Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.620exploits catalogados
35.647CVEs con explotación pública
24.695probados en laboratorio
22.407 exploits
Referência
CVE-2017-11903
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 and R2 SP1, Windows 8.1 and Windows RT 8.1, Windows Se
35RIESGO
abrir
Referência
CVE-2014-6446
The Infusionsoft Gravity Forms plugin 1.5.3 through 1.5.10 for WordPress does not properly restrict access, which allows
50RIESGO
abrir
Referência
CVE-2023-30145
Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats para
60RIESGO
abrir
ReferênciaVexDay Proof
LightOpenCMS 0.1 - 'id' SQL Injection
CVE-2009-1766webappsphp
SQL injection vulnerability in index.php in LightOpenCMS 0.1 allows remote attackers to execute arbitrary SQL commands v
23RIESGO
abrir
Referência
CVE-2010-4749
Multiple cross-site scripting (XSS) vulnerabilities in BLOG:CMS 4.2.1.e, and possibly earlier, allow remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component AlphaUserPoints - SQL Injection
CVE-2009-3342webappsphp
SQL injection vulnerability in frontend/assets/ajax/checkusername.php in the AlphaUserPoints (com_alphauserpoints) compo
23RIESGO
abrir
Referência
CVE-2012-6530
Stack-based buffer overflow in Sysax Multi Server before 5.52, when HTTP is enabled, allows remote authenticated users w
50RIESGO
abrir
Referência
CVE-2018-10201
An issue was discovered in NcMonitorServer.exe in NC Monitor Server in NComputing vSpace Pro 10 and 11. It is possible t
50RIESGO
abrir
ReferênciaVexDay Proof
Ubuntu 6.06 - DHCPd Remote Denial of Service
CVE-2007-5365dosmultiple
Stack-based buffer overflow in the cons_options function in options.c in dhcpd in OpenBSD 4.0 through 4.2, and some othe
45RIESGO
abrir
Referência
CVE-2020-12029
Rockwell Automation FactoryTalk View SE
75RIESGO
abrir
Referência
CVE-2009-3712
Multiple SQL injection vulnerabilities in Ebay Clone 2009 allow remote attackers to execute arbitrary SQL commands via t
23RIESGO
abrir
ReferênciaVexDay Proof
my-colex 1.4.2 - Authentication Bypass / SQL Injection / Cross-Site Scripting
CVE-2009-1810webappsphp
Multiple SQL injection vulnerabilities in myColex 1.4.2 allow remote attackers to execute arbitrary SQL commands via (1)
23RIESGO
abrir
Referência
CVE-2009-2777
SQL injection vulnerability in visitor/view.php in GarageSales Script allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
ReferênciaVexDay Proof
phpBB Plus 1.53 - 'phpbb_root_path' Remote File Inclusion
CVE-2007-5009webappsphp
PHP remote file inclusion vulnerability in language/lang_german/lang_main_album.php in phpBB Plus 1.53, and 1.53a before
35RIESGO
abrir
ReferênciaVexDay Proof
TikiWiki 1.9.8 - Remote PHP Injection
CVE-2007-5423webappsphp
tiki-graph_formula.php in TikiWiki 1.9.8 allows remote attackers to execute arbitrary code via PHP sequences in the f ar
60RIESGO
abrir
Referência
CVE-2016-3301
The Windows font library in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1;
35RIESGO
abrir
Referência
CVE-2015-5539
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linu
35RIESGO
abrir
Referência
CVE-2020-10882
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of TP-Link Arch
68RIESGO
abrir
Referência
CVE-2018-6317
The remote management interface in Claymore Dual Miner 10.5 and earlier is vulnerable to an unauthenticated format strin
50RIESGO
abrir
ReferênciaVexDay Proof
my-gesuad 0.9.14 - Authentication Bypass / SQL Injection / Cross-Site Scripting
CVE-2009-1812webappsphp
Multiple SQL injection vulnerabilities in myGesuad 0.9.14 (aka 0.9) allow remote attackers to execute arbitrary SQL comm
23RIESGO
abrir
Referência
CVE-2023-24709
An issue found in Paradox Security Systems IPR512 allows attackers to cause a denial of service via the login.html and l
53RIESGO
abrir
Referência
CVE-2013-2251
CVE-2013-2251CRITICALbajo ataque
Apache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a
100RIESGO
abrir
Referência
CVE-2018-15710
Nagios XI 5.5.6 allows local authenticated attackers to escalate privileges to root via Autodiscover_new.php.
50RIESGO
abrir
Referência
CVE-2018-15710
Nagios XI 5.5.6 allows local authenticated attackers to escalate privileges to root via Autodiscover_new.php.
50RIESGO
abrir
Referência
CVE-2022-3552
Unrestricted Upload of File with Dangerous Type in boxbilling/boxbilling
53RIESGO
abrir
Referência
CVE-2021-3493
CVE-2021-3493HIGHbajo ataque
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RIESGO
abrir
Referência
CVE-2021-3493
CVE-2021-3493HIGHbajo ataque
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RIESGO
abrir
Referência
CVE-2021-3493
CVE-2021-3493HIGHbajo ataque
The overlayfs implementation in the linux kernel did not properly validate with respect to user namespaces the setting o
98RIESGO
abrir
Referência
CVE-2020-11698
An issue was discovered in Titan SpamTitan 7.07. Improper input sanitization of the parameter community on the page snmp
60RIESGO
abrir
Referência
CVE-2016-0111
Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a
35RIESGO
abrir
anteriorpágina 523 / 747siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.