton RankEm allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
Referência
CVE-2012-0217
The x86-64 kernel system-call functionality in Xen 4.1.2 and earlier, as used in Citrix XenServer 6.0.2 and earlier and
50RIESGO
abrir
ReferênciaVexDay Proof
Product Sale Framework 0.1b - SQL Injection
CVE-2008-5590webappsphp
SQL injection vulnerability in customer.forumtopic.php in Kalptaru Infotech Product Sale Framework 0.1 beta allows remot
23RIESGO
abrir
ReferênciaVexDay Proof
nightfall personal diary 1.0 - Cross-Site Scripting / File Disclosure
CVE-2008-5591webappsphp
Cross-site scripting (XSS) vulnerability in login.asp in Nightfall Personal Diary 1.0 allows remote attackers to inject
23RIESGO
abrir
Referência
CVE-2019-9851
LibreLogo global-event script execution
60RIESGO
abrir
Referência
CVE-2019-16113
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .j
60RIESGO
abrir
Referência
CVE-2008-5595
SQL injection vulnerability in detail.asp in ASP AutoDealer allows remote attackers to execute arbitrary SQL commands vi
23RIESGO
abrir
ReferênciaVexDay Proof
TROforum 0.1 - 'admin.php?site_url' Remote File Inclusion
CVE-2007-2937webappsphp
PHP remote file inclusion vulnerability in admin/admin.php in TROforum 0.1 allows remote attackers to execute arbitrary
35RIESGO
abrir
ReferênciaVexDay Proof
ASPThai.Net WebBoard 6.0 - SQL Injection
CVE-2009-0703webappsphp
SQL injection vulnerability in bview.asp in ASPThai.Net Webboard 6.0 allows remote attackers to execute arbitrary SQL co
23RIESGO
abrir
ReferênciaVexDay Proof
QMail Mailing List Manager 1.2 - Database Disclosure
CVE-2008-5606webappsasp
Gazatem QMail Mailing List Manager 1.2 stores sensitive information under the web root with insufficient access control,
23RIESGO
abrir
Referência
CVE-2014-5005
Directory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers
60RIESGO
abrir
Referência
CVE-2020-8816
CVE-2020-8816CRITICALbajo ataque
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static l
100RIESGO
abrir
Referência
CVE-2020-8816
CVE-2020-8816CRITICALbajo ataque
Pi-hole Web v4.3.2 (aka AdminLTE) allows Remote Code Execution by privileged dashboard users via a crafted DHCP static l
100RIESGO
abrir
Referência
CVE-2017-1000117
A malicious third-party can give a crafted "ssh://..." URL to an unsuspecting victim, and an attempt to visit the URL ca
60RIESGO
abrir
ReferênciaVexDay Proof
ASP AutoDealer - Remote Database Disclosure
CVE-2008-5608webappsasp
ASP AutoDealer stores sensitive information under the web root with insufficient access control, which allows remote att
23RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.