Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.533exploits catalogados
35.607CVEs con explotación pública
24.695probados en laboratorio
22.367 exploits
Referência
CVE-2021-35464
CVE-2021-35464CRITICALbajo ataqueransomware
ForgeRock AM server before 7.0 has a Java deserialization vulnerability in the jato.pageSession parameter on multiple pa
100RIESGO
abrir
Referência
CVE-2021-3560
CVE-2021-3560HIGHbajo ataque
It was found that polkit could be tricked into bypassing the credential checks for D-Bus requests, elevating the privile
91RIESGO
abrir
Referência
CVE-2021-40381
An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. index_MJpeg.cgi allows
28RIESGO
abrir
Referência
CVE-2021-40382
An issue was discovered on Compro IP70 2.08_7130218, IP570 2.08_7130520, IP60, and TN540 devices. mjpegStreamer.cgi allo
28RIESGO
abrir
Referência
CVE-2021-40964
A Path Traversal vulnerability exists in TinyFileManager all version up to and including 2.4.6 that allows attackers to
23RIESGO
abrir
Referência
CVE-2021-41318
In Progress WhatsUp Gold prior to version 21.1.0, an application endpoint failed to adequately sanitize malicious input.
23RIESGO
abrir
Referência
Payara Micro Community 5.2021.6 - Directory Traversal
CVE-2021-41381webappsmultiple
Payara Micro Community 5.2021.6 and below allows Directory Traversal.
50RIESGO
abrir
Referência
CVE-2021-41773
CVE-2021-41773HIGHbajo ataqueransomware
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
Referência
CVE-2021-41773
CVE-2021-41773HIGHbajo ataqueransomware
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
Referência
CVE-2021-41773
CVE-2021-41773HIGHbajo ataqueransomware
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
Referência
CVE-2021-41773
CVE-2021-41773HIGHbajo ataqueransomware
Path traversal and file disclosure vulnerability in Apache HTTP Server 2.4.49
100RIESGO
abrir
ReferênciaVexDay Proof
SaveWeb Portal 3.4 - 'SITE_Path' Remote File Inclusion
CVE-2006-4012webappsphp
Multiple PHP remote file inclusion vulnerabilities in circeOS SaveWeb Portal 3.4 allow remote attackers to execute arbit
23RIESGO
abrir
ReferênciaVexDay Proof
MyBloggie 2.1.4 - 'trackback.php' Multiple SQL Injections
CVE-2006-4042webappsphp
Multiple SQL injection vulnerabilities in trackback.php in myWebland myBloggie 2.1.4 and earlier allow remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
Torbstoff News 4 - 'pfad' Remote File Inclusion
CVE-2006-4045webappsphp
PHP remote file inclusion vulnerability in news.php in Torbstoff News 4 allows remote attackers to execute arbitrary PHP
23RIESGO
abrir
ReferênciaVexDay Proof
Open Cubic Player 2.6.0pre6/0.1.10_rc5 - Multiple Local Buffer Overflows
CVE-2006-4046localwindows
Multiple stack-based buffer overflows in Open Cubic Player 2.6.0pre6 and earlier for Windows, and 0.1.10_rc5 and earlier
28RIESGO
abrir
Referência
WordPress Core 5.8.2 - 'WP_Query' SQL Injection
CVE-2022-21661HIGHwebappsphp
SQL injection in WordPress
78RIESGO
abrir
ReferênciaVexDay Proof
Web Server Creator 0.1 - 'l' Remote File Inclusion
CVE-2006-4746webappsphp
PHP remote file inclusion vulnerability in news/include/customize.php in Web Server Creator 0.1 allows remote attackers
23RIESGO
abrir
Referência
CVE-2022-22831
An issue was discovered in Servisnet Tessa 0.0.2. An attacker can add a new sysadmin user via a manipulation of the Auth
28RIESGO
abrir
Referência
Servisnet Tessa - Add sysAdmin User (Unauthenticated) (Metasploit)
CVE-2022-22831webappsmultiple
An issue was discovered in Servisnet Tessa 0.0.2. An attacker can add a new sysadmin user via a manipulation of the Auth
28RIESGO
abrir
Referência
CVE-2022-22832
An issue was discovered in Servisnet Tessa 0.0.2. Authorization data is available via an unauthenticated /data-service/u
28RIESGO
abrir
Referência
CVE-2022-22947
CVE-2022-22947CRITICALbajo ataque
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack whe
100RIESGO
abrir
ReferênciaVexDay Proof
NaviCOPA Web Server 2.01 - 'GET' Remote Buffer Overflow
CVE-2006-5112remotewindows
Buffer overflow in InterVations NaviCOPA Web Server 2.01 allows remote attackers to execute arbitrary code via a long HT
50RIESGO
abrir
Referência
CVE-2022-26986
SQL Injection in ImpressCMS 1.4.3 and earlier allows remote attackers to inject into the code in unintended way, this al
23RIESGO
abrir
Referência
CVE-2022-27308
A stored cross-site scripting (XSS) vulnerability in PHProjekt PhpSimplyGest v1.3.0 allows attackers to execute arbitrar
23RIESGO
abrir
Referência
CVE-2022-27412
Explore CMS v1.0 was discovered to contain a SQL injection vulnerability via a /page.php?id= request.
23RIESGO
abrir
Referência
CVE-2022-28117
A Server-Side Request Forgery (SSRF) in feed_parser class of Navigate CMS v2.9.4 allows remote attackers to force the ap
43RIESGO
abrir
Referência
CVE-2022-2846
Calendar Event Multi View < 1.4.07 - Unauthenticated Arbitrary Event Creation to Stored XSS
33RIESGO
abrir
Referência
CVE-2022-29296
A reflected cross-site scripting (XSS) vulnerability in the login portal of Avantune Genialcloud ProJ - 10 allows attack
23RIESGO
abrir
Referência
PyScript - Read Remote Python Source Code
CVE-2022-30286remotepython
pyscriptjs (aka PyScript Demonstrator) in PyScript through 2022-05-04 allows a remote user to read Python source code.
28RIESGO
abrir
Referência
CVE-2022-30525
CVE-2022-30525CRITICALbajo ataque
A OS command injection vulnerability in the CGI program of Zyxel USG FLEX 100(W) firmware versions 5.00 through 5.21 Pat
100RIESGO
abrir
anteriorpágina 498 / 746siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.