Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.020exploits catalogados
35.276CVEs con explotación pública
24.695probados en laboratorio
22.166 exploits
ReferênciaVexDay Proof
Interact 2.4.1 - Multiple Remote File Inclusions
CVE-2008-2220webappsphp
Multiple PHP remote file inclusion vulnerabilities in Interact Learning Community Environment Interact 2.4.1, when regis
23RIESGO
abrir
Referência
CVE-2017-0145
CVE-2017-0145HIGHbajo ataqueransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Referência
CVE-2017-0145
CVE-2017-0145HIGHbajo ataqueransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Referência
CVE-2017-0145
CVE-2017-0145HIGHbajo ataqueransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
ReferênciaVexDay Proof
cmsWorks 2.2 RC4 - 'mod_root' Remote File Inclusion
CVE-2008-2877webappsphp
PHP remote file inclusion vulnerability in admin/include/lib.module.php in cmsWorks 2.2 RC4, when register_globals is en
23RIESGO
abrir
ReferênciaVexDay Proof
Free Hosting Manager 1.2/2.0 - Insecure Cookie Handling
CVE-2008-3557webappsphp
Free Hosting Manager 1.2 and 2.0 allows remote attackers to bypass authentication and gain administrative access by sett
23RIESGO
abrir
Referência
CVE-2020-2944
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Common Desktop Environment). Supported version
41RIESGO
abrir
Referência
CVE-2025-34056
AVTECH IP camera, DVR, and NVR Devices Authenticated Root Command Execution
48RIESGO
abrir
Referência
CVE-2025-34056
AVTECH IP camera, DVR, and NVR Devices Authenticated Root Command Execution
48RIESGO
abrir
Referência
CVE-2025-8191
macrozheng mall Swagger UI index.html cross site scripting
33RIESGO
abrir
Referência
CVE-2015-7515
The aiptek_probe function in drivers/input/tablet/aiptek.c in the Linux kernel before 4.4 allows physically proximate at
23RIESGO
abrir
Referência
CVE-2022-43684
ACL bypass in Reporting functionality
48RIESGO
abrir
ReferênciaVexDay Proof
acFTP FTP Server 1.5 - 'REST/PBSZ' Remote Denial of Service
CVE-2006-6775doswindows
acFTP 1.5 allows remote authenticated users to cause a denial of service via a crafted argument to the (1) REST or (2) P
23RIESGO
abrir
Referência
CVE-2015-1423
Multiple SQL injection vulnerabilities in Gecko CMS 2.2 and 2.3 allow remote administrators to execute arbitrary SQL com
23RIESGO
abrir
Referência
CVE-2015-1423
Multiple SQL injection vulnerabilities in Gecko CMS 2.2 and 2.3 allow remote administrators to execute arbitrary SQL com
23RIESGO
abrir
Referência
CVE-2014-10033
SQL injection vulnerability in the update_zone function in catalog/admin/geo_zones.php in osCommerce Online Merchant 2.3
23RIESGO
abrir
Referência
CVE-2017-15727
In phpMyFAQ before 2.9.9, there is Stored Cross-site Scripting (XSS) via an HTML attachment.
23RIESGO
abrir
Referência
CVE-2016-3136
The mct_u232_msr_to_state function in drivers/usb/serial/mct_u232.c in the Linux kernel before 4.5.1 allows physically p
23RIESGO
abrir
Referência
CVE-2018-11403
DomainMod v4.09.03 has XSS via the assets/edit/account-owner.php oid parameter.
23RIESGO
abrir
Referência
CVE-2017-0146
CVE-2017-0146HIGHbajo ataqueransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
Referência
CVE-2018-19750
DomainMOD through 4.11.01 has XSS via the admin/domain-fields/ notes field in an Add Custom Field action for Custom Doma
23RIESGO
abrir
Referência
CVE-2009-4658
Xerver 4.32 allows remote authenticated users to cause a denial of service (daemon crash) via a non-numeric web port ass
23RIESGO
abrir
Referência
CVE-2017-8838
XSS via syncid exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380h
23RIESGO
abrir
Referência
CVE-2017-0146
CVE-2017-0146HIGHbajo ataqueransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
ReferênciaVexDay Proof
IceBB 1.0-rc5 - Remote Code Execution
CVE-2007-1725webappsphp
SQL injection vulnerability in index.php in IceBB 1.0-rc5 allows remote authenticated users to execute arbitrary SQL com
23RIESGO
abrir
ReferênciaVexDay Proof
IceBB 1.0-rc5 - Remote Create Admin
CVE-2007-1725webappsphp
SQL injection vulnerability in index.php in IceBB 1.0-rc5 allows remote authenticated users to execute arbitrary SQL com
23RIESGO
abrir
Referência
CVE-2018-5282
Kentico 9.0 through 11.0 has a stack-based buffer overflow via the SqlName, SqlPswd, Database, UserName, or Password fie
23RIESGO
abrir
Referência
CVE-2020-8424
Cups Easy (Purchase & Inventory) 1.0 is vulnerable to CSRF that leads to admin account takeover via passwordmychange.php
23RIESGO
abrir
ReferênciaVexDay Proof
aspWebLinks 2.0 - SQL Injection / Admin Pass Change
CVE-2006-2848webappsasp
links.asp in aspWebLinks 2.0 allows remote attackers to change the administrative password, possibly via a direct reques
23RIESGO
abrir
Referência
CVE-2017-0148
CVE-2017-0148HIGHbajo ataqueransomware
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows
100RIESGO
abrir
anteriorpágina 399 / 739siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.