Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

79.057exploits catalogados
36.288CVEs con explotación pública
24.695probados en laboratorio
22.573 exploits
Referência
CVE-2018-9160
SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.
60RIESGO
abrir
ReferênciaVexDay Proof
Gnews Publisher .NET - SQL Injection
CVE-2008-5767webappsasp
SQL injection vulnerability in authors.asp in gNews Publisher allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
Referência
CVE-2018-14728
upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter.
60RIESGO
abrir
Referência
CVE-2018-12710
An issue was discovered on D-Link DIR-601 2.02NA devices. Being local to the network and having only "User" account (whi
45RIESGO
abrir
Referência
CVE-2012-4773
Multiple cross-site request forgery (CSRF) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to hijack
23RIESGO
abrir
Referência
CVE-2021-22145
A memory disclosure vulnerability was identified in Elasticsearch 7.10.0 to 7.13.3 error reporting. A user with the abil
60RIESGO
abrir
Referência
CVE-2014-3791
Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 6.8 allows remote attackers to execute arbitrary code
60RIESGO
abrir
Referência
CVE-2012-4773
Multiple cross-site request forgery (CSRF) vulnerabilities in Subrion CMS before 2.2.3 allow remote attackers to hijack
23RIESGO
abrir
ReferênciaVexDay Proof
XOOPS Module Amevents - SQL Injection
CVE-2008-5768webappsphp
SQL injection vulnerability in print.php in the AM Events (aka Amevents) module 0.22 for XOOPS allows remote attackers t
23RIESGO
abrir
Referência
CVE-2021-44529
CVE-2021-44529CRITICALbajo ataqueransomware
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execut
100RIESGO
abrir
Referência
CVE-2021-44529
CVE-2021-44529CRITICALbajo ataqueransomware
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execut
100RIESGO
abrir
ReferênciaVexDay Proof
PHP weather 2.2.2 - Local File Inclusion / Cross-Site Scripting
CVE-2008-5770webappsphp
Cross-site scripting (XSS) vulnerability in config/make_config.php in PHP Weather 2.2.2 allows remote attackers to injec
23RIESGO
abrir
ReferênciaVexDay Proof
FLDS 1.2a - 'report.php' SQL Injection
CVE-2008-5778webappsphp
SQL injection vulnerability in report.php in Free Links Directory Script (FLDS) 1.2a allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
Kipper 2.01 - Cross-Site Scripting / Local File Inclusion / File Disclosure
CVE-2009-0763webappsphp
Cross-site scripting (XSS) vulnerability in default.php in Kipper 2.01 allows remote attackers to inject arbitrary web s
23RIESGO
abrir
Referência
CVE-2021-44596
Wondershare LTD Dr. Fone as of 2021-12-06 version is affected by Remote code execution. Due to software design flaws an
28RIESGO
abrir
Referência
Online Magazine Management System 1.0 - SQLi Authentication Bypass
CVE-2021-44653webappsphp
Online Magazine Management System 1.0 contains a SQL injection authentication bypass vulnerability. The Admin panel auth
23RIESGO
abrir
Referência
CVE-2012-4792
CVE-2012-4792HIGHbajo ataque
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 8 allows remote attackers to execute arbitrary cod
100RIESGO
abrir
Referência
CVE-2013-5486
Directory traversal vulnerability in processImageSave.jsp in DCNM-SAN Server in Cisco Prime Data Center Network Manager
60RIESGO
abrir
Referência
CVE-2019-1003030
CVE-2019-1003030CRITICALbajo ataque
A sandbox bypass vulnerability exists in Jenkins Pipeline: Groovy Plugin 2.63 and earlier in pom.xml, src/main/java/org/
100RIESGO
abrir
Referência
CVE-2023-32243
WordPress Essential Addons for Elementor Plugin 5.4.0-5.7.1 is vulnerable to Privilege Escalation
85RIESGO
abrir
Referência
CVE-2015-0016
CVE-2015-0016HIGHbajo ataque
Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7
100RIESGO
abrir
Referência
CVE-2015-0016
CVE-2015-0016HIGHbajo ataque
Directory traversal vulnerability in the TS WebProxy (aka TSWbPrxy) component in Microsoft Windows Vista SP2, Windows 7
100RIESGO
abrir
ReferênciaVexDay Proof
Forest Blog 1.3.2 - Remote Database Disclosure
CVE-2008-5780webappsasp
Forest Blog 1.3.2 stores sensitive information under the web root with insufficient access control, which allows remote
23RIESGO
abrir
Referência
Online Pre-owned/Used Car Showroom Management System 1.0 - SQLi Authentication Bypass
CVE-2021-44655webappsphp
Online Pre-owned/Used Car Showroom Management System 1.0 contains a SQL injection authentication bypass vulnerability. A
23RIESGO
abrir
Referência
CVE-2017-16921
In OTRS 6.0.x up to and including 6.0.1, OTRS 5.0.x up to and including 5.0.24, and OTRS 4.0.x up to and including 4.0.2
28RIESGO
abrir
ReferênciaVexDay Proof
V3 Chat Profiles/Dating Script 3.0.2 - Insecure Cookie Handling
CVE-2008-5784webappsphp
V3 Chat - Profiles/Dating Script 3.0.2 allows remote attackers to bypass authentication and gain administrative access b
23RIESGO
abrir
ReferênciaVexDay Proof
DELTAScripts PHP Classifieds 7.5 - SQL Injection
CVE-2008-5805webappsphp
SQL injection vulnerability in detail.php in DeltaScripts PHP Classifieds 7.5 and earlier allows remote attackers to exe
23RIESGO
abrir
ReferênciaVexDay Proof
PHPAlumni - SQL Injection
CVE-2008-5815webappsphp
SQL injection vulnerability in Acomment.php in phpAlumni allows remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir
ReferênciaVexDay Proof
Kipper 2.01 - Cross-Site Scripting / Local File Inclusion / File Disclosure
CVE-2009-0767webappsphp
Kipper 2.01 stores sensitive information under the web root with insufficient access control, which allows remote attack
23RIESGO
abrir
Referência
CVE-2019-1937
Cisco Integrated Management Controller Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data Authentication Bypass Vulnerability
85RIESGO
abrir

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.