Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.765exploits catalogados
35.760CVEs con explotación pública
24.695probados en laboratorio
22.429 exploits
Referência
CVE-2016-3963
Siemens SCALANCE S613 allows remote attackers to cause a denial of service (web-server outage) via traffic to TCP port 4
23RIESGO
abrir
ReferênciaVexDay Proof
asg-sentry 7.0.0 - Multiple Vulnerabilities
CVE-2008-1322dosmultiple
The File Check Utility (fcheck.exe) in ASG-Sentry Network Manager 7.0.0 and earlier allows remote attackers to cause a d
23RIESGO
abrir
Referência
CVE-2016-6896
Directory traversal vulnerability in the wp_ajax_update_plugin function in wp-admin/includes/ajax-actions.php in WordPre
35RIESGO
abrir
Referência
CVE-2010-4617
Directory traversal vulnerability in the JotLoader (com_jotloader) component 2.2.1 for Joomla! allows remote attackers t
38RIESGO
abrir
Referência
CVE-2016-10034
The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.
35RIESGO
abrir
Referência
CVE-2010-4617
Directory traversal vulnerability in the JotLoader (com_jotloader) component 2.2.1 for Joomla! allows remote attackers t
38RIESGO
abrir
Referência
CVE-2019-25732
PHP EI-Tube Script 3 SQL Injection via search parameter
41RIESGO
abrir
Referência
CVE-2026-6563
H3C Magic B1 aspForm SetAPWifiorLedInfoById buffer overflow
41RIESGO
abrir
Referência
CVE-2016-5063
The RSCD agent in BMC Server Automation before 8.6 SP1 Patch 2 and 8.7 before Patch 3 on Windows might allow remote atta
23RIESGO
abrir
Referência
CVE-2018-7317
Backup Download exists in the Proclaim 9.1.1 component for Joomla! via a direct request for a .sql file under backup/.
23RIESGO
abrir
Referência
CVE-2010-3460
Directory traversal vulnerability in the HTTP interface in AXIGEN Mail Server 7.4.1 for Windows allows remote attackers
23RIESGO
abrir
Referência
CVE-2009-2917
Stack-based buffer overflow in ImTOO MPEG Encoder 3.1.53 allows remote attackers to cause a denial of service (crash) or
23RIESGO
abrir
Referência
CVE-2022-25359
On ICL ScadaFlex II SCADA Controller SC-1 and SC-2 1.03.07 devices, unauthenticated remote attackers can overwrite, dele
35RIESGO
abrir
ReferênciaVexDay Proof
PHPStore Real Estate - Arbitrary File Upload
CVE-2008-6930webappsphp
Unrestricted file upload vulnerability in PHPStore Real Estate allows remote authenticated users to execute arbitrary co
23RIESGO
abrir
ReferênciaVexDay Proof
ashNews 0.83 - 'pathtoashnews' Remote File Inclusion
CVE-2003-1292webappsphp
PHP remote file include vulnerability in Derek Ashauer ashNews 0.83 allows remote attackers to include and execute arbit
23RIESGO
abrir
Referência
CVE-2019-12252
In Zoho ManageEngine ServiceDesk Plus through 10.5, users with the lowest privileges (guest) can view an arbitrary post
23RIESGO
abrir
Referência
CVE-2019-25487
SAPIDO RB-1732 V2.0.43 Remote Command Execution via formSysCmd
48RIESGO
abrir
Referência
CVE-2017-11398
A session hijacking via log disclosure vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.2 an
23RIESGO
abrir
ReferênciaVexDay Proof
Joomla! Component LMO 1.0b2 - Remote File Inclusion
CVE-2006-3970webappsphp
PHP remote file inclusion vulnerability in lmo.php in the LMO Component (com_lmo) 1.0b2 and earlier for Joomla! allows r
23RIESGO
abrir
Referência
CVE-2010-4279
The default configuration of Pandora FMS 3.1 and earlier specifies an empty string for the loginhash_pwd field, which al
50RIESGO
abrir
Referência
CVE-2010-4281
Incomplete blacklist vulnerability in the safe_url_extraclean function in ajax.php in Pandora FMS before 3.1.1 allows re
23RIESGO
abrir
ReferênciaVexDay Proof
UNAK-CMS 1.5 - 'dirroot' Remote File Inclusion
CVE-2006-4890webappsphp
Multiple PHP remote file inclusion vulnerabilities in UNAK-CMS 1.5 and earlier allow remote attackers to execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
CWB PRO 1.5 - 'INCLUDE_PATH' Remote File Inclusion
CVE-2007-1809webappsphp
Multiple PHP remote file inclusion vulnerabilities in GraFX Company WebSite Builder (CWB) PRO 1.5 allow remote attackers
23RIESGO
abrir
ReferênciaVexDay Proof
XnView 1.92.1 - 'FontName' Slideshow Buffer Overflow
CVE-2008-0069localwindows
Stack-based buffer overflow in XnView 1.92 and 1.92.1 allows user-assisted remote attackers to execute arbitrary code vi
23RIESGO
abrir
ReferênciaVexDay Proof
eXV2 Module MyAnnonces - 'lid' SQL Injection
CVE-2008-1406webappsphp
SQL injection vulnerability in annonces-p-f.php in the MyAnnonces 1.8 module for eXV2 allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
eXV2 Module WebChat 1.60 - 'roomid' SQL Injection
CVE-2008-1407webappsphp
SQL injection vulnerability in index.php in the WebChat 1.60 module for eXV2 allows remote attackers to execute arbitrar
23RIESGO
abrir
Referência
CVE-2015-4038
The WP Membership plugin 1.2.3 for WordPress allows remote authenticated users to gain administrator privileges via an i
23RIESGO
abrir
Referência
CVE-2015-1362
Buffer overflow in the Customize 35mm tab in Two Pilots Exif Pilot 4.7.2 allows remote attackers to execute arbitrary co
23RIESGO
abrir
Referência
CVE-2014-0094
The ParametersInterceptor in Apache Struts before 2.3.16.2 allows remote attackers to "manipulate" the ClassLoader via t
60RIESGO
abrir
ReferênciaVexDay Proof
Eznet 3.5.0 - Remote Stack Overflow / Denial of Service
CVE-2003-1339remotewindows
Stack-based buffer overflow in eZnet.exe, as used in eZ (a) eZphotoshare, (b) eZmeeting, (c) eZnetwork, and (d) eZshare
35RIESGO
abrir
anteriorpágina 546 / 748siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.