Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.772exploits catalogados
35.760CVEs con explotación pública
24.695probados en laboratorio
22.492 exploits
Referência
CVE-2016-0051
The WebDAV client in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Window
43RIESGO
abrir
ReferênciaVexDay Proof
Alstrasoft Template Seller Pro 3.25 - Admin Password Change
CVE-2007-2776webappsphp
AlstraSoft Template Seller Pro 3.25 and earlier sends a redirect to the web browser but does not exit when administrativ
23RIESGO
abrir
Referência
CVE-2011-3142
Stack-based buffer overflow in an ActiveX control in KVWebSvr.dll in WellinTech KingView 6.52 and 6.53 allows remote att
35RIESGO
abrir
Referência
CVE-2010-4231
Directory traversal vulnerability in the web-based administration interface on the Camtron CMNC-200 Full HD IP Camera an
43RIESGO
abrir
ReferênciaVexDay Proof
phpBB XS 0.58 - 'functions.php' Remote File Inclusion
CVE-2006-4780webappsphp
PHP remote file inclusion vulnerability in includes/functions.php in phpBB XS 0.58 and earlier allows remote attackers t
23RIESGO
abrir
ReferênciaVexDay Proof
Versant Object Database 7.0.1.3 - Commands Execution
CVE-2008-1319remotewindows
Untrusted search path and argument injection vulnerability in the VersantD service in Versant Object Database 7.0.1.3 an
23RIESGO
abrir
Referência
CVE-2011-4643
Multiple directory traversal vulnerabilities in Splunk 4.x before 4.2.5 allow remote authenticated users to read arbitra
23RIESGO
abrir
Referência
CVE-2014-2880
Open redirect vulnerability in the Oracle Identity Manager component in Oracle Fusion Middleware 11.1.1.5, 11.1.1.7, 11.
23RIESGO
abrir
Referência
CVE-2012-0389
Cross-site scripting (XSS) vulnerability in ForgottenPassword.aspx in MailEnable Professional, Enterprise, and Premium 4
23RIESGO
abrir
Referência
CVE-2015-2184
ZeusCart 4 allows remote attackers to obtain configuration information via a getphpinfo action to admin/, which calls th
23RIESGO
abrir
Referência
CVE-2018-5753
The frontend component in Open-Xchange OX App Suite before 7.6.3-rev31, 7.8.x before 7.8.2-rev31, 7.8.3 before 7.8.3-rev
23RIESGO
abrir
Referência
CVE-2018-5753
The frontend component in Open-Xchange OX App Suite before 7.6.3-rev31, 7.8.x before 7.8.2-rev31, 7.8.3 before 7.8.3-rev
23RIESGO
abrir
Referência
CVE-2018-8527
An information disclosure vulnerability exists in Microsoft SQL Server Management Studio (SSMS) when parsing a malicious
28RIESGO
abrir
ReferênciaVexDay Proof
Cerulean Portal System 0.7b - Remote File Inclusion
CVE-2007-0684webappsphp
PHP remote file inclusion vulnerability in portal.php in Cerulean Portal System 0.7b allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
Star Articles 6.0 - Arbitrary File Upload
CVE-2008-7076webappsphp
Unrestricted file upload vulnerability in user.modify.profile.php in Kalptaru Infotech Ltd. Star Articles 6.0 allows rem
23RIESGO
abrir
ReferênciaVexDay Proof
BBS E-Market - 'postscript.php?p_mode' Remote File Inclusion
CVE-2007-3934webappsphp
PHP remote file inclusion vulnerability in postscript/postscript.php in BBS E-Market allows remote attackers to execute
23RIESGO
abrir
ReferênciaVexDay Proof
HP Compaq Notebooks - ActiveX Remote Code Execution
CVE-2007-6332remotewindows
The HPInfoDLL.HPInfo.1 ActiveX control in HPInfoDLL.dll 1.0, as shipped with HP Info Center (hpinfocenter.exe) 1.0.1.1 i
23RIESGO
abrir
ReferênciaVexDay Proof
asg-sentry 7.0.0 - Multiple Vulnerabilities
CVE-2008-1321dosmultiple
The FxIAList service in ASG-Sentry Network Manager 7.0.0 and earlier does require authentication, which allows remote at
23RIESGO
abrir
ReferênciaVexDay Proof
Fuzzylime CMS 3.01 - 'admindir' Remote File Inclusion
CVE-2008-1405webappsphp
PHP remote file inclusion vulnerability in code/display.php in fuzzylime (cms) 3.01 allows remote attackers to execute a
35RIESGO
abrir
Referência
CVE-2014-5287
A Bash script injection vulnerability exists in Kemp Load Master 7.1-16 and earlier due to a failure to sanitize input i
23RIESGO
abrir
Referência
CVE-2014-0983
Multiple array index errors in programs that are automatically generated by VBox/HostServices/SharedOpenGL/crserverlib/s
38RIESGO
abrir
ReferênciaVexDay Proof
PHP Live Helper 2.0 - 'abs_path' Remote File Inclusion
CVE-2006-4051webappsphp
PHP remote file inclusion vulnerability in global.php in Turnkey Web Tools PHP Live Helper 2.0 and earlier allows remote
23RIESGO
abrir
Referência
CVE-2014-7288
Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allow remote authenticated administrator
23RIESGO
abrir
Referência
CVE-2015-6787
Multiple unspecified vulnerabilities in Google Chrome before 47.0.2526.73 allow attackers to cause a denial of service o
23RIESGO
abrir
Referência
CVE-2015-6787
Multiple unspecified vulnerabilities in Google Chrome before 47.0.2526.73 allow attackers to cause a denial of service o
23RIESGO
abrir
Referência
CVE-2021-43936
Distributed Data Systems WebHM
60RIESGO
abrir
Referência
CVE-2015-6787
Multiple unspecified vulnerabilities in Google Chrome before 47.0.2526.73 allow attackers to cause a denial of service o
23RIESGO
abrir
Referência
CVE-2010-4513
Multiple cross-site scripting (XSS) vulnerabilities in Zimplit CMS 3.0, and possibly earlier, allow remote attackers to
23RIESGO
abrir
Referência
CVE-2015-7571
Unrestricted file upload vulnerability in Yeager CMS 1.2.1 allows remote attackers to execute arbitrary code by uploadin
23RIESGO
abrir
Referência
CVE-2015-7571
Unrestricted file upload vulnerability in Yeager CMS 1.2.1 allows remote attackers to execute arbitrary code by uploadin
23RIESGO
abrir
anteriorpágina 560 / 750siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.