Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.620exploits catalogados
35.647CVEs con explotación pública
24.695probados en laboratorio
22.367 exploits
Referência
CVE-2020-5741
CVE-2020-5741HIGHbajo ataque
Deserialization of Untrusted Data in Plex Media Server on Windows allows a remote, authenticated attacker to execute arb
100RIESGO
abrir
Referência
CVE-2021-4045
TP-LINK Tapo C200 remote code execution vulnerability
70RIESGO
abrir
ReferênciaVexDay Proof
Check Point Firewall-1 - PKI Web Service HTTP Header Remote Overflow
CVE-2009-1227doshardware
NOTE: this issue has been disputed by the vendor. Buffer overflow in the PKI Web Service in Check Point Firewall-1 PKI
23RIESGO
abrir
ReferênciaVexDay Proof
Arcadwy Arcade Script - 'Username' Static Cross-Site Scripting
CVE-2009-1228webappsphp
Cross-site scripting (XSS) vulnerability in register.php in Arcadwy Arcade Script CMS allows remote attackers to inject
23RIESGO
abrir
Referência62
A PoC exploit for CVE-2024-25600 - WordPress Bricks Builder Remote Code Execution (RCE)
WordPress Bricks Theme <= 1.9.6 - Unauthenticated Remote Code Execution (RCE) vulnerability
85RIESGO
abrir
Referência
CVE-2017-8046
Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions pri
60RIESGO
abrir
Referência
CVE-2017-6326
The Symantec Messaging Gateway can encounter an issue of remote code execution, which describes a situation whereby an i
60RIESGO
abrir
Referência
CVE-2018-7251
An issue was discovered in config/error.php in Anchor 0.12.3. The error log is exposed at an errors.log URI, and contain
60RIESGO
abrir
Referência
CVE-2019-1429
CVE-2019-1429HIGHbajo ataque
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet
93RIESGO
abrir
Referência
CVE-2014-3914
Directory traversal vulnerability in the Admin Center for Tivoli Storage Manager (TSM) in Rocket ServerGraph 1.2 allows
60RIESGO
abrir
Referência
CVE-2017-6316
CVE-2017-6316CRITICALbajo ataque
Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as r
100RIESGO
abrir
Referência
CVE-2017-6316
CVE-2017-6316CRITICALbajo ataque
Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 allow remote attackers to execute arbitrary shell commands as r
100RIESGO
abrir
Referência
CVE-2022-20699
CVE-2022-20699CRITICALbajo ataque
Cisco Small Business RV Series Routers Vulnerabilities
100RIESGO
abrir
Referência
CVE-2017-15889
Command injection vulnerability in smart.cgi in Synology DiskStation Manager (DSM) before 5.2-5967-5 allows remote authe
60RIESGO
abrir
ReferênciaVexDay Proof
Blue Eye CMS 1.0.0 - Remote Cookie SQL Injection
CVE-2009-0883webappsphp
SQL injection vulnerability in Blue Eye CMS 1.0.0 and earlier, when magic_quotes_gpc is disabled, allows remote attacker
23RIESGO
abrir
Referência
CVE-2021-25296
CVE-2021-25296HIGHbajo ataque
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi
100RIESGO
abrir
Referência
CVE-2021-25296
CVE-2021-25296HIGHbajo ataque
Nagios XI version xi-5.7.5 is affected by OS command injection. The vulnerability exists in the file /usr/local/nagiosxi
100RIESGO
abrir
Referência
CVE-2021-39327
BulletProof Security <= 5.1 Sensitive Information Disclosure
70RIESGO
abrir
Referência
CVE-2016-1560
ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and
60RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component com_bookJoomlas 0.1 - SQL Injection
CVE-2009-1263webappsphp
SQL injection vulnerability in sub_commententry.php in the BookJoomlas (com_bookjoomlas) component 0.1 for Joomla! allow
23RIESGO
abrir
ReferênciaVexDay Proof
phpTrafficA 1.4.2 - 'pageid' SQL Injection
CVE-2007-3426webappsphp
Cross-site scripting (XSS) vulnerability in index.php in phpTrafficA 1.4.2 and earlier allows remote attackers to inject
23RIESGO
abrir
Referência
CVE-2017-6334
CVE-2017-6334HIGHbajo ataque
dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute ar
100RIESGO
abrir
Referência
CVE-2017-6334
CVE-2017-6334HIGHbajo ataque
dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute ar
100RIESGO
abrir
Referência
CVE-2017-6334
CVE-2017-6334HIGHbajo ataque
dnslookup.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute ar
100RIESGO
abrir
ReferênciaVexDay Proof
EternalMart Guestbook 1.10 - '/admin/auth.php' Remote File Inclusion
CVE-2003-1314webappsphp
PHP remote file inclusion vulnerability in admin/auth.php in EternalMart Guestbook (EMGB) 1.1 allows remote attackers to
23RIESGO
abrir
Referência
CVE-2017-8729
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to execute arbitrary code in the context of the current u
45RIESGO
abrir
ReferênciaVexDay Proof
Gravity Board X 2.0 Beta - SQL Injection / (Authenticated) Code Execution
CVE-2009-1277webappsphp
SQL injection vulnerability in index.php in Gravity Board X (GBX) 2.0 BETA allows remote attackers to execute arbitrary
23RIESGO
abrir
Referência
CVE-2019-16724
File Sharing Wizard 1.5.0 allows a remote attacker to obtain arbitrary code execution by exploiting a Structured Excepti
60RIESGO
abrir
Referência
CVE-2019-16724
File Sharing Wizard 1.5.0 allows a remote attacker to obtain arbitrary code execution by exploiting a Structured Excepti
60RIESGO
abrir
Referência
CVE-2016-10009
Untrusted search path vulnerability in ssh-agent.c in ssh-agent in OpenSSH before 7.4 allows remote attackers to execute
53RIESGO
abrir
anteriorpágina 512 / 746siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.