Explotación pública

Catálogo de exploits

Todo exploit público que catalogamos, en un solo índice. Busca por CVE, nombre del exploit o tecnología — y mira, al lado, lo que la falla realmente vale: severidad, probabilidad de explotación y si ya está bajo ataque.

77.772exploits catalogados
35.760CVEs con explotación pública
24.695probados en laboratorio
22.523 exploits
Referência
CVE-2025-14708
Shiguangwu sgwbox N3 WIREDCFGGET http_eshell_server buffer overflow
48RIESGO
abrir
Referência
CVE-2018-4193
An issue was discovered in certain Apple products. macOS before 10.13.5 is affected. The issue involves the "Windows Ser
23RIESGO
abrir
Referência
CVE-2017-8869
Buffer overflow in MediaCoder 0.8.48.5888 allows remote attackers to execute arbitrary code via a crafted .m3u file.
43RIESGO
abrir
ReferênciaVexDay Proof
PHPFK 7.03 - 'page_bottom.php' Local File Inclusion
CVE-2009-2112webappsphp
Directory traversal vulnerability in include/page_bottom.php in phpFK 7.03 allows remote attackers to include and execut
23RIESGO
abrir
ReferênciaVexDay Proof
e107 Plugin My_Gallery 2.3 - Arbitrary File Download
CVE-2008-1702webappsphp
Absolute path traversal vulnerability in dload.php in the my_gallery 2.3 plugin for e107 allows remote attackers to obta
23RIESGO
abrir
Referência
CVE-2018-10655
DLPnpAuditor.exe in DeviceLock Plug and Play Auditor (freeware) 5.72 has a Unicode Buffer Overflow (SEH).
28RIESGO
abrir
Referência
CVE-2018-10655
DLPnpAuditor.exe in DeviceLock Plug and Play Auditor (freeware) 5.72 has a Unicode Buffer Overflow (SEH).
28RIESGO
abrir
Referência
CVE-2010-1046
Multiple SQL injection vulnerabilities in index.php in Rostermain 1.1 and earlier allow remote attackers to execute arbi
23RIESGO
abrir
Referência
CVE-2009-3484
Stack-based buffer overflow in Core FTP 2.1 build 1612 allows user-assisted remote attackers to execute arbitrary code v
23RIESGO
abrir
Referência
CVE-2014-0995
The Standalone Enqueue Server in SAP Netweaver 7.20, 7.01, and earlier allows remote attackers to cause a denial of serv
28RIESGO
abrir
Referência
CVE-2012-4864
Oreans WinLicense 2.1.8.0 allows remote attackers to cause a denial of service (memory corruption and crash) and possibl
23RIESGO
abrir
Referência
CVE-2012-4864
Oreans WinLicense 2.1.8.0 allows remote attackers to cause a denial of service (memory corruption and crash) and possibl
23RIESGO
abrir
Referência
CVE-2015-7250
Absolute path traversal vulnerability in cgi-bin/webproc on ZTE ZXHN H108N R1A devices before ZTE.bhs.ZXHNH108NR1A.k_PE
28RIESGO
abrir
Referência
CVE-2012-1933
Multiple PHP remote file inclusion vulnerabilities in Newscoop 3.5.x before 3.5.5 and 4 before RC4, when register_global
23RIESGO
abrir
Referência
CVE-2018-8729
Multiple cross-site scripting (XSS) vulnerabilities in the Activity Log plugin before 2.4.1 for WordPress allow remote a
23RIESGO
abrir
ReferênciaVexDay Proof
Quake 3 Engine Client (Windows x86) - CS_ITEms Remote Overflow
CVE-2006-3401doswindows_x86
Stack-based buffer overflow in Quake 3 Engine as used by Quake 3: Arena 1.32b and 1.32c allows remote attackers to cause
23RIESGO
abrir
Referência
CVE-2013-4094
The Key Management feature in the SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.
23RIESGO
abrir
ReferênciaVexDay Proof
Activist Mobilization Platform (AMP) 3.2 - Remote File Inclusion
CVE-2007-1571webappsphp
PHP remote file inclusion vulnerability in includes/base.php in Radical Designs Activist Mobilization Platform (AMP) 3.2
23RIESGO
abrir
ReferênciaVexDay Proof
Scribe 0.2 - PHP Remote Code Execution
CVE-2007-5822webappsphp
Direct static code injection vulnerability in forum.php in Ben Ng Scribe 0.2 and earlier allows remote attackers to inje
23RIESGO
abrir
ReferênciaVexDay Proof
Apple Mac OSX xnu 1228.3.13 - IPv6-ipcomp Remote kernel Denial of Service (PoC)
CVE-2008-0177dosmultiple
The ipcomp6_input function in sys/netinet6/ipcomp_input.c in the KAME project before 20071201 does not properly check th
28RIESGO
abrir
Referência
CVE-2015-4665
Cross-site scripting (XSS) vulnerability in ajax_cmd.php in Xceedium Xsuite 2.4.4.1 and earlier allows remote attackers
23RIESGO
abrir
Referência
CVE-2015-4665
Cross-site scripting (XSS) vulnerability in ajax_cmd.php in Xceedium Xsuite 2.4.4.1 and earlier allows remote attackers
23RIESGO
abrir
Referência
CVE-2018-5359
The server in Flexense SysGauge 3.6.18 operating on port 9221 can be exploited remotely with the attacker gaining system
23RIESGO
abrir
Referência
CVE-2018-5359
The server in Flexense SysGauge 3.6.18 operating on port 9221 can be exploited remotely with the attacker gaining system
23RIESGO
abrir
Referência
CVE-2009-2564
NOS Microsystems getPlus Download Manager, as used in Adobe Reader 1.6.2.36 and possibly other versions, Corel getPlus D
23RIESGO
abrir
ReferênciaVexDay Proof
Firefly Media Server 0.2.4 - Remote Denial of Service
CVE-2007-5824doslinux
webserver.c in mt-dappd in Firefly Media Server 0.2.4 and earlier allows remote attackers to cause a denial of service (
23RIESGO
abrir
Referência
CVE-2013-4091
The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 does not have an off autocom
23RIESGO
abrir
Referência
CVE-2007-4734
Buffer overflow in Ots Labs OTSTurntables 1.00 allows user-assisted remote attackers to execute arbitrary code via a lon
23RIESGO
abrir
ReferênciaVexDay Proof
MW6 Barcode - ActiveX 'Barcode.dll' Remote Heap Overflow (PoC)
CVE-2009-0298doswindows
Heap-based buffer overflow in MW6 Technologies Barcode ActiveX control (Barcode.MW6Barcode.1, Barcode.dll) 3.0.0.1 allow
23RIESGO
abrir
Referência
CVE-2025-15500
Sangfor Operation and Maintenance Management System HTTP POST Request getHis os command injection
48RIESGO
abrir
anteriorpágina 568 / 751siguiente

Indexamos solo el enlace público a la prueba de concepto — nunca alojamos ni redistribuimos código de explotación. Fuentes: PoC-in-GitHub, Exploit-DB, Nuclei, Metasploit y VulnCheck XDB. La existencia de PoC pública no significa que la falla sea explotable en tu entorno.