Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.772exploits catalogados
35.760CVEs con explotación pública
24.695probados en laboratorio
22.492 exploits
Referência
CVE-2012-2919
Directory traversal vulnerability in Upload/engine.php in Chevereto 1.9.1 allows remote attackers to determine the exist
23RIESGO
abrir
Referência
CVE-2010-0759
Directory traversal vulnerability in plugins/system/cdscriptegrator/libraries/highslide/js/jsloader.php in the Core Desi
43RIESGO
abrir
Referência
CVE-2019-6192
A potential vulnerability has been reported in Lenovo Power Management Driver versions prior to 1.67.17.48 leading to a
33RIESGO
abrir
Referência
CVE-2018-7705
Directory traversal vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote authenticated users to read e-mai
23RIESGO
abrir
Referência
CVE-2022-39195
A cross-site scripting (XSS) vulnerability in the LISTSERV 17 web interface allows remote attackers to inject arbitrary
48RIESGO
abrir
Referência
CVE-2013-1636
Cross-site scripting (XSS) vulnerability in open-flash-chart.swf in Open Flash Chart (aka Open-Flash Chart), as used in
23RIESGO
abrir
Referência
CVE-2013-1636
Cross-site scripting (XSS) vulnerability in open-flash-chart.swf in Open Flash Chart (aka Open-Flash Chart), as used in
23RIESGO
abrir
ReferênciaVexDay Proof
WebSVN 2.0 - Cross-Site Scripting / File Handling / Code Execution
CVE-2008-5919webappsphp
Directory traversal vulnerability in rss.php in WebSVN 2.0 and earlier, when magic_quotes_gpc is disabled, allows remote
23RIESGO
abrir
Referência
CVE-2017-7043
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RIESGO
abrir
Referência
CVE-2017-7039
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RIESGO
abrir
Referência
CVE-2017-7040
An issue was discovered in certain Apple products. iOS before 10.3.3 is affected. Safari before 10.1.2 is affected. iClo
23RIESGO
abrir
ReferênciaVexDay Proof
Flexcustomer 0.0.6 - Admin Authentication Bypass / Possible PHP Code Writing
CVE-2008-6761webappsphp
Static code injection vulnerability in admin/install.php in Flexcustomer 0.0.6 might allow remote attackers to inject ar
23RIESGO
abrir
Referência
CVE-2018-1185
An issue was discovered in EMC RecoverPoint for Virtual Machines versions prior to 5.1.1, EMC RecoverPoint version 5.1.0
23RIESGO
abrir
ReferênciaVexDay Proof
Envolution 1.1.0 - 'PNSVlang' Remote Code Execution
CVE-2006-6445webappsphp
Directory traversal vulnerability in error.php in Envolution 1.1.0 and earlier allows remote attackers to include and ex
23RIESGO
abrir
ReferênciaVexDay Proof
E-GADS! 2.2.6 - 'common.php?locale' Remote File Inclusion
CVE-2007-2521webappsphp
PHP remote file inclusion vulnerability in common.php in E-GADS! before 2.2.7 allows remote attackers to execute arbitra
23RIESGO
abrir
ReferênciaVexDay Proof
samPHPweb 4.2.2 - 'db.php' Remote File Inclusion
CVE-2008-0143webappsphp
PHP remote file inclusion vulnerability in common/db.php in samPHPweb, possibly 4.2.2 and others, as provided with SAM B
23RIESGO
abrir
Referência
CVE-2010-5033
SQL injection vulnerability in ProductList.cfm in Fusebox 5.5.1 allows remote attackers to execute arbitrary SQL command
23RIESGO
abrir
ReferênciaVexDay Proof
PHP-Fusion 7.0.2 - Blind SQL Injection
CVE-2008-1918webappsphp
SQL injection vulnerability in submit.php in PHP-Fusion 6.01.14 and 6.00.307, when magic_quotes_gpc is disabled and the
23RIESGO
abrir
Referência
CVE-2010-5034
SQL injection vulnerability in viewhistorydetail.php in iScripts EasyBiller 1.1 allows remote attackers to execute arbit
23RIESGO
abrir
Referência
CVE-2020-25453
An issue was discovered in BlackCat CMS before 1.4. There is a CSRF vulnerability (bypass csrf_token) that allows remote
23RIESGO
abrir
ReferênciaVexDay Proof
LightNEasy 1.2 - no database Remote Hash Retrieve
CVE-2008-6537webappsphp
LightNEasy/lightneasy.php in LightNEasy No database version 1.2 allows remote attackers to obtain the hash of the admini
23RIESGO
abrir
Referência
CVE-2026-33017
CVE-2026-33017CRITICALbajo ataque
Langflow has Unauthenticated Remote Code Execution via Public Flow Build Endpoint
100RIESGO
abrir
Referência
CVE-2012-4865
Buffer overflow in Oreans Themida 2.1.8.0 allows remote attackers to execute arbitrary code via a crafted .TMD file.
23RIESGO
abrir
Referência
CVE-2019-3859
An out of bounds read flaw was discovered in libssh2 before 1.8.1 in the _libssh2_packet_require and _libssh2_packet_req
48RIESGO
abrir
Referência
CVE-2025-14558
Remote code execution via ND6 Router Advertisements
56RIESGO
abrir
Referência
CVE-2018-10018
The GDASPAMLib.AntiSpam ActiveX control ASK\GDASpam.dll in G DATA Total Security 25.4.0.3 has a buffer overflow via a lo
23RIESGO
abrir
Referência
CVE-2014-10037
Directory traversal vulnerability in DomPHP 0.83 and earlier allows remote attackers to have unspecified impact via a ..
43RIESGO
abrir
ReferênciaVexDay Proof
phosheezy 2.0 - Remote Command Execution
CVE-2009-0250webappsphp
Ryneezy phoSheezy 0.2 stores sensitive information under the web root with insufficient access control, which allows rem
23RIESGO
abrir
Referência
CVE-2017-2469
An issue was discovered in certain Apple products. iOS before 10.3 is affected. Safari before 10.1 is affected. tvOS bef
23RIESGO
abrir
Referência
CVE-2021-22911
A improper input sanitization vulnerability exists in Rocket.Chat server 3.11, 3.12 & 3.13 that could lead to unauthenti
60RIESGO
abrir
anteriorpágina 556 / 750siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.