Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.724exploits catalogados
35.724CVEs con explotación pública
24.695probados en laboratorio
22.407 exploits
ReferênciaVexDay Proof
Joomla! Component juser 1.0.14 - Remote File Inclusion
CVE-2007-6038webappsphp
PHP remote file inclusion vulnerability in xajax_functions.php in the JUser (com_juser) 1.0.14 component for Joomla! all
28RIESGO
abrir
Referência
CVE-2021-21975
CVE-2021-21975HIGHbajo ataqueransomware
Server Side Request Forgery in vRealize Operations Manager API (CVE-2021-21975) prior to 8.4 may allow a malicious actor
100RIESGO
abrir
Referência
CVE-2018-8269
A denial of service vulnerability exists when OData Library improperly handles web requests, aka "OData Denial of Servic
28RIESGO
abrir
Referência
CVE-2012-1226
Multiple directory traversal vulnerabilities in Dolibarr CMS 3.2.0 Alpha allow remote attackers to read arbitrary files
43RIESGO
abrir
Referência
CVE-2004-1560
Microsoft SQL Server 7.0 allows remote attackers to cause a denial of service (mssqlserver service halt) via a long requ
28RIESGO
abrir
Referência
CVE-2016-1011
Use-after-free vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows
28RIESGO
abrir
Referência
CVE-2018-0776
Microsoft Edge in Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to execute arbitra
45RIESGO
abrir
ReferênciaVexDay Proof
Softbiz Freelancers Script 1 - SQL Injection
CVE-2007-6125webappsphp
SQL injection vulnerability in search_form.php in Softbiz Freelancers Script 1 allows remote attackers to execute arbitr
23RIESGO
abrir
Referência
CVE-2009-1492
The getAnnots Doc method in the JavaScript API in Adobe Reader and Acrobat 9.1, 8.1.4, 7.1.1, and earlier allows remote
28RIESGO
abrir
Referência
CVE-2009-4756
Stack-based buffer overflow in TraktorBeatport.exe 1.0.0.283 in Beatport Player 1.0.0.0 allows remote attackers to execu
23RIESGO
abrir
Referência
Wavemaker Studio 6.6 - Server-Side Request Forgery
CVE-2019-8982webappsjava
com/wavemaker/studio/StudioService.java in WaveMaker Studio 6.6 mishandles the studioService.download?method=getContent&
43RIESGO
abrir
Referência
CVE-2015-3073
Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass inten
28RIESGO
abrir
Referência
CVE-2013-2097
ZPanel through 10.1.0 has Remote Command Execution
43RIESGO
abrir
Referência
CVE-2016-4138
Unspecified vulnerability in Adobe Flash Player 21.0.0.242 and earlier, as used in the Adobe Flash libraries in Microsof
28RIESGO
abrir
ReferênciaVexDay Proof
Mp3 ToolBox 1.0 Beta 5 - 'skin_file' Remote File Inclusion
CVE-2007-6139webappsphp
PHP remote file inclusion vulnerability in index.php in Mp3 ToolBox 1.0 beta 5 allows remote attackers to execute arbitr
23RIESGO
abrir
Referência
CVE-2024-49138
CVE-2024-49138HIGHbajo ataque
Windows Common Log File System Driver Elevation of Privilege Vulnerability
76RIESGO
abrir
Referência
CVE-2009-4781
TUKEVA Password Reminder before 1.0.0.4 uses a hard-coded password for rem.accdb, which allows local users to discover c
23RIESGO
abrir
Referência
CVE-2009-4782
Multiple cross-site scripting (XSS) vulnerabilities in Theeta CMS, possibly 0.01, allow remote attackers to inject arbit
23RIESGO
abrir
Referência
CVE-2016-2851
Integer overflow in proto.c in libotr before 4.1.1 on 64-bit platforms allows remote attackers to cause a denial of serv
28RIESGO
abrir
Referência
CVE-2009-4783
Multiple SQL injection vulnerabilities in Theeta CMS, possibly 0.01, allow remote attackers to execute arbitrary SQL com
23RIESGO
abrir
Referência
CVE-2009-4784
SQL injection vulnerability in the Joaktree (com_joaktree) component 1.0 for Joomla! allows remote attackers to execute
23RIESGO
abrir
Referência
ManageEngine OpManager 12.4x - Unauthenticated Remote Command Execution (Metasploit)
CVE-2019-15106remotemultiple
An issue was discovered in Zoho ManageEngine OpManager in builds before 14310. One can bypass the user password requirem
28RIESGO
abrir
Referência
CVE-2016-3216
GDI32.dll in the Graphics component in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, W
28RIESGO
abrir
Referência
CVE-2022-31854
Codoforum v5.1 was discovered to contain an arbitrary file upload vulnerability via the logo change option in the admin
50RIESGO
abrir
Referência
CVE-2009-4855
SQL injection vulnerability in index.php in TYPO3 4.0 allows remote attackers to execute arbitrary SQL commands via the
23RIESGO
abrir
Referência
CVE-2009-4860
SQL injection vulnerability in demo.php in Typing Pal 1.0 and earlier allows remote attackers to execute arbitrary SQL c
23RIESGO
abrir
ReferênciaVexDay Proof
Web-MeetMe 3.0.3 - 'play.php' Remote File Disclosure
CVE-2007-6215webappsphp
Multiple directory traversal vulnerabilities in play.php in Web-MeetMe 3.0.3 allow remote attackers to read arbitrary fi
23RIESGO
abrir
Referência
CVE-2018-19864
NUUO NVRmini2 Network Video Recorder firmware through 3.9.1 allows remote attackers to execute arbitrary code or cause a
28RIESGO
abrir
Referência
CVE-2022-3038
CVE-2022-3038HIGHbajo ataque
Use after free in Network Service in Google Chrome prior to 105.0.5195.52 allowed a remote attacker to potentially explo
76RIESGO
abrir
Referência
CVE-2017-3061
Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability in the SWF parser
28RIESGO
abrir
anteriorpágina 527 / 747siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.