Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.765exploits catalogados
35.760CVEs con explotación pública
24.695probados en laboratorio
22.429 exploits
Referência
CVE-2010-5008
SQL injection vulnerability in pages/contact_list_mail_form.asp in BrightSuite Groupware 5.4 allows remote attackers to
23RIESGO
abrir
Referência
CVE-2010-5009
SQL injection vulnerability in index.php in UTStats Beta 4 and earlier allows remote attackers to execute arbitrary SQL
23RIESGO
abrir
Referência
CVE-2015-1497
radexecd.exe in Persistent Systems Radia Client Automation (RCA) 7.9, 8.1, 9.0, and 9.1 allows remote attackers to execu
60RIESGO
abrir
Referência
CVE-2014-0476
The slapper function in chkrootkit before 0.50 does not properly quote file paths, which allows local users to execute a
38RIESGO
abrir
Referência
CVE-2014-0476
The slapper function in chkrootkit before 0.50 does not properly quote file paths, which allows local users to execute a
38RIESGO
abrir
Referência
CVE-2017-9123
The lqt_frame_duration function in lqt_quicktime.c in libquicktime 1.2.4 allows remote attackers to cause a denial of se
23RIESGO
abrir
Referência
CVE-2012-5897
The (1) SimpleTree and (2) ReportTree classes in the ARDoc ActiveX control (ARDoc.dll) in Quest InTrust 10.4.0.853 and e
23RIESGO
abrir
Referência
CVE-2025-34151
Shenzhen Aitemi M300 Wi-Fi Repeater PPPoE Password Command Injection
48RIESGO
abrir
Referência
CVE-2018-1563
IBM Sterling B2B Integrator Standard Edition (IBM Sterling File Gateway 2.2.0 through 2.2.6) is vulnerable to cross-site
33RIESGO
abrir
Referência
CVE-2023-28489
A vulnerability has been identified in CP-8031 MASTER MODULE (All versions < CPCI85 V05), CP-8050 MASTER MODULE (All ver
48RIESGO
abrir
Referência
CVE-2011-10019
Spreecommerce < 0.60.2 Search Parameter RCE
63RIESGO
abrir
Referência
CVE-2011-10019
Spreecommerce < 0.60.2 Search Parameter RCE
63RIESGO
abrir
Referência
CVE-2012-2913
Multiple cross-site scripting (XSS) vulnerabilities in the Leaflet plugin 0.0.1 for WordPress allow remote attackers to
23RIESGO
abrir
ReferênciaVexDay Proof
phpMyProfiler 0.9.6 - Remote File Inclusion
CVE-2006-5186webappsphp
PHP remote file inclusion vulnerability in functions.php in phpMyProfiler 0.9.6 and earlier, when register_globals is en
23RIESGO
abrir
ReferênciaVexDay Proof
PHP-Stats 0.1.9.1b - 'PHP-stats-options.php' Command Execution
CVE-2006-7173webappsphp
Direct static code injection vulnerability in admin.php in PHP-Stats 0.1.9.1b and earlier allows remote attackers to exe
23RIESGO
abrir
ReferênciaVexDay Proof
CrystalPlayer 1.98 - '.mls' Local Buffer Overflow
CVE-2007-4032localwindows
Buffer overflow in CrystalPlayer Pro 1.98 allows user-assisted remote attackers to execute arbitrary code via a long str
23RIESGO
abrir
ReferênciaVexDay Proof
Flatnuke 3 - Remote Cookie Manipulation / Privilege Escalation
CVE-2007-5772webappsphp
Direct static code injection vulnerability in the download module in Flatnuke 3 allows remote authenticated administrato
23RIESGO
abrir
Referência
CVE-2010-5029
SQL injection vulnerability in index.php in Ecomat CMS 5.0 allows remote attackers to execute arbitrary SQL commands via
23RIESGO
abrir
Referência
CVE-2018-4083
An issue was discovered in certain Apple products. macOS before 10.13.3 is affected. The issue involves the "Touch Bar S
23RIESGO
abrir
Referência
CVE-2020-18723
Stored cross-site scripting (XSS) in file attachment field in MDaemon webmail 19.5.5 allows an attacker to execute code
23RIESGO
abrir
Referência
CVE-2016-0171
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
23RIESGO
abrir
Referência
CVE-2016-0171
The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1,
23RIESGO
abrir
Referência
CVE-2014-5093
Status2k does not remove the install directory allowing credential reset.
23RIESGO
abrir
Referência
CVE-2010-1271
SQL injection vulnerability in showplugs.php in smartplugs 1.3 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
Referência
CVE-2022-26180
qdPM 9.2 allows Cross-Site Request Forgery (CSRF) via the index.php/myAccount/update URI.
23RIESGO
abrir
Referência
CVE-2015-2512
The Adobe Type Manager Library in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Window
23RIESGO
abrir
ReferênciaVexDay Proof
Internet PhotoShow 1.3 - 'page' Remote File Inclusion
CVE-2006-1919webappsphp
PHP remote file inclusion vulnerability in index.php in Internet Photoshow 1.3 allows remote attackers to execute arbitr
23RIESGO
abrir
Referência
CVE-2017-11331
The wav_open function in oggenc/audio.c in Xiph.Org vorbis-tools 1.4.0 allows remote attackers to cause a denial of serv
23RIESGO
abrir
Referência
CVE-2019-1345
An information disclosure vulnerability exists when the Windows kernel improperly handles objects in memory, aka 'Window
23RIESGO
abrir
Referência
CVE-2010-1271
SQL injection vulnerability in showplugs.php in smartplugs 1.3 allows remote attackers to execute arbitrary SQL commands
23RIESGO
abrir
anteriorpágina 547 / 748siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.